<?xml version='1.0' encoding='UTF-8'?>
<nvd xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns="http://nvd.nist.gov/feeds/cve/1.2" nvd_xml_version="1.2" xsi:schemaLocation="http://nvd.nist.gov/feeds/cve/1.2 http://nvd.nist.gov/schema/nvdcve.xsd" pub_date="2012-02-14">
  <entry type="CVE" severity="High" seq="2009-0001" published="2009-01-21" name="CVE-2009-0001" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Heap-based buffer overflow in Apple QuickTime before 7.6 allows remote attackers to cause a denial of service (application termination) and possibly execute arbitrary code via a crafted RTSP URL.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-022A.html" source="CERT">TA09-022A</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2009/Jan/msg00000.html" source="APPLE" patch="1" adv="1">APPLE-SA-2009-01-21</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/48154" source="XF">quicktime-rtspurl-bo(48154)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0212" source="VUPEN">ADV-2009-0212</ref>
      <ref url="http://www.securityfocus.com/bid/33385" source="BID">33385</ref>
      <ref url="http://support.apple.com/kb/HT3403" source="CONFIRM">http://support.apple.com/kb/HT3403</ref>
      <ref url="http://secunia.com/advisories/33632" source="SECUNIA">33632</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6135" source="OVAL">oval:org.mitre.oval:def:6135</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="quicktime">
        <vers num="3" />
        <vers num="4.1.2" />
        <vers num="5.0" />
        <vers num="5.0.1" />
        <vers num="5.0.2" />
        <vers num="6.0" />
        <vers num="6.1" />
        <vers num="6.5" />
        <vers num="6.5.1" />
        <vers num="6.5.2" />
        <vers num="7.0" />
        <vers num="7.0.1" />
        <vers num="7.0.2" />
        <vers num="7.0.3" />
        <vers num="7.0.4" />
        <vers num="7.0.8" />
        <vers num="7.1" />
        <vers num="7.1.1" />
        <vers num="7.1.2" />
        <vers num="7.1.3" />
        <vers num="7.1.4" />
        <vers num="7.1.5" />
        <vers num="7.1.6" />
        <vers num="7.2" />
        <vers num="7.3" />
        <vers num="7.3.1" />
        <vers num="7.3.1.70" />
        <vers num="7.4" />
        <vers num="7.4.1" />
        <vers num="7.4.4" />
        <vers num="7.4.5" />
        <vers num="7.5" />
        <vers prev="1" num="7.5.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0002" published="2009-01-21" name="CVE-2009-0002" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Heap-based buffer overflow in Apple QuickTime before 7.6 allows remote attackers to cause a denial of service (application termination) and possibly execute arbitrary code via a QTVR movie file with crafted THKD atoms.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-022A.html" source="CERT">TA09-022A</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2009/Jan/msg00000.html" source="APPLE" patch="1" adv="1">APPLE-SA-2009-01-21</ref>
      <ref url="http://www.zerodayinitiative.com/advisories/ZDI-09-005/" source="MISC">http://www.zerodayinitiative.com/advisories/ZDI-09-005/</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0212" source="VUPEN">ADV-2009-0212</ref>
      <ref url="http://www.securityfocus.com/bid/33384" source="BID">33384</ref>
      <ref url="http://support.apple.com/kb/HT3403" source="CONFIRM">http://support.apple.com/kb/HT3403</ref>
      <ref url="http://secunia.com/advisories/33632" source="SECUNIA">33632</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5646" source="OVAL">oval:org.mitre.oval:def:5646</ref>
      <ref url="http://osvdb.org/51525" source="OSVDB">51525</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2009-01/0210.html" source="BUGTRAQ">20090121 ZDI-09-005: Apple QuickTime VR Track Header Atom Heap Corruption Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="quicktime">
        <vers num="3" />
        <vers num="4.1.2" />
        <vers num="5.0" />
        <vers num="5.0.1" />
        <vers num="5.0.2" />
        <vers num="6.0" />
        <vers num="6.1" />
        <vers num="6.5" />
        <vers num="6.5.1" />
        <vers num="6.5.2" />
        <vers num="7.0" />
        <vers num="7.0.1" />
        <vers num="7.0.2" />
        <vers num="7.0.3" />
        <vers num="7.0.4" />
        <vers num="7.0.8" />
        <vers num="7.1" />
        <vers num="7.1.1" />
        <vers num="7.1.2" />
        <vers num="7.1.3" />
        <vers num="7.1.4" />
        <vers num="7.1.5" />
        <vers num="7.1.6" />
        <vers num="7.2" />
        <vers num="7.3" />
        <vers num="7.3.1" />
        <vers num="7.3.1.70" />
        <vers num="7.4" />
        <vers num="7.4.1" />
        <vers num="7.4.4" />
        <vers num="7.4.5" />
        <vers num="7.5" />
        <vers prev="1" num="7.5.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0003" published="2009-01-21" name="CVE-2009-0003" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Heap-based buffer overflow in Apple QuickTime before 7.6 allows remote attackers to cause a denial of service (application termination) and execute arbitrary code via an AVI movie file with an invalid nBlockAlign value in the _WAVEFORMATEX structure.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-022A.html" source="CERT">TA09-022A</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2009/Jan/msg00000.html" source="APPLE" patch="1" adv="1">APPLE-SA-2009-01-21</ref>
      <ref url="http://www.zerodayinitiative.com/advisories/ZDI-09-006/" source="MISC">http://www.zerodayinitiative.com/advisories/ZDI-09-006/</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0212" source="VUPEN" adv="1">ADV-2009-0212</ref>
      <ref url="http://www.securityfocus.com/bid/33387" source="BID">33387</ref>
      <ref url="http://support.apple.com/kb/HT3403" source="CONFIRM">http://support.apple.com/kb/HT3403</ref>
      <ref url="http://secunia.com/advisories/33632" source="SECUNIA" adv="1">33632</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6218" source="OVAL">oval:org.mitre.oval:def:6218</ref>
      <ref url="http://osvdb.org/51526" source="OSVDB">51526</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="quicktime">
        <vers num="3" />
        <vers num="4.1.2" />
        <vers num="5.0" />
        <vers num="5.0.1" />
        <vers num="5.0.2" />
        <vers num="6.0" />
        <vers num="6.1" />
        <vers num="6.5" />
        <vers num="6.5.1" />
        <vers num="6.5.2" />
        <vers num="7.0" />
        <vers num="7.0.1" />
        <vers num="7.0.2" />
        <vers num="7.0.3" />
        <vers num="7.0.4" />
        <vers num="7.0.8" />
        <vers num="7.1" />
        <vers num="7.1.1" />
        <vers num="7.1.2" />
        <vers num="7.1.3" />
        <vers num="7.1.4" />
        <vers num="7.1.5" />
        <vers num="7.1.6" />
        <vers num="7.2" />
        <vers num="7.3" />
        <vers num="7.3.1" />
        <vers num="7.3.1.70" />
        <vers num="7.4" />
        <vers num="7.4.1" />
        <vers num="7.4.4" />
        <vers num="7.4.5" />
        <vers num="7.5" />
        <vers prev="1" num="7.5.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0004" published="2009-01-21" name="CVE-2009-0004" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Buffer overflow in Apple QuickTime before 7.6 allows remote attackers to cause a denial of service (application termination) and possibly execute arbitrary code via a crafted MP3 audio file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-022A.html" source="CERT" patch="1">TA09-022A</ref>
      <ref url="http://support.apple.com/kb/HT3403" source="CONFIRM" patch="1" adv="1">http://support.apple.com/kb/HT3403</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2009/Jan/msg00000.html" source="APPLE" patch="1" adv="1">APPLE-SA-2009-01-21</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/48157" source="XF">quicktime-mpeg2-bo(48157)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0212" source="VUPEN">ADV-2009-0212</ref>
      <ref url="http://secunia.com/advisories/33632" source="SECUNIA" adv="1">33632</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6211" source="OVAL">oval:org.mitre.oval:def:6211</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="quicktime">
        <vers num="3" />
        <vers num="4.1.2" />
        <vers num="5.0" />
        <vers num="5.0.1" />
        <vers num="5.0.2" />
        <vers num="6.0" />
        <vers num="6.1" />
        <vers num="6.5" />
        <vers num="6.5.1" />
        <vers num="6.5.2" />
        <vers num="7.0" />
        <vers num="7.0.1" />
        <vers num="7.0.2" />
        <vers num="7.0.3" />
        <vers num="7.0.4" />
        <vers num="7.0.8" />
        <vers num="7.1" />
        <vers num="7.1.1" />
        <vers num="7.1.2" />
        <vers num="7.1.3" />
        <vers num="7.1.4" />
        <vers num="7.1.5" />
        <vers num="7.1.6" />
        <vers num="7.2" />
        <vers num="7.3" />
        <vers num="7.3.1" />
        <vers num="7.3.1.70" />
        <vers num="7.4" />
        <vers num="7.4.1" />
        <vers num="7.4.4" />
        <vers num="7.4.5" />
        <vers num="7.5" />
        <vers prev="1" num="7.5.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0005" published="2009-01-21" name="CVE-2009-0005" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Unspecified vulnerability in Apple QuickTime before 7.6 allows remote attackers to cause a denial of service (application termination) and possibly execute arbitrary code via a crafted H.263 encoded movie file that triggers memory corruption.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-022A.html" source="CERT">TA09-022A</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2009/Jan/msg00000.html" source="APPLE" patch="1" adv="1">APPLE-SA-2009-01-21</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/48158" source="XF">quicktime-h263-movie-code-execution(48158)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0212" source="VUPEN">ADV-2009-0212</ref>
      <ref url="http://www.securityfocus.com/bid/33386" source="BID">33386</ref>
      <ref url="http://support.apple.com/kb/HT3403" source="CONFIRM">http://support.apple.com/kb/HT3403</ref>
      <ref url="http://secunia.com/advisories/33632" source="SECUNIA">33632</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6187" source="OVAL">oval:org.mitre.oval:def:6187</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="quicktime">
        <vers num="3" />
        <vers num="4.1.2" />
        <vers num="5.0" />
        <vers num="5.0.1" />
        <vers num="5.0.2" />
        <vers num="6.0" />
        <vers num="6.1" />
        <vers num="6.5" />
        <vers num="6.5.1" />
        <vers num="6.5.2" />
        <vers num="7.0" />
        <vers num="7.0.1" />
        <vers num="7.0.2" />
        <vers num="7.0.3" />
        <vers num="7.0.4" />
        <vers num="7.0.8" />
        <vers num="7.1" />
        <vers num="7.1.1" />
        <vers num="7.1.2" />
        <vers num="7.1.3" />
        <vers num="7.1.4" />
        <vers num="7.1.5" />
        <vers num="7.1.6" />
        <vers num="7.2" />
        <vers num="7.3" />
        <vers num="7.3.1" />
        <vers num="7.3.1.70" />
        <vers num="7.4" />
        <vers num="7.4.1" />
        <vers num="7.4.4" />
        <vers num="7.4.5" />
        <vers num="7.5" />
        <vers prev="1" num="7.5.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0006" published="2009-01-21" name="CVE-2009-0006" modified="2011-10-11" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Integer signedness error in Apple QuickTime before 7.6 allows remote attackers to cause a denial of service (application termination) and possibly execute arbitrary code via a Cinepak encoded movie file with a crafted MDAT atom that triggers a heap-based buffer overflow.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-022A.html" source="CERT">TA09-022A</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2009/Jan/msg00000.html" source="APPLE" patch="1" adv="1">APPLE-SA-2009-01-21</ref>
      <ref url="http://www.zerodayinitiative.com/advisories/ZDI-09-007/" source="MISC">http://www.zerodayinitiative.com/advisories/ZDI-09-007/</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0212" source="VUPEN" adv="1">ADV-2009-0212</ref>
      <ref url="http://www.securityfocus.com/bid/33388" source="BID">33388</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/500391/100/0/threaded" source="BUGTRAQ">20090124 Re: ZDI-09-007: Apple QuickTime Cinepak Codec MDAT Heap Corruption Vulnerability</ref>
      <ref url="http://support.apple.com/kb/HT3403" source="CONFIRM">http://support.apple.com/kb/HT3403</ref>
      <ref url="http://secunia.com/advisories/33632" source="SECUNIA" adv="1">33632</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6153" source="OVAL">oval:org.mitre.oval:def:6153</ref>
      <ref url="http://osvdb.org/51529" source="OSVDB">51529</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2009-01/0215.html" source="BUGTRAQ">20090121 ZDI-09-007: Apple QuickTime Cinepak Codec MDAT Heap Corruption Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="quicktime">
        <vers num="3" />
        <vers num="4.1.2" />
        <vers num="5.0" />
        <vers num="5.0.1" />
        <vers num="5.0.2" />
        <vers num="6.0" />
        <vers num="6.1" />
        <vers num="6.5" />
        <vers num="6.5.1" />
        <vers num="6.5.2" />
        <vers num="7.0" />
        <vers num="7.0.1" />
        <vers num="7.0.2" />
        <vers num="7.0.3" />
        <vers num="7.0.4" />
        <vers num="7.0.8" />
        <vers num="7.1" />
        <vers num="7.1.1" />
        <vers num="7.1.2" />
        <vers num="7.1.3" />
        <vers num="7.1.4" />
        <vers num="7.1.5" />
        <vers num="7.1.6" />
        <vers num="7.2" />
        <vers num="7.3" />
        <vers num="7.3.1" />
        <vers num="7.3.1.70" />
        <vers num="7.4" />
        <vers num="7.4.1" />
        <vers num="7.4.4" />
        <vers num="7.4.5" />
        <vers num="7.5" />
        <vers prev="1" num="7.5.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0007" published="2009-01-21" name="CVE-2009-0007" modified="2011-10-18" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Heap-based buffer overflow in Apple QuickTime before 7.6 allows remote attackers to cause a denial of service (application termination) and possibly execute arbitrary code via a QuickTime movie file containing invalid image width data in JPEG atoms within STSD atoms.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-022A.html" source="CERT">TA09-022A</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2009/Jan/msg00000.html" source="APPLE" patch="1" adv="1">APPLE-SA-2009-01-21</ref>
      <ref url="http://www.zerodayinitiative.com/advisories/ZDI-09-008/" source="MISC">http://www.zerodayinitiative.com/advisories/ZDI-09-008/</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0212" source="VUPEN" adv="1">ADV-2009-0212</ref>
      <ref url="http://www.securityfocus.com/bid/33390" source="BID">33390</ref>
      <ref url="http://support.apple.com/kb/HT3403" source="CONFIRM" adv="1">http://support.apple.com/kb/HT3403</ref>
      <ref url="http://secunia.com/advisories/33632" source="SECUNIA" adv="1">33632</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6132" source="OVAL">oval:org.mitre.oval:def:6132</ref>
      <ref url="http://osvdb.org/51530" source="OSVDB">51530</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="quicktime">
        <vers num="3" />
        <vers num="4.1.2" />
        <vers num="5.0" />
        <vers num="5.0.1" />
        <vers num="5.0.2" />
        <vers num="6.0" />
        <vers num="6.1" />
        <vers num="6.5" />
        <vers num="6.5.1" />
        <vers num="6.5.2" />
        <vers num="7.0" />
        <vers num="7.0.1" />
        <vers num="7.0.2" />
        <vers num="7.0.3" />
        <vers num="7.0.4" />
        <vers num="7.0.8" />
        <vers num="7.1" />
        <vers num="7.1.1" />
        <vers num="7.1.2" />
        <vers num="7.1.3" />
        <vers num="7.1.4" />
        <vers num="7.1.5" />
        <vers num="7.1.6" />
        <vers num="7.2" />
        <vers num="7.3" />
        <vers num="7.3.1" />
        <vers num="7.3.1.70" />
        <vers num="7.4" />
        <vers num="7.4.1" />
        <vers num="7.4.4" />
        <vers num="7.4.5" />
        <vers num="7.5" />
        <vers prev="1" num="7.5.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0008" published="2009-01-22" name="CVE-2009-0008" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)" CVSS_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_base_score="7.6">
    <desc>
      <descript source="cve">Unspecified vulnerability in Apple QuickTime MPEG-2 Playback Component before 7.60.92.0 on Windows allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via a crafted MPEG-2 movie.</descript>
      <descript source="nvd">per http://lists.apple.com/archives/security-announce//2009/Jan/msg00001.html

"This issue does not
affect systems running Mac OS X."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/48162" source="XF">quicktime-mpeg2playback-code-execution(48162)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0211" source="VUPEN">ADV-2009-0211</ref>
      <ref url="http://www.securitytracker.com/id?1021621" source="SECTRACK">1021621</ref>
      <ref url="http://www.securityfocus.com/bid/33393" source="BID">33393</ref>
      <ref url="http://support.apple.com/kb/HT3404" source="CONFIRM" adv="1">http://support.apple.com/kb/HT3404</ref>
      <ref url="http://secunia.com/advisories/33642" source="SECUNIA" adv="1">33642</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5974" source="OVAL">oval:org.mitre.oval:def:5974</ref>
      <ref url="http://lists.apple.com/archives/security-announce//2009/Jan/msg00001.html" source="APPLE" adv="1">APPLE-SA-2009-01-21</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="quicktime_mpeg-2_playback_component">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0009" published="2009-02-12" name="CVE-2009-0009" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Pixlet codec in Apple Mac OS X 10.4.11 and 10.5.6 allows remote attackers to cause a denial of service (application termination) and possibly execute arbitrary code via a crafted movie file that triggers memory corruption.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/48713" source="XF">macosx-pixlet-codec-code-execution(48713)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0422" source="VUPEN">ADV-2009-0422</ref>
      <ref url="http://www.securityfocus.com/bid/33759" source="BID">33759</ref>
      <ref url="http://support.apple.com/kb/HT3438" source="CONFIRM">http://support.apple.com/kb/HT3438</ref>
      <ref url="http://securitytracker.com/alerts/2009/Feb/1021718.html" source="SECTRACK">1021718</ref>
      <ref url="http://secunia.com/advisories/33937" source="SECUNIA">33937</ref>
      <ref url="http://osvdb.org/51980" source="OSVDB">51980</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2009/Feb/msg00000.html" source="APPLE">APPLE-SA-2009-02-12</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.4.11" />
        <vers num="10.5.6" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.4.11" />
        <vers num="10.5.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0010" published="2009-05-13" name="CVE-2009-0010" modified="2009-06-04" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Integer underflow in QuickDraw Manager in Apple Mac OS X 10.4.11 and 10.5 before 10.5.7, and Apple QuickTime before 7.6.2, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a PICT image with a crafted 0x77 Poly tag and a crafted length field, which triggers a heap-based buffer overflow.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-133A.html" source="CERT">TA09-133A</ref>
      <ref url="http://support.apple.com/kb/HT3549" source="CONFIRM" patch="1" adv="1">http://support.apple.com/kb/HT3549</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2009/May/msg00002.html" source="APPLE" patch="1" adv="1">APPLE-SA-2009-05-12</ref>
      <ref url="http://www.zerodayinitiative.com/advisories/ZDI-09-021/" source="MISC">http://www.zerodayinitiative.com/advisories/ZDI-09-021/</ref>
      <ref url="http://www.zerodayinitiative.com/advisories/ZDI-09-021" source="MISC">http://www.zerodayinitiative.com/advisories/ZDI-09-021</ref>
      <ref url="http://www.vupen.com/exploits/Apple_QuickTime_PICT_Poly_Tag_Parsing_Heap_Overflow_PoC_Exploit_1407144.php" source="MISC">http://www.vupen.com/exploits/Apple_QuickTime_PICT_Poly_Tag_Parsing_Heap_Overflow_PoC_Exploit_1407144.php</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1407" source="VUPEN">ADV-2009-1407</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1297" source="VUPEN">ADV-2009-1297</ref>
      <ref url="http://www.securitytracker.com/id?1022209" source="SECTRACK">1022209</ref>
      <ref url="http://www.securityfocus.com/bid/34938" source="BID">34938</ref>
      <ref url="http://www.securityfocus.com/bid/34926" source="BID">34926</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/503878/100/0/threaded" source="BUGTRAQ">20090527 ZDI-09-021: Apple QuickTime PICT Unspecified Tag Heap Overflow Vulnerability</ref>
      <ref url="http://support.apple.com/kb/HT3591" source="CONFIRM">http://support.apple.com/kb/HT3591</ref>
      <ref url="http://secunia.com/advisories/35091" source="SECUNIA">35091</ref>
      <ref url="http://secunia.com/advisories/35074" source="SECUNIA">35074</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2009/Jun/msg00000.html" source="APPLE">APPLE-SA-2009-06-01-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.4.11" />
        <vers num="10.5" />
        <vers num="10.5.0" />
        <vers num="10.5.1" />
        <vers num="10.5.2" />
        <vers num="10.5.3" />
        <vers num="10.5.4" />
        <vers num="10.5.5" />
        <vers num="10.5.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0011" published="2009-02-12" name="CVE-2009-0011" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Certificate Assistant in Apple Mac OS X 10.5.6 allows local users to overwrite arbitrary files via unknown vectors related to an "insecure file operation" on a temporary file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/33759" source="BID" patch="1">33759</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2009/Feb/msg00000.html" source="APPLE" patch="1" adv="1">APPLE-SA-2009-02-12</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/48715" source="XF">macosx-certificate-asst-file-overwrite(48715)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0422" source="VUPEN">ADV-2009-0422</ref>
      <ref url="http://support.apple.com/kb/HT3438" source="CONFIRM">http://support.apple.com/kb/HT3438</ref>
      <ref url="http://securitytracker.com/alerts/2009/Feb/1021720.html" source="SECTRACK">1021720</ref>
      <ref url="http://secunia.com/advisories/33937" source="SECUNIA" adv="1">33937</ref>
      <ref url="http://osvdb.org/51979" source="OSVDB">51979</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.5.6" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.5.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0012" published="2009-02-12" name="CVE-2009-0012" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Heap-based buffer overflow in CoreText in Apple Mac OS X 10.5.6 allows remote attackers to execute arbitrary code via a crafted Unicode string.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://lists.apple.com/archives/security-announce/2009/Feb/msg00000.html" source="APPLE" patch="1" adv="1">APPLE-SA-2009-02-12</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0422" source="VUPEN" adv="1">ADV-2009-0422</ref>
      <ref url="http://www.securityfocus.com/bid/33809" source="BID">33809</ref>
      <ref url="http://www.securityfocus.com/bid/33759" source="BID">33759</ref>
      <ref url="http://support.apple.com/kb/HT3438" source="CONFIRM">http://support.apple.com/kb/HT3438</ref>
      <ref url="http://secunia.com/advisories/33937" source="SECUNIA" adv="1">33937</ref>
      <ref url="http://osvdb.org/51977" source="OSVDB">51977</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.5.6" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.5.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2009-0013" published="2009-02-12" name="CVE-2009-0013" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">dscl in DS Tools in Apple Mac OS X 10.4.11 and 10.5.6 requires that passwords must be provided as command line arguments, which allows local users to gain privileges by listing process information.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://lists.apple.com/archives/security-announce/2009/Feb/msg00000.html" source="APPLE" patch="1" adv="1">APPLE-SA-2009-02-12</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/48717" source="XF">macosx-dstools-information-disclosure(48717)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0422" source="VUPEN">ADV-2009-0422</ref>
      <ref url="http://www.securityfocus.com/bid/33815" source="BID">33815</ref>
      <ref url="http://www.securityfocus.com/bid/33759" source="BID">33759</ref>
      <ref url="http://support.apple.com/kb/HT3438" source="CONFIRM">http://support.apple.com/kb/HT3438</ref>
      <ref url="http://securitytracker.com/alerts/2009/Feb/1021722.html" source="SECTRACK">1021722</ref>
      <ref url="http://secunia.com/advisories/33937" source="SECUNIA">33937</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.4.11" />
        <vers num="10.5.6" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.4.11" />
        <vers num="10.5.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2009-0014" published="2009-02-12" name="CVE-2009-0014" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Folder Manager in Apple Mac OS X 10.5.6 uses insecure default permissions when recreating a Downloads folder after it has been deleted, which allows local users to bypass intended access restrictions and read the Downloads folder.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://lists.apple.com/archives/security-announce/2009/Feb/msg00000.html" source="APPLE" patch="1" adv="1">APPLE-SA-2009-02-12</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0422" source="VUPEN">ADV-2009-0422</ref>
      <ref url="http://www.securityfocus.com/bid/33820" source="BID">33820</ref>
      <ref url="http://www.securityfocus.com/bid/33759" source="BID">33759</ref>
      <ref url="http://support.apple.com/kb/HT3438" source="CONFIRM">http://support.apple.com/kb/HT3438</ref>
      <ref url="http://secunia.com/advisories/33937" source="SECUNIA">33937</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.5.6" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.5.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0015" published="2009-02-12" name="CVE-2009-0015" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:N/A:N)" CVSS_score="4.9" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="3.9" CVSS_base_score="4.9">
    <desc>
      <descript source="cve">Unspecified vulnerability in fseventsd in the FSEvents framework in Apple Mac OS X 10.5.6 allows local users to obtain sensitive information (filesystem activities and directory names) via unknown vectors related to "credential management."</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://lists.apple.com/archives/security-announce/2009/Feb/msg00000.html" source="APPLE" patch="1" adv="1">APPLE-SA-2009-02-12</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0422" source="VUPEN">ADV-2009-0422</ref>
      <ref url="http://www.securityfocus.com/bid/33821" source="BID">33821</ref>
      <ref url="http://www.securityfocus.com/bid/33759" source="BID">33759</ref>
      <ref url="http://support.apple.com/kb/HT3438" source="CONFIRM">http://support.apple.com/kb/HT3438</ref>
      <ref url="http://secunia.com/advisories/33937" source="SECUNIA">33937</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.5.6" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.5.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0016" published="2009-03-14" name="CVE-2009-0016" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Apple iTunes before 8.1 on Windows allows remote attackers to cause a denial of service (infinite loop) via a Digital Audio Access Protocol (DAAP) message with a crafted Content-Length header.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://support.apple.com/kb/HT3487" source="CONFIRM" patch="1" adv="1">http://support.apple.com/kb/HT3487</ref>
      <ref url="http://lists.apple.com/archives/security-announce//2009/Mar/msg00001.html" source="APPLE" patch="1" adv="1">APPLE-SA-2009-03-11</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/49200" source="XF">itunes-daap-dos(49200)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0702" source="VUPEN">ADV-2009-0702</ref>
      <ref url="http://www.securityfocus.com/bid/34094" source="BID">34094</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/501758/100/0/threaded" source="BUGTRAQ">20090313 Apple iTunes DAAP Messages Handling Denial of Service Vulnerability</ref>
      <ref url="http://www.fortiguardcenter.com/advisory/FGA-2009-11.html" source="MISC">http://www.fortiguardcenter.com/advisory/FGA-2009-11.html</ref>
      <ref url="http://securitytracker.com/id?1021842" source="SECTRACK">1021842</ref>
      <ref url="http://secunia.com/advisories/34254" source="SECUNIA" adv="1">34254</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6001" source="OVAL">oval:org.mitre.oval:def:6001</ref>
      <ref url="http://osvdb.org/52578" source="OSVDB">52578</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2009-03/0236.html" source="FULLDISC">20090312 Apple iTunes DAAP Messages Handling Denial of Service Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="itunes">
        <vers num="1.0" edition="" />
        <vers num="1.0" edition=":windows" />
        <vers num="1.1.1" edition="" />
        <vers num="1.1.1" edition=":windows" />
        <vers num="1.1.2" edition="" />
        <vers num="1.1.2" edition=":windows" />
        <vers num="2.0" edition="" />
        <vers num="2.0" edition=":windows" />
        <vers num="2.0.1" edition="" />
        <vers num="2.0.1" edition=":windows" />
        <vers num="2.0.2" edition="" />
        <vers num="2.0.2" edition=":windows" />
        <vers num="2.0.3" edition="" />
        <vers num="2.0.3" edition=":windows" />
        <vers num="2.0.4" edition="" />
        <vers num="2.0.4" edition=":windows" />
        <vers num="3.0" edition="" />
        <vers num="3.0" edition=":windows" />
        <vers num="3.0.1" edition="" />
        <vers num="3.0.1" edition=":windows" />
        <vers num="4.0" edition="" />
        <vers num="4.0" edition=":windows" />
        <vers num="4.0.0" edition="-" />
        <vers num="4.0.0" edition="-:windows" />
        <vers num="4.0.1" edition="" />
        <vers num="4.0.1" edition=":windows" />
        <vers num="4.0.1" edition="-" />
        <vers num="4.0.1" edition="-:windows" />
        <vers num="4.1" edition="" />
        <vers num="4.1" edition=":windows" />
        <vers num="4.1.0" edition="-" />
        <vers num="4.1.0" edition="-:windows" />
        <vers num="4.2" edition="" />
        <vers num="4.2" edition=":windows" />
        <vers num="4.2.0" edition="-" />
        <vers num="4.2.0" edition="-:windows" />
        <vers num="4.2.72" edition="" />
        <vers num="4.2.72" edition=":windows" />
        <vers num="4.5" edition="" />
        <vers num="4.5" edition=":windows" />
        <vers num="4.5.0" edition="-" />
        <vers num="4.5.0" edition="-:windows" />
        <vers num="4.6" edition="" />
        <vers num="4.6" edition=":windows" />
        <vers num="4.6.0" edition="-" />
        <vers num="4.6.0" edition="-:windows" />
        <vers num="4.7" edition="" />
        <vers num="4.7" edition=":windows" />
        <vers num="4.7.0" edition="-" />
        <vers num="4.7.0" edition="-:windows" />
        <vers num="4.7.1" edition="" />
        <vers num="4.7.1" edition=":windows" />
        <vers num="4.7.1" edition="-" />
        <vers num="4.7.1" edition="-:windows" />
        <vers num="4.7.1.30" edition="" />
        <vers num="4.7.1.30" edition=":windows" />
        <vers num="4.8" edition="" />
        <vers num="4.8" edition=":windows" />
        <vers num="4.8.0" edition="-" />
        <vers num="4.8.0" edition="-:windows" />
        <vers num="4.9" edition="" />
        <vers num="4.9" edition=":windows" />
        <vers num="4.9.0" edition="-" />
        <vers num="4.9.0" edition="-:windows" />
        <vers num="5.0" edition="" />
        <vers num="5.0" edition=":windows" />
        <vers num="5.0.0" edition="-" />
        <vers num="5.0.0" edition="-:windows" />
        <vers num="5.0.1" edition="" />
        <vers num="5.0.1" edition=":windows" />
        <vers num="5.0.1" edition="-" />
        <vers num="5.0.1" edition="-:windows" />
        <vers num="6.0" edition="" />
        <vers num="6.0" edition=":windows" />
        <vers num="6.0.0" edition="-" />
        <vers num="6.0.0" edition="-:windows" />
        <vers num="6.0.1" edition="" />
        <vers num="6.0.1" edition=":windows" />
        <vers num="6.0.1" edition="-" />
        <vers num="6.0.1" edition="-:windows" />
        <vers num="6.0.2" edition="" />
        <vers num="6.0.2" edition=":windows" />
        <vers num="6.0.2" edition="-" />
        <vers num="6.0.2" edition="-:windows" />
        <vers num="6.0.3" edition="" />
        <vers num="6.0.3" edition=":windows" />
        <vers num="6.0.3" edition="-" />
        <vers num="6.0.3" edition="-:windows" />
        <vers num="6.0.4" edition="" />
        <vers num="6.0.4" edition=":windows" />
        <vers num="6.0.4" edition="-" />
        <vers num="6.0.4" edition="-:windows" />
        <vers num="6.0.4.2" edition="" />
        <vers num="6.0.4.2" edition=":windows" />
        <vers num="6.0.5" edition="" />
        <vers num="6.0.5" edition=":windows" />
        <vers num="6.0.5" edition="-" />
        <vers num="6.0.5" edition="-:windows" />
        <vers num="7.0.0" edition="-" />
        <vers num="7.0.0" edition="-:windows" />
        <vers num="7.0.1" edition="-" />
        <vers num="7.0.1" edition="-:windows" />
        <vers num="7.0.2" edition="" />
        <vers num="7.0.2" edition=":windows" />
        <vers num="7.0.2" edition="-" />
        <vers num="7.0.2" edition="-:windows" />
        <vers num="7.1.0" edition="-" />
        <vers num="7.1.0" edition="-:windows" />
        <vers num="7.1.1" edition="-" />
        <vers num="7.1.1" edition="-:windows" />
        <vers num="7.2.0" edition="-" />
        <vers num="7.2.0" edition="-:windows" />
        <vers num="7.3.0" edition="-" />
        <vers num="7.3.0" edition="-:windows" />
        <vers num="7.3.1" edition="-" />
        <vers num="7.3.1" edition="-:windows" />
        <vers num="7.3.2" edition="" />
        <vers num="7.3.2" edition=":windows" />
        <vers num="7.3.2" edition="-" />
        <vers num="7.3.2" edition="-:windows" />
        <vers num="7.4" edition="" />
        <vers num="7.4" edition=":windows" />
        <vers num="7.4.0" edition="-" />
        <vers num="7.4.0" edition="-:windows" />
        <vers num="7.4.1" edition="" />
        <vers num="7.4.1" edition=":windows" />
        <vers num="7.4.1" edition="-" />
        <vers num="7.4.1" edition="-:windows" />
        <vers num="7.4.2" edition="" />
        <vers num="7.4.2" edition=":windows" />
        <vers num="7.4.2" edition="-" />
        <vers num="7.4.2" edition="-:windows" />
        <vers num="7.4.3" edition="" />
        <vers num="7.4.3" edition=":windows" />
        <vers num="7.5" edition="" />
        <vers num="7.5" edition=":windows" />
        <vers num="7.5.0" edition="-" />
        <vers num="7.5.0" edition="-:windows" />
        <vers num="7.6" edition="" />
        <vers num="7.6" edition=":windows" />
        <vers num="7.6.0" edition="-" />
        <vers num="7.6.0" edition="-:windows" />
        <vers num="7.6.1" edition="" />
        <vers num="7.6.1" edition=":windows" />
        <vers num="7.6.1" edition="-" />
        <vers num="7.6.1" edition="-:windows" />
        <vers num="7.6.2" edition="-" />
        <vers num="7.6.2" edition="-:windows" />
        <vers num="7.7" edition="" />
        <vers num="7.7" edition=":windows" />
        <vers num="7.7.0" edition="-" />
        <vers num="7.7.0" edition="-:windows" />
        <vers num="7.7.1" edition="" />
        <vers num="7.7.1" edition=":windows" />
        <vers num="7.7.1" edition="-" />
        <vers num="7.7.1" edition="-:windows" />
        <vers prev="1" num="8.0" edition="" />
        <vers prev="1" num="8.0" edition=":windows" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0017" published="2009-02-12" name="CVE-2009-0017" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">csregprinter in the Printing component in Apple Mac OS X 10.4.11 and 10.5.6 does not properly handle error conditions, which allows local users to execute arbitrary code via unknown vectors that trigger a heap-based buffer overflow.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://lists.apple.com/archives/security-announce/2009/Feb/msg00000.html" source="APPLE" patch="1" adv="1">APPLE-SA-2009-02-12</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0422" source="VUPEN">ADV-2009-0422</ref>
      <ref url="http://www.securityfocus.com/bid/33811" source="BID">33811</ref>
      <ref url="http://www.securityfocus.com/bid/33759" source="BID">33759</ref>
      <ref url="http://support.apple.com/kb/HT3438" source="CONFIRM">http://support.apple.com/kb/HT3438</ref>
      <ref url="http://secunia.com/advisories/33937" source="SECUNIA">33937</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.4.11" />
        <vers num="10.5.6" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.4.11" />
        <vers num="10.5.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0018" published="2009-02-12" name="CVE-2009-0018" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:N/A:N)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">The Remote Apple Events server in Apple Mac OS X 10.4.11 and 10.5.6 does not properly initialize a buffer, which allows remote attackers to read portions of memory.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2009/0422" source="VUPEN">ADV-2009-0422</ref>
      <ref url="http://www.securityfocus.com/bid/33816" source="BID">33816</ref>
      <ref url="http://www.securityfocus.com/bid/33759" source="BID">33759</ref>
      <ref url="http://support.apple.com/kb/HT3438" source="CONFIRM">http://support.apple.com/kb/HT3438</ref>
      <ref url="http://secunia.com/advisories/33937" source="SECUNIA">33937</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2009/Feb/msg00000.html" source="APPLE">APPLE-SA-2009-02-12</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.4.11" />
        <vers num="10.5.6" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.4.11" />
        <vers num="10.5.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0019" published="2009-02-12" name="CVE-2009-0019" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Remote Apple Events in Apple Mac OS X 10.4.11 and 10.5.6 allows remote attackers to cause a denial of service (application termination) or obtain sensitive information via unspecified vectors that trigger an out-of-bounds memory access.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2009/0422" source="VUPEN">ADV-2009-0422</ref>
      <ref url="http://www.securityfocus.com/bid/33814" source="BID">33814</ref>
      <ref url="http://www.securityfocus.com/bid/33759" source="BID">33759</ref>
      <ref url="http://support.apple.com/kb/HT3438" source="CONFIRM">http://support.apple.com/kb/HT3438</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2009/Feb/msg00000.html" source="APPLE" adv="1">APPLE-SA-2009-02-12</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.4.11" />
        <vers num="10.5.6" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.4.11" />
        <vers num="10.5.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0020" published="2009-02-12" name="CVE-2009-0020" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Unspecified vulnerability in CarbonCore in Apple Mac OS X 10.4.11 and 10.5.6 allows remote attackers to cause a denial of service (application termination) and execute arbitrary code via a crafted resource fork that triggers memory corruption.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://lists.apple.com/archives/security-announce/2009/Feb/msg00000.html" source="APPLE" patch="1" adv="1">APPLE-SA-2009-02-12</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0422" source="VUPEN">ADV-2009-0422</ref>
      <ref url="http://www.securityfocus.com/bid/33759" source="BID">33759</ref>
      <ref url="http://support.apple.com/kb/HT3438" source="CONFIRM">http://support.apple.com/kb/HT3438</ref>
      <ref url="http://secunia.com/advisories/33937" source="SECUNIA">33937</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.4.11" />
        <vers num="10.5.6" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.4.11" />
        <vers num="10.5.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0021" published="2009-01-07" name="CVE-2009-0021" modified="2011-08-31" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">NTP 4.2.4 before 4.2.4p5 and 4.2.5 before 4.2.5p150 does not properly check the return value from the OpenSSL EVP_VerifyFinal function, which allows remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature for DSA and ECDSA keys, a similar vulnerability to CVE-2008-5077.</descript>
      <descript source="nvd">Note that versions 4.2.5 before 4.2.5p150 are development versions and not production versions.  Development versions are not included in the CPE configuration for CVEs.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-133A.html" source="CERT">TA09-133A</ref>
      <ref url="https://lists.ntp.org/pipermail/announce/2009-January/000055.html" source="MLIST">[announce] 20090108 NTP 4.2.4p6 Released</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1297" source="VUPEN" adv="1">ADV-2009-1297</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0042" source="VUPEN" adv="1">ADV-2009-0042</ref>
      <ref url="http://www.securitytracker.com/id?1021533" source="SECTRACK">1021533</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-0046.html" source="REDHAT">RHSA-2009:0046</ref>
      <ref url="http://www.ocert.org/advisories/ocert-2008-016.html" source="MISC">http://www.ocert.org/advisories/ocert-2008-016.html</ref>
      <ref url="http://support.apple.com/kb/HT3549" source="CONFIRM">http://support.apple.com/kb/HT3549</ref>
      <ref url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2009&amp;m=slackware-security.531177" source="SLACKWARE">SSA:2009-014-03</ref>
      <ref url="http://secunia.com/advisories/35074" source="SECUNIA" adv="1">35074</ref>
      <ref url="http://secunia.com/advisories/34642" source="SECUNIA" adv="1">34642</ref>
      <ref url="http://secunia.com/advisories/33648" source="SECUNIA" adv="1">33648</ref>
      <ref url="http://secunia.com/advisories/33558" source="SECUNIA" adv="1">33558</ref>
      <ref url="http://secunia.com/advisories/33406" source="SECUNIA" adv="1">33406</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10035" source="OVAL">oval:org.mitre.oval:def:10035</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-04/msg00003.html" source="SUSE">SUSE-SR:2009:008</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-03/msg00000.html" source="SUSE">SUSE-SR:2009:005</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2009/May/msg00002.html" source="APPLE">APPLE-SA-2009-05-12</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ntp" name="ntp">
        <vers num="4.2.0" />
        <vers num="4.2.2" />
        <vers num="4.2.4p1" />
        <vers num="4.2.4p2" />
        <vers num="4.2.4p3" />
        <vers prev="1" num="4.2.4p4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0022" published="2009-01-05" name="CVE-2009-0022" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:S/C:C/I:N/A:N)" CVSS_score="6.3" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="6.8" CVSS_base_score="6.3">
    <desc>
      <descript source="cve">Samba 3.2.0 through 3.2.6, when registry shares are enabled, allows remote authenticated users to access the root filesystem via a crafted connection request that specifies a blank share name.</descript>
    </desc>
    <sols>
      <sol source="nvd">Patch Information - http://www.samba.org/samba/history/security.html</sol>
    </sols>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-January/msg00309.html" source="FEDORA">FEDORA-2009-0268</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/47733" source="XF">samba-file-system-security-bypass(47733)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0017" source="VUPEN">ADV-2009-0017</ref>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-702-1" source="UBUNTU">USN-702-1</ref>
      <ref url="http://www.securitytracker.com/id?1021513" source="SECTRACK">1021513</ref>
      <ref url="http://www.securityfocus.com/bid/33118" source="BID">33118</ref>
      <ref url="http://www.samba.org/samba/security/CVE-2009-0022.html" source="CONFIRM">http://www.samba.org/samba/security/CVE-2009-0022.html</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:042" source="MANDRIVA">MDVSA-2009:042</ref>
      <ref url="http://secunia.com/advisories/33431" source="SECUNIA">33431</ref>
      <ref url="http://secunia.com/advisories/33392" source="SECUNIA">33392</ref>
      <ref url="http://secunia.com/advisories/33379" source="SECUNIA" adv="1">33379</ref>
      <ref url="http://osvdb.org/51152" source="OSVDB">51152</ref>
      <ref url="http://master.samba.org/samba/ftp/patches/security/samba-3.2.6-CVE-2009-0022.patch" source="MISC">http://master.samba.org/samba/ftp/patches/security/samba-3.2.6-CVE-2009-0022.patch</ref>
    </refs>
    <vuln_soft>
      <prod vendor="samba" name="samba">
        <vers num="3.2.0" />
        <vers num="3.2.1" />
        <vers num="3.2.2" />
        <vers num="3.2.3" />
        <vers num="3.2.4" />
        <vers num="3.2.5" />
        <vers num="3.2.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0023" published="2009-06-07" name="CVE-2009-0023" modified="2011-07-18" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">The apr_strmatch_precompile function in strmatch/apr_strmatch.c in Apache APR-util before 1.3.5 allows remote attackers to cause a denial of service (daemon crash) via crafted input involving (1) a .htaccess file used with the Apache HTTP Server, (2) the SVNMasterURI directive in the mod_dav_svn module in the Apache HTTP Server, (3) the mod_apreq2 module for the Apache HTTP Server, or (4) an application that uses the libapreq2 library, which triggers a heap-based buffer underflow.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=503928" source="CONFIRM" patch="1">https://bugzilla.redhat.com/show_bug.cgi?id=503928</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1812" source="DEBIAN" patch="1">DSA-1812</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-June/msg01228.html" source="FEDORA">FEDORA-2009-5969</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-June/msg01201.html" source="FEDORA">FEDORA-2009-6261</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-June/msg01173.html" source="FEDORA">FEDORA-2009-6014</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/50964" source="XF">apache-aprstrmatchprecompile-dos(50964)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/3184" source="VUPEN">ADV-2009-3184</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1907" source="VUPEN">ADV-2009-1907</ref>
      <ref url="http://www.ubuntu.com/usn/usn-787-1" source="UBUNTU">USN-787-1</ref>
      <ref url="http://www.ubuntu.com/usn/usn-786-1" source="UBUNTU">USN-786-1</ref>
      <ref url="http://www.securityfocus.com/bid/35221" source="BID">35221</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/507855/100/0/threaded" source="BUGTRAQ">20091112 rPSA-2009-0144-1 apr-util</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-1108.html" source="REDHAT">RHSA-2009:1108</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-1107.html" source="REDHAT">RHSA-2009:1107</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:131" source="MANDRIVA">MDVSA-2009:131</ref>
      <ref url="http://www.apache.org/dist/apr/CHANGES-APR-UTIL-1.3" source="CONFIRM">http://www.apache.org/dist/apr/CHANGES-APR-UTIL-1.3</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg27014463" source="CONFIRM">http://www-01.ibm.com/support/docview.wss?uid=swg27014463</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg1PK99478" source="AIXAPAR">PK99478</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg1PK91241" source="AIXAPAR">PK91241</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg1PK88341" source="AIXAPAR">PK88341</ref>
      <ref url="http://wiki.rpath.com/Advisories:rPSA-2009-0144" source="CONFIRM">http://wiki.rpath.com/Advisories:rPSA-2009-0144</ref>
      <ref url="http://svn.apache.org/viewvc?view=rev&amp;revision=779880" source="CONFIRM">http://svn.apache.org/viewvc?view=rev&amp;revision=779880</ref>
      <ref url="http://support.apple.com/kb/HT3937" source="CONFIRM">http://support.apple.com/kb/HT3937</ref>
      <ref url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2009&amp;m=slackware-security.538210" source="SLACKWARE">SSA:2009-167-02</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200907-03.xml" source="GENTOO">GLSA-200907-03</ref>
      <ref url="http://secunia.com/advisories/37221" source="SECUNIA">37221</ref>
      <ref url="http://secunia.com/advisories/35843" source="SECUNIA">35843</ref>
      <ref url="http://secunia.com/advisories/35797" source="SECUNIA">35797</ref>
      <ref url="http://secunia.com/advisories/35710" source="SECUNIA">35710</ref>
      <ref url="http://secunia.com/advisories/35565" source="SECUNIA">35565</ref>
      <ref url="http://secunia.com/advisories/35487" source="SECUNIA">35487</ref>
      <ref url="http://secunia.com/advisories/35444" source="SECUNIA">35444</ref>
      <ref url="http://secunia.com/advisories/35395" source="SECUNIA">35395</ref>
      <ref url="http://secunia.com/advisories/35360" source="SECUNIA" adv="1">35360</ref>
      <ref url="http://secunia.com/advisories/35284" source="SECUNIA" adv="1">35284</ref>
      <ref url="http://secunia.com/advisories/34724" source="SECUNIA">34724</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:12321" source="OVAL">oval:org.mitre.oval:def:12321</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10968" source="OVAL">oval:org.mitre.oval:def:10968</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=129190899612998&amp;w=2" source="HP">HPSBUX02612</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=129190899612998&amp;w=2" source="HP">HPSBUX02612</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2009/Nov/msg00000.html" source="APPLE">APPLE-SA-2009-11-09-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apache" name="apr-util">
        <vers num="0.9.1" />
        <vers num="0.9.2" />
        <vers num="0.9.3" />
        <vers num="0.9.4" />
        <vers num="0.9.5" />
        <vers num="1.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.1.0" />
        <vers num="1.1.1" />
        <vers num="1.1.2" />
        <vers num="1.2.1" />
        <vers num="1.2.2" />
        <vers num="1.2.6" />
        <vers num="1.2.7" />
        <vers num="1.2.8" />
        <vers num="1.3.0" />
        <vers num="1.3.1" />
        <vers num="1.3.2" />
        <vers num="1.3.3" />
        <vers prev="1" num="1.3.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0024" published="2009-01-13" name="CVE-2009-0024" modified="2009-01-13" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">The sys_remap_file_pages function in mm/fremap.c in the Linux kernel before 2.6.24.1 allows local users to cause a denial of service or gain privileges via unspecified vectors, related to the vm_file structure member, and the mmap_region and do_munmap functions.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/33211" source="BID" patch="1">33211</ref>
      <ref url="http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.24.1" source="CONFIRM">http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.24.1</ref>
      <ref url="http://openwall.com/lists/oss-security/2009/01/12/1" source="MLIST">[oss-security] 20090112 CVE-2009-0024 kernel: local privilege escalation in sys_remap_file_pages</ref>
      <ref url="http://git.kernel.org/?p=linux/kernel/git/stable/linux-2.6.24.y.git;a=commit;h=8a459e44ad837018ea5c34a9efe8eb4ad27ded26" source="CONFIRM">http://git.kernel.org/?p=linux/kernel/git/stable/linux-2.6.24.y.git;a=commit;h=8a459e44ad837018ea5c34a9efe8eb4ad27ded26</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="kernel">
        <vers num="2.2.27" />
        <vers num="2.4.36" />
        <vers num="2.4.36.1" />
        <vers num="2.4.36.2" />
        <vers num="2.4.36.3" />
        <vers num="2.4.36.4" />
        <vers num="2.4.36.5" />
        <vers num="2.4.36.6" />
        <vers num="2.6" />
        <vers num="2.6.0" />
        <vers num="2.6.1" />
        <vers num="2.6.10" />
        <vers num="2.6.11" />
        <vers num="2.6.11.1" />
        <vers num="2.6.11.10" />
        <vers num="2.6.11.11" />
        <vers num="2.6.11.12" />
        <vers num="2.6.11.2" />
        <vers num="2.6.11.3" />
        <vers num="2.6.11.4" />
        <vers num="2.6.11.5" />
        <vers num="2.6.11.6" />
        <vers num="2.6.11.7" />
        <vers num="2.6.11.8" />
        <vers num="2.6.11.9" />
        <vers num="2.6.12" />
        <vers num="2.6.12.1" />
        <vers num="2.6.12.2" />
        <vers num="2.6.12.3" />
        <vers num="2.6.12.4" />
        <vers num="2.6.12.5" />
        <vers num="2.6.12.6" />
        <vers num="2.6.13" />
        <vers num="2.6.13.1" />
        <vers num="2.6.13.2" />
        <vers num="2.6.13.3" />
        <vers num="2.6.13.4" />
        <vers num="2.6.13.5" />
        <vers num="2.6.14" />
        <vers num="2.6.14.1" />
        <vers num="2.6.14.2" />
        <vers num="2.6.14.3" />
        <vers num="2.6.14.4" />
        <vers num="2.6.14.5" />
        <vers num="2.6.14.6" />
        <vers num="2.6.14.7" />
        <vers num="2.6.15" />
        <vers num="2.6.15.1" />
        <vers num="2.6.15.2" />
        <vers num="2.6.15.3" />
        <vers num="2.6.15.4" />
        <vers num="2.6.15.5" />
        <vers num="2.6.15.6" />
        <vers num="2.6.15.7" />
        <vers num="2.6.16" />
        <vers num="2.6.16.1" />
        <vers num="2.6.16.10" />
        <vers num="2.6.16.11" />
        <vers num="2.6.16.12" />
        <vers num="2.6.16.13" />
        <vers num="2.6.16.14" />
        <vers num="2.6.16.15" />
        <vers num="2.6.16.16" />
        <vers num="2.6.16.17" />
        <vers num="2.6.16.18" />
        <vers num="2.6.16.19" />
        <vers num="2.6.16.2" />
        <vers num="2.6.16.20" />
        <vers num="2.6.16.21" />
        <vers num="2.6.16.22" />
        <vers num="2.6.16.23" />
        <vers num="2.6.16.24" />
        <vers num="2.6.16.25" />
        <vers num="2.6.16.26" />
        <vers num="2.6.16.27" />
        <vers num="2.6.16.28" />
        <vers num="2.6.16.29" />
        <vers num="2.6.16.3" />
        <vers num="2.6.16.30" />
        <vers num="2.6.16.31" />
        <vers num="2.6.16.32" />
        <vers num="2.6.16.33" />
        <vers num="2.6.16.34" />
        <vers num="2.6.16.35" />
        <vers num="2.6.16.36" />
        <vers num="2.6.16.37" />
        <vers num="2.6.16.38" />
        <vers num="2.6.16.39" />
        <vers num="2.6.16.4" />
        <vers num="2.6.16.40" />
        <vers num="2.6.16.41" />
        <vers num="2.6.16.42" />
        <vers num="2.6.16.43" />
        <vers num="2.6.16.44" />
        <vers num="2.6.16.45" />
        <vers num="2.6.16.46" />
        <vers num="2.6.16.47" />
        <vers num="2.6.16.48" />
        <vers num="2.6.16.49" />
        <vers num="2.6.16.5" />
        <vers num="2.6.16.50" />
        <vers num="2.6.16.51" />
        <vers num="2.6.16.52" />
        <vers num="2.6.16.53" />
        <vers num="2.6.16.54" />
        <vers num="2.6.16.55" />
        <vers num="2.6.16.56" />
        <vers num="2.6.16.57" />
        <vers num="2.6.16.58" />
        <vers num="2.6.16.59" />
        <vers num="2.6.16.6" />
        <vers num="2.6.16.60" />
        <vers num="2.6.16.61" />
        <vers num="2.6.16.62" />
        <vers num="2.6.16.7" />
        <vers num="2.6.16.8" />
        <vers num="2.6.16.9" />
        <vers num="2.6.17" />
        <vers num="2.6.17.1" />
        <vers num="2.6.17.10" />
        <vers num="2.6.17.11" />
        <vers num="2.6.17.12" />
        <vers num="2.6.17.13" />
        <vers num="2.6.17.14" />
        <vers num="2.6.17.2" />
        <vers num="2.6.17.3" />
        <vers num="2.6.17.4" />
        <vers num="2.6.17.5" />
        <vers num="2.6.17.6" />
        <vers num="2.6.17.7" />
        <vers num="2.6.17.8" />
        <vers num="2.6.17.9" />
        <vers num="2.6.18" edition="rc1" />
        <vers num="2.6.18" edition="rc2" />
        <vers num="2.6.18" edition="rc3" />
        <vers num="2.6.18" edition="rc4" />
        <vers num="2.6.18" edition="rc5" />
        <vers num="2.6.18" edition="rc6" />
        <vers num="2.6.18" edition="rc7" />
        <vers num="2.6.18.1" />
        <vers num="2.6.18.2" />
        <vers num="2.6.18.3" />
        <vers num="2.6.18.4" />
        <vers num="2.6.18.5" />
        <vers num="2.6.18.6" />
        <vers num="2.6.18.7" />
        <vers num="2.6.18.8" />
        <vers num="2.6.19" />
        <vers num="2.6.19.1" />
        <vers num="2.6.19.2" />
        <vers num="2.6.19.3" />
        <vers num="2.6.19.4" />
        <vers num="2.6.19.5" />
        <vers num="2.6.19.6" />
        <vers num="2.6.19.7" />
        <vers num="2.6.2" />
        <vers num="2.6.20" />
        <vers num="2.6.20.1" />
        <vers num="2.6.20.10" />
        <vers num="2.6.20.11" />
        <vers num="2.6.20.12" />
        <vers num="2.6.20.13" />
        <vers num="2.6.20.14" />
        <vers num="2.6.20.15" />
        <vers num="2.6.20.16" />
        <vers num="2.6.20.17" />
        <vers num="2.6.20.18" />
        <vers num="2.6.20.19" />
        <vers num="2.6.20.2" />
        <vers num="2.6.20.20" />
        <vers num="2.6.20.21" />
        <vers num="2.6.20.3" />
        <vers num="2.6.20.4" />
        <vers num="2.6.20.5" />
        <vers num="2.6.20.6" />
        <vers num="2.6.20.7" />
        <vers num="2.6.20.8" />
        <vers num="2.6.20.9" />
        <vers num="2.6.21" />
        <vers num="2.6.21.1" />
        <vers num="2.6.21.2" />
        <vers num="2.6.21.3" />
        <vers num="2.6.21.4" />
        <vers num="2.6.21.5" />
        <vers num="2.6.21.6" />
        <vers num="2.6.21.7" />
        <vers num="2.6.22" />
        <vers num="2.6.22.1" />
        <vers num="2.6.22.10" />
        <vers num="2.6.22.11" />
        <vers num="2.6.22.12" />
        <vers num="2.6.22.13" />
        <vers num="2.6.22.14" />
        <vers num="2.6.22.15" />
        <vers num="2.6.22.16" />
        <vers num="2.6.22.17" />
        <vers num="2.6.22.18" />
        <vers num="2.6.22.19" />
        <vers num="2.6.22.2" />
        <vers num="2.6.22.20" />
        <vers num="2.6.22.21" />
        <vers num="2.6.22.22" />
        <vers num="2.6.22.3" />
        <vers num="2.6.22.4" />
        <vers num="2.6.22.5" />
        <vers num="2.6.22.6" />
        <vers num="2.6.22.7" />
        <vers num="2.6.22.8" />
        <vers num="2.6.22.9" />
        <vers num="2.6.22_rc1" />
        <vers num="2.6.22_rc7" />
        <vers num="2.6.23" edition="rc1" />
        <vers num="2.6.23" edition="rc2" />
        <vers num="2.6.23.1" />
        <vers num="2.6.23.10" />
        <vers num="2.6.23.11" />
        <vers num="2.6.23.12" />
        <vers num="2.6.23.13" />
        <vers num="2.6.23.14" />
        <vers num="2.6.23.15" />
        <vers num="2.6.23.16" />
        <vers num="2.6.23.17" />
        <vers num="2.6.23.2" />
        <vers num="2.6.23.3" />
        <vers num="2.6.23.4" />
        <vers num="2.6.23.5" />
        <vers num="2.6.23.6" />
        <vers num="2.6.23.7" />
        <vers num="2.6.23.8" />
        <vers num="2.6.23.9" />
        <vers prev="1" num="2.6.24" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0025" published="2009-01-07" name="CVE-2009-0025" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">BIND 9.6.0, 9.5.1, 9.5.0, 9.4.3, and earlier does not properly check the return value from the OpenSSL DSA_verify function, which allows remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature, a similar vulnerability to CVE-2008-5077.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-133A.html" source="CERT">TA09-133A</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-January/msg00393.html" source="FEDORA">FEDORA-2009-0350</ref>
      <ref url="https://www.isc.org/software/bind/advisories/cve-2009-0025" source="CONFIRM">https://www.isc.org/software/bind/advisories/cve-2009-0025</ref>
      <ref url="https://issues.rpath.com/browse/RPL-2938" source="CONFIRM">https://issues.rpath.com/browse/RPL-2938</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1297" source="VUPEN">ADV-2009-1297</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0904" source="VUPEN">ADV-2009-0904</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0366" source="VUPEN">ADV-2009-0366</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0043" source="VUPEN">ADV-2009-0043</ref>
      <ref url="http://www.vmware.com/security/advisories/VMSA-2009-0004.html" source="CONFIRM">http://www.vmware.com/security/advisories/VMSA-2009-0004.html</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/502322/100/0/threaded" source="BUGTRAQ">20090401 VMSA-2009-0004 ESX Service Console updates for openssl, bind, and vim</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/500207/100/0/threaded" source="BUGTRAQ">20090120 rPSA-2009-0009-1 bind bind-utils</ref>
      <ref url="http://www.openbsd.org/errata44.html#008_bind" source="CONFIRM">http://www.openbsd.org/errata44.html#008_bind</ref>
      <ref url="http://www.ocert.org/advisories/ocert-2008-016.html" source="MISC">http://www.ocert.org/advisories/ocert-2008-016.html</ref>
      <ref url="http://wiki.rpath.com/Advisories:rPSA-2009-0009" source="CONFIRM">http://wiki.rpath.com/Advisories:rPSA-2009-0009</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2009-045.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2009-045.htm</ref>
      <ref url="http://support.apple.com/kb/HT3549" source="CONFIRM">http://support.apple.com/kb/HT3549</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-250846-1" source="SUNALERT">250846</ref>
      <ref url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2009&amp;m=slackware-security.540362" source="SLACKWARE">SSA:2009-014-02</ref>
      <ref url="http://security.freebsd.org/advisories/FreeBSD-SA-09:04.bind.asc" source="FREEBSD">FreeBSD-SA-09:04</ref>
      <ref url="http://secunia.com/advisories/35074" source="SECUNIA">35074</ref>
      <ref url="http://secunia.com/advisories/33882" source="SECUNIA">33882</ref>
      <ref url="http://secunia.com/advisories/33683" source="SECUNIA">33683</ref>
      <ref url="http://secunia.com/advisories/33559" source="SECUNIA">33559</ref>
      <ref url="http://secunia.com/advisories/33551" source="SECUNIA">33551</ref>
      <ref url="http://secunia.com/advisories/33546" source="SECUNIA">33546</ref>
      <ref url="http://secunia.com/advisories/33494" source="SECUNIA">33494</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5569" source="OVAL">oval:org.mitre.oval:def:5569</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10879" source="OVAL">oval:org.mitre.oval:def:10879</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2009/May/msg00002.html" source="APPLE">APPLE-SA-2009-05-12</ref>
      <ref url="http://groups.google.com/group/comp.protocols.dns.bind/browse_thread/thread/49ef622c8329fd33" source="MISC">http://groups.google.com/group/comp.protocols.dns.bind/browse_thread/thread/49ef622c8329fd33</ref>
    </refs>
    <vuln_soft>
      <prod vendor="isc" name="bind">
        <vers num="4" />
        <vers num="4.9" />
        <vers num="4.9.10" />
        <vers num="4.9.2" />
        <vers num="4.9.3" />
        <vers num="4.9.4" />
        <vers num="4.9.5" edition="p1" />
        <vers num="4.9.6" />
        <vers num="4.9.7" />
        <vers num="4.9.8" />
        <vers num="4.9.9" />
        <vers num="8" />
        <vers num="8.1" />
        <vers num="8.1.1" />
        <vers num="8.1.2" />
        <vers num="8.2" edition="p1" />
        <vers num="8.2.1" />
        <vers num="8.2.2" edition="p1" />
        <vers num="8.2.2" edition="p2" />
        <vers num="8.2.2" edition="p3" />
        <vers num="8.2.2" edition="p4" />
        <vers num="8.2.2" edition="p5" />
        <vers num="8.2.2" edition="p6" />
        <vers num="8.2.2" edition="p7" />
        <vers num="8.2.3" />
        <vers num="8.2.3_t1a" />
        <vers num="8.2.3_t9b" />
        <vers num="8.2.4" />
        <vers num="8.2.5" />
        <vers num="8.2.6" />
        <vers num="8.2.7" />
        <vers num="8.3.0" />
        <vers num="8.3.1" />
        <vers num="8.3.2" />
        <vers num="8.3.3" />
        <vers num="8.3.4" />
        <vers num="8.3.5" />
        <vers num="8.3.6" />
        <vers num="8.4" />
        <vers num="8.4.1" />
        <vers num="8.4.4" />
        <vers num="8.4.5" />
        <vers num="8.4.7" />
        <vers num="9.0" />
        <vers num="9.0.1" />
        <vers num="9.1" />
        <vers num="9.1.1" />
        <vers num="9.1.2" />
        <vers num="9.1.3" />
        <vers num="9.2" />
        <vers num="9.2.0" />
        <vers num="9.2.1" />
        <vers num="9.2.2" edition="p3" />
        <vers num="9.2.3" />
        <vers num="9.2.4" />
        <vers num="9.2.5" />
        <vers num="9.2.6" />
        <vers num="9.2.7" />
        <vers num="9.2.9" />
        <vers num="9.3" />
        <vers num="9.3.0" />
        <vers num="9.3.1" />
        <vers num="9.3.2" />
        <vers num="9.3.3" />
        <vers num="9.3.5-p2-w1" edition="windows" />
        <vers num="9.4" />
        <vers num="9.4.0" edition="rc1" />
        <vers num="9.4.0a1" />
        <vers num="9.4.0a2" />
        <vers num="9.4.0a3" />
        <vers num="9.4.0a4" />
        <vers num="9.4.0a5" />
        <vers num="9.4.0a6" />
        <vers num="9.4.0b1" />
        <vers num="9.4.0b2" />
        <vers num="9.4.0b3" />
        <vers num="9.4.0b4" />
        <vers num="9.4.1" />
        <vers num="9.4.2" />
        <vers prev="1" num="9.4.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0026" published="2009-01-21" name="CVE-2009-0026" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Apache Jackrabbit before 1.5.2 allow remote attackers to inject arbitrary web script or HTML via the q parameter to (1) search.jsp or (2) swr.jsp.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="https://issues.apache.org/jira/browse/JCR-1925" source="CONFIRM" adv="1">https://issues.apache.org/jira/browse/JCR-1925</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/48110" source="XF">jackrabbit-search-swr-xss(48110)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0177" source="VUPEN">ADV-2009-0177</ref>
      <ref url="http://www.securityfocus.com/bid/33360" source="BID">33360</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/500196/100/0/threaded" source="BUGTRAQ">20090120 [ANNOUNCE] Apache Jackrabbit 1.5.2 released</ref>
      <ref url="http://www.apache.org/dist/jackrabbit/RELEASE-NOTES-1.5.2.txt" source="CONFIRM">http://www.apache.org/dist/jackrabbit/RELEASE-NOTES-1.5.2.txt</ref>
      <ref url="http://securityreason.com/securityalert/4942" source="SREASON">4942</ref>
      <ref url="http://secunia.com/advisories/33576" source="SECUNIA" adv="1">33576</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apache" name="jackrabbit">
        <vers num="1.4" />
        <vers num="1.5.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0027" published="2009-03-09" name="CVE-2009-0027" modified="2009-03-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The request handler in JBossWS in JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2 before 4.2.0.CP06 and 4.3 before 4.3.0.CP04 does not properly validate the resource path during a request for a WSDL file with a custom web-service endpoint, which allows remote attackers to read arbitrary XML files via a crafted request.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://rhn.redhat.com/errata/RHSA-2009-0349.html" source="REDHAT" patch="1" adv="1">RHSA-2009:0349</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2009-0347.html" source="REDHAT" patch="1">RHSA-2009:0347</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2009-0346.html" source="REDHAT" patch="1">RHSA-2009:0346</ref>
      <ref url="https://jira.jboss.org/jira/browse/JBPAPP-1548" source="CONFIRM">https://jira.jboss.org/jira/browse/JBPAPP-1548</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=479668" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=479668</ref>
      <ref url="http://www.securitytracker.com/id?1021817" source="SECTRACK">1021817</ref>
      <ref url="http://www.securityfocus.com/bid/34023" source="BID">34023</ref>
      <ref url="http://secunia.com/advisories/34112" source="SECUNIA">34112</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2009-0348.html" source="REDHAT" adv="1">RHSA-2009:0348</ref>
    </refs>
    <vuln_soft>
      <prod vendor="redhat" name="jboss_enterprise_application_platform">
        <vers num="4.2.0" edition="cp01" />
        <vers num="4.2.0" edition="cp02" />
        <vers num="4.2.0" edition="cp03" />
        <vers num="4.2.0" edition="cp04" />
        <vers num="4.2.0" edition="cp05" />
        <vers num="4.2.0" edition="cp06" />
        <vers num="4.3.0" edition="cp01" />
        <vers num="4.3.0" edition="cp02" />
        <vers num="4.3.0" edition="cp03" />
        <vers num="4.3.0" edition="cp04" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2009-0028" published="2009-02-27" name="CVE-2009-0028" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">The clone system call in the Linux kernel 2.6.28 and earlier allows local users to send arbitrary signals to a parent process from an unprivileged child process by launching an additional child process with the CLONE_PARENT flag, and then letting this new process exit.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=479932" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=479932</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/3316" source="VUPEN">ADV-2009-3316</ref>
      <ref url="http://www.vmware.com/security/advisories/VMSA-2009-0016.html" source="CONFIRM">http://www.vmware.com/security/advisories/VMSA-2009-0016.html</ref>
      <ref url="http://www.ubuntu.com/usn/usn-751-1" source="UBUNTU">USN-751-1</ref>
      <ref url="http://www.securityfocus.com/bid/33906" source="BID">33906</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/507985/100/0/threaded" source="BUGTRAQ">20091120 VMSA-2009-0016 VMware vCenter and ESX update release and vMA patch release address multiple security issue in third party components</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/503610/100/0/threaded" source="BUGTRAQ">20090516 rPSA-2009-0084-1 kernel</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-0451.html" source="REDHAT">RHSA-2009:0451</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-0326.html" source="REDHAT">RHSA-2009:0326</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:118" source="MANDRIVA">MDVSA-2009:118</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1800" source="DEBIAN">DSA-1800</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1794" source="DEBIAN">DSA-1794</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1787" source="DEBIAN">DSA-1787</ref>
      <ref url="http://wiki.rpath.com/Advisories:rPSA-2009-0084" source="CONFIRM">http://wiki.rpath.com/Advisories:rPSA-2009-0084</ref>
      <ref url="http://secunia.com/advisories/37471" source="SECUNIA">37471</ref>
      <ref url="http://secunia.com/advisories/35394" source="SECUNIA">35394</ref>
      <ref url="http://secunia.com/advisories/35390" source="SECUNIA">35390</ref>
      <ref url="http://secunia.com/advisories/35121" source="SECUNIA">35121</ref>
      <ref url="http://secunia.com/advisories/35120" source="SECUNIA">35120</ref>
      <ref url="http://secunia.com/advisories/35011" source="SECUNIA">35011</ref>
      <ref url="http://secunia.com/advisories/34981" source="SECUNIA">34981</ref>
      <ref url="http://secunia.com/advisories/34962" source="SECUNIA">34962</ref>
      <ref url="http://secunia.com/advisories/34917" source="SECUNIA">34917</ref>
      <ref url="http://secunia.com/advisories/34680" source="SECUNIA">34680</ref>
      <ref url="http://secunia.com/advisories/34033" source="SECUNIA">34033</ref>
      <ref url="http://secunia.com/advisories/33758" source="SECUNIA">33758</ref>
      <ref url="http://scarybeastsecurity.blogspot.com/2009/02/linux-kernel-minor-signal-vulnerability.html" source="MISC">http://scarybeastsecurity.blogspot.com/2009/02/linux-kernel-minor-signal-vulnerability.html</ref>
      <ref url="http://scary.beasts.org/security/CESA-2009-002.html" source="MISC">http://scary.beasts.org/security/CESA-2009-002.html</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2009-0459.html" source="REDHAT">RHSA-2009:0459</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7947" source="OVAL">oval:org.mitre.oval:def:7947</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11187" source="OVAL">oval:org.mitre.oval:def:11187</ref>
      <ref url="http://osvdb.org/52204" source="OSVDB">52204</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-06/msg00001.html" source="SUSE">SUSE-SA:2009:031</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-06/msg00000.html" source="SUSE">SUSE-SA:2009:030</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-02/msg00003.html" source="SUSE">SUSE-SA:2009:010</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="kernel">
        <vers num="2.2.27" />
        <vers num="2.4.36" />
        <vers num="2.4.36.1" />
        <vers num="2.4.36.2" />
        <vers num="2.4.36.3" />
        <vers num="2.4.36.4" />
        <vers num="2.4.36.5" />
        <vers num="2.4.36.6" />
        <vers num="2.6" />
        <vers num="2.6.0" />
        <vers num="2.6.1" />
        <vers num="2.6.10" />
        <vers num="2.6.11" />
        <vers num="2.6.11.1" />
        <vers num="2.6.11.10" />
        <vers num="2.6.11.11" />
        <vers num="2.6.11.12" />
        <vers num="2.6.11.2" />
        <vers num="2.6.11.3" />
        <vers num="2.6.11.4" />
        <vers num="2.6.11.5" />
        <vers num="2.6.11.6" />
        <vers num="2.6.11.7" />
        <vers num="2.6.11.8" />
        <vers num="2.6.11.9" />
        <vers num="2.6.12" />
        <vers num="2.6.12.1" />
        <vers num="2.6.12.2" />
        <vers num="2.6.12.3" />
        <vers num="2.6.12.4" />
        <vers num="2.6.12.5" />
        <vers num="2.6.12.6" />
        <vers num="2.6.13" />
        <vers num="2.6.13.1" />
        <vers num="2.6.13.2" />
        <vers num="2.6.13.3" />
        <vers num="2.6.13.4" />
        <vers num="2.6.13.5" />
        <vers num="2.6.14" />
        <vers num="2.6.14.1" />
        <vers num="2.6.14.2" />
        <vers num="2.6.14.3" />
        <vers num="2.6.14.4" />
        <vers num="2.6.14.5" />
        <vers num="2.6.14.6" />
        <vers num="2.6.14.7" />
        <vers num="2.6.15" />
        <vers num="2.6.15.1" />
        <vers num="2.6.15.2" />
        <vers num="2.6.15.3" />
        <vers num="2.6.15.4" />
        <vers num="2.6.15.5" />
        <vers num="2.6.15.6" />
        <vers num="2.6.15.7" />
        <vers num="2.6.16" />
        <vers num="2.6.16.1" />
        <vers num="2.6.16.10" />
        <vers num="2.6.16.11" />
        <vers num="2.6.16.12" />
        <vers num="2.6.16.13" />
        <vers num="2.6.16.14" />
        <vers num="2.6.16.15" />
        <vers num="2.6.16.16" />
        <vers num="2.6.16.17" />
        <vers num="2.6.16.18" />
        <vers num="2.6.16.19" />
        <vers num="2.6.16.2" />
        <vers num="2.6.16.20" />
        <vers num="2.6.16.21" />
        <vers num="2.6.16.22" />
        <vers num="2.6.16.23" />
        <vers num="2.6.16.24" />
        <vers num="2.6.16.25" />
        <vers num="2.6.16.26" />
        <vers num="2.6.16.27" />
        <vers num="2.6.16.28" />
        <vers num="2.6.16.29" />
        <vers num="2.6.16.3" />
        <vers num="2.6.16.30" />
        <vers num="2.6.16.31" />
        <vers num="2.6.16.32" />
        <vers num="2.6.16.33" />
        <vers num="2.6.16.34" />
        <vers num="2.6.16.35" />
        <vers num="2.6.16.36" />
        <vers num="2.6.16.37" />
        <vers num="2.6.16.38" />
        <vers num="2.6.16.39" />
        <vers num="2.6.16.4" />
        <vers num="2.6.16.40" />
        <vers num="2.6.16.41" />
        <vers num="2.6.16.42" />
        <vers num="2.6.16.43" />
        <vers num="2.6.16.44" />
        <vers num="2.6.16.45" />
        <vers num="2.6.16.46" />
        <vers num="2.6.16.47" />
        <vers num="2.6.16.48" />
        <vers num="2.6.16.49" />
        <vers num="2.6.16.5" />
        <vers num="2.6.16.50" />
        <vers num="2.6.16.51" />
        <vers num="2.6.16.52" />
        <vers num="2.6.16.53" />
        <vers num="2.6.16.54" />
        <vers num="2.6.16.55" />
        <vers num="2.6.16.56" />
        <vers num="2.6.16.57" />
        <vers num="2.6.16.58" />
        <vers num="2.6.16.59" />
        <vers num="2.6.16.6" />
        <vers num="2.6.16.60" />
        <vers num="2.6.16.61" />
        <vers num="2.6.16.62" />
        <vers num="2.6.16.7" />
        <vers num="2.6.16.8" />
        <vers num="2.6.16.9" />
        <vers num="2.6.17" />
        <vers num="2.6.17.1" />
        <vers num="2.6.17.10" />
        <vers num="2.6.17.11" />
        <vers num="2.6.17.12" />
        <vers num="2.6.17.13" />
        <vers num="2.6.17.14" />
        <vers num="2.6.17.2" />
        <vers num="2.6.17.3" />
        <vers num="2.6.17.4" />
        <vers num="2.6.17.5" />
        <vers num="2.6.17.6" />
        <vers num="2.6.17.7" />
        <vers num="2.6.17.8" />
        <vers num="2.6.17.9" />
        <vers num="2.6.18" edition="rc1" />
        <vers num="2.6.18" edition="rc2" />
        <vers num="2.6.18" edition="rc3" />
        <vers num="2.6.18" edition="rc4" />
        <vers num="2.6.18" edition="rc5" />
        <vers num="2.6.18" edition="rc6" />
        <vers num="2.6.18" edition="rc7" />
        <vers num="2.6.18.1" />
        <vers num="2.6.18.2" />
        <vers num="2.6.18.3" />
        <vers num="2.6.18.4" />
        <vers num="2.6.18.5" />
        <vers num="2.6.18.6" />
        <vers num="2.6.18.7" />
        <vers num="2.6.18.8" />
        <vers num="2.6.19" />
        <vers num="2.6.19.1" />
        <vers num="2.6.19.2" />
        <vers num="2.6.19.3" />
        <vers num="2.6.19.4" />
        <vers num="2.6.19.5" />
        <vers num="2.6.19.6" />
        <vers num="2.6.19.7" />
        <vers num="2.6.2" />
        <vers num="2.6.20" />
        <vers num="2.6.20.1" />
        <vers num="2.6.20.10" />
        <vers num="2.6.20.11" />
        <vers num="2.6.20.12" />
        <vers num="2.6.20.13" />
        <vers num="2.6.20.14" />
        <vers num="2.6.20.15" />
        <vers num="2.6.20.16" />
        <vers num="2.6.20.17" />
        <vers num="2.6.20.18" />
        <vers num="2.6.20.19" />
        <vers num="2.6.20.2" />
        <vers num="2.6.20.20" />
        <vers num="2.6.20.21" />
        <vers num="2.6.20.3" />
        <vers num="2.6.20.4" />
        <vers num="2.6.20.5" />
        <vers num="2.6.20.6" />
        <vers num="2.6.20.7" />
        <vers num="2.6.20.8" />
        <vers num="2.6.20.9" />
        <vers num="2.6.21" />
        <vers num="2.6.21.1" />
        <vers num="2.6.21.2" />
        <vers num="2.6.21.3" />
        <vers num="2.6.21.4" />
        <vers num="2.6.21.5" />
        <vers num="2.6.21.6" />
        <vers num="2.6.21.7" />
        <vers num="2.6.22" />
        <vers num="2.6.22.1" />
        <vers num="2.6.22.10" />
        <vers num="2.6.22.11" />
        <vers num="2.6.22.12" />
        <vers num="2.6.22.13" />
        <vers num="2.6.22.14" />
        <vers num="2.6.22.15" />
        <vers num="2.6.22.16" />
        <vers num="2.6.22.17" />
        <vers num="2.6.22.18" />
        <vers num="2.6.22.19" />
        <vers num="2.6.22.2" />
        <vers num="2.6.22.20" />
        <vers num="2.6.22.21" />
        <vers num="2.6.22.22" />
        <vers num="2.6.22.3" />
        <vers num="2.6.22.4" />
        <vers num="2.6.22.5" />
        <vers num="2.6.22.6" />
        <vers num="2.6.22.7" />
        <vers num="2.6.22.8" />
        <vers num="2.6.22.9" />
        <vers num="2.6.22_rc1" />
        <vers num="2.6.22_rc7" />
        <vers num="2.6.23" edition="rc1" />
        <vers num="2.6.23" edition="rc2" />
        <vers num="2.6.23.1" />
        <vers num="2.6.23.10" />
        <vers num="2.6.23.11" />
        <vers num="2.6.23.12" />
        <vers num="2.6.23.13" />
        <vers num="2.6.23.14" />
        <vers num="2.6.23.15" />
        <vers num="2.6.23.16" />
        <vers num="2.6.23.17" />
        <vers num="2.6.23.2" />
        <vers num="2.6.23.3" />
        <vers num="2.6.23.4" />
        <vers num="2.6.23.5" />
        <vers num="2.6.23.6" />
        <vers num="2.6.23.7" />
        <vers num="2.6.23.8" />
        <vers num="2.6.23.9" />
        <vers num="2.6.23_rc1" />
        <vers num="2.6.24" edition="rc1" />
        <vers num="2.6.24" edition="rc2" />
        <vers num="2.6.24" edition="rc3" />
        <vers num="2.6.24" edition="rc4" />
        <vers num="2.6.24" edition="rc5" />
        <vers num="2.6.24.1" />
        <vers num="2.6.24.2" />
        <vers num="2.6.24.3" />
        <vers num="2.6.24.4" />
        <vers num="2.6.24.5" />
        <vers num="2.6.24.6" />
        <vers num="2.6.24.7" />
        <vers num="2.6.24_rc1" />
        <vers num="2.6.24_rc4" />
        <vers num="2.6.24_rc5" />
        <vers num="2.6.25" edition="" />
        <vers num="2.6.25" edition=":x86_64" />
        <vers num="2.6.25.1" edition="" />
        <vers num="2.6.25.1" edition=":x86_64" />
        <vers num="2.6.25.10" edition="" />
        <vers num="2.6.25.10" edition=":x86_64" />
        <vers num="2.6.25.11" edition="" />
        <vers num="2.6.25.11" edition=":x86_64" />
        <vers num="2.6.25.12" edition="" />
        <vers num="2.6.25.12" edition=":x86_64" />
        <vers num="2.6.25.13" />
        <vers num="2.6.25.14" />
        <vers num="2.6.25.15" />
        <vers num="2.6.25.16" />
        <vers num="2.6.25.17" />
        <vers num="2.6.25.18" />
        <vers num="2.6.25.19" />
        <vers num="2.6.25.2" edition="" />
        <vers num="2.6.25.2" edition=":x86_64" />
        <vers num="2.6.25.20" />
        <vers num="2.6.25.3" edition="" />
        <vers num="2.6.25.3" edition=":x86_64" />
        <vers num="2.6.25.4" edition="" />
        <vers num="2.6.25.4" edition=":x86_64" />
        <vers num="2.6.25.5" edition="" />
        <vers num="2.6.25.5" edition=":x86_64" />
        <vers num="2.6.25.6" edition="" />
        <vers num="2.6.25.6" edition=":x86_64" />
        <vers num="2.6.25.7" edition="" />
        <vers num="2.6.25.7" edition=":x86_64" />
        <vers num="2.6.25.8" edition="" />
        <vers num="2.6.25.8" edition=":x86_64" />
        <vers num="2.6.25.9" edition="" />
        <vers num="2.6.25.9" edition=":x86_64" />
        <vers num="2.6.26" edition="rc4" />
        <vers num="2.6.26.1" />
        <vers num="2.6.26.2" />
        <vers num="2.6.26.3" />
        <vers num="2.6.26.4" />
        <vers num="2.6.26.5" />
        <vers num="2.6.26.6" />
        <vers num="2.6.26.7" />
        <vers num="2.6.26.8" />
        <vers num="2.6.27" edition="rc1" />
        <vers num="2.6.27" edition="rc2" />
        <vers num="2.6.27" edition="rc3" />
        <vers num="2.6.27" edition="rc4" />
        <vers num="2.6.27" edition="rc5" />
        <vers num="2.6.27" edition="rc6" />
        <vers num="2.6.27" edition="rc7" />
        <vers num="2.6.27" edition="rc8" />
        <vers num="2.6.27" edition="rc9" />
        <vers num="2.6.27.1" />
        <vers num="2.6.27.10" />
        <vers num="2.6.27.11" />
        <vers num="2.6.27.12" />
        <vers num="2.6.27.2" />
        <vers num="2.6.27.3" />
        <vers num="2.6.27.4" />
        <vers num="2.6.27.5" />
        <vers num="2.6.27.6" />
        <vers num="2.6.27.7" />
        <vers num="2.6.27.8" />
        <vers num="2.6.27.9" />
        <vers prev="1" num="2.6.28" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0029" published="2009-01-15" name="CVE-2009-0029" modified="2009-06-20" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">The ABI in the Linux kernel 2.6.28 and earlier on s390, powerpc, sparc64, and mips 64-bit platforms requires that a 32-bit argument in a 64-bit register was properly sign extended when sent from a user-mode application, but cannot verify this, which allows local users to cause a denial of service (crash) or possibly gain privileges via a crafted system call.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-January/msg01045.html" source="FEDORA">FEDORA-2009-0816</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=479969" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=479969</ref>
      <ref url="http://www.securityfocus.com/bid/33275" source="BID">33275</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:135" source="MANDRIVA">MDVSA-2009:135</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1794" source="DEBIAN">DSA-1794</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1787" source="DEBIAN">DSA-1787</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1749" source="DEBIAN">DSA-1749</ref>
      <ref url="http://secunia.com/advisories/35011" source="SECUNIA">35011</ref>
      <ref url="http://secunia.com/advisories/34981" source="SECUNIA">34981</ref>
      <ref url="http://secunia.com/advisories/34394" source="SECUNIA">34394</ref>
      <ref url="http://secunia.com/advisories/33674" source="SECUNIA">33674</ref>
      <ref url="http://secunia.com/advisories/33477" source="SECUNIA" adv="1">33477</ref>
      <ref url="http://marc.info/?l=linux-kernel&amp;m=123155111608910&amp;w=2" source="MLIST">[linux-kernel] 20090110 Re: [PATCH -v7][RFC]: mutex: implement adaptive spinning</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-02/msg00003.html" source="SUSE">SUSE-SA:2009:010</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="kernel">
        <vers num="2.2.27" />
        <vers num="2.4.36" />
        <vers num="2.4.36.1" />
        <vers num="2.4.36.2" />
        <vers num="2.4.36.3" />
        <vers num="2.4.36.4" />
        <vers num="2.4.36.5" />
        <vers num="2.4.36.6" />
        <vers num="2.6" />
        <vers num="2.6.18" edition="rc1" />
        <vers num="2.6.18" edition="rc2" />
        <vers num="2.6.18" edition="rc3" />
        <vers num="2.6.18" edition="rc4" />
        <vers num="2.6.18" edition="rc5" />
        <vers num="2.6.18" edition="rc6" />
        <vers num="2.6.18" edition="rc7" />
        <vers num="2.6.19.4" />
        <vers num="2.6.19.5" />
        <vers num="2.6.19.6" />
        <vers num="2.6.19.7" />
        <vers num="2.6.20.16" />
        <vers num="2.6.20.17" />
        <vers num="2.6.20.18" />
        <vers num="2.6.20.19" />
        <vers num="2.6.20.20" />
        <vers num="2.6.20.21" />
        <vers num="2.6.21.5" />
        <vers num="2.6.21.6" />
        <vers num="2.6.21.7" />
        <vers num="2.6.22" />
        <vers num="2.6.22.1" />
        <vers num="2.6.22.10" />
        <vers num="2.6.22.11" />
        <vers num="2.6.22.12" />
        <vers num="2.6.22.13" />
        <vers num="2.6.22.14" />
        <vers num="2.6.22.15" />
        <vers num="2.6.22.17" />
        <vers num="2.6.22.18" />
        <vers num="2.6.22.19" />
        <vers num="2.6.22.2" />
        <vers num="2.6.22.20" />
        <vers num="2.6.22.21" />
        <vers num="2.6.22.22" />
        <vers num="2.6.22.8" />
        <vers num="2.6.22.9" />
        <vers num="2.6.22_rc1" />
        <vers num="2.6.22_rc7" />
        <vers num="2.6.23" />
        <vers num="2.6.23.10" />
        <vers num="2.6.23.11" />
        <vers num="2.6.23.12" />
        <vers num="2.6.23.13" />
        <vers num="2.6.23.15" />
        <vers num="2.6.23.16" />
        <vers num="2.6.23.17" />
        <vers num="2.6.23.8" />
        <vers num="2.6.23.9" />
        <vers num="2.6.23_rc1" />
        <vers num="2.6.24" />
        <vers num="2.6.24.1" />
        <vers num="2.6.24.2" />
        <vers num="2.6.24.3" />
        <vers num="2.6.24.4" />
        <vers num="2.6.24.5" />
        <vers num="2.6.24.6" />
        <vers num="2.6.24.7" />
        <vers num="2.6.24_rc1" />
        <vers num="2.6.24_rc4" />
        <vers num="2.6.24_rc5" />
        <vers num="2.6.25" edition="" />
        <vers num="2.6.25" edition=":x86_64" />
        <vers num="2.6.25.1" edition="" />
        <vers num="2.6.25.1" edition=":x86_64" />
        <vers num="2.6.25.10" edition="" />
        <vers num="2.6.25.10" edition=":x86_64" />
        <vers num="2.6.25.11" edition="" />
        <vers num="2.6.25.11" edition=":x86_64" />
        <vers num="2.6.25.12" edition="" />
        <vers num="2.6.25.12" edition=":x86_64" />
        <vers num="2.6.25.13" />
        <vers num="2.6.25.14" />
        <vers num="2.6.25.15" />
        <vers num="2.6.25.16" />
        <vers num="2.6.25.17" />
        <vers num="2.6.25.2" edition="" />
        <vers num="2.6.25.2" edition=":x86_64" />
        <vers num="2.6.25.3" edition="" />
        <vers num="2.6.25.3" edition=":x86_64" />
        <vers num="2.6.25.4" edition="" />
        <vers num="2.6.25.4" edition=":x86_64" />
        <vers num="2.6.25.5" edition="" />
        <vers num="2.6.25.5" edition=":x86_64" />
        <vers num="2.6.25.6" edition="" />
        <vers num="2.6.25.6" edition=":x86_64" />
        <vers num="2.6.25.7" edition="" />
        <vers num="2.6.25.7" edition=":x86_64" />
        <vers num="2.6.25.8" edition="" />
        <vers num="2.6.25.8" edition=":x86_64" />
        <vers num="2.6.25.9" edition="" />
        <vers num="2.6.25.9" edition=":x86_64" />
        <vers num="2.6.26" />
        <vers num="2.6.26.1" />
        <vers num="2.6.26.2" />
        <vers num="2.6.26.3" />
        <vers num="2.6.26.4" />
        <vers num="2.6.26.5" />
        <vers num="2.6.27" />
        <vers prev="1" num="2.6.28" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0030" published="2009-01-21" name="CVE-2009-0030" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)" CVSS_score="6.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.0" CVSS_base_score="6.5">
    <desc>
      <descript source="cve">A certain Red Hat patch for SquirrelMail 1.4.8 sets the same SQMSESSID cookie value for all sessions, which allows remote authenticated users to access other users' folder lists and configuration data in opportunistic circumstances by using the standard webmail.php interface.  NOTE: this vulnerability exists because of an incorrect fix for CVE-2008-3663.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="https://rhn.redhat.com/errata/RHSA-2009-0057.html" source="REDHAT">RHSA-2009:0057</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=480488" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=480488</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=480224" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=480224</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/48115" source="XF">squirrelmail-sessionid-session-hijacking(48115)</ref>
      <ref url="http://www.securityfocus.com/bid/33354" source="BID">33354</ref>
      <ref url="http://securitytracker.com/id?1021611" source="SECTRACK">1021611</ref>
      <ref url="http://secunia.com/advisories/33611" source="SECUNIA" adv="1">33611</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10366" source="OVAL">oval:org.mitre.oval:def:10366</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-02/msg00002.html" source="SUSE">SUSE-SR:2009:004</ref>
    </refs>
    <vuln_soft>
      <prod vendor="squirrelmail" name="squirrelmail">
        <vers num="1.4.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0031" published="2009-01-20" name="CVE-2009-0031" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="4.9" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="3.9" CVSS_base_score="4.9">
    <desc>
      <descript source="cve">Memory leak in the keyctl_join_session_keyring function (security/keys/keyctl.c) in Linux kernel 2.6.29-rc2 and earlier allows local users to cause a denial of service (kernel memory consumption) via unknown vectors related to a "missing kfree."</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.ubuntu.com/usn/usn-751-1" source="UBUNTU">USN-751-1</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-0360.html" source="REDHAT">RHSA-2009:0360</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-0331.html" source="REDHAT">RHSA-2009:0331</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2009/01/19/4" source="MLIST">[oss-security] 20090119 CVE-2009-0031 kernel: local denial of service in keyctl_join_session_keyring</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1794" source="DEBIAN">DSA-1794</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1787" source="DEBIAN">DSA-1787</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1749" source="DEBIAN">DSA-1749</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2009-114.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2009-114.htm</ref>
      <ref url="http://secunia.com/advisories/35011" source="SECUNIA">35011</ref>
      <ref url="http://secunia.com/advisories/34981" source="SECUNIA">34981</ref>
      <ref url="http://secunia.com/advisories/34762" source="SECUNIA">34762</ref>
      <ref url="http://secunia.com/advisories/34502" source="SECUNIA">34502</ref>
      <ref url="http://secunia.com/advisories/34394" source="SECUNIA">34394</ref>
      <ref url="http://secunia.com/advisories/34252" source="SECUNIA">34252</ref>
      <ref url="http://secunia.com/advisories/33858" source="SECUNIA">33858</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2009-0264.html" source="REDHAT">RHSA-2009:0264</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11386" source="OVAL">oval:org.mitre.oval:def:11386</ref>
      <ref url="http://osvdb.org/51501" source="OSVDB">51501</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-02/msg00003.html" source="SUSE">SUSE-SA:2009:010</ref>
      <ref url="http://git2.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=0d54ee1c7850a954026deec4cd4885f331da35cc" source="CONFIRM">http://git2.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=0d54ee1c7850a954026deec4cd4885f331da35cc</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="kernel">
        <vers num="2.2.27" />
        <vers num="2.4.36" />
        <vers num="2.4.36.1" />
        <vers num="2.4.36.2" />
        <vers num="2.4.36.3" />
        <vers num="2.4.36.4" />
        <vers num="2.4.36.5" />
        <vers num="2.4.36.6" />
        <vers num="2.6" />
        <vers num="2.6.18" edition="rc1" />
        <vers num="2.6.18" edition="rc2" />
        <vers num="2.6.18" edition="rc3" />
        <vers num="2.6.18" edition="rc4" />
        <vers num="2.6.18" edition="rc5" />
        <vers num="2.6.18" edition="rc6" />
        <vers num="2.6.18" edition="rc7" />
        <vers num="2.6.19.4" />
        <vers num="2.6.19.5" />
        <vers num="2.6.19.6" />
        <vers num="2.6.19.7" />
        <vers num="2.6.20.16" />
        <vers num="2.6.20.17" />
        <vers num="2.6.20.18" />
        <vers num="2.6.20.19" />
        <vers num="2.6.20.20" />
        <vers num="2.6.20.21" />
        <vers num="2.6.21.5" />
        <vers num="2.6.21.6" />
        <vers num="2.6.21.7" />
        <vers num="2.6.22" />
        <vers num="2.6.22.1" />
        <vers num="2.6.22.10" />
        <vers num="2.6.22.11" />
        <vers num="2.6.22.12" />
        <vers num="2.6.22.13" />
        <vers num="2.6.22.14" />
        <vers num="2.6.22.15" />
        <vers num="2.6.22.17" />
        <vers num="2.6.22.18" />
        <vers num="2.6.22.19" />
        <vers num="2.6.22.2" />
        <vers num="2.6.22.20" />
        <vers num="2.6.22.21" />
        <vers num="2.6.22.22" />
        <vers num="2.6.22.8" />
        <vers num="2.6.22.9" />
        <vers num="2.6.22_rc1" />
        <vers num="2.6.22_rc7" />
        <vers num="2.6.23" />
        <vers num="2.6.23.10" />
        <vers num="2.6.23.11" />
        <vers num="2.6.23.12" />
        <vers num="2.6.23.13" />
        <vers num="2.6.23.15" />
        <vers num="2.6.23.16" />
        <vers num="2.6.23.17" />
        <vers num="2.6.23.8" />
        <vers num="2.6.23.9" />
        <vers num="2.6.23_rc1" />
        <vers num="2.6.24" />
        <vers num="2.6.24.1" />
        <vers num="2.6.24.2" />
        <vers num="2.6.24.3" />
        <vers num="2.6.24.4" />
        <vers num="2.6.24.5" />
        <vers num="2.6.24.6" />
        <vers num="2.6.24.7" />
        <vers num="2.6.24_rc1" />
        <vers num="2.6.24_rc4" />
        <vers num="2.6.24_rc5" />
        <vers num="2.6.25" edition="" />
        <vers num="2.6.25" edition=":x86_64" />
        <vers num="2.6.25.1" edition="" />
        <vers num="2.6.25.1" edition=":x86_64" />
        <vers num="2.6.25.10" edition="" />
        <vers num="2.6.25.10" edition=":x86_64" />
        <vers num="2.6.25.11" edition="" />
        <vers num="2.6.25.11" edition=":x86_64" />
        <vers num="2.6.25.12" edition="" />
        <vers num="2.6.25.12" edition=":x86_64" />
        <vers num="2.6.25.13" />
        <vers num="2.6.25.14" />
        <vers num="2.6.25.15" />
        <vers num="2.6.25.16" />
        <vers num="2.6.25.17" />
        <vers num="2.6.25.2" edition="" />
        <vers num="2.6.25.2" edition=":x86_64" />
        <vers num="2.6.25.3" edition="" />
        <vers num="2.6.25.3" edition=":x86_64" />
        <vers num="2.6.25.4" edition="" />
        <vers num="2.6.25.4" edition=":x86_64" />
        <vers num="2.6.25.5" edition="" />
        <vers num="2.6.25.5" edition=":x86_64" />
        <vers num="2.6.25.6" edition="" />
        <vers num="2.6.25.6" edition=":x86_64" />
        <vers num="2.6.25.7" edition="" />
        <vers num="2.6.25.7" edition=":x86_64" />
        <vers num="2.6.25.8" edition="" />
        <vers num="2.6.25.8" edition=":x86_64" />
        <vers num="2.6.25.9" edition="" />
        <vers num="2.6.25.9" edition=":x86_64" />
        <vers num="2.6.26" />
        <vers num="2.6.26.1" />
        <vers num="2.6.26.2" />
        <vers num="2.6.26.3" />
        <vers num="2.6.26.4" />
        <vers num="2.6.26.5" />
        <vers num="2.6.27" />
        <vers num="2.6.28" />
        <vers prev="1" num="2.6.28.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0032" published="2009-01-27" name="CVE-2009-0032" modified="2009-01-28" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="6.9" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.4" CVSS_base_score="6.9">
    <desc>
      <descript source="cve">CUPS on Mandriva Linux 2008.0, 2008.1, 2009.0, Corporate Server (CS) 3.0 and 4.0, and Multi Network Firewall (MNF) 2.0 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/pdf.log temporary file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/48210" source="XF">cups-pdflog-symlink(48210)</ref>
      <ref url="http://www.securityfocus.com/bid/33418" source="BID">33418</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:029" source="MANDRIVA" adv="1">MDVSA-2009:029</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:028" source="MANDRIVA">MDVSA-2009:028</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:027" source="MANDRIVA" adv="1">MDVSA-2009:027</ref>
      <ref url="http://securitytracker.com/id?1021637" source="SECTRACK">1021637</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="cups">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0033" published="2009-06-05" name="CVE-2009-0033" modified="2011-09-06" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Apache Tomcat 4.1.0 through 4.1.39, 5.5.0 through 5.5.27, and 6.0.0 through 6.0.18, when the Java AJP connector and mod_jk load balancing are used, allows remote attackers to cause a denial of service (application outage) via a crafted request with invalid headers, related to temporary blocking of connectors that have encountered errors, as demonstrated by an error involving a malformed HTTP Host header.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2009/1496" source="VUPEN" patch="1" adv="1">ADV-2009-1496</ref>
      <ref url="http://www.securityfocus.com/bid/35193" source="BID" patch="1">35193</ref>
      <ref url="http://tomcat.apache.org/security-6.html" source="CONFIRM" patch="1" adv="1">http://tomcat.apache.org/security-6.html</ref>
      <ref url="http://tomcat.apache.org/security-5.html" source="CONFIRM" patch="1" adv="1">http://tomcat.apache.org/security-5.html</ref>
      <ref url="http://tomcat.apache.org/security-4.html" source="CONFIRM" patch="1" adv="1">http://tomcat.apache.org/security-4.html</ref>
      <ref url="http://svn.apache.org/viewvc?rev=781362&amp;view=rev" source="CONFIRM" patch="1" adv="1">http://svn.apache.org/viewvc?rev=781362&amp;view=rev</ref>
      <ref url="http://svn.apache.org/viewvc?rev=742915&amp;view=rev" source="CONFIRM" patch="1" adv="1">http://svn.apache.org/viewvc?rev=742915&amp;view=rev</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-November/msg01246.html" source="FEDORA">FEDORA-2009-11356</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-November/msg01216.html" source="FEDORA">FEDORA-2009-11352</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-November/msg01156.html" source="FEDORA">FEDORA-2009-11374</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/50928" source="XF">tomcat-ajp-dos(50928)</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/3056" source="VUPEN">ADV-2010-3056</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/3316" source="VUPEN">ADV-2009-3316</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1856" source="VUPEN">ADV-2009-1856</ref>
      <ref url="http://www.vmware.com/security/advisories/VMSA-2009-0016.html" source="CONFIRM">http://www.vmware.com/security/advisories/VMSA-2009-0016.html</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/507985/100/0/threaded" source="BUGTRAQ">20091120 VMSA-2009-0016 VMware vCenter and ESX update release and vMA patch release address multiple security issue in third party components</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/504044/100/0/threaded" source="BUGTRAQ">20090603 [SECURITY] CVE-2009-0033 Apache Tomcat DoS when using Java AJP connector</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2010:176" source="MANDRIVA">MDVSA-2010:176</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:138" source="MANDRIVA">MDVSA-2009:138</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:136" source="MANDRIVA">MDVSA-2009:136</ref>
      <ref url="http://www.debian.org/security/2011/dsa-2207" source="DEBIAN">DSA-2207</ref>
      <ref url="http://support.apple.com/kb/HT4077" source="CONFIRM">http://support.apple.com/kb/HT4077</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-263529-1" source="SUNALERT">263529</ref>
      <ref url="http://securitytracker.com/id?1022331" source="SECTRACK">1022331</ref>
      <ref url="http://secunia.com/advisories/42368" source="SECUNIA">42368</ref>
      <ref url="http://secunia.com/advisories/37460" source="SECUNIA">37460</ref>
      <ref url="http://secunia.com/advisories/35788" source="SECUNIA">35788</ref>
      <ref url="http://secunia.com/advisories/35685" source="SECUNIA">35685</ref>
      <ref url="http://secunia.com/advisories/35344" source="SECUNIA" adv="1">35344</ref>
      <ref url="http://secunia.com/advisories/35326" source="SECUNIA" adv="1">35326</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5739" source="OVAL">oval:org.mitre.oval:def:5739</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10231" source="OVAL">oval:org.mitre.oval:def:10231</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=129070310906557&amp;w=2" source="HP">SSRT100203</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=129070310906557&amp;w=2" source="HP">SSRT100203</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-07/msg00002.html" source="SUSE">SUSE-SR:2009:012</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Mar/msg00001.html" source="APPLE">APPLE-SA-2010-03-29-1</ref>
      <ref url="http://jvn.jp/en/jp/JVN87272440/index.html" source="JVN">JVN#87272440</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apache" name="tomcat">
        <vers num="4.1.0" />
        <vers num="4.1.1" />
        <vers num="4.1.10" />
        <vers num="4.1.11" />
        <vers num="4.1.12" />
        <vers num="4.1.13" />
        <vers num="4.1.14" />
        <vers num="4.1.15" />
        <vers num="4.1.16" />
        <vers num="4.1.17" />
        <vers num="4.1.18" />
        <vers num="4.1.19" />
        <vers num="4.1.2" />
        <vers num="4.1.20" />
        <vers num="4.1.21" />
        <vers num="4.1.22" />
        <vers num="4.1.23" />
        <vers num="4.1.24" />
        <vers num="4.1.25" />
        <vers num="4.1.26" />
        <vers num="4.1.27" />
        <vers num="4.1.28" />
        <vers num="4.1.29" />
        <vers num="4.1.3" edition="beta" />
        <vers num="4.1.30" />
        <vers num="4.1.31" />
        <vers num="4.1.32" />
        <vers num="4.1.33" />
        <vers num="4.1.34" />
        <vers num="4.1.35" />
        <vers num="4.1.36" />
        <vers num="4.1.37" />
        <vers num="4.1.38" />
        <vers num="4.1.39" />
        <vers num="4.1.4" />
        <vers num="4.1.5" />
        <vers num="4.1.6" />
        <vers num="4.1.7" />
        <vers num="4.1.8" />
        <vers num="4.1.9" edition="beta" />
        <vers num="5.5.0" />
        <vers num="5.5.1" />
        <vers num="5.5.10" />
        <vers num="5.5.11" />
        <vers num="5.5.12" />
        <vers num="5.5.13" />
        <vers num="5.5.14" />
        <vers num="5.5.15" />
        <vers num="5.5.16" />
        <vers num="5.5.17" />
        <vers num="5.5.18" />
        <vers num="5.5.19" />
        <vers num="5.5.2" />
        <vers num="5.5.20" />
        <vers num="5.5.21" />
        <vers num="5.5.22" />
        <vers num="5.5.23" />
        <vers num="5.5.24" />
        <vers num="5.5.25" />
        <vers num="5.5.26" />
        <vers num="5.5.27" />
        <vers num="5.5.3" />
        <vers num="5.5.4" />
        <vers num="5.5.5" />
        <vers num="5.5.6" />
        <vers num="5.5.7" />
        <vers num="5.5.8" />
        <vers num="5.5.9" />
        <vers num="6.0.0" />
        <vers num="6.0.1" />
        <vers num="6.0.10" />
        <vers num="6.0.11" />
        <vers num="6.0.12" />
        <vers num="6.0.13" />
        <vers num="6.0.14" />
        <vers num="6.0.15" />
        <vers num="6.0.16" />
        <vers num="6.0.2" />
        <vers num="6.0.3" />
        <vers num="6.0.4" />
        <vers num="6.0.5" />
        <vers num="6.0.6" />
        <vers num="6.0.7" />
        <vers num="6.0.8" />
        <vers num="6.0.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0034" published="2009-01-30" name="CVE-2009-0034" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="6.9" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.4" CVSS_base_score="6.9">
    <desc>
      <descript source="cve">parse.c in sudo 1.6.9p17 through 1.6.9p19 does not properly interpret a system group (aka %group) in the sudoers file during authorization decisions for a user who belongs to that group, which allows local users to leverage an applicable sudoers file and gain root privileges via a sudo command.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="https://issues.rpath.com/browse/RPL-2954" source="CONFIRM">https://issues.rpath.com/browse/RPL-2954</ref>
      <ref url="https://bugzilla.novell.com/show_bug.cgi?id=468923" source="CONFIRM">https://bugzilla.novell.com/show_bug.cgi?id=468923</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1865" source="VUPEN">ADV-2009-1865</ref>
      <ref url="http://www.vmware.com/security/advisories/VMSA-2009-0009.html" source="CONFIRM">http://www.vmware.com/security/advisories/VMSA-2009-0009.html</ref>
      <ref url="http://www.sudo.ws/cgi-bin/cvsweb/sudo/parse.c.diff?r1=1.160.2.21&amp;r2=1.160.2.22&amp;f=h" source="CONFIRM">http://www.sudo.ws/cgi-bin/cvsweb/sudo/parse.c.diff?r1=1.160.2.21&amp;r2=1.160.2.22&amp;f=h</ref>
      <ref url="http://www.securitytracker.com/id?1021688" source="SECTRACK">1021688</ref>
      <ref url="http://www.securityfocus.com/bid/33517" source="BID">33517</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/504849/100/0/threaded" source="BUGTRAQ">20090711 VMSA-2009-0009 ESX Service Console updates for udev, sudo, and curl</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/500546/100/0/threaded" source="BUGTRAQ">20090129 rPSA-2009-0021-1 sudo</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-0267.html" source="REDHAT">RHSA-2009:0267</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:033" source="MANDRIVA">MDVSA-2009:033</ref>
      <ref url="http://www.gratisoft.us/bugzilla/show_bug.cgi?id=327" source="CONFIRM">http://www.gratisoft.us/bugzilla/show_bug.cgi?id=327</ref>
      <ref url="http://wiki.rpath.com/Advisories:rPSA-2009-0021" source="CONFIRM">http://wiki.rpath.com/Advisories:rPSA-2009-0021</ref>
      <ref url="http://secunia.com/advisories/35766" source="SECUNIA">35766</ref>
      <ref url="http://secunia.com/advisories/33885" source="SECUNIA">33885</ref>
      <ref url="http://secunia.com/advisories/33840" source="SECUNIA">33840</ref>
      <ref url="http://secunia.com/advisories/33753" source="SECUNIA">33753</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6462" source="OVAL">oval:org.mitre.oval:def:6462</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10856" source="OVAL">oval:org.mitre.oval:def:10856</ref>
      <ref url="http://osvdb.org/51736" source="OSVDB">51736</ref>
      <ref url="http://lists.vmware.com/pipermail/security-announce/2009/000060.html" source="MLIST">[Security-announce] 20090710 VMSA-2009-0009 ESX Service Console updates for udev, sudo, and curl</ref>
    </refs>
    <vuln_soft>
      <prod vendor="todd_miller" name="sudo">
        <vers num="1.6.9_p17" />
        <vers num="1.6.9_p18" />
        <vers num="1.6.9_p19" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0036" published="2009-02-11" name="CVE-2009-0036" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="4.4" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.4" CVSS_base_score="4.4">
    <desc>
      <descript source="cve">Buffer overflow in the proxyReadClientSocket function in proxy/libvirt_proxy.c in libvirt_proxy 0.5.1 might allow local users to gain privileges by sending a portion of the header of a virProxyPacket packet, and then sending the remainder of the packet with crafted values in the header, related to use of uninitialized memory in a validation check.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="https://www.redhat.com/archives/libvir-list/2009-January/msg00728.html" source="MLIST" adv="1">[libvir-list] 20090128 Re: [libvirt] [PATCH] proxy: Fix use of uninitalized memory</ref>
      <ref url="https://www.redhat.com/archives/libvir-list/2009-January/msg00726.html" source="MLIST" adv="1">[libvir-list] 20090128 Re: [libvirt] [PATCH] proxy: Fix use of uninitalized memory</ref>
      <ref url="https://www.redhat.com/archives/libvir-list/2009-January/msg00699.html" source="MLIST" adv="1">[libvir-list] 20090127 [libvirt] [PATCH] proxy: Fix use of uninitalized memory</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=484947" source="CONFIRM" adv="1">https://bugzilla.redhat.com/show_bug.cgi?id=484947</ref>
      <ref url="http://www.securityfocus.com/bid/33724" source="BID">33724</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-0382.html" source="REDHAT">RHSA-2009:0382</ref>
      <ref url="http://secunia.com/advisories/34397" source="SECUNIA">34397</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10127" source="OVAL">oval:org.mitre.oval:def:10127</ref>
      <ref url="http://openwall.com/lists/oss-security/2009/02/10/8" source="MLIST">[oss-security] 20090210 libvirt_proxy heads up</ref>
      <ref url="http://git.et.redhat.com/?p=libvirt.git;a=commitdiff;h=2bb0657e28" source="CONFIRM" adv="1">http://git.et.redhat.com/?p=libvirt.git;a=commitdiff;h=2bb0657e28</ref>
    </refs>
    <vuln_soft>
      <prod vendor="libvirt" name="libvirt">
        <vers num="0.5.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0037" published="2009-03-04" name="CVE-2009-0037" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">The redirect implementation in curl and libcurl 5.11 through 7.19.3, when CURLOPT_FOLLOWLOCATION is enabled, accepts arbitrary Location values, which might allow remote HTTP servers to (1) trigger arbitrary requests to intranet servers, (2) read or overwrite arbitrary files via a redirect to a file: URL, or (3) execute arbitrary commands via a redirect to an scp: URL.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2009/0581" source="VUPEN" patch="1" adv="1">ADV-2009-0581</ref>
      <ref url="http://www.securityfocus.com/bid/33962" source="BID" patch="1">33962</ref>
      <ref url="http://curl.haxx.se/lxr/source/CHANGES" source="CONFIRM" patch="1" adv="1">http://curl.haxx.se/lxr/source/CHANGES</ref>
      <ref url="http://curl.haxx.se/docs/adv_20090303.html" source="CONFIRM" patch="1" adv="1">http://curl.haxx.se/docs/adv_20090303.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/49030" source="XF">curl-location-security-bypass(49030)</ref>
      <ref url="http://www.withdk.com/archives/Libcurl_arbitrary_file_access.pdf" source="MISC">http://www.withdk.com/archives/Libcurl_arbitrary_file_access.pdf</ref>
      <ref url="http://www.withdk.com/2009/03/03/curllibcurl-redirect-arbitrary-file-access/" source="MISC">http://www.withdk.com/2009/03/03/curllibcurl-redirect-arbitrary-file-access/</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1865" source="VUPEN">ADV-2009-1865</ref>
      <ref url="http://www.vmware.com/security/advisories/VMSA-2009-0009.html" source="CONFIRM">http://www.vmware.com/security/advisories/VMSA-2009-0009.html</ref>
      <ref url="http://www.ubuntu.com/usn/USN-726-1" source="UBUNTU">USN-726-1</ref>
      <ref url="http://www.securitytracker.com/id?1021783" source="SECTRACK">1021783</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/504849/100/0/threaded" source="BUGTRAQ">20090711 VMSA-2009-0009 ESX Service Console updates for udev, sudo, and curl</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/501757/100/0/threaded" source="BUGTRAQ">20090312 rPSA-2009-0042-1 curl</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-0341.html" source="REDHAT">RHSA-2009:0341</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1738" source="DEBIAN">DSA-1738</ref>
      <ref url="http://wiki.rpath.com/wiki/Advisories:rPSA-2009-0042" source="CONFIRM">http://wiki.rpath.com/wiki/Advisories:rPSA-2009-0042</ref>
      <ref url="http://support.apple.com/kb/HT4077" source="CONFIRM">http://support.apple.com/kb/HT4077</ref>
      <ref url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2009&amp;m=slackware-security.476602" source="SLACKWARE">SSA:2009-069-01</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200903-21.xml" source="GENTOO">GLSA-200903-21</ref>
      <ref url="http://secunia.com/advisories/35766" source="SECUNIA">35766</ref>
      <ref url="http://secunia.com/advisories/34399" source="SECUNIA">34399</ref>
      <ref url="http://secunia.com/advisories/34259" source="SECUNIA">34259</ref>
      <ref url="http://secunia.com/advisories/34255" source="SECUNIA">34255</ref>
      <ref url="http://secunia.com/advisories/34251" source="SECUNIA">34251</ref>
      <ref url="http://secunia.com/advisories/34237" source="SECUNIA">34237</ref>
      <ref url="http://secunia.com/advisories/34202" source="SECUNIA">34202</ref>
      <ref url="http://secunia.com/advisories/34138" source="SECUNIA" adv="1">34138</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6074" source="OVAL">oval:org.mitre.oval:def:6074</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11054" source="OVAL">oval:org.mitre.oval:def:11054</ref>
      <ref url="http://lists.vmware.com/pipermail/security-announce/2009/000060.html" source="MLIST">[Security-announce] 20090710 VMSA-2009-0009 ESX Service Console updates for udev, sudo, and curl</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-03/msg00001.html" source="SUSE">SUSE-SR:2009:006</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Mar/msg00001.html" source="APPLE">APPLE-SA-2010-03-29-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="curl" name="curl">
        <vers num="5.11" />
        <vers num="6.0" />
        <vers num="6.1beta" />
        <vers num="6.2" />
        <vers num="6.3" />
        <vers num="6.3.1" />
        <vers num="6.4" />
        <vers num="6.5" />
        <vers num="6.5.1" />
        <vers num="6.5.2" />
        <vers num="7.1" />
        <vers num="7.1.1" />
        <vers num="7.10" />
        <vers num="7.10.1" />
        <vers num="7.10.2" />
        <vers num="7.10.3" />
        <vers num="7.10.4" />
        <vers num="7.10.5" />
        <vers num="7.10.6" />
        <vers num="7.10.7" />
        <vers num="7.10.8" />
        <vers num="7.11.1" />
        <vers num="7.12" />
        <vers num="7.12.1" />
        <vers num="7.12.2" />
        <vers num="7.13" />
        <vers num="7.13.2" />
        <vers num="7.14" />
        <vers num="7.14.1" />
        <vers num="7.15" />
        <vers num="7.15.1" />
        <vers num="7.15.3" />
        <vers num="7.16.3" />
        <vers num="7.16.4" />
        <vers num="7.17" />
        <vers num="7.18" />
        <vers num="7.19.3" />
        <vers num="7.2" />
        <vers num="7.2.1" />
        <vers num="7.3" />
        <vers num="7.4" />
        <vers num="7.4.1" />
        <vers num="7.4.2" />
        <vers num="7.5" />
        <vers num="7.5.1" />
        <vers num="7.5.2" />
        <vers num="7.6" />
        <vers num="7.6.1" />
        <vers num="7.7" />
        <vers num="7.7.1" />
        <vers num="7.7.2" />
        <vers num="7.7.3" />
        <vers num="7.8" />
        <vers num="7.8.1" />
        <vers num="7.8.2" />
        <vers num="7.9" />
        <vers num="7.9.1" />
        <vers num="7.9.2" />
        <vers num="7.9.3" />
        <vers num="7.9.4" />
        <vers num="7.9.5" />
        <vers num="7.9.6" />
        <vers num="7.9.7" />
        <vers num="7.9.8" />
      </prod>
      <prod vendor="curl" name="libcurl">
        <vers num="5.11" />
        <vers num="7.12" />
        <vers num="7.12.1" />
        <vers num="7.12.2" />
        <vers num="7.12.3" />
        <vers num="7.13" />
        <vers num="7.13.1" />
        <vers num="7.13.2" />
        <vers num="7.14" />
        <vers num="7.14.1" />
        <vers num="7.15" />
        <vers num="7.15.1" />
        <vers num="7.15.2" />
        <vers num="7.15.3" />
        <vers num="7.16.3" />
        <vers num="7.19.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0038" published="2009-04-17" name="CVE-2009-0038" modified="2009-04-28" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in the web administration console in Apache Geronimo Application Server 2.1 through 2.1.3 allow remote attackers to inject arbitrary web script or HTML via the (1) name, (2) ip, (3) username, or (4) description parameter to console/portal/Server/Monitoring; or (5) the PATH_INFO to the default URI under console/portal/.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://issues.apache.org/jira/browse/GERONIMO-4597" source="CONFIRM" patch="1">http://issues.apache.org/jira/browse/GERONIMO-4597</ref>
      <ref url="http://geronimo.apache.org/21x-security-report.html#2.1.xSecurityReport-214" source="CONFIRM" patch="1" adv="1">http://geronimo.apache.org/21x-security-report.html#2.1.xSecurityReport-214</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1089" source="VUPEN">ADV-2009-1089</ref>
      <ref url="http://www.securityfocus.com/bid/34562" source="BID">34562</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/502734/100/0/threaded" source="BUGTRAQ">20090416 [DSECRG-09-019] Apache Geronimo - XSS vulnerabilities.txt</ref>
      <ref url="http://secunia.com/advisories/34715" source="SECUNIA">34715</ref>
      <ref url="http://dsecrg.com/pages/vul/show.php?id=119" source="MISC">http://dsecrg.com/pages/vul/show.php?id=119</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apache" name="geronimo">
        <vers num="2.1" />
        <vers num="2.1.1" />
        <vers num="2.1.2" />
        <vers num="2.1.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0039" published="2009-04-17" name="CVE-2009-0039" modified="2009-04-28" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple cross-site request forgery (CSRF) vulnerabilities in the web administration console in Apache Geronimo Application Server 2.1 through 2.1.3 allow remote attackers to hijack the authentication of administrators for requests that (1) change the web administration password, (2) upload applications, and perform unspecified other administrative actions, as demonstrated by (3) a Shutdown request to console/portal//Server/Shutdown.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2009/1089" source="VUPEN">ADV-2009-1089</ref>
      <ref url="http://www.securityfocus.com/bid/34562" source="BID">34562</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/502735/100/0/threaded" source="BUGTRAQ">20090416 [DSECRG-09-020] Apache Geronimo - XSRF vulnerabilities</ref>
      <ref url="http://secunia.com/advisories/34715" source="SECUNIA">34715</ref>
      <ref url="http://issues.apache.org/jira/browse/GERONIMO-4597" source="CONFIRM" adv="1">http://issues.apache.org/jira/browse/GERONIMO-4597</ref>
      <ref url="http://geronimo.apache.org/21x-security-report.html#2.1.xSecurityReport-214" source="CONFIRM" adv="1">http://geronimo.apache.org/21x-security-report.html#2.1.xSecurityReport-214</ref>
      <ref url="http://dsecrg.com/pages/vul/show.php?id=120" source="MISC">http://dsecrg.com/pages/vul/show.php?id=120</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apache" name="geronimo">
        <vers num="2.1" />
        <vers num="2.1.1" />
        <vers num="2.1.2" />
        <vers num="2.1.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0040" published="2009-02-22" name="CVE-2009-0040" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">The PNG reference library (aka libpng) before 1.0.43, and 1.2.x before 1.2.35, as used in pngcrush and other applications, allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PNG file that triggers a free of an uninitialized pointer in (1) the png_read_png function, (2) pCAL chunk handling, or (3) setup of 16-bit gamma tables.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-218A.html" source="CERT">TA09-218A</ref>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-133A.html" source="CERT">TA09-133A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/649212" source="CERT-VN">VU#649212</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-March/msg00771.html" source="FEDORA">FEDORA-2009-2884</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-March/msg00769.html" source="FEDORA">FEDORA-2009-2882</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-March/msg00412.html" source="FEDORA">FEDORA-2009-1976</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-March/msg00272.html" source="FEDORA">FEDORA-2009-2045</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/48819" source="XF">libpng-pointer-arrays-code-execution(48819)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/2172" source="VUPEN">ADV-2009-2172</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1621" source="VUPEN">ADV-2009-1621</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1560" source="VUPEN">ADV-2009-1560</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1522" source="VUPEN">ADV-2009-1522</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1462" source="VUPEN">ADV-2009-1462</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1451" source="VUPEN">ADV-2009-1451</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1297" source="VUPEN">ADV-2009-1297</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0632" source="VUPEN">ADV-2009-0632</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0473" source="VUPEN">ADV-2009-0473</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0469" source="VUPEN">ADV-2009-0469</ref>
      <ref url="http://www.vmware.com/security/advisories/VMSA-2009-0007.html" source="CONFIRM">http://www.vmware.com/security/advisories/VMSA-2009-0007.html</ref>
      <ref url="http://www.securityfocus.com/bid/33990" source="BID">33990</ref>
      <ref url="http://www.securityfocus.com/bid/33827" source="BID">33827</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/505990/100/0/threaded" source="BUGTRAQ">20090821 VMSA-2009-0010 VMware Hosted products update libpng and Apache HTTP Server</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/503912/100/0/threaded" source="BUGTRAQ">20090529 VMSA-2009-0007 VMware Hosted products and ESX and ESXi patches resolve security issues</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/501767/100/0/threaded" source="BUGTRAQ">20090312 rPSA-2009-0046-1 libpng</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-0340.html" source="REDHAT">RHSA-2009:0340</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-0333.html" source="REDHAT">RHSA-2009:0333</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-0325.html" source="REDHAT">RHSA-2009:0325</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-0315.html" source="REDHAT">RHSA-2009:0315</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:083" source="MANDRIVA">MDVSA-2009:083</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:075" source="MANDRIVA">MDVSA-2009:075</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:051" source="MANDRIVA">MDVSA-2009:051</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1830" source="DEBIAN">DSA-1830</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1750" source="DEBIAN">DSA-1750</ref>
      <ref url="http://wiki.rpath.com/Advisories:rPSA-2009-0046" source="CONFIRM">http://wiki.rpath.com/Advisories:rPSA-2009-0046</ref>
      <ref url="http://support.avaya.com/japple/css/japple?temp.documentID=366362&amp;temp.productID=154235&amp;temp.releaseID=361845&amp;temp.bucketID=126655&amp;PAGE=Document" source="CONFIRM">http://support.avaya.com/japple/css/japple?temp.documentID=366362&amp;temp.productID=154235&amp;temp.releaseID=361845&amp;temp.bucketID=126655&amp;PAGE=Document</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2009-208.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2009-208.htm</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2009-069.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2009-069.htm</ref>
      <ref url="http://support.apple.com/kb/HT3757" source="CONFIRM">http://support.apple.com/kb/HT3757</ref>
      <ref url="http://support.apple.com/kb/HT3639" source="CONFIRM">http://support.apple.com/kb/HT3639</ref>
      <ref url="http://support.apple.com/kb/HT3613" source="CONFIRM">http://support.apple.com/kb/HT3613</ref>
      <ref url="http://support.apple.com/kb/HT3549" source="CONFIRM">http://support.apple.com/kb/HT3549</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-77-1020521.1-1" source="SUNALERT">1020521</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-259989-1" source="SUNALERT">259989</ref>
      <ref url="http://sourceforge.net/project/shownotes.php?group_id=1689&amp;release_id=662441" source="CONFIRM">http://sourceforge.net/project/shownotes.php?group_id=1689&amp;release_id=662441</ref>
      <ref url="http://sourceforge.net/mailarchive/message.php?msg_name=e56ccc8f0902181726i200f4bf0n20d919473ec409b7%40mail.gmail.com" source="MLIST">[png-mng-implement] 20090219 libpng-1.2.35 and libpng-1.0.43 fix security vulnerability</ref>
      <ref url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2009&amp;m=slackware-security.433952" source="SLACKWARE">SSA:2009-083-03</ref>
      <ref url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2009&amp;m=slackware-security.405420" source="SLACKWARE">SSA:2009-083-02</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200903-28.xml" source="GENTOO">GLSA-200903-28</ref>
      <ref url="http://secunia.com/advisories/36096" source="SECUNIA">36096</ref>
      <ref url="http://secunia.com/advisories/35386" source="SECUNIA">35386</ref>
      <ref url="http://secunia.com/advisories/35379" source="SECUNIA">35379</ref>
      <ref url="http://secunia.com/advisories/35302" source="SECUNIA">35302</ref>
      <ref url="http://secunia.com/advisories/35258" source="SECUNIA">35258</ref>
      <ref url="http://secunia.com/advisories/35074" source="SECUNIA">35074</ref>
      <ref url="http://secunia.com/advisories/34464" source="SECUNIA">34464</ref>
      <ref url="http://secunia.com/advisories/34462" source="SECUNIA">34462</ref>
      <ref url="http://secunia.com/advisories/34388" source="SECUNIA">34388</ref>
      <ref url="http://secunia.com/advisories/34324" source="SECUNIA">34324</ref>
      <ref url="http://secunia.com/advisories/34320" source="SECUNIA">34320</ref>
      <ref url="http://secunia.com/advisories/34272" source="SECUNIA">34272</ref>
      <ref url="http://secunia.com/advisories/34265" source="SECUNIA">34265</ref>
      <ref url="http://secunia.com/advisories/34210" source="SECUNIA">34210</ref>
      <ref url="http://secunia.com/advisories/34152" source="SECUNIA">34152</ref>
      <ref url="http://secunia.com/advisories/34145" source="SECUNIA">34145</ref>
      <ref url="http://secunia.com/advisories/34143" source="SECUNIA">34143</ref>
      <ref url="http://secunia.com/advisories/34140" source="SECUNIA">34140</ref>
      <ref url="http://secunia.com/advisories/34137" source="SECUNIA">34137</ref>
      <ref url="http://secunia.com/advisories/33976" source="SECUNIA" adv="1">33976</ref>
      <ref url="http://secunia.com/advisories/33970" source="SECUNIA" adv="1">33970</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6458" source="OVAL">oval:org.mitre.oval:def:6458</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10316" source="OVAL">oval:org.mitre.oval:def:10316</ref>
      <ref url="http://lists.vmware.com/pipermail/security-announce/2009/000062.html" source="MLIST">[security-announce] 20090820 VMSA-2009-0010 VMware Hosted products update libpng and Apache HTTP Server</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-04/msg00009.html" source="SUSE">SUSE-SA:2009:023</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-03/msg00002.html" source="SUSE">SUSE-SA:2009:012</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-03/msg00000.html" source="SUSE">SUSE-SR:2009:005</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2009/May/msg00002.html" source="APPLE">APPLE-SA-2009-05-12</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2009/Jun/msg00005.html" source="APPLE">APPLE-SA-2009-06-17-1</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2009/jun/msg00002.html" source="APPLE">APPLE-SA-2009-06-08-1</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2009/Aug/msg00001.html" source="APPLE">APPLE-SA-2009-08-05-1</ref>
      <ref url="http://downloads.sourceforge.net/libpng/libpng-1.2.34-ADVISORY.txt" source="CONFIRM">http://downloads.sourceforge.net/libpng/libpng-1.2.34-ADVISORY.txt</ref>
      <ref url="ftp://ftp.simplesystems.org/pub/png/src/libpng-1.2.34-ADVISORY.txt" source="CONFIRM" adv="1">ftp://ftp.simplesystems.org/pub/png/src/libpng-1.2.34-ADVISORY.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="libpng" name="libpng">
        <vers num="0.89c" />
        <vers num="0.95" />
        <vers num="1.0.0" />
        <vers num="1.0.1" />
        <vers num="1.0.10" edition="beta1" />
        <vers num="1.0.10" edition="rc1" />
        <vers num="1.0.11" edition="beta1" />
        <vers num="1.0.11" edition="beta2" />
        <vers num="1.0.11" edition="beta3" />
        <vers num="1.0.11" edition="rc1" />
        <vers num="1.0.12" edition="beta1" />
        <vers num="1.0.12" edition="rc1" />
        <vers num="1.0.13" />
        <vers num="1.0.14" />
        <vers num="1.0.15" edition="rc1" />
        <vers num="1.0.15" edition="rc2" />
        <vers num="1.0.15" edition="rc3" />
        <vers num="1.0.16" />
        <vers num="1.0.17" edition="rc1" />
        <vers num="1.0.18" />
        <vers num="1.0.19" edition="rc1" />
        <vers num="1.0.19" edition="rc2" />
        <vers num="1.0.19" edition="rc3" />
        <vers num="1.0.19" edition="rc5" />
        <vers num="1.0.2" />
        <vers num="1.0.20" />
        <vers num="1.0.21" edition="rc1" />
        <vers num="1.0.21" edition="rc2" />
        <vers num="1.0.22" edition="rc1" />
        <vers num="1.0.23" edition="rc1" />
        <vers num="1.0.23" edition="rc2" />
        <vers num="1.0.23" edition="rc3" />
        <vers num="1.0.23" edition="rc4" />
        <vers num="1.0.23" edition="rc5" />
        <vers num="1.0.24" edition="rc1" />
        <vers num="1.0.25" edition="rc1" />
        <vers num="1.0.25" edition="rc2" />
        <vers num="1.0.26" />
        <vers num="1.0.27" edition="rc1" />
        <vers num="1.0.27" edition="rc2" />
        <vers num="1.0.27" edition="rc3" />
        <vers num="1.0.27" edition="rc4" />
        <vers num="1.0.27" edition="rc5" />
        <vers num="1.0.27" edition="rc6" />
        <vers num="1.0.28" edition="rc2" />
        <vers num="1.0.28" edition="rc3" />
        <vers num="1.0.28" edition="rc4" />
        <vers num="1.0.28" edition="rc5" />
        <vers num="1.0.28" edition="rc6" />
        <vers num="1.0.29" edition="beta1" />
        <vers num="1.0.29" edition="rc1" />
        <vers num="1.0.29" edition="rc2" />
        <vers num="1.0.29" edition="rc3" />
        <vers num="1.0.3" />
        <vers num="1.0.30" />
        <vers num="1.0.31" />
        <vers num="1.0.32" />
        <vers num="1.0.33" />
        <vers num="1.0.34" />
        <vers num="1.0.35" />
        <vers num="1.0.37" />
        <vers num="1.0.38" />
        <vers num="1.0.39" />
        <vers num="1.0.40" />
        <vers num="1.0.41" />
        <vers prev="1" num="1.0.42" />
        <vers num="1.0.5" />
        <vers num="1.0.6" edition="a" />
        <vers num="1.0.6" edition="d" />
        <vers num="1.0.6" edition="e" />
        <vers num="1.0.6" edition="f" />
        <vers num="1.0.6" edition="g" />
        <vers num="1.0.6" edition="h" />
        <vers num="1.0.6" edition="i" />
        <vers num="1.0.6" edition="j" />
        <vers num="1.0.7" edition="beta11" />
        <vers num="1.0.7" edition="beta12" />
        <vers num="1.0.7" edition="beta13" />
        <vers num="1.0.7" edition="beta14" />
        <vers num="1.0.7" edition="beta15" />
        <vers num="1.0.7" edition="beta16" />
        <vers num="1.0.7" edition="beta17" />
        <vers num="1.0.7" edition="beta18" />
        <vers num="1.0.7" edition="rc1" />
        <vers num="1.0.7" edition="rc2" />
        <vers num="1.0.8" edition="beta1" />
        <vers num="1.0.8" edition="beta2" />
        <vers num="1.0.8" edition="beta3" />
        <vers num="1.0.8" edition="beta4" />
        <vers num="1.0.8" edition="rc1" />
        <vers num="1.0.9" edition="beta1" />
        <vers num="1.0.9" edition="beta10" />
        <vers num="1.0.9" edition="beta2" />
        <vers num="1.0.9" edition="beta3" />
        <vers num="1.0.9" edition="beta4" />
        <vers num="1.0.9" edition="beta5" />
        <vers num="1.0.9" edition="beta6" />
        <vers num="1.0.9" edition="beta7" />
        <vers num="1.0.9" edition="beta8" />
        <vers num="1.0.9" edition="beta9" />
        <vers num="1.0.9" edition="rc1" />
        <vers num="1.0.9" edition="rc2" />
        <vers num="1.2.0" edition="beta1" />
        <vers num="1.2.0" edition="beta2" />
        <vers num="1.2.0" edition="beta3" />
        <vers num="1.2.0" edition="beta4" />
        <vers num="1.2.0" edition="beta5" />
        <vers num="1.2.0" edition="rc1" />
        <vers num="1.2.1" edition="beta1" />
        <vers num="1.2.1" edition="beta2" />
        <vers num="1.2.1" edition="beta3" />
        <vers num="1.2.1" edition="beta4" />
        <vers num="1.2.1" edition="rc1" />
        <vers num="1.2.1" edition="rc2" />
        <vers num="1.2.10" edition="beta1" />
        <vers num="1.2.10" edition="beta2" />
        <vers num="1.2.10" edition="beta3" />
        <vers num="1.2.10" edition="beta4" />
        <vers num="1.2.10" edition="beta5" />
        <vers num="1.2.10" edition="beta6" />
        <vers num="1.2.10" edition="beta7" />
        <vers num="1.2.10" edition="rc1" />
        <vers num="1.2.10" edition="rc2" />
        <vers num="1.2.10" edition="rc3" />
        <vers num="1.2.11" edition="beta1" />
        <vers num="1.2.11" edition="beta2" />
        <vers num="1.2.11" edition="beta3" />
        <vers num="1.2.11" edition="beta4" />
        <vers num="1.2.11" edition="rc1" />
        <vers num="1.2.11" edition="rc2" />
        <vers num="1.2.11" edition="rc3" />
        <vers num="1.2.11" edition="rc5" />
        <vers num="1.2.13" edition="beta1" />
        <vers num="1.2.13" edition="rc1" />
        <vers num="1.2.13" edition="rc2" />
        <vers num="1.2.14" edition="beta1" />
        <vers num="1.2.14" edition="beta2" />
        <vers num="1.2.14" edition="rc1" />
        <vers num="1.2.15" edition="beta1" />
        <vers num="1.2.15" edition="beta2" />
        <vers num="1.2.15" edition="beta3" />
        <vers num="1.2.15" edition="beta4" />
        <vers num="1.2.15" edition="beta5" />
        <vers num="1.2.15" edition="beta6" />
        <vers num="1.2.15" edition="rc1" />
        <vers num="1.2.15" edition="rc2" />
        <vers num="1.2.15" edition="rc3" />
        <vers num="1.2.15" edition="rc4" />
        <vers num="1.2.15" edition="rc5" />
        <vers num="1.2.16" edition="beta1" />
        <vers num="1.2.16" edition="beta2" />
        <vers num="1.2.16" edition="rc1" />
        <vers num="1.2.17" edition="beta1" />
        <vers num="1.2.17" edition="beta2" />
        <vers num="1.2.17" edition="rc1" />
        <vers num="1.2.17" edition="rc2" />
        <vers num="1.2.17" edition="rc3" />
        <vers num="1.2.17" edition="rc4" />
        <vers num="1.2.18" />
        <vers num="1.2.19" edition="beta1" />
        <vers num="1.2.19" edition="beta10" />
        <vers num="1.2.19" edition="beta11" />
        <vers num="1.2.19" edition="beta12" />
        <vers num="1.2.19" edition="beta13" />
        <vers num="1.2.19" edition="beta14" />
        <vers num="1.2.19" edition="beta15" />
        <vers num="1.2.19" edition="beta16" />
        <vers num="1.2.19" edition="beta17" />
        <vers num="1.2.19" edition="beta18" />
        <vers num="1.2.19" edition="beta19" />
        <vers num="1.2.19" edition="beta2" />
        <vers num="1.2.19" edition="beta20" />
        <vers num="1.2.19" edition="beta21" />
        <vers num="1.2.19" edition="beta22" />
        <vers num="1.2.19" edition="beta23" />
        <vers num="1.2.19" edition="beta24" />
        <vers num="1.2.19" edition="beta25" />
        <vers num="1.2.19" edition="beta26" />
        <vers num="1.2.19" edition="beta27" />
        <vers num="1.2.19" edition="beta28" />
        <vers num="1.2.19" edition="beta29" />
        <vers num="1.2.19" edition="beta3" />
        <vers num="1.2.19" edition="beta30" />
        <vers num="1.2.19" edition="beta31" />
        <vers num="1.2.19" edition="beta32" />
        <vers num="1.2.19" edition="beta33" />
        <vers num="1.2.19" edition="beta4" />
        <vers num="1.2.19" edition="beta5" />
        <vers num="1.2.19" edition="beta6" />
        <vers num="1.2.19" edition="beta7" />
        <vers num="1.2.19" edition="beta8" />
        <vers num="1.2.19" edition="beta9" />
        <vers num="1.2.19" edition="rc1" />
        <vers num="1.2.19" edition="rc2" />
        <vers num="1.2.19" edition="rc3" />
        <vers num="1.2.19" edition="rc4" />
        <vers num="1.2.19" edition="rc5" />
        <vers num="1.2.19" edition="rc6" />
        <vers num="1.2.2" edition="beta1" />
        <vers num="1.2.2" edition="beta2" />
        <vers num="1.2.2" edition="beta3" />
        <vers num="1.2.2" edition="beta4" />
        <vers num="1.2.2" edition="beta5" />
        <vers num="1.2.2" edition="beta6" />
        <vers num="1.2.2" edition="rc1" />
        <vers num="1.2.20" edition="rc1" />
        <vers num="1.2.20" edition="rc2" />
        <vers num="1.2.20" edition="rc3" />
        <vers num="1.2.20" edition="rc4" />
        <vers num="1.2.20" edition="rc5" />
        <vers num="1.2.20" edition="rc6" />
        <vers num="1.2.21" edition="beta1" />
        <vers num="1.2.21" edition="beta2" />
        <vers num="1.2.21" edition="rc1" />
        <vers num="1.2.21" edition="rc2" />
        <vers num="1.2.21" edition="rc3" />
        <vers num="1.2.22" edition="beta1" />
        <vers num="1.2.22" edition="beta2" />
        <vers num="1.2.22" edition="beta3" />
        <vers num="1.2.22" edition="beta4" />
        <vers num="1.2.22" edition="rc1" />
        <vers num="1.2.23" />
        <vers num="1.2.24" />
        <vers num="1.2.25" edition="beta03" />
        <vers num="1.2.25" edition="beta04" />
        <vers num="1.2.25" edition="beta05" />
        <vers num="1.2.25" edition="beta06" />
        <vers num="1.2.25" edition="rc01" />
        <vers num="1.2.25" edition="rc02" />
        <vers num="1.2.26" edition="beta01" />
        <vers num="1.2.26" edition="beta02" />
        <vers num="1.2.26" edition="beta03" />
        <vers num="1.2.26" edition="beta04" />
        <vers num="1.2.26" edition="beta05" />
        <vers num="1.2.26" edition="beta06" />
        <vers num="1.2.26" edition="rc01" />
        <vers num="1.2.27" />
        <vers num="1.2.28" />
        <vers num="1.2.29" />
        <vers num="1.2.3" edition="rc1" />
        <vers num="1.2.3" edition="rc2" />
        <vers num="1.2.3" edition="rc3" />
        <vers num="1.2.3" edition="rc4" />
        <vers num="1.2.3" edition="rc5" />
        <vers num="1.2.3" edition="rc6" />
        <vers num="1.2.30" />
        <vers num="1.2.31" />
        <vers num="1.2.32" />
        <vers num="1.2.33" />
        <vers num="1.2.34" />
        <vers num="1.2.4" edition="beta1" />
        <vers num="1.2.4" edition="beta2" />
        <vers num="1.2.4" edition="beta3" />
        <vers num="1.2.4" edition="rc1" />
        <vers num="1.2.5" edition="beta1" />
        <vers num="1.2.5" edition="beta2" />
        <vers num="1.2.5" edition="beta3" />
        <vers num="1.2.5" edition="rc1" />
        <vers num="1.2.5" edition="rc2" />
        <vers num="1.2.5" edition="rc3" />
        <vers num="1.2.6" edition="beta1" />
        <vers num="1.2.6" edition="beta2" />
        <vers num="1.2.6" edition="beta3" />
        <vers num="1.2.6" edition="beta4" />
        <vers num="1.2.6" edition="rc1" />
        <vers num="1.2.6" edition="rc2" />
        <vers num="1.2.6" edition="rc3" />
        <vers num="1.2.6" edition="rc4" />
        <vers num="1.2.6" edition="rc5" />
        <vers num="1.2.7" edition="beta1" />
        <vers num="1.2.7" edition="beta2" />
        <vers num="1.2.8" edition="beta1" />
        <vers num="1.2.8" edition="beta2" />
        <vers num="1.2.8" edition="beta3" />
        <vers num="1.2.8" edition="beta4" />
        <vers num="1.2.8" edition="beta5" />
        <vers num="1.2.8" edition="rc1" />
        <vers num="1.2.8" edition="rc2" />
        <vers num="1.2.8" edition="rc3" />
        <vers num="1.2.8" edition="rc4" />
        <vers num="1.2.8" edition="rc5" />
        <vers num="1.2.9" edition="beta1" />
        <vers num="1.2.9" edition="beta10" />
        <vers num="1.2.9" edition="beta2" />
        <vers num="1.2.9" edition="beta3" />
        <vers num="1.2.9" edition="beta4" />
        <vers num="1.2.9" edition="beta5" />
        <vers num="1.2.9" edition="beta6" />
        <vers num="1.2.9" edition="beta7" />
        <vers num="1.2.9" edition="beta8" />
        <vers num="1.2.9" edition="beta9" />
        <vers num="1.2.9" edition="rc1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0041" published="2009-01-14" name="CVE-2009-0041" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">IAX2 in Asterisk Open Source 1.2.x before 1.2.31, 1.4.x before 1.4.23-rc4, and 1.6.x before 1.6.0.3-rc2; Business Edition A.x.x, B.x.x before B.2.5.7, C.1.x.x before C.1.10.4, and C.2.x.x before C.2.1.2.1; and s800i 1.2.x before 1.3.0 responds differently to a failed login attempt depending on whether the user account exists, which allows remote attackers to enumerate valid usernames.</descript>
      <descript source="nvd">Vendor Advisory: http://downloads.digium.com/pub/security/AST-2009-001.html</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/33174" source="BID" patch="1">33174</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0063" source="VUPEN">ADV-2009-0063</ref>
      <ref url="http://www.securitytracker.com/id?1021549" source="SECTRACK">1021549</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/499884/100/0/threaded" source="BUGTRAQ">20090108 AST-2009-001: Information leak in IAX2 authentication</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1952" source="DEBIAN">DSA-1952</ref>
      <ref url="http://securityreason.com/securityalert/4910" source="SREASON">4910</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200905-01.xml" source="GENTOO">GLSA-200905-01</ref>
      <ref url="http://secunia.com/advisories/37677" source="SECUNIA">37677</ref>
      <ref url="http://secunia.com/advisories/34982" source="SECUNIA">34982</ref>
      <ref url="http://secunia.com/advisories/33453" source="SECUNIA">33453</ref>
      <ref url="http://downloads.digium.com/pub/security/AST-2009-001.html" source="CONFIRM">http://downloads.digium.com/pub/security/AST-2009-001.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="asterisk" name="asterisk_business_edition">
        <vers num="a" />
        <vers num="b.1.3.2" />
        <vers num="b.1.3.3" />
        <vers num="b.2.2.0" />
        <vers num="b.2.2.1" />
        <vers num="b.2.3.1" />
        <vers num="b.2.3.2" />
        <vers num="b.2.3.3" />
        <vers num="b.2.3.4" />
        <vers num="b.2.3.5" />
        <vers num="b.2.3.6" />
        <vers num="b.2.5.0" />
        <vers num="b.2.5.1" />
        <vers prev="1" num="b.2.5.2" />
        <vers num="b.2.5.3" />
        <vers prev="1" num="c.1.0" edition="beta7" />
        <vers prev="1" num="c.1.0" edition="beta8" />
      </prod>
      <prod vendor="asterisk" name="open_source">
        <vers num="1.2.0" edition="beta1" />
        <vers num="1.2.0" edition="beta2" />
        <vers num="1.2.0" edition="rc1" />
        <vers num="1.2.0" edition="rc2" />
        <vers num="1.2.0beta1" />
        <vers num="1.2.0beta2" />
        <vers num="1.2.1" />
        <vers num="1.2.10" edition="netsec" />
        <vers num="1.2.11" edition="netsec" />
        <vers num="1.2.12" edition="netsec" />
        <vers num="1.2.12.1" edition="netsec" />
        <vers num="1.2.13" edition="netsec" />
        <vers num="1.2.14" edition="netsec" />
        <vers num="1.2.15" edition="netsec" />
        <vers num="1.2.16" edition="netsec" />
        <vers num="1.2.17" edition="netsec" />
        <vers num="1.2.18" edition="netsec" />
        <vers num="1.2.19" edition="netsec" />
        <vers num="1.2.2" edition="netsec" />
        <vers num="1.2.20" edition="netsec" />
        <vers num="1.2.21" edition="netsec" />
        <vers num="1.2.21.1" edition="netsec" />
        <vers num="1.2.22" edition="netsec" />
        <vers num="1.2.23" edition="netsec" />
        <vers num="1.2.24" edition="netsec" />
        <vers num="1.2.25" edition="netsec" />
        <vers num="1.2.26" edition="netsec" />
        <vers num="1.2.26.1" edition="netsec" />
        <vers num="1.2.26.2" edition="netsec" />
        <vers num="1.2.27" />
        <vers num="1.2.28" />
        <vers num="1.2.29" />
        <vers num="1.2.3" edition="netsec" />
        <vers num="1.2.30" />
        <vers num="1.2.30.2" />
        <vers num="1.2.30.3" />
        <vers prev="1" num="1.2.30.4" />
        <vers num="1.4.0" edition="beta2" />
        <vers num="1.4.0" edition="beta3" />
        <vers num="1.4.0" edition="beta4" />
        <vers num="1.4.1" />
        <vers num="1.4.10" />
        <vers num="1.4.10.1" />
        <vers num="1.4.11" />
        <vers num="1.4.12" />
        <vers num="1.4.12.1" />
        <vers num="1.4.13" />
        <vers num="1.4.14" />
        <vers num="1.4.15" />
        <vers num="1.4.16" />
        <vers num="1.4.16.1" />
        <vers num="1.4.16.2" />
        <vers num="1.4.17" />
        <vers num="1.4.18" />
        <vers num="1.4.18.1" />
        <vers num="1.4.19" edition="rc1" />
        <vers num="1.4.19" edition="rc2" />
        <vers num="1.4.19" edition="rc3" />
        <vers num="1.4.19" edition="rc4" />
        <vers num="1.4.19.1" />
        <vers num="1.4.19.2" />
        <vers num="1.4.2" />
        <vers num="1.4.20" edition="rc1" />
        <vers num="1.4.20" edition="rc2" />
        <vers num="1.4.20" edition="rc3" />
        <vers num="1.4.21" edition="rc1" />
        <vers num="1.4.21" edition="rc2" />
        <vers num="1.4.21.1" />
        <vers num="1.4.21.2" />
        <vers num="1.4.22" edition="rc3" />
        <vers num="1.4.22" edition="rc4" />
        <vers num="1.4.22.1" />
        <vers num="1.4.22.2" />
        <vers prev="1" num="1.4.23" edition="rc1" />
        <vers prev="1" num="1.4.23" edition="rc2" />
        <vers prev="1" num="1.4.23" edition="rc3" />
        <vers num="1.4.3" />
        <vers num="1.4.4" />
        <vers num="1.4.5" />
        <vers num="1.4.6" />
        <vers num="1.4.7" />
        <vers num="1.4.7.1" />
        <vers num="1.4.8" />
        <vers num="1.4.9" />
        <vers num="1.4_revision_95946" />
        <vers num="1.4beta" />
        <vers num="1.6.0" edition="beta1" />
        <vers num="1.6.0" edition="beta2" />
        <vers num="1.6.0" edition="beta3" />
        <vers num="1.6.0" edition="beta4" />
        <vers num="1.6.0" edition="beta5" />
        <vers num="1.6.0" edition="beta7" />
        <vers num="1.6.0" edition="beta7.1" />
        <vers num="1.6.0" edition="beta8" />
        <vers num="1.6.0" edition="beta9" />
        <vers num="1.6.0" edition="rc4" />
        <vers num="1.6.0" edition="rc5" />
        <vers num="1.6.0" edition="rc6" />
        <vers num="1.6.0.1" />
        <vers num="1.6.0.2" />
        <vers prev="1" num="1.6.0.3" edition="rc1" />
      </prod>
      <prod vendor="asterisk" name="s800i_appliance">
        <vers num="1.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0042" published="2009-01-27" name="CVE-2009-0042" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Multiple unspecified vulnerabilities in the Arclib library (arclib.dll) before 7.3.0.15 in the CA Anti-Virus engine for CA Anti-Virus for the Enterprise 7.1, r8, and r8.1; Anti-Virus 2007 v8 and 2008; Internet Security Suite 2007 v3 and 2008; and other CA products allow remote attackers to bypass virus detection via a malformed archive file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/48261" source="XF">ca-antivirus-engine-security-bypass(48261)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0270" source="VUPEN">ADV-2009-0270</ref>
      <ref url="http://www.securitytracker.com/id?1021639" source="SECTRACK">1021639</ref>
      <ref url="http://www.securityfocus.com/bid/33464" source="BID">33464</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/500417/100/0/threaded" source="BUGTRAQ">20090127 CA20090126-01: CA Anti-Virus Engine Detection Evasion Multiple Vulnerabilities</ref>
      <ref url="http://support.ca.com/irj/portal/anonymous/phpsupcontent?contentID=197601" source="CONFIRM">http://support.ca.com/irj/portal/anonymous/phpsupcontent?contentID=197601</ref>
      <ref url="http://community.ca.com/blogs/casecurityresponseblog/archive/2009/01/26/ca20090126-01-ca-anti-virus-engine-detection-evasion-multiple-vulnerabilities.aspx" source="CONFIRM" adv="1">http://community.ca.com/blogs/casecurityresponseblog/archive/2009/01/26/ca20090126-01-ca-anti-virus-engine-detection-evasion-multiple-vulnerabilities.aspx</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ca" name="anti-spyware">
        <vers num="2007" />
        <vers num="2008" />
      </prod>
      <prod vendor="ca" name="anti-spyware_for_the_enterprise">
        <vers num="8.1" />
        <vers num="r8" />
      </prod>
      <prod vendor="ca" name="anti-virus">
        <vers num="2007" edition="8" />
        <vers num="2008" />
      </prod>
      <prod vendor="ca" name="anti-virus_for_the_enterprise">
        <vers num="7.1" />
        <vers num="8.1" />
        <vers num="r8" />
      </prod>
      <prod vendor="ca" name="anti-virus_sdk">
        <vers num="" />
      </prod>
      <prod vendor="ca" name="antivirus_gateway">
        <vers num="7.1" />
      </prod>
      <prod vendor="ca" name="arcserve_backup">
        <vers num="r11.1" edition="_nil_" />
        <vers num="r11.1" edition="_nil_:linux" />
        <vers num="r11.1" edition="_nil_:windows" />
        <vers num="r11.5_nil_" edition="linux" />
        <vers num="r11.5_nil_" edition="windows" />
        <vers num="r12.0_nil_" edition="windows" />
      </prod>
      <prod vendor="ca" name="arcserve_client_agent">
        <vers num="_nil_" edition="_nil_" />
        <vers num="_nil_" edition="_nil_:windows" />
      </prod>
      <prod vendor="ca" name="common_services">
        <vers num="11" />
        <vers num="11.1" />
      </prod>
      <prod vendor="ca" name="etrust_ez_antivirus">
        <vers num="r6.1" />
        <vers num="r7" />
      </prod>
      <prod vendor="ca" name="etrust_intrusion_detection">
        <vers num="2.0" edition="sp1" />
        <vers num="3.0" edition="sp1" />
        <vers num="4.0" />
      </prod>
      <prod vendor="ca" name="internet_security_suite_2007">
        <vers num="3" />
      </prod>
      <prod vendor="ca" name="internet_security_suite_2008">
        <vers num="" />
      </prod>
      <prod vendor="ca" name="internet_security_suite_plus_2008">
        <vers num="" />
      </prod>
      <prod vendor="ca" name="network_and_systems_management">
        <vers num="r11" />
        <vers num="r11.1" />
        <vers num="r3.0" />
        <vers num="r3.1" />
      </prod>
      <prod vendor="ca" name="protection_suites">
        <vers num="r2" />
        <vers num="r3" />
        <vers num="r3.1" />
      </prod>
      <prod vendor="ca" name="secure_content_manager">
        <vers num="8.0" />
        <vers num="8.1" />
      </prod>
      <prod vendor="ca" name="threat_manager_for_the_enterprise">
        <vers num="8.1" />
        <vers num="r8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0043" published="2009-01-08" name="CVE-2009-0043" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">The smmsnmpd service in CA Service Metric Analysis r11.0 through r11.1 SP1 and Service Level Management 3.5 does not properly restrict access, which allows remote attackers to execute arbitrary commands via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" admin="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="https://support.ca.com/irj/portal/anonymous/phpsupcontent?contentID=196148" source="CONFIRM" patch="1">https://support.ca.com/irj/portal/anonymous/phpsupcontent?contentID=196148</ref>
      <ref url="http://www.securityfocus.com/bid/33161" source="BID" patch="1">33161</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0053" source="VUPEN">ADV-2009-0053</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/499857/100/0/threaded" source="BUGTRAQ">20090107 CA20090107-01: CA Service Metric Analysis and CA Service Level Management smmsnmpd Arbitrary Command Execution Vulnerability</ref>
      <ref url="http://securityreason.com/securityalert/4887" source="SREASON">4887</ref>
      <ref url="http://community.ca.com/blogs/casecurityresponseblog/archive/2009/01/07.aspx" source="CONFIRM" adv="1">http://community.ca.com/blogs/casecurityresponseblog/archive/2009/01/07.aspx</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ca" name="service_level_management">
        <vers num="3.5" />
      </prod>
      <prod vendor="ca" name="service_metric_analysis">
        <vers num="r11.0" />
        <vers num="r11.1" edition="sp1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0046" published="2009-01-07" name="CVE-2009-0046" modified="2011-07-28" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Sun GridEngine 5.3 and earlier does not properly check the return value from the OpenSSL EVP_VerifyFinal function, which allows remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature for DSA and ECDSA keys, a similar vulnerability to CVE-2008-5077.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2009/0045" source="VUPEN" adv="1">ADV-2009-0045</ref>
      <ref url="http://www.ocert.org/advisories/ocert-2008-016.html" source="MISC">http://www.ocert.org/advisories/ocert-2008-016.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="grid_engine">
        <vers prev="1" num="5.3" edition="beta1" />
        <vers prev="1" num="5.3" edition="beta2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0047" published="2009-01-07" name="CVE-2009-0047" modified="2011-10-18" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Gale 0.99 and earlier does not properly check the return value from the OpenSSL EVP_VerifyFinal function, which allows remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature for DSA and ECDSA keys, a similar vulnerability to CVE-2008-5077.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2009/0046" source="VUPEN" adv="1">ADV-2009-0046</ref>
      <ref url="http://www.ocert.org/advisories/ocert-2008-016.html" source="MISC">http://www.ocert.org/advisories/ocert-2008-016.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gale" name="gale">
        <vers num="0.15" />
        <vers num="0.15b" />
        <vers num="0.15c" />
        <vers num="0.16" />
        <vers num="0.16a" />
        <vers num="0.17" />
        <vers num="0.17a" />
        <vers num="0.18" />
        <vers num="0.18b" />
        <vers num="0.18c" />
        <vers num="0.19" />
        <vers num="0.19a" />
        <vers num="0.19b" />
        <vers num="0.20a" />
        <vers num="0.21" />
        <vers num="0.90a" />
        <vers num="0.90b" />
        <vers num="0.90c" />
        <vers num="0.91" />
        <vers num="0.91a" />
        <vers num="0.91b" />
        <vers prev="1" num="0.99" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0048" published="2009-01-07" name="CVE-2009-0048" modified="2011-08-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">OpenEvidence 1.0.6 and earlier does not properly check the return value from the OpenSSL EVP_VerifyFinal function, which allows remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature for DSA and ECDSA keys, a similar vulnerability to CVE-2008-5077.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2009/0047" source="VUPEN" adv="1">ADV-2009-0047</ref>
      <ref url="http://www.ocert.org/advisories/ocert-2008-016.html" source="MISC">http://www.ocert.org/advisories/ocert-2008-016.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="openevidence" name="openevidence">
        <vers num="1.0.5" />
        <vers prev="1" num="1.0.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0049" published="2009-01-07" name="CVE-2009-0049" modified="2009-03-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Belgian eID middleware (eidlib) 2.6.0 and earlier does not properly check the return value from the OpenSSL EVP_VerifyFinal function, which allows remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature for DSA and ECDSA keys, a similar vulnerability to CVE-2008-5077.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.ocert.org/advisories/ocert-2008-016.html" source="MISC">http://www.ocert.org/advisories/ocert-2008-016.html</ref>
      <ref url="http://secunia.com/advisories/34029" source="SECUNIA">34029</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-03/msg00000.html" source="SUSE">SUSE-SR:2009:005</ref>
    </refs>
    <vuln_soft>
      <prod vendor="eid" name="eidlib">
        <vers prev="1" num="2.6.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0050" published="2009-01-07" name="CVE-2009-0050" modified="2009-02-12" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Lasso 2.2.1 and earlier does not properly check the return value from the OpenSSL DSA_verify function, which allows remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature, a similar vulnerability to CVE-2008-5077.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/47837" source="XF">openssl-dsa-verify-security-bypass(47837)</ref>
      <ref url="http://www.ocert.org/advisories/ocert-2008-016.html" source="MISC">http://www.ocert.org/advisories/ocert-2008-016.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="lasso" name="lasso">
        <vers num="1.9.9.0" />
        <vers num="2.0.0-1" />
        <vers prev="1" num="2.2.1-0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0051" published="2009-01-07" name="CVE-2009-0051" modified="2009-02-12" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">ZXID 0.29 and earlier does not properly check the return value from the OpenSSL DSA_verify function, which allows remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature, a similar vulnerability to CVE-2008-5077.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/47837" source="XF">openssl-dsa-verify-security-bypass(47837)</ref>
      <ref url="http://www.ocert.org/advisories/ocert-2008-016.html" source="MISC">http://www.ocert.org/advisories/ocert-2008-016.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="zxid" name="zxid">
        <vers num="0.1" />
        <vers num="0.10" />
        <vers num="0.11" />
        <vers num="0.12" />
        <vers num="0.13" />
        <vers num="0.14" />
        <vers num="0.15" />
        <vers num="0.16" />
        <vers num="0.17" />
        <vers num="0.18" />
        <vers num="0.19" />
        <vers num="0.2" />
        <vers num="0.20" />
        <vers num="0.21" />
        <vers num="0.22" />
        <vers num="0.25" />
        <vers num="0.26" />
        <vers num="0.27" />
        <vers num="0.28" />
        <vers prev="1" num="0.29" />
        <vers num="0.3" />
        <vers num="0.4" />
        <vers num="0.5" />
        <vers num="0.6" />
        <vers num="0.7" />
        <vers num="0.8" />
        <vers num="0.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0052" published="2009-11-12" name="CVE-2009-0052" modified="2012-01-05" CVSS_version="2.0" CVSS_vector="(AV:A/AC:L/Au:S/C:N/I:N/A:C)" CVSS_score="5.5" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="5.1" CVSS_base_score="5.5">
    <desc>
      <descript source="cve">The Atheros wireless driver, as used in Netgear WNDAP330 Wi-Fi access point with firmware 2.1.11 and other versions before 3.0.3 on the Atheros AR9160-BC1A chipset, and other products, allows remote authenticated users to cause a denial of service (device reboot or hang) and possibly execute arbitrary code via a truncated reserved management frame.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <local_network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/54216" source="XF">netgear-wndap330-frame-dos(54216)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/3212" source="VUPEN" adv="1">ADV-2009-3212</ref>
      <ref url="http://www.securityfocus.com/bid/36991" source="BID">36991</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/507777/100/0/threaded" source="BUGTRAQ">20091110 Atheros Driver Reserved Frame Vulnerability</ref>
      <ref url="http://www.osvdb.org/59880" source="OSVDB">59880</ref>
      <ref url="http://secunia.com/advisories/37344" source="SECUNIA" adv="1">37344</ref>
    </refs>
    <vuln_soft>
      <prod vendor="netgear" name="wndap330_firmware">
        <vers num="2.1.11" />
      </prod>
      <prod vendor="atheros" name="ar9160-bc1a_chipset">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0053" published="2009-01-16" name="CVE-2009-0053" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">PXE Encryption in Cisco IronPort Encryption Appliance 6.2.4 before 6.2.4.1.1, 6.2.5, 6.2.6, 6.2.7 before 6.2.7.7, 6.3 before 6.3.0.4, and 6.5 before 6.5.0.2; and Cisco IronPort PostX 6.2.1 before 6.2.1.1 and 6.2.2 before 6.2.2.3; allows remote attackers to obtain the decryption key via unspecified vectors, related to a "logic error."</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2009/0140" source="VUPEN">ADV-2009-0140</ref>
      <ref url="http://www.securityfocus.com/bid/33268" source="BID">33268</ref>
      <ref url="http://www.cisco.com/en/US/products/products_security_advisory09186a0080a5c4f7.shtml" source="CISCO" adv="1">20090114 IronPort Encryption Appliance / PostX and PXE Encryption Vulnerabilities</ref>
      <ref url="http://securitytracker.com/id?1021593" source="SECTRACK">1021593</ref>
      <ref url="http://secunia.com/advisories/33479" source="SECUNIA">33479</ref>
      <ref url="http://osvdb.org/51395" source="OSVDB">51395</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="ironport_encryption_appliance">
        <vers num="6.2.4" />
        <vers num="6.2.4.1" />
        <vers num="6.2.5" />
        <vers num="6.2.6" />
        <vers num="6.2.7" />
        <vers num="6.2.7.1" />
        <vers num="6.2.7.2" />
        <vers num="6.2.7.3" />
        <vers num="6.2.7.4" />
        <vers num="6.2.7.5" />
        <vers num="6.2.7.6" />
        <vers num="6.3" />
        <vers num="6.3.0.1" />
        <vers num="6.3.0.2" />
        <vers num="6.3.0.3" />
        <vers num="6.5" />
        <vers num="6.5.0.1" />
      </prod>
      <prod vendor="cisco" name="ironport_postx">
        <vers num="6.2.1" />
        <vers num="6.2.2" />
        <vers num="6.2.2.1" />
        <vers num="6.2.2.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0054" published="2009-01-16" name="CVE-2009-0054" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">PXE Encryption in Cisco IronPort Encryption Appliance 6.2.4 before 6.2.4.1.1, 6.2.5, 6.2.6, 6.2.7 before 6.2.7.7, 6.3 before 6.3.0.4, and 6.5 before 6.5.0.2; and Cisco IronPort PostX 6.2.1 before 6.2.1.1 and 6.2.2 before 6.2.2.3; allows remote attackers to capture credentials by tricking a user into reading a modified or crafted e-mail message.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2009/0140" source="VUPEN">ADV-2009-0140</ref>
      <ref url="http://www.securityfocus.com/bid/33268" source="BID">33268</ref>
      <ref url="http://www.cisco.com/en/US/products/products_security_advisory09186a0080a5c4f7.shtml" source="CISCO" adv="1">20090114 IronPort Encryption Appliance / PostX and PXE Encryption Vulnerabilities</ref>
      <ref url="http://securitytracker.com/id?1021593" source="SECTRACK">1021593</ref>
      <ref url="http://secunia.com/advisories/33479" source="SECUNIA">33479</ref>
      <ref url="http://osvdb.org/51396" source="OSVDB">51396</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="ironport_encryption_appliance">
        <vers num="6.2.4" />
        <vers num="6.2.4.1" />
        <vers num="6.2.5" />
        <vers num="6.2.6" />
        <vers num="6.2.7" />
        <vers num="6.2.7.1" />
        <vers num="6.2.7.2" />
        <vers num="6.2.7.3" />
        <vers num="6.2.7.4" />
        <vers num="6.2.7.5" />
        <vers num="6.2.7.6" />
        <vers num="6.3" />
        <vers num="6.3.0.1" />
        <vers num="6.3.0.2" />
        <vers num="6.3.0.3" />
        <vers num="6.5" />
        <vers num="6.5.0.1" />
      </prod>
      <prod vendor="cisco" name="ironport_postx">
        <vers num="6.2.1" />
        <vers num="6.2.2" />
        <vers num="6.2.2.1" />
        <vers num="6.2.2.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0055" published="2009-01-16" name="CVE-2009-0055" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site request forgery (CSRF) vulnerability in the administration interface in Cisco IronPort Encryption Appliance 6.2.4 before 6.2.4.1.1, 6.2.5, 6.2.6, 6.2.7 before 6.2.7.7, 6.3 before 6.3.0.4, and 6.5 before 6.5.0.2; and Cisco IronPort PostX 6.2.1 before 6.2.1.1 and 6.2.2 before 6.2.2.3; allows remote attackers to modify appliance preferences as arbitrary users via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2009/0140" source="VUPEN">ADV-2009-0140</ref>
      <ref url="http://www.securityfocus.com/bid/33268" source="BID">33268</ref>
      <ref url="http://www.cisco.com/en/US/products/products_security_advisory09186a0080a5c4f7.shtml" source="CISCO" adv="1">20090114 IronPort Encryption Appliance / PostX and PXE Encryption Vulnerabilities</ref>
      <ref url="http://securitytracker.com/id?1021594" source="SECTRACK">1021594</ref>
      <ref url="http://secunia.com/advisories/33479" source="SECUNIA">33479</ref>
      <ref url="http://osvdb.org/51397" source="OSVDB">51397</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="ironport_encryption_appliance">
        <vers num="6.2.4" />
        <vers num="6.2.4.1" />
        <vers num="6.2.5" />
        <vers num="6.2.6" />
        <vers num="6.2.7" />
        <vers num="6.2.7.1" />
        <vers num="6.2.7.2" />
        <vers num="6.2.7.3" />
        <vers num="6.2.7.4" />
        <vers num="6.2.7.5" />
        <vers num="6.2.7.6" />
        <vers num="6.3" />
        <vers num="6.3.0.1" />
        <vers num="6.3.0.2" />
        <vers num="6.3.0.3" />
        <vers num="6.5" />
        <vers num="6.5.0.1" />
      </prod>
      <prod vendor="cisco" name="ironport_postx">
        <vers num="6.2.1" />
        <vers num="6.2.2" />
        <vers num="6.2.2.1" />
        <vers num="6.2.2.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0056" published="2009-01-16" name="CVE-2009-0056" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site request forgery (CSRF) vulnerability in the administration interface in Cisco IronPort Encryption Appliance 6.2.4 before 6.2.4.1.1, 6.2.5, 6.2.6, 6.2.7 before 6.2.7.7, 6.3 before 6.3.0.4, and 6.5 before 6.5.0.2; and Cisco IronPort PostX 6.2.1 before 6.2.1.1 and 6.2.2 before 6.2.2.3; allows remote attackers to execute commands and modify appliance preferences as arbitrary users via a logout action.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2009/0140" source="VUPEN">ADV-2009-0140</ref>
      <ref url="http://www.securityfocus.com/bid/33268" source="BID">33268</ref>
      <ref url="http://www.cisco.com/en/US/products/products_security_advisory09186a0080a5c4f7.shtml" source="CISCO" adv="1">20090114 IronPort Encryption Appliance / PostX and PXE Encryption Vulnerabilities</ref>
      <ref url="http://securitytracker.com/id?1021594" source="SECTRACK">1021594</ref>
      <ref url="http://secunia.com/advisories/33479" source="SECUNIA">33479</ref>
      <ref url="http://osvdb.org/51398" source="OSVDB">51398</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="ironport_encryption_appliance">
        <vers num="6.2.4" />
        <vers num="6.2.4.1" />
        <vers num="6.2.5" />
        <vers num="6.2.6" />
        <vers num="6.2.7" />
        <vers num="6.2.7.1" />
        <vers num="6.2.7.2" />
        <vers num="6.2.7.3" />
        <vers num="6.2.7.4" />
        <vers num="6.2.7.5" />
        <vers num="6.2.7.6" />
        <vers num="6.3" />
        <vers num="6.3.0.1" />
        <vers num="6.3.0.2" />
        <vers num="6.3.0.3" />
        <vers num="6.5" />
        <vers num="6.5.0.1" />
      </prod>
      <prod vendor="cisco" name="ironport_postx">
        <vers num="6.2.1" />
        <vers num="6.2.2" />
        <vers num="6.2.2.1" />
        <vers num="6.2.2.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0057" published="2009-01-22" name="CVE-2009-0057" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">The Certificate Authority Proxy Function (CAPF) service in Cisco Unified Communications Manager 5.x before 5.1(3e) and 6.x before 6.1(3) allows remote attackers to cause a denial of service (voice service outage) by sending malformed input over a TCP session in which the "client terminates prematurely."</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/48139" source="XF">cucm-capf-dos-var1(48139)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0213" source="VUPEN">ADV-2009-0213</ref>
      <ref url="http://www.securitytracker.com/id?1021620" source="SECTRACK">1021620</ref>
      <ref url="http://www.securityfocus.com/bid/33379" source="BID">33379</ref>
      <ref url="http://www.cisco.com/en/US/products/products_security_advisory09186a0080a61928.shtml" source="CISCO" adv="1">20090121 Cisco Unified Communications Manager CAPF Denial of Service Vulnerability</ref>
      <ref url="http://secunia.com/advisories/33588" source="SECUNIA" adv="1">33588</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="unified_communications_manager">
        <vers num="5.0" />
        <vers num="5.0_1" />
        <vers num="5.0_2" />
        <vers num="5.0_3" />
        <vers num="5.0_3a" />
        <vers num="5.0_4" />
        <vers num="5.0_4a" />
        <vers num="5.0_4a_su1" />
        <vers num="5.1" edition="(1)" />
        <vers num="5.1" edition="(2)" />
        <vers num="5.1" edition="(2a)" />
        <vers num="5.1" edition="(2b)" />
        <vers num="5.1" edition="(3a)" />
        <vers num="5.1" edition="5.1(1)" />
        <vers num="5.1" edition="5.1_(2a)" />
        <vers num="5.1(1)" />
        <vers num="5.1(2)" />
        <vers num="5.1(3c)" />
        <vers num="5.1.2" />
        <vers num="5.1_(2a)" />
        <vers num="5.1_1" />
        <vers num="5.1_2" />
        <vers num="5.1_2a" />
        <vers num="5.1_2b" />
        <vers num="5.1_3a" />
        <vers num="6.0" edition="(1)" />
        <vers num="6.0" edition="(1a)" />
        <vers num="6.0_1" />
        <vers num="6.0_1a" />
        <vers num="6.1" edition="(1a)" />
        <vers num="6.1(2)" />
        <vers num="6.1.0" />
        <vers num="6.1_1a" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0058" published="2009-02-04" name="CVE-2009-0058" modified="2009-03-06" CVSS_version="2.0" CVSS_vector="(AV:A/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="6.1" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="6.5" CVSS_base_score="6.1">
    <desc>
      <descript source="cve">The Cisco Wireless LAN Controller (WLC), Cisco Catalyst 6500 Wireless Services Module (WiSM), and Cisco Catalyst 3750 Integrated Wireless LAN Controller with software 4.x before 4.2.176.0 and 5.x before 5.2 allow remote attackers to cause a denial of service (web authentication outage or device reload) via unspecified network traffic, as demonstrated by a vulnerability scanner.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <local_network />
    </range>
    <refs>
      <ref url="http://www.securitytracker.com/id?1021679" source="SECTRACK">1021679</ref>
      <ref url="http://www.securityfocus.com/bid/33608" source="BID">33608</ref>
      <ref url="http://www.cisco.com/en/US/products/products_security_advisory09186a0080a6c1dd.shtml" source="CISCO" adv="1">20090204 Multiple Vulnerabilities in Cisco Wireless LAN Controllers</ref>
      <ref url="http://secunia.com/advisories/33749" source="SECUNIA">33749</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="4400_wireless_lan_controller">
        <vers num="4.1" />
        <vers num="4.2" />
        <vers num="5.2" />
      </prod>
      <prod vendor="cisco" name="catalyst_3750_series_integrated_wireless_lan_controller">
        <vers num="4.1" />
        <vers num="4.2" />
        <vers num="5.2" />
      </prod>
      <prod vendor="cisco" name="catalyst_6500_series_integrated_wireless_lan_controller">
        <vers num="4.1" />
        <vers num="4.2" />
        <vers num="5.2" />
      </prod>
      <prod vendor="cisco" name="catalyst_7600_series_wireless_lan_controller">
        <vers num="4.1" />
        <vers num="4.2" />
        <vers num="5.2" />
      </prod>
      <prod vendor="cisco" name="wireless_lan_controller">
        <vers num="4.1" />
        <vers num="4.2" />
        <vers num="5.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0059" published="2009-02-04" name="CVE-2009-0059" modified="2009-03-06" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">The Cisco Wireless LAN Controller (WLC), Cisco Catalyst 6500 Wireless Services Module (WiSM), and Cisco Catalyst 3750 Integrated Wireless LAN Controller with software 4.x before 4.2.176.0 and 5.2.x before 5.2.157.0 allow remote attackers to cause a denial of service (device reload) via a web authentication (aka WebAuth) session that includes a malformed POST request to login.html.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securitytracker.com/id?1021679" source="SECTRACK">1021679</ref>
      <ref url="http://www.securityfocus.com/bid/33608" source="BID">33608</ref>
      <ref url="http://www.cisco.com/en/US/products/products_security_advisory09186a0080a6c1dd.shtml" source="CISCO" adv="1">20090204 Multiple Vulnerabilities in Cisco Wireless LAN Controllers</ref>
      <ref url="http://secunia.com/advisories/33749" source="SECUNIA">33749</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="4400_wireless_lan_controller">
        <vers num="4.1" />
        <vers num="4.2" />
        <vers num="5.2" />
      </prod>
      <prod vendor="cisco" name="catalyst_3750_series_integrated_wireless_lan_controller">
        <vers num="4.1" />
        <vers num="4.2" />
        <vers num="5.2" />
      </prod>
      <prod vendor="cisco" name="catalyst_6500_series_integrated_wireless_lan_controller">
        <vers num="4.1" />
        <vers num="4.2" />
        <vers num="5.2" />
      </prod>
      <prod vendor="cisco" name="catalyst_7600_series_wireless_lan_controller">
        <vers num="4.1" />
        <vers num="4.2" />
        <vers num="5.2" />
      </prod>
      <prod vendor="cisco" name="wireless_lan_controller">
        <vers num="4.1" />
        <vers num="4.2" />
        <vers num="5.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0061" published="2009-02-04" name="CVE-2009-0061" modified="2009-03-06" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Wireless LAN Controller (WLC) TSEC driver in the Cisco 4400 WLC, Cisco Catalyst 6500 and 7600 Wireless Services Module (WiSM), and Cisco Catalyst 3750 Integrated Wireless LAN Controller with software 4.x before 4.2.176.0 and 5.x before 5.1 allows remote attackers to cause a denial of service (device crash or hang) via unknown IP packets.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securitytracker.com/id?1021679" source="SECTRACK">1021679</ref>
      <ref url="http://www.securityfocus.com/bid/33608" source="BID">33608</ref>
      <ref url="http://www.cisco.com/en/US/products/products_security_advisory09186a0080a6c1dd.shtml" source="CISCO" adv="1">20090204 Multiple Vulnerabilities in Cisco Wireless LAN Controllers</ref>
      <ref url="http://secunia.com/advisories/33749" source="SECUNIA">33749</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="4400_wireless_lan_controller">
        <vers num="4.1" />
        <vers num="4.2" />
        <vers num="5.0" />
      </prod>
      <prod vendor="cisco" name="catalyst_3750_series_integrated_wireless_lan_controller">
        <vers num="4.1" />
        <vers num="4.2" />
        <vers num="5.0" />
      </prod>
      <prod vendor="cisco" name="catalyst_6500_series_integrated_wireless_lan_controller">
        <vers num="4.1" />
        <vers num="4.2" />
        <vers num="5.0" />
      </prod>
      <prod vendor="cisco" name="catalyst_7600_series_wireless_lan_controller">
        <vers num="4.1" />
        <vers num="4.2" />
        <vers num="5.0" />
      </prod>
      <prod vendor="cisco" name="wireless_lan_controller">
        <vers num="4.1" />
        <vers num="4.2" />
        <vers num="5.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0062" published="2009-02-04" name="CVE-2009-0062" modified="2009-03-06" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:C/I:C/A:C)" CVSS_score="9.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.0" CVSS_base_score="9.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Cisco Wireless LAN Controller (WLC), Cisco Catalyst 6500 Wireless Services Module (WiSM), and Cisco Catalyst 3750 Integrated Wireless LAN Controller with software 4.2.173.0 allows remote authenticated users to gain privileges via unknown vectors, as demonstrated by escalation from the (1) Lobby Admin and (2) Local Management User privilege levels.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securitytracker.com/id?1021678" source="SECTRACK">1021678</ref>
      <ref url="http://www.securityfocus.com/bid/33608" source="BID">33608</ref>
      <ref url="http://www.cisco.com/en/US/products/products_security_advisory09186a0080a6c1dd.shtml" source="CISCO" adv="1">20090204 Multiple Vulnerabilities in Cisco Wireless LAN Controllers</ref>
      <ref url="http://secunia.com/advisories/33749" source="SECUNIA">33749</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="catalyst_3750_series_integrated_wireless_lan_controller">
        <vers num="4.2" />
        <vers num="4.2.173.0" />
      </prod>
      <prod vendor="cisco" name="catalyst_6500_wireless_services_modules">
        <vers num="4.2" />
        <vers num="4.2.173.0" />
      </prod>
      <prod vendor="cisco" name="wireless_lan_controller">
        <vers num="4.2" />
        <vers num="4.2.173.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0063" published="2009-04-24" name="CVE-2009-0063" modified="2009-04-30" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the Control Center in Symantec Brightmail Gateway Appliance before 8.0.1 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2009/1155" source="VUPEN" patch="1" adv="1">ADV-2009-1155</ref>
      <ref url="http://www.symantec.com/business/security_response/securityupdates/detail.jsp?fid=security_advisory&amp;pvid=security_advisory&amp;year=2009&amp;suid=20090423_01" source="CONFIRM" patch="1" adv="1">http://www.symantec.com/business/security_response/securityupdates/detail.jsp?fid=security_advisory&amp;pvid=security_advisory&amp;year=2009&amp;suid=20090423_01</ref>
      <ref url="http://securitytracker.com/id?1022116" source="SECTRACK" patch="1">1022116</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/50074" source="XF">brightmail-controlcenter-xss(50074)</ref>
      <ref url="http://www.securityfocus.com/bid/34641" source="BID">34641</ref>
      <ref url="http://secunia.com/advisories/34885" source="SECUNIA">34885</ref>
      <ref url="http://osvdb.org/53944" source="OSVDB">53944</ref>
    </refs>
    <vuln_soft>
      <prod vendor="symantec" name="brightmail_gateway_appliance">
        <vers num="7.5" />
        <vers num="7.6" />
        <vers num="7.7" />
        <vers prev="1" num="8.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0064" published="2009-04-24" name="CVE-2009-0064" modified="2009-04-30" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:C/I:C/A:C)" CVSS_score="9.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.0" CVSS_base_score="9.0">
    <desc>
      <descript source="cve">Multiple unspecified vulnerabilities in the Control Center in Symantec Brightmail Gateway Appliance before 8.0.1 allow remote authenticated users to gain privileges, and possibly obtain sensitive information or hijack sessions of arbitrary users, via vectors involving (1) administrative scripts or (2) console functions.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2009/1155" source="VUPEN" patch="1" adv="1">ADV-2009-1155</ref>
      <ref url="http://www.symantec.com/business/security_response/securityupdates/detail.jsp?fid=security_advisory&amp;pvid=security_advisory&amp;year=2009&amp;suid=20090423_01" source="CONFIRM" patch="1" adv="1">http://www.symantec.com/business/security_response/securityupdates/detail.jsp?fid=security_advisory&amp;pvid=security_advisory&amp;year=2009&amp;suid=20090423_01</ref>
      <ref url="http://securitytracker.com/id?1022117" source="SECTRACK" patch="1">1022117</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/50075" source="XF">brightmail-consolescripts-priv-escalation(50075)</ref>
      <ref url="http://www.securityfocus.com/bid/34639" source="BID">34639</ref>
      <ref url="http://secunia.com/advisories/34885" source="SECUNIA">34885</ref>
      <ref url="http://osvdb.org/53945" source="OSVDB">53945</ref>
    </refs>
    <vuln_soft>
      <prod vendor="symantec" name="brightmail_gateway_appliance">
        <vers num="7.5" />
        <vers num="7.6" />
        <vers num="7.7" />
        <vers prev="1" num="8.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0065" published="2009-01-07" name="CVE-2009-0065" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in net/sctp/sm_statefuns.c in the Stream Control Transmission Protocol (sctp) implementation in the Linux kernel before 2.6.28-git8 allows remote attackers to have an unknown impact via an FWD-TSN (aka FORWARD-TSN) chunk with a large stream ID.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-January/msg01045.html" source="FEDORA">FEDORA-2009-0816</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=478800" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=478800</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/2193" source="VUPEN">ADV-2009-2193</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0029" source="VUPEN">ADV-2009-0029</ref>
      <ref url="http://www.ubuntu.com/usn/usn-751-1" source="UBUNTU">USN-751-1</ref>
      <ref url="http://www.securitytracker.com/id?1022698" source="SECTRACK">1022698</ref>
      <ref url="http://www.securityfocus.com/bid/33113" source="BID">33113</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-1055.html" source="REDHAT">RHSA-2009:1055</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-0331.html" source="REDHAT">RHSA-2009:0331</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-0053.html" source="REDHAT">RHSA-2009:0053</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2009/01/05/1" source="MLIST">[oss-security] 20090105 CVE request: kernel: sctp: memory overflow when FWD-TSN chunk is received with bad stream ID</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1794" source="DEBIAN">DSA-1794</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1787" source="DEBIAN">DSA-1787</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1749" source="DEBIAN">DSA-1749</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2009-114.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2009-114.htm</ref>
      <ref url="http://secunia.com/advisories/36191" source="SECUNIA">36191</ref>
      <ref url="http://secunia.com/advisories/35394" source="SECUNIA">35394</ref>
      <ref url="http://secunia.com/advisories/35390" source="SECUNIA">35390</ref>
      <ref url="http://secunia.com/advisories/35174" source="SECUNIA">35174</ref>
      <ref url="http://secunia.com/advisories/35011" source="SECUNIA">35011</ref>
      <ref url="http://secunia.com/advisories/34981" source="SECUNIA">34981</ref>
      <ref url="http://secunia.com/advisories/34762" source="SECUNIA">34762</ref>
      <ref url="http://secunia.com/advisories/34680" source="SECUNIA">34680</ref>
      <ref url="http://secunia.com/advisories/34394" source="SECUNIA">34394</ref>
      <ref url="http://secunia.com/advisories/34252" source="SECUNIA">34252</ref>
      <ref url="http://secunia.com/advisories/33858" source="SECUNIA">33858</ref>
      <ref url="http://secunia.com/advisories/33854" source="SECUNIA">33854</ref>
      <ref url="http://secunia.com/advisories/33674" source="SECUNIA">33674</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2009-0264.html" source="REDHAT">RHSA-2009:0264</ref>
      <ref url="http://patchwork.ozlabs.org/patch/15024/" source="CONFIRM">http://patchwork.ozlabs.org/patch/15024/</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10872" source="OVAL">oval:org.mitre.oval:def:10872</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-06/msg00001.html" source="SUSE">SUSE-SA:2009:031</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-06/msg00000.html" source="SUSE">SUSE-SA:2009:030</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-02/msg00003.html" source="SUSE">SUSE-SA:2009:010</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01832118" source="HP">SSSRT090149</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01832118" source="HP">SSSRT090149</ref>
      <ref url="http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=9fcb95a105758b81ef0131cd18e2db5149f13e95" source="CONFIRM">http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=9fcb95a105758b81ef0131cd18e2db5149f13e95</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="kernel">
        <vers num="2.2.27" />
        <vers num="2.4.36" />
        <vers num="2.4.36.1" />
        <vers num="2.4.36.2" />
        <vers num="2.4.36.3" />
        <vers num="2.4.36.4" />
        <vers num="2.4.36.5" />
        <vers num="2.4.36.6" />
        <vers num="2.6" />
        <vers num="2.6.18" edition="rc1" />
        <vers num="2.6.18" edition="rc2" />
        <vers num="2.6.18" edition="rc3" />
        <vers num="2.6.18" edition="rc4" />
        <vers num="2.6.18" edition="rc5" />
        <vers num="2.6.18" edition="rc6" />
        <vers num="2.6.18" edition="rc7" />
        <vers num="2.6.19.4" />
        <vers num="2.6.19.5" />
        <vers num="2.6.19.6" />
        <vers num="2.6.19.7" />
        <vers num="2.6.20.16" />
        <vers num="2.6.20.17" />
        <vers num="2.6.20.18" />
        <vers num="2.6.20.19" />
        <vers num="2.6.20.20" />
        <vers num="2.6.20.21" />
        <vers num="2.6.21.5" />
        <vers num="2.6.21.6" />
        <vers num="2.6.21.7" />
        <vers num="2.6.22" />
        <vers num="2.6.22.1" />
        <vers num="2.6.22.10" />
        <vers num="2.6.22.11" />
        <vers num="2.6.22.12" />
        <vers num="2.6.22.13" />
        <vers num="2.6.22.14" />
        <vers num="2.6.22.15" />
        <vers num="2.6.22.17" />
        <vers num="2.6.22.18" />
        <vers num="2.6.22.19" />
        <vers num="2.6.22.2" />
        <vers num="2.6.22.20" />
        <vers num="2.6.22.21" />
        <vers num="2.6.22.22" />
        <vers num="2.6.22.8" />
        <vers num="2.6.22.9" />
        <vers num="2.6.22_rc1" />
        <vers num="2.6.22_rc7" />
        <vers num="2.6.23" />
        <vers num="2.6.23.10" />
        <vers num="2.6.23.11" />
        <vers num="2.6.23.12" />
        <vers num="2.6.23.13" />
        <vers num="2.6.23.15" />
        <vers num="2.6.23.16" />
        <vers num="2.6.23.17" />
        <vers num="2.6.23.8" />
        <vers num="2.6.23.9" />
        <vers num="2.6.23_rc1" />
        <vers num="2.6.24" />
        <vers num="2.6.24.1" />
        <vers num="2.6.24.2" />
        <vers num="2.6.24.3" />
        <vers num="2.6.24.4" />
        <vers num="2.6.24.5" />
        <vers num="2.6.24.6" />
        <vers num="2.6.24.7" />
        <vers num="2.6.24_rc1" />
        <vers num="2.6.24_rc4" />
        <vers num="2.6.24_rc5" />
        <vers num="2.6.25" edition="" />
        <vers num="2.6.25" edition=":x86_64" />
        <vers num="2.6.25.1" edition="" />
        <vers num="2.6.25.1" edition=":x86_64" />
        <vers num="2.6.25.10" edition="" />
        <vers num="2.6.25.10" edition=":x86_64" />
        <vers num="2.6.25.11" edition="" />
        <vers num="2.6.25.11" edition=":x86_64" />
        <vers num="2.6.25.12" edition="" />
        <vers num="2.6.25.12" edition=":x86_64" />
        <vers num="2.6.25.13" />
        <vers num="2.6.25.14" />
        <vers num="2.6.25.15" />
        <vers num="2.6.25.16" />
        <vers num="2.6.25.17" />
        <vers num="2.6.25.2" edition="" />
        <vers num="2.6.25.2" edition=":x86_64" />
        <vers num="2.6.25.3" edition="" />
        <vers num="2.6.25.3" edition=":x86_64" />
        <vers num="2.6.25.4" edition="" />
        <vers num="2.6.25.4" edition=":x86_64" />
        <vers num="2.6.25.5" edition="" />
        <vers num="2.6.25.5" edition=":x86_64" />
        <vers num="2.6.25.6" edition="" />
        <vers num="2.6.25.6" edition=":x86_64" />
        <vers num="2.6.25.7" edition="" />
        <vers num="2.6.25.7" edition=":x86_64" />
        <vers num="2.6.25.8" edition="" />
        <vers num="2.6.25.8" edition=":x86_64" />
        <vers num="2.6.25.9" edition="" />
        <vers num="2.6.25.9" edition=":x86_64" />
        <vers num="2.6.26" />
        <vers num="2.6.26.1" />
        <vers num="2.6.26.2" />
        <vers num="2.6.26.3" />
        <vers num="2.6.26.4" />
        <vers num="2.6.26.5" />
        <vers prev="1" num="2.6.27" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0066" published="2009-01-07" name="CVE-2009-0066" modified="2009-01-08" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)" CVSS_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_base_score="7.6">
    <desc>
      <descript source="cve">Multiple unspecified vulnerabilities in Intel system software for Trusted Execution Technology (TXT) allow attackers to bypass intended loader integrity protections, as demonstrated by exploitation of tboot.  NOTE: as of 20090107, the only disclosure is a vague pre-advisory with no actionable information. However, because it is from a well-known researcher, it is being assigned a CVE identifier for tracking purposes.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/33119" source="BID">33119</ref>
      <ref url="http://theinvisiblethings.blogspot.com/2009/01/attacking-intel-trusted-execution.html" source="MISC">http://theinvisiblethings.blogspot.com/2009/01/attacking-intel-trusted-execution.html</ref>
      <ref url="http://invisiblethingslab.com/press/itl-press-2009-01.pdf" source="MISC">http://invisiblethingslab.com/press/itl-press-2009-01.pdf</ref>
      <ref url="http://blackhat.com/html/bh-dc-09/bh-dc-09-speakers.html#Wojtczuk" source="MISC">http://blackhat.com/html/bh-dc-09/bh-dc-09-speakers.html#Wojtczuk</ref>
    </refs>
    <vuln_soft>
      <prod vendor="intel" name="trusted_execution_technology">
        <vers num="_nil_" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0068" published="2009-01-07" name="CVE-2009-0068" modified="2009-02-10" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Interaction error in xdg-open allows remote attackers to execute arbitrary code by sending a file with a dangerous MIME type but using a safe type that Firefox sends to xdg-open, which causes xdg-open to process the dangerous file type through automatic type detection, as demonstrated by overwriting the .desktop file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="https://bugs.freedesktop.org/show_bug.cgi?id=19377" source="MISC">https://bugs.freedesktop.org/show_bug.cgi?id=19377</ref>
      <ref url="http://www.securityfocus.com/bid/33137" source="BID">33137</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2009/01/06/1" source="MLIST">[oss-security] 20090106 Fwd: Using xdg-open in /etc/mailcap causes hole in Firefox (Demonstration/Exploit included)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="freedesktop" name="xdg-utils">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0069" published="2009-01-07" name="CVE-2009-0069" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="4.9" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="3.9" CVSS_base_score="4.9">
    <desc>
      <descript source="cve">Unspecified vulnerability in the nfs4rename_persistent_fh function in the NFS 4 (aka NFSv4) client in the kernel in Sun Solaris 10 and OpenSolaris before snv_102 allows local users to cause a denial of service (recursive mutex_enter and panic) via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-21-139466-02-1" source="CONFIRM" patch="1">http://sunsolve.sun.com/search/document.do?assetkey=1-21-139466-02-1</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/47750" source="XF">solaris-nfs4client-dos(47750)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0030" source="VUPEN">ADV-2009-0030</ref>
      <ref url="http://www.securitytracker.com/id?1021519" source="SECTRACK">1021519</ref>
      <ref url="http://www.securityfocus.com/bid/33128" source="BID">33128</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-248566-1" source="SUNALERT" adv="1">248566</ref>
      <ref url="http://secunia.com/advisories/33361" source="SECUNIA" adv="1">33361</ref>
      <ref url="http://mail.opensolaris.org/pipermail/onnv-notify/2008-October/015342.html" source="MLIST">[onnv-notify] 20081021 6300710 recursive mutex_enter in nfs4rename_persistent_fh()</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="opensolaris">
        <vers num="snv_01" edition="" />
        <vers num="snv_01" edition=":sparc" />
        <vers num="snv_01" edition=":x86" />
        <vers num="snv_02" edition="" />
        <vers num="snv_02" edition=":sparc" />
        <vers num="snv_02" edition=":x86" />
        <vers num="snv_03" edition="" />
        <vers num="snv_03" edition=":x86" />
        <vers num="snv_03" edition=":sparc" />
        <vers num="snv_04" edition="" />
        <vers num="snv_04" edition=":x86" />
        <vers num="snv_04" edition=":sparc" />
        <vers num="snv_05" edition="" />
        <vers num="snv_05" edition=":sparc" />
        <vers num="snv_05" edition=":x86" />
        <vers num="snv_06" edition="" />
        <vers num="snv_06" edition=":sparc" />
        <vers num="snv_06" edition=":x86" />
        <vers num="snv_07" edition="" />
        <vers num="snv_07" edition=":sparc" />
        <vers num="snv_07" edition=":x86" />
        <vers num="snv_08" edition="" />
        <vers num="snv_08" edition=":x86" />
        <vers num="snv_08" edition=":sparc" />
        <vers num="snv_09" edition="" />
        <vers num="snv_09" edition=":x86" />
        <vers num="snv_09" edition=":sparc" />
        <vers num="snv_10" edition="" />
        <vers num="snv_10" edition=":x86" />
        <vers num="snv_10" edition=":sparc" />
        <vers num="snv_100" edition="" />
        <vers num="snv_100" edition=":sparc" />
        <vers num="snv_100" edition=":x86" />
        <vers prev="1" num="snv_101" edition="" />
        <vers prev="1" num="snv_101" edition=":x86" />
        <vers prev="1" num="snv_101" edition=":sparc" />
        <vers num="snv_104" edition="" />
        <vers num="snv_104" edition=":sparc" />
        <vers num="snv_11" edition="" />
        <vers num="snv_11" edition=":x86" />
        <vers num="snv_11" edition=":sparc" />
        <vers num="snv_12" edition="" />
        <vers num="snv_12" edition=":x86" />
        <vers num="snv_12" edition=":sparc" />
        <vers num="snv_13" edition="" />
        <vers num="snv_13" edition=":x86" />
        <vers num="snv_13" edition=":sparc" />
        <vers num="snv_14" edition="" />
        <vers num="snv_14" edition=":sparc" />
        <vers num="snv_14" edition=":x86" />
        <vers num="snv_15" edition="" />
        <vers num="snv_15" edition=":x86" />
        <vers num="snv_15" edition=":sparc" />
        <vers num="snv_16" edition="" />
        <vers num="snv_16" edition=":sparc" />
        <vers num="snv_16" edition=":x86" />
        <vers num="snv_17" edition="" />
        <vers num="snv_17" edition=":x86" />
        <vers num="snv_17" edition=":sparc" />
        <vers num="snv_18" edition="" />
        <vers num="snv_18" edition=":x86" />
        <vers num="snv_18" edition=":sparc" />
        <vers num="snv_19" edition="" />
        <vers num="snv_19" edition=":sparc" />
        <vers num="snv_19" edition=":x86" />
        <vers num="snv_20" edition="" />
        <vers num="snv_20" edition=":x86" />
        <vers num="snv_20" edition=":sparc" />
        <vers num="snv_21" edition="" />
        <vers num="snv_21" edition=":sparc" />
        <vers num="snv_21" edition=":x86" />
        <vers num="snv_22" edition="" />
        <vers num="snv_22" edition=":sparc" />
        <vers num="snv_22" edition=":x86" />
        <vers num="snv_23" edition="" />
        <vers num="snv_23" edition=":sparc" />
        <vers num="snv_23" edition=":x86" />
        <vers num="snv_24" edition="" />
        <vers num="snv_24" edition=":sparc" />
        <vers num="snv_24" edition=":x86" />
        <vers num="snv_25" edition="" />
        <vers num="snv_25" edition=":x86" />
        <vers num="snv_25" edition=":sparc" />
        <vers num="snv_26" edition="" />
        <vers num="snv_26" edition=":x86" />
        <vers num="snv_26" edition=":sparc" />
        <vers num="snv_27" edition="" />
        <vers num="snv_27" edition=":sparc" />
        <vers num="snv_27" edition=":x86" />
        <vers num="snv_28" edition="" />
        <vers num="snv_28" edition=":x86" />
        <vers num="snv_28" edition=":sparc" />
        <vers num="snv_29" edition="" />
        <vers num="snv_29" edition=":x86" />
        <vers num="snv_29" edition=":sparc" />
        <vers num="snv_30" edition="" />
        <vers num="snv_30" edition=":sparc" />
        <vers num="snv_30" edition=":x86" />
        <vers num="snv_31" edition="" />
        <vers num="snv_31" edition=":sparc" />
        <vers num="snv_31" edition=":x86" />
        <vers num="snv_32" edition="" />
        <vers num="snv_32" edition=":x86" />
        <vers num="snv_32" edition=":sparc" />
        <vers num="snv_33" edition="" />
        <vers num="snv_33" edition=":x86" />
        <vers num="snv_33" edition=":sparc" />
        <vers num="snv_34" edition="" />
        <vers num="snv_34" edition=":sparc" />
        <vers num="snv_34" edition=":x86" />
        <vers num="snv_35" edition="" />
        <vers num="snv_35" edition=":sparc" />
        <vers num="snv_35" edition=":x86" />
        <vers num="snv_36" edition="" />
        <vers num="snv_36" edition=":x86" />
        <vers num="snv_36" edition=":sparc" />
        <vers num="snv_37" edition="" />
        <vers num="snv_37" edition=":sparc" />
        <vers num="snv_37" edition=":x86" />
        <vers num="snv_38" edition="" />
        <vers num="snv_38" edition=":sparc" />
        <vers num="snv_38" edition=":x86" />
        <vers num="snv_39" edition="" />
        <vers num="snv_39" edition=":sparc" />
        <vers num="snv_39" edition=":x86" />
        <vers num="snv_40" edition="" />
        <vers num="snv_40" edition=":sparc" />
        <vers num="snv_40" edition=":x86" />
        <vers num="snv_41" edition="" />
        <vers num="snv_41" edition=":sparc" />
        <vers num="snv_41" edition=":x86" />
        <vers num="snv_42" edition="" />
        <vers num="snv_42" edition=":x86" />
        <vers num="snv_42" edition=":sparc" />
        <vers num="snv_43" edition="" />
        <vers num="snv_43" edition=":sparc" />
        <vers num="snv_43" edition=":x86" />
        <vers num="snv_44" edition="" />
        <vers num="snv_44" edition=":x86" />
        <vers num="snv_44" edition=":sparc" />
        <vers num="snv_45" edition="" />
        <vers num="snv_45" edition=":x86" />
        <vers num="snv_45" edition=":sparc" />
        <vers num="snv_46" edition="" />
        <vers num="snv_46" edition=":x86" />
        <vers num="snv_46" edition=":sparc" />
        <vers num="snv_47" edition="" />
        <vers num="snv_47" edition=":x86" />
        <vers num="snv_47" edition=":sparc" />
        <vers num="snv_48" edition="" />
        <vers num="snv_48" edition=":sparc" />
        <vers num="snv_48" edition=":x86" />
        <vers num="snv_49" edition="" />
        <vers num="snv_49" edition=":sparc" />
        <vers num="snv_49" edition=":x86" />
        <vers num="snv_50" edition="" />
        <vers num="snv_50" edition=":sparc" />
        <vers num="snv_50" edition=":x86" />
        <vers num="snv_51" edition="" />
        <vers num="snv_51" edition=":sparc" />
        <vers num="snv_51" edition=":x86" />
        <vers num="snv_52" edition="" />
        <vers num="snv_52" edition=":sparc" />
        <vers num="snv_52" edition=":x86" />
        <vers num="snv_53" edition="" />
        <vers num="snv_53" edition=":sparc" />
        <vers num="snv_53" edition=":x86" />
        <vers num="snv_54" edition="" />
        <vers num="snv_54" edition=":x86" />
        <vers num="snv_54" edition=":sparc" />
        <vers num="snv_55" edition="" />
        <vers num="snv_55" edition=":sparc" />
        <vers num="snv_55" edition=":x86" />
        <vers num="snv_56" edition="" />
        <vers num="snv_56" edition=":x86" />
        <vers num="snv_56" edition=":sparc" />
        <vers num="snv_57" edition="" />
        <vers num="snv_57" edition=":x86" />
        <vers num="snv_57" edition=":sparc" />
        <vers num="snv_58" edition="" />
        <vers num="snv_58" edition=":sparc" />
        <vers num="snv_58" edition=":x86" />
        <vers num="snv_59" edition="" />
        <vers num="snv_59" edition=":sparc" />
        <vers num="snv_59" edition=":x86" />
        <vers num="snv_60" edition="" />
        <vers num="snv_60" edition=":x86" />
        <vers num="snv_60" edition=":sparc" />
        <vers num="snv_61" edition="" />
        <vers num="snv_61" edition=":sparc" />
        <vers num="snv_61" edition=":x86" />
        <vers num="snv_62" edition="" />
        <vers num="snv_62" edition=":x86" />
        <vers num="snv_62" edition=":sparc" />
        <vers num="snv_63" edition="" />
        <vers num="snv_63" edition=":sparc" />
        <vers num="snv_63" edition=":x86" />
        <vers num="snv_64" edition="" />
        <vers num="snv_64" edition=":x86" />
        <vers num="snv_64" edition=":sparc" />
        <vers num="snv_65" edition="" />
        <vers num="snv_65" edition=":x86" />
        <vers num="snv_65" edition=":sparc" />
        <vers num="snv_66" edition="" />
        <vers num="snv_66" edition=":x86" />
        <vers num="snv_66" edition=":sparc" />
        <vers num="snv_67" edition="" />
        <vers num="snv_67" edition=":sparc" />
        <vers num="snv_67" edition=":x86" />
        <vers num="snv_68" edition="" />
        <vers num="snv_68" edition=":x86" />
        <vers num="snv_68" edition=":sparc" />
        <vers num="snv_69" edition="" />
        <vers num="snv_69" edition=":sparc" />
        <vers num="snv_69" edition=":x86" />
        <vers num="snv_70" edition="" />
        <vers num="snv_70" edition=":sparc" />
        <vers num="snv_70" edition=":x86" />
        <vers num="snv_71" edition="" />
        <vers num="snv_71" edition=":x86" />
        <vers num="snv_71" edition=":sparc" />
        <vers num="snv_72" edition="" />
        <vers num="snv_72" edition=":x86" />
        <vers num="snv_72" edition=":sparc" />
        <vers num="snv_73" edition="" />
        <vers num="snv_73" edition=":x86" />
        <vers num="snv_73" edition=":sparc" />
        <vers num="snv_74" edition="" />
        <vers num="snv_74" edition=":sparc" />
        <vers num="snv_74" edition=":x86" />
        <vers num="snv_75" edition="" />
        <vers num="snv_75" edition=":sparc" />
        <vers num="snv_75" edition=":x86" />
        <vers num="snv_76" edition="" />
        <vers num="snv_76" edition=":x86" />
        <vers num="snv_76" edition=":sparc" />
        <vers num="snv_77" edition="" />
        <vers num="snv_77" edition=":sparc" />
        <vers num="snv_77" edition=":x86" />
        <vers num="snv_78" edition="" />
        <vers num="snv_78" edition=":sparc" />
        <vers num="snv_78" edition=":x86" />
        <vers num="snv_79" edition="" />
        <vers num="snv_79" edition=":x86" />
        <vers num="snv_79" edition=":sparc" />
        <vers num="snv_80" edition="" />
        <vers num="snv_80" edition=":x86" />
        <vers num="snv_80" edition=":sparc" />
        <vers num="snv_81" edition="" />
        <vers num="snv_81" edition=":x86" />
        <vers num="snv_81" edition=":sparc" />
        <vers num="snv_82" edition="" />
        <vers num="snv_82" edition=":x86" />
        <vers num="snv_82" edition=":sparc" />
        <vers num="snv_83" edition="" />
        <vers num="snv_83" edition=":x86" />
        <vers num="snv_83" edition=":sparc" />
        <vers num="snv_84" edition="" />
        <vers num="snv_84" edition=":x86" />
        <vers num="snv_84" edition=":sparc" />
        <vers num="snv_85" edition="" />
        <vers num="snv_85" edition=":x86" />
        <vers num="snv_85" edition=":sparc" />
        <vers num="snv_86" edition="" />
        <vers num="snv_86" edition=":sparc" />
        <vers num="snv_86" edition=":x86" />
        <vers num="snv_87" edition="" />
        <vers num="snv_87" edition=":sparc" />
        <vers num="snv_87" edition=":x86" />
        <vers num="snv_88" edition="" />
        <vers num="snv_88" edition=":x86" />
        <vers num="snv_88" edition=":sparc" />
        <vers num="snv_89" edition="" />
        <vers num="snv_89" edition=":x86" />
        <vers num="snv_89" edition=":sparc" />
        <vers num="snv_90" edition="" />
        <vers num="snv_90" edition=":sparc" />
        <vers num="snv_90" edition=":x86" />
        <vers num="snv_91" edition="" />
        <vers num="snv_91" edition=":sparc" />
        <vers num="snv_91" edition=":x86" />
        <vers num="snv_92" edition="" />
        <vers num="snv_92" edition=":sparc" />
        <vers num="snv_92" edition=":x86" />
        <vers num="snv_93" edition="" />
        <vers num="snv_93" edition=":sparc" />
        <vers num="snv_93" edition=":x86" />
        <vers num="snv_94" edition="" />
        <vers num="snv_94" edition=":x86" />
        <vers num="snv_94" edition=":sparc" />
        <vers num="snv_95" edition="" />
        <vers num="snv_95" edition=":x86" />
        <vers num="snv_95" edition=":sparc" />
        <vers num="snv_96" edition="" />
        <vers num="snv_96" edition=":sparc" />
        <vers num="snv_96" edition=":x86" />
        <vers num="snv_97" edition="" />
        <vers num="snv_97" edition=":x86" />
        <vers num="snv_97" edition=":sparc" />
        <vers num="snv_98" edition="" />
        <vers num="snv_98" edition=":sparc" />
        <vers num="snv_98" edition=":x86" />
        <vers num="snv_99" edition="" />
        <vers num="snv_99" edition=":sparc" />
        <vers num="snv_99" edition=":x86" />
      </prod>
      <prod vendor="sun" name="solaris">
        <vers num="10" edition="" />
        <vers num="10" edition=":sparc" />
        <vers num="10" edition=":x86" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0070" published="2009-01-08" name="CVE-2009-0070" modified="2009-01-29" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Integer signedness error in Apple Safari allows remote attackers to read the contents of arbitrary memory locations, cause a denial of service (application crash), and probably have unspecified other impact via the array index of the arguments array in a JavaScript function, possibly a related issue to CVE-2008-2307.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/48214" source="XF">safari-array-memory-disclosure(48214)</ref>
      <ref url="http://www.milw0rm.com/exploits/7673" source="MILW0RM">7673</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="safari">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2009-0071" published="2009-01-08" name="CVE-2009-0071" modified="2009-03-25" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:N/A:P)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Mozilla Firefox 3.0.5 and earlier 3.0.x versions, when designMode is enabled, allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a certain (a) replaceChild or (b) removeChild call, followed by a (1) queryCommandValue, (2) queryCommandState, or (3) queryCommandIndeterm call.  NOTE: it was later reported that 3.0.6 and 3.0.7 are also affected.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=472507" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=472507</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=456727" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=456727</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=448329" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=448329</ref>
      <ref url="http://www.securityfocus.com/bid/33154" source="BID">33154</ref>
      <ref url="http://www.milw0rm.com/exploits/8219" source="MILW0RM">8219</ref>
      <ref url="http://www.milw0rm.com/exploits/8091" source="MILW0RM">8091</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2009-01/0224.html" source="FULLDISC">20090107 Re: Firefox 3.0.5 remote vulnerability via queryCommandState</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2009-01/0223.html" source="FULLDISC">20090107 Re: Firefox 3.0.5 remote vulnerability via queryCommandState</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2009-01/0220.html" source="FULLDISC">20090107 Firefox 3.0.5 remote vulnerability via queryCommandState</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="3.0" edition="alpha" />
        <vers num="3.0" edition="beta2" />
        <vers num="3.0" edition="beta5" />
        <vers num="3.0.1" />
        <vers num="3.0.2" />
        <vers num="3.0.3" />
        <vers num="3.0.4" />
        <vers num="3.0.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0072" published="2009-01-08" name="CVE-2009-0072" modified="2009-01-09" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Microsoft Internet Explorer 6.0 through 8.0 beta2 allows remote attackers to cause a denial of service (application crash) via an onload=screen[""] attribute value in a BODY element.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/47788" source="XF">ie-javascript-screen-dos(47788)</ref>
      <ref url="http://www.securityfocus.com/bid/33149" source="BID">33149</ref>
      <ref url="http://skypher.com/index.php/2009/01/07/msie-screen-null-ptr-dos-details/" source="MISC">http://skypher.com/index.php/2009/01/07/msie-screen-null-ptr-dos-details/</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="internet_explorer">
        <vers num="6" edition="sp1" />
        <vers num="6" edition="sp2" />
        <vers num="7" />
        <vers num="8" edition="beta1" />
        <vers num="8" edition="beta2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0075" published="2009-02-10" name="CVE-2009-0075" modified="2010-03-30" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Microsoft Internet Explorer 7 does not properly handle errors during attempted access to deleted objects, which allows remote attackers to execute arbitrary code via a crafted HTML document, related to CFunctionPointer and the appending of document objects, aka "Uninitialized Memory Corruption Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-041A.html" source="CERT">TA09-041A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS09-002.mspx" source="MS" patch="1" adv="1">MS09-002</ref>
      <ref url="http://www.zerodayinitiative.com/advisories/ZDI-09-011/" source="MISC">http://www.zerodayinitiative.com/advisories/ZDI-09-011/</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0389" source="VUPEN" adv="1">ADV-2009-0389</ref>
      <ref url="http://www.securityfocus.com/bid/33627" source="BID">33627</ref>
      <ref url="http://www.milw0rm.com/exploits/8082" source="MILW0RM">8082</ref>
      <ref url="http://www.milw0rm.com/exploits/8080" source="MILW0RM">8080</ref>
      <ref url="http://www.milw0rm.com/exploits/8079" source="MILW0RM">8079</ref>
      <ref url="http://www.milw0rm.com/exploits/8077" source="MILW0RM">8077</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6000" source="OVAL">oval:org.mitre.oval:def:6000</ref>
      <ref url="http://osvdb.org/51839" source="OSVDB">51839</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="internet_explorer">
        <vers num="7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0076" published="2009-02-10" name="CVE-2009-0076" modified="2009-03-06" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Microsoft Internet Explorer 7, when XHTML strict mode is used, allows remote attackers to execute arbitrary code via the zoom style directive in conjunction with unspecified other directives in a malformed Cascading Style Sheets (CSS) stylesheet in a crafted HTML document, aka "CSS Memory Corruption Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-041A.html" source="CERT">TA09-041A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS09-002.mspx" source="MS" patch="1" adv="1">MS09-002</ref>
      <ref url="http://www.zerodayinitiative.com/advisories/ZDI-09-012/" source="MISC">http://www.zerodayinitiative.com/advisories/ZDI-09-012/</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0389" source="VUPEN">ADV-2009-0389</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6081" source="OVAL">oval:org.mitre.oval:def:6081</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="internet_explorer">
        <vers num="7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0077" published="2009-04-15" name="CVE-2009-0077" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The firewall engine in Microsoft Forefront Threat Management Gateway, Medium Business Edition (TMG MBE); and Internet Security and Acceleration (ISA) Server 2004 SP3, 2006, 2006 Supportability Update, and 2006 SP1; does not properly manage the session state of web listeners, which allows remote attackers to cause a denial of service (many stale sessions) via crafted packets, aka "Web Proxy TCP State Limited Denial of Service Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-104A.html" source="CERT">TA09-104A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS09-016.mspx" source="MS" patch="1" adv="1">MS09-016</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1030" source="VUPEN">ADV-2009-1030</ref>
      <ref url="http://www.securitytracker.com/id?1022045" source="SECTRACK">1022045</ref>
      <ref url="http://secunia.com/advisories/34687" source="SECUNIA">34687</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6068" source="OVAL">oval:org.mitre.oval:def:6068</ref>
      <ref url="http://osvdb.org/53636" source="OSVDB">53636</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="forefront_threat_management_gateway">
        <vers num="-" edition="-" />
        <vers num="-" edition="-:medium_business" />
      </prod>
      <prod vendor="microsoft" name="internet_security_and_acceleration_server">
        <vers num="2004" edition="sp3" />
        <vers num="2004" edition="sp3:enterprise" />
        <vers num="2004" edition="sp3:standard" />
        <vers num="2006" edition="sp1" />
        <vers num="2006" edition="supportability" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0078" published="2009-04-15" name="CVE-2009-0078" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">The Windows Management Instrumentation (WMI) provider in Microsoft Windows XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 does not properly implement isolation among a set of distinct processes that (1) all run under the NetworkService account or (2) all run under the LocalService account, which allows local users to gain privileges by accessing the resources of one of the processes, aka "Windows WMI Service Isolation Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-104A.html" source="CERT">TA09-104A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS09-012.mspx" source="MS" patch="1" adv="1">MS09-012</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1026" source="VUPEN">ADV-2009-1026</ref>
      <ref url="http://www.securitytracker.com/id?1022044" source="SECTRACK">1022044</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6193" source="OVAL">oval:org.mitre.oval:def:6193</ref>
      <ref url="http://osvdb.org/53666" source="OSVDB">53666</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_server_2003">
        <vers num="" edition=":x64" />
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:itanium" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:itanium" />
        <vers num="" edition="sp2:x64" />
      </prod>
      <prod vendor="microsoft" name="windows_server_2008">
        <vers num="" edition=":32_bit" />
        <vers num="" edition=":itanium" />
        <vers num="" edition=":x64" />
      </prod>
      <prod vendor="microsoft" name="windows_vista">
        <vers num="" edition=":x64" />
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:x64" />
        <vers num="gold" />
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition=":pro_x64" />
        <vers num="" edition="sp1" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:pro_x64" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0079" published="2009-04-15" name="CVE-2009-0079" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="6.9" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.4" CVSS_base_score="6.9">
    <desc>
      <descript source="cve">The RPCSS service in Microsoft Windows XP SP2 and SP3 and Server 2003 SP1 and SP2 does not properly implement isolation among a set of distinct processes that (1) all run under the NetworkService account or (2) all run under the LocalService account, which allows local users to gain privileges by accessing the resources of one of the processes, aka "Windows RPCSS Service Isolation Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-104A.html" source="CERT">TA09-104A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS09-012.mspx" source="MS" patch="1" adv="1">MS09-012</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1026" source="VUPEN">ADV-2009-1026</ref>
      <ref url="http://www.securitytracker.com/id?1022044" source="SECTRACK">1022044</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6147" source="OVAL">oval:org.mitre.oval:def:6147</ref>
      <ref url="http://osvdb.org/53667" source="OSVDB">53667</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_server_2003">
        <vers num="" edition=":x64" />
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:itanium" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:itanium" />
        <vers num="" edition="sp2:x64" />
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition=":pro_x64" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:pro_x64" />
        <vers num="" edition="sp3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0080" published="2009-04-15" name="CVE-2009-0080" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="6.9" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.4" CVSS_base_score="6.9">
    <desc>
      <descript source="cve">The ThreadPool class in Windows Vista Gold and SP1, and Server 2008, does not properly implement isolation among a set of distinct processes that (1) all run under the NetworkService account or (2) all run under the LocalService account, which allows local users to gain privileges by leveraging incorrect thread ACLs to access the resources of one of the processes, aka "Windows Thread Pool ACL Weakness Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-104A.html" source="CERT">TA09-104A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS09-012.mspx" source="MS" patch="1" adv="1">MS09-012</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1026" source="VUPEN">ADV-2009-1026</ref>
      <ref url="http://www.securitytracker.com/id?1022044" source="SECTRACK">1022044</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6177" source="OVAL">oval:org.mitre.oval:def:6177</ref>
      <ref url="http://osvdb.org/53668" source="OSVDB">53668</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_server">
        <vers num="2008" edition="-" />
        <vers num="2008" edition="-:x32" />
        <vers num="2008" edition="-:x64" />
        <vers num="2008" edition="-:itanium" />
      </prod>
      <prod vendor="microsoft" name="windows_vista">
        <vers num="" edition=":x64" />
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:x64" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0081" published="2009-03-10" name="CVE-2009-0081" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">The graphics device interface (GDI) implementation in the kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 does not properly validate input received from user mode, which allows remote attackers to execute arbitrary code via a crafted (1) Windows Metafile (aka WMF) or (2) Enhanced Metafile (aka EMF) image file, aka "Windows Kernel Input Validation Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-069A.html" source="CERT">TA09-069A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS09-006.mspx" source="MS" patch="1" adv="1">MS09-006</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0659" source="VUPEN">ADV-2009-0659</ref>
      <ref url="http://www.securitytracker.com/id?1021826" source="SECTRACK">1021826</ref>
      <ref url="http://www.securityfocus.com/bid/34012" source="BID">34012</ref>
      <ref url="http://support.nortel.com/go/main.jsp?cscat=BLTNDETAIL&amp;DocumentOID=842987&amp;poid=" source="CONFIRM">http://support.nortel.com/go/main.jsp?cscat=BLTNDETAIL&amp;DocumentOID=842987&amp;poid=</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2009-079.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2009-079.htm</ref>
      <ref url="http://secunia.com/advisories/34117" source="SECUNIA">34117</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6202" source="OVAL">oval:org.mitre.oval:def:6202</ref>
      <ref url="http://osvdb.org/52522" source="OSVDB">52522</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition="sp4" />
      </prod>
      <prod vendor="microsoft" name="windows_server_2003">
        <vers num="" edition=":x64" />
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:itanium" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:itanium" />
        <vers num="" edition="sp2:x64" />
      </prod>
      <prod vendor="microsoft" name="windows_server_2008">
        <vers num="" edition=":itanium" />
        <vers num="" edition=":x64" />
      </prod>
      <prod vendor="microsoft" name="windows_vista">
        <vers num="" edition=":x64" />
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:x64" />
        <vers num="gold" />
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition=":x64" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:x64" />
        <vers num="" edition="sp3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0082" published="2009-03-10" name="CVE-2009-0082" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">The kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 does not properly validate handles, which allows local users to gain privileges via a crafted application that triggers unspecified "actions," aka "Windows Kernel Handle Validation Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-069A.html" source="CERT">TA09-069A</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0659" source="VUPEN">ADV-2009-0659</ref>
      <ref url="http://www.securitytracker.com/id?1021827" source="SECTRACK">1021827</ref>
      <ref url="http://www.securityfocus.com/bid/34027" source="BID">34027</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS09-006.mspx" source="MS">MS09-006</ref>
      <ref url="http://support.nortel.com/go/main.jsp?cscat=BLTNDETAIL&amp;DocumentOID=842987&amp;poid=" source="CONFIRM">http://support.nortel.com/go/main.jsp?cscat=BLTNDETAIL&amp;DocumentOID=842987&amp;poid=</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2009-079.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2009-079.htm</ref>
      <ref url="http://secunia.com/advisories/34117" source="SECUNIA">34117</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6036" source="OVAL">oval:org.mitre.oval:def:6036</ref>
      <ref url="http://osvdb.org/52523" source="OSVDB">52523</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition="sp4" />
      </prod>
      <prod vendor="microsoft" name="windows_server_2003">
        <vers num="" edition=":x64" />
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:itanium" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:itanium" />
        <vers num="" edition="sp2:x64" />
      </prod>
      <prod vendor="microsoft" name="windows_server_2008">
        <vers num="" edition=":itanium" />
        <vers num="" edition=":x64" />
      </prod>
      <prod vendor="microsoft" name="windows_vista">
        <vers num="" edition=":x64" />
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:x64" />
        <vers num="gold" />
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition=":x64" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:x64" />
        <vers num="" edition="sp3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0083" published="2009-03-10" name="CVE-2009-0083" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">The kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP1 does not properly handle invalid pointers, which allows local users to gain privileges via an application that triggers use of a crafted pointer, aka "Windows Kernel Invalid Pointer Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-069A.html" source="CERT">TA09-069A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS09-006.mspx" source="MS" patch="1" adv="1">MS09-006</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0659" source="VUPEN">ADV-2009-0659</ref>
      <ref url="http://www.securitytracker.com/id?1021827" source="SECTRACK">1021827</ref>
      <ref url="http://www.securityfocus.com/bid/34025" source="BID">34025</ref>
      <ref url="http://support.nortel.com/go/main.jsp?cscat=BLTNDETAIL&amp;DocumentOID=842987&amp;poid=" source="CONFIRM">http://support.nortel.com/go/main.jsp?cscat=BLTNDETAIL&amp;DocumentOID=842987&amp;poid=</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2009-079.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2009-079.htm</ref>
      <ref url="http://secunia.com/advisories/34117" source="SECUNIA">34117</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5440" source="OVAL">oval:org.mitre.oval:def:5440</ref>
      <ref url="http://osvdb.org/52524" source="OSVDB">52524</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition="sp4" />
      </prod>
      <prod vendor="microsoft" name="windows_server_2003">
        <vers num="" edition=":x64" />
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:itanium" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:itanium" />
        <vers num="" edition="sp2:x64" />
      </prod>
      <prod vendor="microsoft" name="windows_server_2008">
        <vers num="" edition=":itanium" />
        <vers num="" edition=":x64" />
      </prod>
      <prod vendor="microsoft" name="windows_vista">
        <vers num="" edition=":x64" />
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:x64" />
        <vers num="gold" />
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition=":x64" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:x64" />
        <vers num="" edition="sp3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0084" published="2009-04-15" name="CVE-2009-0084" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Use-after-free vulnerability in DirectShow in Microsoft DirectX 8.1 and 9.0 allows remote attackers to execute arbitrary code via an MJPEG file or video stream with a malformed Huffman table, which triggers an exception that frees heap memory that is later accessed, aka "MJPEG Decompression Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-104A.html" source="CERT">TA09-104A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS09-011.mspx" source="MS" patch="1" adv="1">MS09-011</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1025" source="VUPEN">ADV-2009-1025</ref>
      <ref url="http://www.securitytracker.com/id?1022040" source="SECTRACK">1022040</ref>
      <ref url="http://www.securityfocus.com/bid/34460" source="BID">34460</ref>
      <ref url="http://www.piotrbania.com/all/adv/ms-directx-mjpeg-adv.txt" source="MISC">http://www.piotrbania.com/all/adv/ms-directx-mjpeg-adv.txt</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2009-132.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2009-132.htm</ref>
      <ref url="http://secunia.com/advisories/34665" source="SECUNIA">34665</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5618" source="OVAL">oval:org.mitre.oval:def:5618</ref>
      <ref url="http://osvdb.org/53632" source="OSVDB">53632</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="directx">
        <vers num="8.1" />
        <vers num="9.0" />
        <vers num="9.0a" />
        <vers num="9.0b" />
        <vers num="9.0c" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0085" published="2009-03-10" name="CVE-2009-0085" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:C/A:N)" CVSS_score="7.1" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="8.6" CVSS_base_score="7.1">
    <desc>
      <descript source="cve">The Secure Channel (aka SChannel) authentication component in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008, when certificate authentication is used, does not properly validate the client's key exchange data in Transport Layer Security (TLS) handshake messages, which allows remote attackers to spoof authentication by crafting a TLS packet based on knowledge of the certificate but not the private key, aka "SChannel Spoofing Vulnerability."</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-069A.html" source="CERT">TA09-069A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS09-007.mspx" source="MS" patch="1" adv="1">MS09-007</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0660" source="VUPEN">ADV-2009-0660</ref>
      <ref url="http://www.securitytracker.com/id?1021828" source="SECTRACK">1021828</ref>
      <ref url="http://secunia.com/advisories/34215" source="SECUNIA">34215</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6011" source="OVAL">oval:org.mitre.oval:def:6011</ref>
      <ref url="http://osvdb.org/52521" source="OSVDB">52521</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition="sp4" />
      </prod>
      <prod vendor="microsoft" name="windows_server_2003">
        <vers num="" edition=":x64" />
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:itanium" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:itanium" />
        <vers num="" edition="sp2:x64" />
      </prod>
      <prod vendor="microsoft" name="windows_server_2008">
        <vers num="" edition=":itanium" />
        <vers num="" edition=":x64" />
      </prod>
      <prod vendor="microsoft" name="windows_vista">
        <vers num="" edition=":x64" />
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:x64" />
        <vers num="gold" />
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition=":x64" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:x64" />
        <vers num="" edition="sp3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0086" published="2009-04-15" name="CVE-2009-0086" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Integer underflow in Windows HTTP Services (aka WinHTTP) in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 allows remote HTTP servers to execute arbitrary code via crafted parameter values in a response, related to error handling, aka "Windows HTTP Services Integer Underflow Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-104A.html" source="CERT">TA09-104A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS09-013.mspx" source="MS" patch="1" adv="1">MS09-013</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1027" source="VUPEN">ADV-2009-1027</ref>
      <ref url="http://www.securitytracker.com/id?1022041" source="SECTRACK">1022041</ref>
      <ref url="http://www.securityfocus.com/bid/34435" source="BID">34435</ref>
      <ref url="http://secunia.com/advisories/34677" source="SECUNIA">34677</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6149" source="OVAL">oval:org.mitre.oval:def:6149</ref>
      <ref url="http://osvdb.org/53620" source="OSVDB">53620</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition="sp4" />
      </prod>
      <prod vendor="microsoft" name="windows_server_2003">
        <vers num="" edition=":x64" />
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:itanium" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:itanium" />
        <vers num="" edition="sp2:x64" />
      </prod>
      <prod vendor="microsoft" name="windows_server_2008">
        <vers num="" edition=":32_bit" />
        <vers num="" edition=":itanium" />
        <vers num="" edition=":x64" />
      </prod>
      <prod vendor="microsoft" name="windows_vista">
        <vers num="" edition=":x64" />
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:x64" />
        <vers num="gold" />
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition="sp2" />
        <vers num="" edition="sp3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0087" published="2009-04-15" name="CVE-2009-0087" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Word 6 text converter in WordPad in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP1 and SP2; and the Word 6 text converter in Microsoft Office Word 2000 SP3 and 2002 SP3; allows remote attackers to execute arbitrary code via a crafted Word 6 file that contains malformed data, aka "WordPad and Office Text Converter Memory Corruption Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-104A.html" source="CERT">TA09-104A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS09-010.mspx" source="MS" patch="1" adv="1">MS09-010</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1024" source="VUPEN">ADV-2009-1024</ref>
      <ref url="http://www.securitytracker.com/id?1022043" source="SECTRACK">1022043</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5799" source="OVAL">oval:org.mitre.oval:def:5799</ref>
      <ref url="http://osvdb.org/53662" source="OSVDB">53662</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="office_word">
        <vers num="2000" edition="sp3" />
        <vers num="2002" edition="sp3" />
      </prod>
      <prod vendor="microsoft" name="windows">
        <vers num="2000" edition="sp4" />
      </prod>
      <prod vendor="microsoft" name="windows_server">
        <vers num="2003" edition="sp1" />
        <vers num="2003" edition="sp2" />
      </prod>
      <prod vendor="microsoft" name="windows_srv">
        <vers num="2003" edition="-" />
        <vers num="2003" edition="-:x64" />
        <vers num="2003" edition="sp1" />
        <vers num="2003" edition="sp1:itanium" />
        <vers num="2003" edition="sp2" />
        <vers num="2003" edition="sp2:x64" />
        <vers num="2003" edition="sp2:itanium" />
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition=":pro_x64" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:pro_x64" />
        <vers num="" edition="sp3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0088" published="2009-04-15" name="CVE-2009-0088" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">The WordPerfect 6.x Converter (WPFT632.CNV, 1998.1.27.0) in Microsoft Office Word 2000 SP3 and Microsoft Office Converter Pack does not properly validate the length of an unspecified string, which allows remote attackers to execute arbitrary code via a crafted WordPerfect 6.x file, related to an unspecified counter and control structures on the stack, aka "Word 2000 WordPerfect 6.x Converter Stack Corruption Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-104A.html" source="CERT">TA09-104A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS09-010.mspx" source="MS" patch="1" adv="1">MS09-010</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1024" source="VUPEN">ADV-2009-1024</ref>
      <ref url="http://www.securitytracker.com/id?1022043" source="SECTRACK">1022043</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5736" source="OVAL">oval:org.mitre.oval:def:5736</ref>
      <ref url="http://osvdb.org/53663" source="OSVDB">53663</ref>
      <ref url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=782" source="IDEFENSE">20090414 Microsoft Word 2000 WordPerfect 6.x Converter Stack Corruption Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="office_converter_pack">
        <vers num="2003" />
      </prod>
      <prod vendor="microsoft" name="office_word">
        <vers num="2000" edition="sp3" />
        <vers num="2002" edition="sp3" />
      </prod>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition="sp4" />
      </prod>
      <prod vendor="microsoft" name="windows_server_2003">
        <vers num="" edition=":x64" />
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:itanium" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:itanium" />
        <vers num="" edition="sp2:x64" />
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition=":pro_x64" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:pro_x64" />
        <vers num="" edition="sp3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0089" published="2009-04-15" name="CVE-2009-0089" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:P)" CVSS_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_base_score="5.8">
    <desc>
      <descript source="cve">Windows HTTP Services (aka WinHTTP) in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, and Vista Gold allows remote web servers to impersonate arbitrary https web sites by using DNS spoofing to "forward a connection" to a different https web site that has a valid certificate matching its own domain name, but not a certificate matching the domain name of the host requested by the user, aka "Windows HTTP Services Certificate Name Mismatch Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-104A.html" source="CERT">TA09-104A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS09-013.mspx" source="MS" patch="1" adv="1">MS09-013</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1027" source="VUPEN">ADV-2009-1027</ref>
      <ref url="http://www.securitytracker.com/id?1022041" source="SECTRACK">1022041</ref>
      <ref url="http://www.securityfocus.com/bid/34437" source="BID">34437</ref>
      <ref url="http://secunia.com/advisories/34677" source="SECUNIA">34677</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6027" source="OVAL">oval:org.mitre.oval:def:6027</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition="sp4" />
      </prod>
      <prod vendor="microsoft" name="windows_server_2003">
        <vers num="" edition=":x64" />
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:itanium" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:itanium" />
        <vers num="" edition="sp2:x64" />
      </prod>
      <prod vendor="microsoft" name="windows_server_2008">
        <vers num="" edition=":itanium" />
        <vers num="" edition=":x64" />
        <vers num="" edition=":x32" />
      </prod>
      <prod vendor="microsoft" name="windows_vista">
        <vers num="" edition=":x64" />
        <vers num="" edition="gold" />
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:x64" />
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition=":pro_x64" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:pro_x64" />
        <vers num="" edition="sp3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0090" published="2009-10-14" name="CVE-2009-0090" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Microsoft .NET Framework 1.0 SP3, 1.1 SP1, and 2.0 SP1 does not properly validate .NET verifiable code, which allows remote attackers to obtain unintended access to stack memory, and execute arbitrary code, via (1) a crafted XAML browser application (XBAP), (2) a crafted ASP.NET application, or (3) a crafted .NET Framework application, aka "Microsoft .NET Framework Pointer Verification Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-286A.html" source="CERT">TA09-286A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS09-061.mspx" source="MS" patch="1" adv="1">MS09-061</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5716" source="OVAL">oval:org.mitre.oval:def:5716</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name=".net_framework">
        <vers num="1.0" edition="sp3" />
        <vers num="1.1" edition="sp1" />
        <vers num="2.0" edition="sp1" />
        <vers num="2.0" edition="sp2" />
        <vers num="3.5" edition="sp1" />
      </prod>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition="sp4" />
      </prod>
      <prod vendor="microsoft" name="windows_7">
        <vers num="-" edition="-" />
        <vers num="-" edition="-:x32" />
        <vers num="-" edition="-:x64" />
      </prod>
      <prod vendor="microsoft" name="windows_server_2003">
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:itanium" />
        <vers num="" edition="sp2:x64" />
      </prod>
      <prod vendor="microsoft" name="windows_server_2008">
        <vers num="" edition=":x32" />
        <vers num="" edition=":itanium" />
        <vers num="" edition=":x64" />
        <vers num="" edition="r2" />
        <vers num="" edition="r2:x64" />
        <vers num="" edition="r2:itanium" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:x64" />
        <vers num="" edition="sp2:itanium" />
        <vers num="-" edition="sp2" />
        <vers num="-" edition="sp2:x32" />
      </prod>
      <prod vendor="microsoft" name="windows_vista">
        <vers num="" edition=":x64" />
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:x64" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:x64" />
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition="sp2" />
        <vers num="" edition="sp3" />
        <vers num="-" edition="sp2" />
        <vers num="-" edition="sp2:x64" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0091" published="2009-10-14" name="CVE-2009-0091" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Microsoft .NET Framework 2.0, 2.0 SP1, and 3.5 does not properly enforce a certain type-equality constraint in .NET verifiable code, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (XBAP), (2) a crafted ASP.NET application, or (3) a crafted .NET Framework application, aka "Microsoft .NET Framework Type Verification Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-286A.html" source="CERT">TA09-286A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS09-061.mspx" source="MS" patch="1" adv="1">MS09-061</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6451" source="OVAL">oval:org.mitre.oval:def:6451</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name=".net_framework">
        <vers num="1.0" edition="sp3" />
        <vers num="1.1" edition="sp1" />
        <vers num="2.0" edition="sp1" />
        <vers num="2.0" edition="sp2" />
        <vers num="3.5" edition="sp1" />
      </prod>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition="sp4" />
      </prod>
      <prod vendor="microsoft" name="windows_7">
        <vers num="-" edition="-" />
        <vers num="-" edition="-:x32" />
        <vers num="-" edition="-:x64" />
      </prod>
      <prod vendor="microsoft" name="windows_server_2003">
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:itanium" />
        <vers num="" edition="sp2:x64" />
      </prod>
      <prod vendor="microsoft" name="windows_server_2008">
        <vers num="" edition=":x32" />
        <vers num="" edition=":itanium" />
        <vers num="" edition=":x64" />
        <vers num="" edition="r2" />
        <vers num="" edition="r2:x64" />
        <vers num="" edition="r2:itanium" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:x64" />
        <vers num="" edition="sp2:itanium" />
        <vers num="-" edition="sp2" />
        <vers num="-" edition="sp2:x32" />
      </prod>
      <prod vendor="microsoft" name="windows_vista">
        <vers num="" edition=":x64" />
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:x64" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:x64" />
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition="sp2" />
        <vers num="" edition="sp3" />
        <vers num="-" edition="sp2" />
        <vers num="-" edition="sp2:x64" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2009-0093" published="2009-03-11" name="CVE-2009-0093" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:S/C:N/I:P/A:N)" CVSS_score="3.5" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="6.8" CVSS_base_score="3.5">
    <desc>
      <descript source="cve">Windows DNS Server in Microsoft Windows 2000 SP4, Server 2003 SP1 and SP2, and Server 2008, when dynamic updates are enabled, does not restrict registration of the "wpad" hostname, which allows remote authenticated users to hijack the Web Proxy Auto-Discovery (WPAD) feature, and conduct man-in-the-middle attacks by spoofing a proxy server, via a Dynamic Update request for this hostname, aka "DNS Server Vulnerability in WPAD Registration Vulnerability," a related issue to CVE-2007-1692.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-069A.html" source="CERT">TA09-069A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS09-008.mspx" source="MS" patch="1" adv="1">MS09-008</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0661" source="VUPEN">ADV-2009-0661</ref>
      <ref url="http://www.securitytracker.com/id?1021830" source="SECTRACK">1021830</ref>
      <ref url="http://www.securityfocus.com/bid/33989" source="BID">33989</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2009-083.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2009-083.htm</ref>
      <ref url="http://secunia.com/advisories/34217" source="SECUNIA">34217</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6138" source="OVAL">oval:org.mitre.oval:def:6138</ref>
      <ref url="http://osvdb.org/52519" source="OSVDB">52519</ref>
      <ref url="http://blogs.technet.com/srd/archive/2009/03/13/ms09-008-dns-and-wins-server-security-update-in-more-detail.aspx" source="CONFIRM">http://blogs.technet.com/srd/archive/2009/03/13/ms09-008-dns-and-wins-server-security-update-in-more-detail.aspx</ref>
      <ref url="http://blog.ncircle.com/blogs/vert/archives/2009/03/successful_exploit_renders_mic.html" source="MISC">http://blog.ncircle.com/blogs/vert/archives/2009/03/successful_exploit_renders_mic.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition="sp4" />
      </prod>
      <prod vendor="microsoft" name="windows_server_2003">
        <vers num="" edition=":x64" />
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:itanium" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:itanium" />
        <vers num="" edition="sp2:x64" />
      </prod>
      <prod vendor="microsoft" name="windows_server_2008">
        <vers num="" edition=":x64" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0094" published="2009-03-11" name="CVE-2009-0094" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:N/I:P/A:P)" CVSS_score="5.5" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.0" CVSS_base_score="5.5">
    <desc>
      <descript source="cve">The WINS server in Microsoft Windows 2000 SP4 and Server 2003 SP1 and SP2 does not restrict registration of the (1) "wpad" and (2) "isatap" NetBIOS names, which allows remote authenticated users to hijack the Web Proxy Auto-Discovery (WPAD) and Intra-Site Automatic Tunnel Addressing Protocol (ISATAP) features, and conduct man-in-the-middle attacks by spoofing a proxy server or ISATAP route, by registering one of these names in the WINS database, aka "WPAD WINS Server Registration Vulnerability," a related issue to CVE-2007-1692.</descript>
      <descript source="nvd">Per: http://www.microsoft.com/technet/security/Bulletin/MS09-008.mspx

Mitigating Factors for WPAD WINS Server Registration Vulnerability - CVE-2009-0094

Mitigation refers to a setting, common configuration, or general best-practice, existing in a default state, that could reduce the severity of exploitation of a vulnerability. The following mitigating factors may be helpful in your situation.	

If WINS server already has WPAD and ISATAP registered than an attacker will not be able to register these as well.
</descript>
    </desc>
    <loss_types>
      <avail />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-069A.html" source="CERT">TA09-069A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS09-008.mspx" source="MS" patch="1" adv="1">MS09-008</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0661" source="VUPEN">ADV-2009-0661</ref>
      <ref url="http://www.securitytracker.com/id?1021829" source="SECTRACK">1021829</ref>
      <ref url="http://www.securityfocus.com/bid/34013" source="BID">34013</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2009-083.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2009-083.htm</ref>
      <ref url="http://secunia.com/advisories/34217" source="SECUNIA">34217</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6117" source="OVAL">oval:org.mitre.oval:def:6117</ref>
      <ref url="http://osvdb.org/52520" source="OSVDB">52520</ref>
      <ref url="http://blogs.technet.com/srd/archive/2009/03/13/ms09-008-dns-and-wins-server-security-update-in-more-detail.aspx" source="CONFIRM">http://blogs.technet.com/srd/archive/2009/03/13/ms09-008-dns-and-wins-server-security-update-in-more-detail.aspx</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition="sp4" />
      </prod>
      <prod vendor="microsoft" name="windows_server_2003">
        <vers num="" edition=":x64" />
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:itanium" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:itanium" />
        <vers num="" edition="sp2:x64" />
      </prod>
      <prod vendor="microsoft" name="windows_server_2008">
        <vers num="" edition=":x64" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0095" published="2009-02-10" name="CVE-2009-0095" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Microsoft Office Visio 2002 SP2, 2003 SP3, and 2007 SP1 does not properly validate object data in Visio files, which allows remote attackers to execute arbitrary code via a crafted file, aka "Memory Validation Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-041A.html" source="CERT">TA09-041A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS09-005.mspx" source="MS" patch="1" adv="1">MS09-005</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0391" source="VUPEN">ADV-2009-0391</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6179" source="OVAL">oval:org.mitre.oval:def:6179</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="visio">
        <vers num="2002" edition="sp2" />
        <vers num="2003" edition="sp3" />
        <vers num="2007" edition="sp1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0096" published="2009-02-10" name="CVE-2009-0096" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Microsoft Office Visio 2002 SP2, 2003 SP3, and 2007 SP1 does not properly perform memory copy operations for object data, which allows remote attackers to execute arbitrary code via a crafted Visio document, aka "Memory Corruption Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-041A.html" source="CERT">TA09-041A</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0391" source="VUPEN">ADV-2009-0391</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS09-005.mspx" source="MS" adv="1">MS09-005</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6172" source="OVAL">oval:org.mitre.oval:def:6172</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="visio">
        <vers num="2002" edition="sp2" />
        <vers num="2003" edition="sp3" />
        <vers num="2007" edition="sp1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0097" published="2009-02-10" name="CVE-2009-0097" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Microsoft Office Visio 2002 SP2 and 2003 SP3 does not properly validate memory allocation for Visio files, which allows remote attackers to execute arbitrary code via a crafted file, aka "Memory Corruption Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-041A.html" source="CERT">TA09-041A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS09-005.mspx" source="MS" patch="1" adv="1">MS09-005</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0391" source="VUPEN">ADV-2009-0391</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6188" source="OVAL">oval:org.mitre.oval:def:6188</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="visio">
        <vers num="2002" edition="sp2" />
        <vers num="2003" edition="sp3" />
        <vers num="2007" edition="sp1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0098" published="2009-02-10" name="CVE-2009-0098" modified="2009-03-04" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Microsoft Exchange 2000 Server SP3, Exchange Server 2003 SP2, and Exchange Server 2007 SP1 do not properly interpret Transport Neutral Encapsulation (TNEF) properties, which allows remote attackers to execute arbitrary code via a crafted TNEF message, aka "Memory Corruption Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-041A.html" source="CERT">TA09-041A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS09-003.mspx" source="MS" patch="1" adv="1">MS09-003</ref>
      <ref url="http://secunia.com/advisories/33838" source="SECUNIA">33838</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6114" source="OVAL">oval:org.mitre.oval:def:6114</ref>
      <ref url="http://osvdb.org/51837" source="OSVDB">51837</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="exchange_server">
        <vers num="2000" edition="sp3" />
        <vers num="2003" edition="sp2" />
        <vers num="2007" edition="sp1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0099" published="2009-02-10" name="CVE-2009-0099" modified="2009-03-04" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The Electronic Messaging System Microsoft Data Base (EMSMDB32) provider in Microsoft Exchange 2000 Server SP3 and Exchange Server 2003 SP2, as used in Exchange System Attendant, allows remote attackers to cause a denial of service (application outage) via a malformed MAPI command, aka "Literal Processing Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-041A.html" source="CERT">TA09-041A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS09-003.mspx" source="MS" patch="1" adv="1">MS09-003</ref>
      <ref url="http://secunia.com/advisories/33838" source="SECUNIA">33838</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6159" source="OVAL">oval:org.mitre.oval:def:6159</ref>
      <ref url="http://osvdb.org/51838" source="OSVDB">51838</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="exchange_server">
        <vers num="2000" edition="sp3" />
        <vers num="2003" edition="sp2" />
        <vers num="2007" edition="sp1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0100" published="2009-04-15" name="CVE-2009-0100" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Microsoft Office Excel 2000 SP3, 2002 SP3, 2003 SP3, and 2007 SP1; Excel in Microsoft Office 2004 and 2008 for Mac; Microsoft Office Excel Viewer and Excel Viewer 2003 SP3; and Microsoft Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 do not properly parse the Excel spreadsheet file format, which allows remote attackers to execute arbitrary code via a crafted spreadsheet that contains a malformed object with "an offset and a two-byte value" that trigger a memory calculation error, aka "Memory Corruption Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-104A.html" source="CERT">TA09-104A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS09-009.mspx" source="MS" patch="1" adv="1">MS09-009</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1023" source="VUPEN">ADV-2009-1023</ref>
      <ref url="http://www.securitytracker.com/id?1022039" source="SECTRACK">1022039</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/502696/100/0/threaded" source="BUGTRAQ">20090415 Microsoft Office Excel Remote Memory Corruption Vulnerability</ref>
      <ref url="http://www.fortiguardcenter.com/advisory/FGA-2009-16.html" source="MISC">http://www.fortiguardcenter.com/advisory/FGA-2009-16.html</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6043" source="OVAL">oval:org.mitre.oval:def:6043</ref>
      <ref url="http://osvdb.org/53665" source="OSVDB">53665</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="office">
        <vers num="2004" edition="" />
        <vers num="2004" edition=":mac" />
        <vers num="2008" edition="" />
        <vers num="2008" edition=":mac" />
      </prod>
      <prod vendor="microsoft" name="office_compatibility_pack_for_word_excel_ppt_2007">
        <vers num="" edition="sp1" />
      </prod>
      <prod vendor="microsoft" name="office_excel">
        <vers num="2000" edition="sp3" />
        <vers num="2002" edition="sp3" />
        <vers num="2003" edition="sp3" />
        <vers num="2007" edition="sp1" />
      </prod>
      <prod vendor="microsoft" name="office_excel_viewer">
        <vers num="2003" edition="sp3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0102" published="2009-12-09" name="CVE-2009-0102" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Microsoft Project 2000 SR1 and 2002 SP1, and Office Project 2003 SP3, does not properly handle memory allocation for Project files, which allows remote attackers to execute arbitrary code via a malformed file, aka "Project Memory Validation Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-342A.html" source="CERT">TA09-342A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS09-074.mspx" source="MS" patch="1" adv="1">MS09-074</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6298" source="OVAL">oval:org.mitre.oval:def:6298</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="office_project">
        <vers num="2007" edition="sp1" />
        <vers num="2007" edition="sp2" />
      </prod>
      <prod vendor="microsoft" name="project_portfolio_server">
        <vers num="2007" edition="sp1" />
        <vers num="2007" edition="sp2" />
      </prod>
      <prod vendor="microsoft" name="project_server">
        <vers num="2003" edition="sp3" />
        <vers num="2007" edition="sp1" />
        <vers num="2007" edition="sp2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0103" published="2009-01-09" name="CVE-2009-0103" modified="2009-01-29" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple PHP remote file inclusion vulnerabilities in playSMS 0.9.3 allow remote attackers to execute arbitrary PHP code via a URL in the (1) apps_path[plug] parameter to plugin/gateway/gnokii/init.php, the (2) apps_path[themes] parameter to plugin/themes/default/init.php, and the (3) apps_path[libs] parameter to lib/function.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/33138" source="BID">33138</ref>
      <ref url="http://www.milw0rm.com/exploits/7687" source="MILW0RM">7687</ref>
      <ref url="http://securityreason.com/securityalert/4888" source="SREASON">4888</ref>
      <ref url="http://secunia.com/advisories/33386" source="SECUNIA" adv="1">33386</ref>
    </refs>
    <vuln_soft>
      <prod vendor="playsms" name="playsms">
        <vers num="0.9.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0104" published="2009-01-09" name="CVE-2009-0104" modified="2009-01-29" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in index.php in EZpack 4.2b2 allows remote attackers to execute arbitrary SQL commands via the qType parameter in a webboard prog action.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/33131" source="BID">33131</ref>
      <ref url="http://www.milw0rm.com/exploits/7680" source="MILW0RM">7680</ref>
      <ref url="http://securityreason.com/securityalert/4890" source="SREASON">4890</ref>
    </refs>
    <vuln_soft>
      <prod vendor="se-ed" name="ezpack">
        <vers num="4.2" edition="beta2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0105" published="2009-01-09" name="CVE-2009-0105" modified="2009-01-29" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in index.php in EZpack 4.2b2 allows remote attackers to inject arbitrary web script or HTML via the mdfd parameter in a prog action.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/33131" source="BID">33131</ref>
      <ref url="http://www.milw0rm.com/exploits/7680" source="MILW0RM">7680</ref>
      <ref url="http://securityreason.com/securityalert/4890" source="SREASON">4890</ref>
    </refs>
    <vuln_soft>
      <prod vendor="se-ed" name="ezpack">
        <vers num="4.2" edition="beta2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0106" published="2009-01-09" name="CVE-2009-0106" modified="2009-04-10" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in profile.php in PHPAuctions (aka PHPAuctionSystem) allows remote attackers to execute arbitrary SQL commands via the user_id parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/43264" source="XF">phpauctions-profile-sql-injection(43264)</ref>
      <ref url="http://www.securityfocus.com/bid/33115" source="BID">33115</ref>
      <ref url="http://secunia.com/advisories/33331" source="SECUNIA" adv="1">33331</ref>
      <ref url="http://osvdb.org/51144" source="OSVDB">51144</ref>
      <ref url="http://milw0rm.com/exploits/7672" source="MILW0RM">7672</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpauctions" name="phpauctions">
        <vers num="_nil_" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0107" published="2009-01-09" name="CVE-2009-0107" modified="2009-01-09" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in profile.php in PHPAuctions (aka PHPAuctionSystem) allows remote attackers to inject arbitrary web script or HTML via the user_id parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/33115" source="BID">33115</ref>
      <ref url="http://secunia.com/advisories/33331" source="SECUNIA" adv="1">33331</ref>
      <ref url="http://osvdb.org/51145" source="OSVDB">51145</ref>
      <ref url="http://milw0rm.com/exploits/7672" source="MILW0RM">7672</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpauctions" name="phpauctions">
        <vers num="_nil_" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0108" published="2009-01-09" name="CVE-2009-0108" modified="2009-01-29" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHPAuctions (aka PHPAuctionSystem) allows remote attackers to bypass authentication and gain administrative access via modified (1) PHPAUCTION_RM_ID, (2) PHPAUCTION_RM_NAME, (3) PHPAUCTION_RM_USERNAME, and (4) PHPAUCTION_RM_EMAIL cookies.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/33120" source="BID">33120</ref>
      <ref url="http://www.milw0rm.com/exploits/7674" source="MILW0RM">7674</ref>
      <ref url="http://securityreason.com/securityalert/4891" source="SREASON">4891</ref>
      <ref url="http://secunia.com/advisories/33331" source="SECUNIA" adv="1">33331</ref>
      <ref url="http://osvdb.org/51146" source="OSVDB">51146</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpauctions" name="phpauctions">
        <vers num="_nil_" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0109" published="2009-01-09" name="CVE-2009-0109" modified="2009-01-29" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in index.php in RiotPix 0.61 and earlier allows remote attackers to execute arbitrary SQL commands via the username parameter.  NOTE: some of these details are obtained from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/33132" source="BID">33132</ref>
      <ref url="http://www.milw0rm.com/exploits/7682" source="MILW0RM">7682</ref>
      <ref url="http://securityreason.com/securityalert/4892" source="SREASON">4892</ref>
      <ref url="http://secunia.com/advisories/33395" source="SECUNIA" adv="1">33395</ref>
    </refs>
    <vuln_soft>
      <prod vendor="riotpix" name="riotpix">
        <vers num=".05" />
        <vers num="0.5" />
        <vers num="0.51" edition="beta" />
        <vers num="0.52" />
        <vers num="0.60" />
        <vers prev="1" num="0.61" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0110" published="2009-01-09" name="CVE-2009-0110" modified="2009-01-29" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in read.php in RiotPix 0.61 and earlier allows remote attackers to execute arbitrary SQL commands via the forumid parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/33129" source="BID">33129</ref>
      <ref url="http://www.milw0rm.com/exploits/7679" source="MILW0RM">7679</ref>
      <ref url="http://securityreason.com/securityalert/4893" source="SREASON">4893</ref>
      <ref url="http://secunia.com/advisories/33395" source="SECUNIA" adv="1">33395</ref>
    </refs>
    <vuln_soft>
      <prod vendor="riotpix" name="riotpix">
        <vers num=".05" />
        <vers num="0.5" />
        <vers num="0.51" edition="beta" />
        <vers num="0.52" />
        <vers num="0.60" />
        <vers prev="1" num="0.61" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0111" published="2009-01-09" name="CVE-2009-0111" modified="2009-01-29" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in frontpage.php in Goople CMS 1.8.2 and earlier allows remote attackers to execute arbitrary SQL commands via the username parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/33135" source="BID">33135</ref>
      <ref url="http://www.milw0rm.com/exploits/7683" source="MILW0RM">7683</ref>
      <ref url="http://securityreason.com/securityalert/4894" source="SREASON">4894</ref>
      <ref url="http://secunia.com/advisories/33393" source="SECUNIA" adv="1">33393</ref>
    </refs>
    <vuln_soft>
      <prod vendor="goople_cms" name="goople_cms">
        <vers prev="1" num="1.8.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0112" published="2009-01-09" name="CVE-2009-0112" modified="2009-01-29" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site request forgery (CSRF) vulnerability in admin/agent_edit.asp in PollPro 3.0 allows remote attackers to create or modify accounts as administrators via the username, password, and name parameters.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/47754" source="XF">pollpro-unspecified-csrf(47754)</ref>
      <ref url="http://securityreason.com/securityalert/4895" source="SREASON">4895</ref>
      <ref url="http://secunia.com/advisories/33319" source="SECUNIA" adv="1">33319</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=123117044713213&amp;w=2" source="BUGTRAQ">20090103 PollPro 3.0 XSRF VuLn</ref>
    </refs>
    <vuln_soft>
      <prod vendor="expinion" name="poll_pro">
        <vers num="3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0113" published="2009-01-09" name="CVE-2009-0113" modified="2009-01-29" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in attachmentlibrary.php in the XStandard component for Joomla! 1.5.8 and earlier allows remote attackers to list arbitrary directories via a .. (dot dot) in the X_CMS_LIBRARY_PATH HTTP header.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/33143" source="BID">33143</ref>
      <ref url="http://www.milw0rm.com/exploits/7691" source="MILW0RM">7691</ref>
      <ref url="http://securityreason.com/securityalert/4896" source="SREASON">4896</ref>
      <ref url="http://secunia.com/advisories/33377" source="SECUNIA" adv="1">33377</ref>
    </refs>
    <vuln_soft>
      <prod vendor="joomla" name="xstandard">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0114" published="2009-02-26" name="CVE-2009-0114" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:P)" CVSS_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_base_score="5.8">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Settings Manager in Adobe Flash Player 9.x before 9.0.159.0 and 10.x before 10.0.22.87, and possibly other versions, allows remote attackers to trick a user into visiting an arbitrary URL via unknown vectors, related to "a potential Clickjacking issue variant."</descript>
    </desc>
    <loss_types>
      <avail />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-133A.html" source="CERT">TA09-133A</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0513" source="VUPEN" patch="1">ADV-2009-0513</ref>
      <ref url="http://www.adobe.com/support/security/bulletins/apsb09-01.html" source="CONFIRM" patch="1" adv="1">http://www.adobe.com/support/security/bulletins/apsb09-01.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/48902" source="XF">flash-settings-manager-click-hijacking(48902)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1297" source="VUPEN">ADV-2009-1297</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0743" source="VUPEN">ADV-2009-0743</ref>
      <ref url="http://support.apple.com/kb/HT3549" source="CONFIRM">http://support.apple.com/kb/HT3549</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-254909-1" source="SUNALERT">254909</ref>
      <ref url="http://securitytracker.com/id?1021751" source="SECTRACK">1021751</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200903-23.xml" source="GENTOO">GLSA-200903-23</ref>
      <ref url="http://secunia.com/advisories/35074" source="SECUNIA">35074</ref>
      <ref url="http://secunia.com/advisories/34293" source="SECUNIA">34293</ref>
      <ref url="http://secunia.com/advisories/34226" source="SECUNIA">34226</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6662" source="OVAL">oval:org.mitre.oval:def:6662</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2009/May/msg00002.html" source="APPLE">APPLE-SA-2009-05-12</ref>
      <ref url="http://isc.sans.org/diary.html?storyid=5929" source="MISC">http://isc.sans.org/diary.html?storyid=5929</ref>
    </refs>
    <vuln_soft>
      <prod vendor="adobe" name="air">
        <vers num="1.5" />
      </prod>
      <prod vendor="adobe" name="flash_player">
        <vers num="10.0.0.584" />
        <vers num="10.0.12.10" />
        <vers prev="1" num="10.0.12.36" />
        <vers num="7.0" />
        <vers num="7.0.1" />
        <vers num="7.0.25" />
        <vers num="7.0.63" edition="" />
        <vers num="7.0.63" edition=":linux" />
        <vers num="7.0.69.0" />
        <vers num="7.0.70.0" />
        <vers num="7.1" />
        <vers num="7.1.1" />
        <vers num="7.2" />
        <vers num="8.0" edition="" />
        <vers num="8.0" edition=":pro" />
        <vers num="8.0" edition=":basic" />
        <vers num="8.0.24.0" />
        <vers num="8.0.34.0" />
        <vers num="8.0.35.0" />
        <vers num="8.0.39.0" />
        <vers num="9.0.112.0" />
        <vers num="9.0.114.0" />
        <vers num="9.0.115.0" />
        <vers num="9.0.124.0" />
        <vers num="9.0.16" />
        <vers num="9.0.20" />
        <vers num="9.0.20.0" />
        <vers num="9.0.28" />
        <vers num="9.0.28.0" />
        <vers num="9.0.31.0" />
        <vers num="9.0.45.0" />
        <vers num="9.0.47.0" />
        <vers num="9.0.48.0" />
        <vers num="cs3" edition="" />
        <vers num="cs3" edition=":pro" />
        <vers num="cs4" edition="" />
        <vers num="cs4" edition=":pro" />
      </prod>
      <prod vendor="adobe" name="flash_player_for_linux">
        <vers prev="1" num="10.0.15.3" />
      </prod>
      <prod vendor="adobe" name="flex">
        <vers num="3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0115" published="2009-03-30" name="CVE-2009-0115" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">The Device Mapper multipathing driver (aka multipath-tools or device-mapper-multipath) 0.4.8, as used in SUSE openSUSE, SUSE Linux Enterprise Server (SLES), Fedora, and possibly other operating systems, uses world-writable permissions for the socket file (aka /var/run/multipathd.sock), which allows local users to send arbitrary commands to the multipath daemon.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-April/msg00236.html" source="FEDORA">FEDORA-2009-3453</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-April/msg00231.html" source="FEDORA">FEDORA-2009-3449</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0528" source="VUPEN">ADV-2010-0528</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1767" source="DEBIAN">DSA-1767</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2009-128.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2009-128.htm</ref>
      <ref url="http://secunia.com/advisories/38794" source="SECUNIA" adv="1">38794</ref>
      <ref url="http://secunia.com/advisories/34759" source="SECUNIA" adv="1">34759</ref>
      <ref url="http://secunia.com/advisories/34710" source="SECUNIA" adv="1">34710</ref>
      <ref url="http://secunia.com/advisories/34694" source="SECUNIA" adv="1">34694</ref>
      <ref url="http://secunia.com/advisories/34642" source="SECUNIA" adv="1">34642</ref>
      <ref url="http://secunia.com/advisories/34418" source="SECUNIA" adv="1">34418</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9214" source="OVAL">oval:org.mitre.oval:def:9214</ref>
      <ref url="http://lists.vmware.com/pipermail/security-announce/2010/000082.html" source="MLIST">[security-announce] 20100303 VMSA-2010-0004 ESX Service Console and vMA third party updates</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-04/msg00003.html" source="SUSE">SUSE-SR:2009:008</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-03/msg00004.html" source="SUSE">SUSE-SR:2009:007</ref>
      <ref url="http://launchpad.net/bugs/cve/2009-0115" source="MISC">http://launchpad.net/bugs/cve/2009-0115</ref>
      <ref url="http://download.opensuse.org/update/10.3-test/repodata/patch-kpartx-6082.xml" source="CONFIRM">http://download.opensuse.org/update/10.3-test/repodata/patch-kpartx-6082.xml</ref>
    </refs>
    <vuln_soft>
      <prod vendor="christophe.varoqui" name="multipath-tools">
        <vers num="0.4.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0119" published="2009-01-14" name="CVE-2009-0119" modified="2009-01-29" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in Microsoft Windows XP SP3 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via a crafted .chm file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/33204" source="BID">33204</ref>
      <ref url="http://www.milw0rm.com/exploits/7720" source="MILW0RM">7720</ref>
      <ref url="http://securityreason.com/securityalert/4912" source="SREASON">4912</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition="sp3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0120" published="2009-01-14" name="CVE-2009-0120" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">The IBM WebSphere DataPower XML Security Gateway XS40 with firmware 3.6.1.5 allows remote attackers to cause a denial of service (device reboot) by sending data over an established SSL connection, as demonstrated by the abc\r\n\r\n string data.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2009/0111" source="VUPEN">ADV-2009-0111</ref>
      <ref url="http://www.securitytracker.com/id?1021547" source="SECTRACK">1021547</ref>
      <ref url="http://www.securityfocus.com/bid/33169" source="BID">33169</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/499870/100/0/threaded" source="BUGTRAQ">20090108 [IBM Datapower XS40] Denial of Service</ref>
      <ref url="http://securityreason.com/securityalert/4911" source="SREASON">4911</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="websphere_datapower_xml_security_gateway_xs40">
        <vers num="3.6.1.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0121" published="2009-01-14" name="CVE-2009-0121" modified="2009-01-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in frontpage.php in Goople CMS 1.8.2 allows remote attackers to execute arbitrary SQL commands via the password parameter.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/33393" source="SECUNIA" adv="1">33393</ref>
    </refs>
    <vuln_soft>
      <prod vendor="goople_cms" name="goople_cms">
        <vers num="1.8.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0122" published="2009-01-15" name="CVE-2009-0122" modified="2009-01-31" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="6.9" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.4" CVSS_base_score="6.9">
    <desc>
      <descript source="cve">hplip.postinst in HP Linux Imaging and Printing (HPLIP) 2.7.7 and 2.8.2 on Ubuntu allows local users to change the ownership of arbitrary files via unspecified manipulations in advance of an HPLIP installation or upgrade by an administrator, related to the product's attempt to correct the ownership of its configuration files within home directories.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/33249" source="BID" patch="1">33249</ref>
      <ref url="https://launchpad.net/bugs/191299" source="CONFIRM">https://launchpad.net/bugs/191299</ref>
      <ref url="http://www.ubuntu.com/usn/usn-708-1" source="UBUNTU">USN-708-1</ref>
      <ref url="http://secunia.com/advisories/33539" source="SECUNIA">33539</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="hplip">
        <vers num="2.7.7" />
        <vers num="2.8.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0123" published="2009-01-15" name="CVE-2009-0123" modified="2009-01-22" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:N/A:N)" CVSS_score="7.1" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="8.6" CVSS_base_score="7.1">
    <desc>
      <descript source="cve">Unspecified vulnerability in Apple Safari on Mac OS X 10.5 and Windows allows remote attackers to read arbitrary files on a client machine via vectors related to the association of Safari with the (1) feed, (2) feeds, and (3) feedsearch URL types for RSS feeds.  NOTE: as of 20090114, the only disclosure is a vague pre-advisory. However, because it is from a well-known researcher, it is being assigned a CVE identifier for tracking purposes.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/47917" source="XF">safari-rss-feed-info-disclosure(47917)</ref>
      <ref url="http://www.securitytracker.com/id?1021581" source="SECTRACK">1021581</ref>
      <ref url="http://www.securityfocus.com/bid/33234" source="BID">33234</ref>
      <ref url="http://secunia.com/advisories/33458" source="SECUNIA">33458</ref>
      <ref url="http://isc.sans.org/diary.html?storyid=5689" source="MISC">http://isc.sans.org/diary.html?storyid=5689</ref>
      <ref url="http://brian.mastenbrook.net/display/27" source="MISC">http://brian.mastenbrook.net/display/27</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="safari">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0124" published="2009-01-15" name="CVE-2009-0124" modified="2009-02-06" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The tqsl_verifyDataBlock function in openssl_cert.cpp in American Radio Relay League (ARRL) tqsllib 2.0 does not properly check the return value from the OpenSSL EVP_VerifyFinal function, which allows remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature, a similar vulnerability to CVE-2008-5077.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-January/msg00557.html" source="FEDORA">FEDORA-2009-0543</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=479650" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=479650</ref>
      <ref url="http://secunia.com/advisories/33543" source="SECUNIA">33543</ref>
      <ref url="http://openwall.com/lists/oss-security/2009/01/12/4" source="MLIST">[oss-security] 20090112 CVE Request -- tsqllib, slurm-llnl, libnasl, libcrypt-openssl-dsa-perl, erlang, boinc-client, m2crypto</ref>
      <ref url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=511509" source="MISC">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=511509</ref>
    </refs>
    <vuln_soft>
      <prod vendor="arrl" name="tqsllib">
        <vers num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0125" published="2009-01-15" name="CVE-2009-0125" modified="2009-02-10" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">** DISPUTED **  NOTE: this issue has been disputed by the upstream vendor. nasl/nasl_crypto2.c in the Nessus Attack Scripting Language library (aka libnasl) 2.2.11 does not properly check the return value from the OpenSSL DSA_do_verify function, which allows remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature, a similar vulnerability to CVE-2008-5077.  NOTE: the upstream vendor has disputed this issue, stating "while we do misuse this function (this is a bug), it has absolutely no security ramification."</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=479655" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=479655</ref>
      <ref url="http://www.attrition.org/pipermail/vim/2009-January/002133.html" source="VIM">20090120 CVE-2009-0125 (fwd)</ref>
      <ref url="http://openwall.com/lists/oss-security/2009/01/12/4" source="MLIST">[oss-security] 20090112 CVE Request -- tsqllib, slurm-llnl, libnasl, libcrypt-openssl-dsa-perl, erlang, boinc-client, m2crypto</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-02/msg00000.html" source="SUSE">SUSE-SR:2009:003</ref>
      <ref url="http://cvs.fedoraproject.org/viewvc/rpms/libnasl/F-10/libnasl.spec?r1=1.16&amp;r2=1.17" source="CONFIRM">http://cvs.fedoraproject.org/viewvc/rpms/libnasl/F-10/libnasl.spec?r1=1.16&amp;r2=1.17</ref>
      <ref url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=511517" source="MISC">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=511517</ref>
    </refs>
    <vuln_soft>
      <prod vendor="finkproject" name="libnasl">
        <vers num="2.2.11" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0126" published="2009-01-15" name="CVE-2009-0126" modified="2009-03-06" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The decrypt_public function in lib/crypt.cpp in the client in Berkeley Open Infrastructure for Network Computing (BOINC) 6.2.14 and 6.4.5 does not check the return value from the OpenSSL RSA_public_decrypt function, which allows remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature, a similar vulnerability to CVE-2008-5077.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-February/msg00034.html" source="FEDORA">FEDORA-2009-0578</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=479664" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=479664</ref>
      <ref url="http://secunia.com/advisories/33828" source="SECUNIA">33828</ref>
      <ref url="http://secunia.com/advisories/33806" source="SECUNIA">33806</ref>
      <ref url="http://openwall.com/lists/oss-security/2009/01/12/4" source="MLIST">[oss-security] 20090112 CVE Request -- tsqllib, slurm-llnl, libnasl, libcrypt-openssl-dsa-perl, erlang, boinc-client, m2crypto</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-02/msg00000.html" source="SUSE">SUSE-SR:2009:003</ref>
      <ref url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=511521" source="CONFIRM">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=511521</ref>
      <ref url="http://boinc.berkeley.edu/trac/ticket/823" source="CONFIRM" adv="1">http://boinc.berkeley.edu/trac/ticket/823</ref>
      <ref url="http://boinc.berkeley.edu/trac/changeset/16883" source="CONFIRM">http://boinc.berkeley.edu/trac/changeset/16883</ref>
    </refs>
    <vuln_soft>
      <prod vendor="berkeley" name="boinc_client">
        <vers num="6.2.14" />
        <vers num="6.4.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0127" published="2009-01-15" name="CVE-2009-0127" modified="2009-01-16" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">** DISPUTED ** M2Crypto does not properly check the return value from the OpenSSL EVP_VerifyFinal, DSA_verify, ECDSA_verify, DSA_do_verify, and ECDSA_do_verify functions, which might allow remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature, a similar vulnerability to CVE-2008-5077.  NOTE: a Linux vendor disputes the relevance of this report to the M2Crypto product because "these functions are not used anywhere in m2crypto."</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=479676" source="MISC">https://bugzilla.redhat.com/show_bug.cgi?id=479676</ref>
      <ref url="http://openwall.com/lists/oss-security/2009/01/12/4" source="MLIST">[oss-security] 20090112 CVE Request -- tsqllib, slurm-llnl, libnasl, libcrypt-openssl-dsa-perl, erlang, boinc-client, m2crypto</ref>
      <ref url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=511515" source="MISC">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=511515</ref>
    </refs>
    <vuln_soft>
      <prod vendor="heikkitoivonen" name="m2crypto">
        <vers num="_nil_" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0128" published="2009-01-15" name="CVE-2009-0128" modified="2009-01-16" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">plugins/crypto/openssl/crypto_openssl.c in Simple Linux Utility for Resource Management (aka SLURM or slurm-llnl) does not properly check the return value from the OpenSSL EVP_VerifyFinal function, which allows remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature, a similar vulnerability to CVE-2008-5077.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://openwall.com/lists/oss-security/2009/01/12/4" source="MLIST">[oss-security] 20090112 CVE Request -- tsqllib, slurm-llnl, libnasl, libcrypt-openssl-dsa-perl, erlang, boinc-client, m2crypto</ref>
      <ref url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=511511" source="MISC">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=511511</ref>
    </refs>
    <vuln_soft>
      <prod vendor="llnl" name="slurm">
        <vers num="_nil_" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0129" published="2009-01-15" name="CVE-2009-0129" modified="2009-01-16" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">libcrypt-openssl-dsa-perl does not properly check the return value from the OpenSSL DSA_verify and DSA_do_verify functions, which might allow remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature, a similar vulnerability to CVE-2008-5077.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://openwall.com/lists/oss-security/2009/01/12/4" source="MLIST">[oss-security] 20090112 CVE Request -- tsqllib, slurm-llnl, libnasl, libcrypt-openssl-dsa-perl, erlang, boinc-client, m2crypto</ref>
      <ref url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=511519" source="CONFIRM">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=511519</ref>
    </refs>
    <vuln_soft>
      <prod vendor="perl-openssl" name="libcrypt-openssl-dsa-perl">
        <vers num="_nil_" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0130" published="2009-01-15" name="CVE-2009-0130" modified="2009-01-16" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">** DISPUTED ** lib/crypto/c_src/crypto_drv.c in erlang does not properly check the return value from the OpenSSL DSA_do_verify function, which might allow remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature, a similar vulnerability to CVE-2008-5077.  NOTE: a package maintainer disputes this issue, reporting that there is a proper check within the only code that uses the applicable part of crypto_drv.c, and thus "this report is invalid."</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://openwall.com/lists/oss-security/2009/01/12/4" source="MLIST">[oss-security] 20090112 CVE Request -- tsqllib, slurm-llnl, libnasl, libcrypt-openssl-dsa-perl, erlang, boinc-client, m2crypto</ref>
      <ref url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=511520" source="MISC">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=511520</ref>
    </refs>
    <vuln_soft>
      <prod vendor="erlang" name="erlang">
        <vers num="_nil_" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0131" published="2009-01-15" name="CVE-2009-0131" modified="2009-02-05" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="4.9" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="3.9" CVSS_base_score="4.9">
    <desc>
      <descript source="cve">The UFS implementation in the kernel in Sun OpenSolaris snv_29 through snv_90 allows local users to cause a denial of service (panic) via the single posix_fallocate test in the SUSv3 POSIX test suite, related to an F_ALLOCSP fcntl call.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securitytracker.com/id?1021600" source="SECTRACK">1021600</ref>
      <ref url="http://www.securityfocus.com/bid/33267" source="BID">33267</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-239188-1" source="SUNALERT">239188</ref>
      <ref url="http://bugs.opensolaris.org/view_bug.do?bug_id=6711995" source="CONFIRM">http://bugs.opensolaris.org/view_bug.do?bug_id=6711995</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="opensolaris">
        <vers num="snv_29" edition="" />
        <vers num="snv_29" edition=":x86" />
        <vers num="snv_29" edition=":sparc" />
        <vers num="snv_30" edition="" />
        <vers num="snv_30" edition=":sparc" />
        <vers num="snv_30" edition=":x86" />
        <vers num="snv_31" edition="" />
        <vers num="snv_31" edition=":sparc" />
        <vers num="snv_31" edition=":x86" />
        <vers num="snv_32" edition="" />
        <vers num="snv_32" edition=":x86" />
        <vers num="snv_32" edition=":sparc" />
        <vers num="snv_33" edition="" />
        <vers num="snv_33" edition=":x86" />
        <vers num="snv_33" edition=":sparc" />
        <vers num="snv_34" edition="" />
        <vers num="snv_34" edition=":sparc" />
        <vers num="snv_34" edition=":x86" />
        <vers num="snv_35" edition="" />
        <vers num="snv_35" edition=":sparc" />
        <vers num="snv_35" edition=":x86" />
        <vers num="snv_36" edition="" />
        <vers num="snv_36" edition=":sparc" />
        <vers num="snv_36" edition=":x86" />
        <vers num="snv_37" edition="" />
        <vers num="snv_37" edition=":sparc" />
        <vers num="snv_37" edition=":x86" />
        <vers num="snv_38" edition="" />
        <vers num="snv_38" edition=":sparc" />
        <vers num="snv_38" edition=":x86" />
        <vers num="snv_39" edition="" />
        <vers num="snv_39" edition=":sparc" />
        <vers num="snv_39" edition=":x86" />
        <vers num="snv_40" edition="" />
        <vers num="snv_40" edition=":x86" />
        <vers num="snv_40" edition=":sparc" />
        <vers num="snv_41" edition="" />
        <vers num="snv_41" edition=":sparc" />
        <vers num="snv_41" edition=":x86" />
        <vers num="snv_42" edition="" />
        <vers num="snv_42" edition=":x86" />
        <vers num="snv_42" edition=":sparc" />
        <vers num="snv_43" edition="" />
        <vers num="snv_43" edition=":sparc" />
        <vers num="snv_43" edition=":x86" />
        <vers num="snv_44" edition="" />
        <vers num="snv_44" edition=":x86" />
        <vers num="snv_44" edition=":sparc" />
        <vers num="snv_45" edition="" />
        <vers num="snv_45" edition=":x86" />
        <vers num="snv_45" edition=":sparc" />
        <vers num="snv_46" edition="" />
        <vers num="snv_46" edition=":sparc" />
        <vers num="snv_46" edition=":x86" />
        <vers num="snv_47" edition="" />
        <vers num="snv_47" edition=":x86" />
        <vers num="snv_47" edition=":sparc" />
        <vers num="snv_48" edition="" />
        <vers num="snv_48" edition=":sparc" />
        <vers num="snv_48" edition=":x86" />
        <vers num="snv_49" edition="" />
        <vers num="snv_49" edition=":sparc" />
        <vers num="snv_49" edition=":x86" />
        <vers num="snv_50" edition="" />
        <vers num="snv_50" edition=":sparc" />
        <vers num="snv_50" edition=":x86" />
        <vers num="snv_51" edition="" />
        <vers num="snv_51" edition=":x86" />
        <vers num="snv_51" edition=":sparc" />
        <vers num="snv_52" edition="" />
        <vers num="snv_52" edition=":x86" />
        <vers num="snv_52" edition=":sparc" />
        <vers num="snv_53" edition="" />
        <vers num="snv_53" edition=":sparc" />
        <vers num="snv_53" edition=":x86" />
        <vers num="snv_54" edition="" />
        <vers num="snv_54" edition=":sparc" />
        <vers num="snv_54" edition=":x86" />
        <vers num="snv_55" edition="" />
        <vers num="snv_55" edition=":sparc" />
        <vers num="snv_55" edition=":x86" />
        <vers num="snv_56" edition="" />
        <vers num="snv_56" edition=":x86" />
        <vers num="snv_56" edition=":sparc" />
        <vers num="snv_57" edition="" />
        <vers num="snv_57" edition=":x86" />
        <vers num="snv_57" edition=":sparc" />
        <vers num="snv_58" edition="" />
        <vers num="snv_58" edition=":sparc" />
        <vers num="snv_58" edition=":x86" />
        <vers num="snv_59" edition="" />
        <vers num="snv_59" edition=":sparc" />
        <vers num="snv_59" edition=":x86" />
        <vers num="snv_60" edition="" />
        <vers num="snv_60" edition=":x86" />
        <vers num="snv_60" edition=":sparc" />
        <vers num="snv_61" edition="" />
        <vers num="snv_61" edition=":sparc" />
        <vers num="snv_61" edition=":x86" />
        <vers num="snv_62" edition="" />
        <vers num="snv_62" edition=":x86" />
        <vers num="snv_62" edition=":sparc" />
        <vers num="snv_63" edition="" />
        <vers num="snv_63" edition=":x86" />
        <vers num="snv_63" edition=":sparc" />
        <vers num="snv_64" edition="" />
        <vers num="snv_64" edition=":x86" />
        <vers num="snv_64" edition=":sparc" />
        <vers num="snv_65" edition="" />
        <vers num="snv_65" edition=":sparc" />
        <vers num="snv_65" edition=":x86" />
        <vers num="snv_66" edition="" />
        <vers num="snv_66" edition=":x86" />
        <vers num="snv_66" edition=":sparc" />
        <vers num="snv_67" edition="" />
        <vers num="snv_67" edition=":sparc" />
        <vers num="snv_67" edition=":x86" />
        <vers num="snv_68" edition="" />
        <vers num="snv_68" edition=":x86" />
        <vers num="snv_68" edition=":sparc" />
        <vers num="snv_69" edition="" />
        <vers num="snv_69" edition=":sparc" />
        <vers num="snv_69" edition=":x86" />
        <vers num="snv_70" edition="" />
        <vers num="snv_70" edition=":sparc" />
        <vers num="snv_70" edition=":x86" />
        <vers num="snv_71" edition="" />
        <vers num="snv_71" edition=":sparc" />
        <vers num="snv_71" edition=":x86" />
        <vers num="snv_72" edition="" />
        <vers num="snv_72" edition=":x86" />
        <vers num="snv_72" edition=":sparc" />
        <vers num="snv_73" edition="" />
        <vers num="snv_73" edition=":x86" />
        <vers num="snv_73" edition=":sparc" />
        <vers num="snv_74" edition="" />
        <vers num="snv_74" edition=":x86" />
        <vers num="snv_74" edition=":sparc" />
        <vers num="snv_75" edition="" />
        <vers num="snv_75" edition=":x86" />
        <vers num="snv_75" edition=":sparc" />
        <vers num="snv_76" edition="" />
        <vers num="snv_76" edition=":sparc" />
        <vers num="snv_76" edition=":x86" />
        <vers num="snv_77" edition="" />
        <vers num="snv_77" edition=":sparc" />
        <vers num="snv_77" edition=":x86" />
        <vers num="snv_78" edition="" />
        <vers num="snv_78" edition=":sparc" />
        <vers num="snv_78" edition=":x86" />
        <vers num="snv_79" edition="" />
        <vers num="snv_79" edition=":x86" />
        <vers num="snv_79" edition=":sparc" />
        <vers num="snv_80" edition="" />
        <vers num="snv_80" edition=":x86" />
        <vers num="snv_80" edition=":sparc" />
        <vers num="snv_81" edition="" />
        <vers num="snv_81" edition=":x86" />
        <vers num="snv_81" edition=":sparc" />
        <vers num="snv_82" edition="" />
        <vers num="snv_82" edition=":x86" />
        <vers num="snv_82" edition=":sparc" />
        <vers num="snv_83" edition="" />
        <vers num="snv_83" edition=":sparc" />
        <vers num="snv_83" edition=":x86" />
        <vers num="snv_84" edition="" />
        <vers num="snv_84" edition=":x86" />
        <vers num="snv_84" edition=":sparc" />
        <vers num="snv_85" edition="" />
        <vers num="snv_85" edition=":sparc" />
        <vers num="snv_85" edition=":x86" />
        <vers num="snv_86" edition="" />
        <vers num="snv_86" edition=":sparc" />
        <vers num="snv_86" edition=":x86" />
        <vers num="snv_87" edition="" />
        <vers num="snv_87" edition=":sparc" />
        <vers num="snv_87" edition=":x86" />
        <vers num="snv_88" edition="" />
        <vers num="snv_88" edition=":x86" />
        <vers num="snv_88" edition=":sparc" />
        <vers num="snv_89" edition="" />
        <vers num="snv_89" edition=":x86" />
        <vers num="snv_89" edition=":sparc" />
        <vers num="snv_90" edition="" />
        <vers num="snv_90" edition=":sparc" />
        <vers num="snv_90" edition=":x86" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0132" published="2009-01-15" name="CVE-2009-0132" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="4.9" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="3.9" CVSS_base_score="4.9">
    <desc>
      <descript source="cve">Integer overflow in the aio_suspend function in Sun Solaris 8 through 10 and OpenSolaris, when 32-bit mode is enabled, allows local users to cause a denial of service (panic) via a large integer value in the second argument (aka nent argument).</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/33188" source="BID" patch="1">33188</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-21-117350-59-1" source="CONFIRM" patch="1">http://sunsolve.sun.com/search/document.do?assetkey=1-21-117350-59-1</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0099" source="VUPEN">ADV-2009-0099</ref>
      <ref url="http://www.trapkit.de/advisories/TKADV2009-001.txt" source="MISC">http://www.trapkit.de/advisories/TKADV2009-001.txt</ref>
      <ref url="http://www.securitytracker.com/id?1021553" source="SECTRACK">1021553</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-247986-1" source="SUNALERT" adv="1">247986</ref>
      <ref url="http://secunia.com/advisories/33516" source="SECUNIA">33516</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="opensolaris">
        <vers num="" edition=":sparc" />
        <vers num="" edition=":x86" />
      </prod>
      <prod vendor="sun" name="solaris">
        <vers num="10" edition="" />
        <vers num="10" edition=":x86" />
        <vers num="10" edition=":sparc" />
        <vers num="8" edition="" />
        <vers num="8" edition=":x86" />
        <vers num="8" edition=":sparc" />
        <vers num="9" edition="" />
        <vers num="9" edition=":sparc" />
        <vers num="9" edition=":x86" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0133" published="2009-01-15" name="CVE-2009-0133" modified="2009-01-29" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in Microsoft HTML Help Workshop 4.74 and earlier allows context-dependent attackers to execute arbitrary code via a .hhp file with a long "Index file" field, possibly a related issue to CVE-2006-0564.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.milw0rm.com/exploits/7727" source="MILW0RM">7727</ref>
      <ref url="http://securityreason.com/securityalert/4914" source="SREASON">4914</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="html_help_workshop">
        <vers num="4.74" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0134" published="2009-01-16" name="CVE-2009-0134" modified="2009-01-29" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Insecure method vulnerability in the EasyGrid.SGCtrl.32 ActiveX control in EasyGrid.ocx 1.0.0.1 in AAA EasyGrid ActiveX 3.51 allows remote attackers to create and overwrite arbitrary files via the (1) DoSaveFile or (2) DoSaveHtmlFile method.  NOTE: vector 1 could be leveraged for code execution by creating executable files in Startup folders or by accessing files using hcp:// URLs.  NOTE: some of these details are obtained from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/47946" source="XF">easygrid-activex-dosavefile-file-overwrite(47946)</ref>
      <ref url="http://www.securityfocus.com/bid/33272" source="BID">33272</ref>
      <ref url="http://www.milw0rm.com/exploits/7779" source="MILW0RM">7779</ref>
      <ref url="http://securityreason.com/securityalert/4913" source="SREASON">4913</ref>
      <ref url="http://secunia.com/advisories/33537" source="SECUNIA" adv="1">33537</ref>
    </refs>
    <vuln_soft>
      <prod vendor="share2" name="easy_grid_control">
        <vers num="3.51" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0135" published="2009-01-16" name="CVE-2009-0135" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Multiple integer overflows in the Audible::Tag::readTag function in metadata/audible/audibletag.cpp in Amarok 1.4.10 through 2.0.1 allow remote attackers to execute arbitrary code via an Audible Audio (.aa) file with a large (1) nlen or (2) vlen Tag value, each of which triggers a heap-based buffer overflow.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-January/msg00708.html" source="FEDORA">FEDORA-2009-0715</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=479946" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=479946</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=479560" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=479560</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0100" source="VUPEN">ADV-2009-0100</ref>
      <ref url="http://www.ubuntu.com/usn/USN-739-1" source="UBUNTU">USN-739-1</ref>
      <ref url="http://www.securitytracker.com/id?1021558" source="SECTRACK">1021558</ref>
      <ref url="http://www.securityfocus.com/bid/33210" source="BID">33210</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/499984/100/0/threaded" source="BUGTRAQ">20090111 [TKADV2009-002] Amarok Integer Overflow and Unchecked Allocation Vulnerabilities</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:030" source="MANDRIVA">MDVSA-2009:030</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1706" source="DEBIAN">DSA-1706</ref>
      <ref url="http://websvn.kde.org/?view=rev&amp;revision=908415" source="CONFIRM">http://websvn.kde.org/?view=rev&amp;revision=908415</ref>
      <ref url="http://websvn.kde.org/?view=rev&amp;revision=908401" source="CONFIRM">http://websvn.kde.org/?view=rev&amp;revision=908401</ref>
      <ref url="http://websvn.kde.org/?view=rev&amp;revision=908391" source="CONFIRM">http://websvn.kde.org/?view=rev&amp;revision=908391</ref>
      <ref url="http://trapkit.de/advisories/TKADV2009-002.txt" source="MISC">http://trapkit.de/advisories/TKADV2009-002.txt</ref>
      <ref url="http://securityreason.com/securityalert/4915" source="SREASON">4915</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200903-34.xml" source="GENTOO">GLSA-200903-34</ref>
      <ref url="http://secunia.com/advisories/34407" source="SECUNIA">34407</ref>
      <ref url="http://secunia.com/advisories/34315" source="SECUNIA">34315</ref>
      <ref url="http://secunia.com/advisories/33819" source="SECUNIA">33819</ref>
      <ref url="http://secunia.com/advisories/33640" source="SECUNIA">33640</ref>
      <ref url="http://secunia.com/advisories/33522" source="SECUNIA">33522</ref>
      <ref url="http://secunia.com/advisories/33505" source="SECUNIA" adv="1">33505</ref>
      <ref url="http://openwall.com/lists/oss-security/2009/01/14/2" source="MLIST">[oss-security] 20090114 CVE Request -- amarok</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-02/msg00000.html" source="SUSE">SUSE-SR:2009:003</ref>
      <ref url="http://bugs.gentoo.org/show_bug.cgi?id=254896" source="CONFIRM">http://bugs.gentoo.org/show_bug.cgi?id=254896</ref>
      <ref url="http://amarok.kde.org/en/releases/2.0.1.1" source="CONFIRM" adv="1">http://amarok.kde.org/en/releases/2.0.1.1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="amarok" name="amarok">
        <vers num="1.4.10" />
        <vers num="2.0" />
        <vers num="2.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0136" published="2009-01-16" name="CVE-2009-0136" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Multiple array index errors in the Audible::Tag::readTag function in metadata/audible/audibletag.cpp in Amarok 1.4.10 through 2.0.1 allow remote attackers to cause a denial of service (application crash) or execute arbitrary code via an Audible Audio (.aa) file with a crafted (1) nlen or (2) vlen Tag value, each of which can lead to an invalid pointer dereference, or the writing of a 0x00 byte to an arbitrary memory location, after an allocation failure.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-January/msg00708.html" source="FEDORA">FEDORA-2009-0715</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=479946" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=479946</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=479560" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=479560</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0100" source="VUPEN">ADV-2009-0100</ref>
      <ref url="http://www.ubuntu.com/usn/USN-739-1" source="UBUNTU">USN-739-1</ref>
      <ref url="http://www.securitytracker.com/id?1021558" source="SECTRACK">1021558</ref>
      <ref url="http://www.securityfocus.com/bid/33210" source="BID">33210</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/499984/100/0/threaded" source="BUGTRAQ">20090111 [TKADV2009-002] Amarok Integer Overflow and Unchecked Allocation Vulnerabilities</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:030" source="MANDRIVA">MDVSA-2009:030</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1706" source="DEBIAN">DSA-1706</ref>
      <ref url="http://websvn.kde.org/?view=rev&amp;revision=908415" source="CONFIRM">http://websvn.kde.org/?view=rev&amp;revision=908415</ref>
      <ref url="http://websvn.kde.org/?view=rev&amp;revision=908401" source="CONFIRM">http://websvn.kde.org/?view=rev&amp;revision=908401</ref>
      <ref url="http://websvn.kde.org/?view=rev&amp;revision=908391" source="CONFIRM">http://websvn.kde.org/?view=rev&amp;revision=908391</ref>
      <ref url="http://trapkit.de/advisories/TKADV2009-002.txt" source="MISC">http://trapkit.de/advisories/TKADV2009-002.txt</ref>
      <ref url="http://securityreason.com/securityalert/4915" source="SREASON">4915</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200903-34.xml" source="GENTOO">GLSA-200903-34</ref>
      <ref url="http://secunia.com/advisories/34407" source="SECUNIA">34407</ref>
      <ref url="http://secunia.com/advisories/34315" source="SECUNIA">34315</ref>
      <ref url="http://secunia.com/advisories/33819" source="SECUNIA">33819</ref>
      <ref url="http://secunia.com/advisories/33640" source="SECUNIA">33640</ref>
      <ref url="http://secunia.com/advisories/33522" source="SECUNIA">33522</ref>
      <ref url="http://secunia.com/advisories/33505" source="SECUNIA" adv="1">33505</ref>
      <ref url="http://openwall.com/lists/oss-security/2009/01/14/2" source="MLIST">[oss-security] 20090114 CVE Request -- amarok</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-02/msg00000.html" source="SUSE">SUSE-SR:2009:003</ref>
      <ref url="http://bugs.gentoo.org/show_bug.cgi?id=254896" source="CONFIRM">http://bugs.gentoo.org/show_bug.cgi?id=254896</ref>
      <ref url="http://amarok.kde.org/en/releases/2.0.1.1" source="CONFIRM" adv="1">http://amarok.kde.org/en/releases/2.0.1.1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="amarok" name="amarok">
        <vers num="1.4.10" />
        <vers num="2.0" />
        <vers num="2.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0137" published="2009-02-12" name="CVE-2009-0137" modified="2009-08-19" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Multiple unspecified vulnerabilities in Safari RSS in Apple Mac OS X 10.4.11 and 10.5.6, and Windows XP and Vista, allow remote attackers to execute arbitrary JavaScript in the local security zone via a crafted feed: URL, related to "input validation issues."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://lists.apple.com/archives/security-announce/2009/Feb/msg00001.html" source="APPLE" patch="1" adv="1">APPLE-SA-2009-02-12</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2009/Feb/msg00000.html" source="APPLE" patch="1" adv="1">APPLE-SA-2009-02-12</ref>
      <ref url="http://support.apple.com/kb/HT3438" source="CONFIRM">http://support.apple.com/kb/HT3438</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="safari">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0138" published="2009-02-12" name="CVE-2009-0138" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">servermgrd (Server Manager) in Apple Mac OS X 10.5.6 does not properly validate authentication credentials, which allows remote attackers to modify the system configuration.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://lists.apple.com/archives/security-announce/2009/Feb/msg00000.html" source="APPLE" patch="1" adv="1">APPLE-SA-2009-02-12</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0422" source="VUPEN">ADV-2009-0422</ref>
      <ref url="http://www.securityfocus.com/bid/33813" source="BID">33813</ref>
      <ref url="http://www.securityfocus.com/bid/33759" source="BID">33759</ref>
      <ref url="http://support.apple.com/kb/HT3438" source="CONFIRM">http://support.apple.com/kb/HT3438</ref>
      <ref url="http://secunia.com/advisories/33937" source="SECUNIA">33937</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.5.6" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.5.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0139" published="2009-02-12" name="CVE-2009-0139" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Integer overflow in the SMB component in Apple Mac OS X 10.5.6 allows remote SMB servers to cause a denial of service (system shutdown) or execute arbitrary code via a crafted SMB file system that triggers a heap-based buffer overflow.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://lists.apple.com/archives/security-announce/2009/Feb/msg00000.html" source="APPLE" patch="1" adv="1">APPLE-SA-2009-02-12</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0422" source="VUPEN">ADV-2009-0422</ref>
      <ref url="http://support.apple.com/kb/HT3438" source="CONFIRM">http://support.apple.com/kb/HT3438</ref>
      <ref url="http://secunia.com/advisories/33937" source="SECUNIA">33937</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.5.6" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.5.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0140" published="2009-02-12" name="CVE-2009-0140" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Unspecified vulnerability in the SMB component in Apple Mac OS X 10.4.11 and 10.5.6 allows remote SMB servers to cause a denial of service (memory exhaustion and system shutdown) via a crafted file system name.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://lists.apple.com/archives/security-announce/2009/Feb/msg00000.html" source="APPLE" patch="1" adv="1">APPLE-SA-2009-02-12</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0422" source="VUPEN">ADV-2009-0422</ref>
      <ref url="http://support.apple.com/kb/HT3438" source="CONFIRM">http://support.apple.com/kb/HT3438</ref>
      <ref url="http://secunia.com/advisories/33937" source="SECUNIA">33937</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.4.11" />
        <vers num="10.5.6" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.4.11" />
        <vers num="10.5.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2009-0141" published="2009-02-12" name="CVE-2009-0141" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">XTerm in Apple Mac OS X 10.4.11 and 10.5.6, when used with luit, creates tty devices with insecure world-writable permissions, which allows local users to write to the Xterm of another user.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/48727" source="XF">macosx-xterm-information-disclosure(48727)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0422" source="VUPEN">ADV-2009-0422</ref>
      <ref url="http://www.securityfocus.com/bid/33759" source="BID">33798</ref>
      <ref url="http://support.apple.com/kb/HT3438" source="CONFIRM">http://support.apple.com/kb/HT3438</ref>
      <ref url="http://securitytracker.com/alerts/2009/Feb/1021729.html" source="SECTRACK">1021729</ref>
      <ref url="http://secunia.com/advisories/33937" source="SECUNIA">33937</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2009/Feb/msg00000.html" source="APPLE" adv="1">APPLE-SA-2009-02-12</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.4.11" />
        <vers num="10.5.6" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.4.11" />
        <vers num="10.5.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2009-0142" published="2009-02-12" name="CVE-2009-0142" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:N/I:N/A:P)" CVSS_score="1.9" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.4" CVSS_base_score="1.9">
    <desc>
      <descript source="cve">Race condition in AFP Server in Apple Mac OS X 10.5.6 allows local users to cause a denial of service (infinite loop) via unspecified vectors related to "file enumeration logic."</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2009/0422" source="VUPEN">ADV-2009-0422</ref>
      <ref url="http://www.securityfocus.com/bid/33812" source="BID">33812</ref>
      <ref url="http://www.securityfocus.com/bid/33759" source="BID">33759</ref>
      <ref url="http://support.apple.com/kb/HT3438" source="CONFIRM">http://support.apple.com/kb/HT3438</ref>
      <ref url="http://secunia.com/advisories/33937" source="SECUNIA">33937</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2009/Feb/msg00000.html" source="APPLE">APPLE-SA-2009-02-12</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.5.6" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.5.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0143" published="2009-03-14" name="CVE-2009-0143" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Apple iTunes before 8.1 does not properly inform the user about the origin of an authentication request, which makes it easier for remote podcast servers to trick a user into providing a username and password when subscribing to a crafted podcast.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://support.apple.com/kb/HT3487" source="CONFIRM" patch="1" adv="1">http://support.apple.com/kb/HT3487</ref>
      <ref url="http://lists.apple.com/archives/security-announce//2009/Mar/msg00001.html" source="APPLE" patch="1" adv="1">APPLE-SA-2009-03-11</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/49201" source="XF">itunes-podcast-information-disclosure(49201)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0702" source="VUPEN">ADV-2009-0702</ref>
      <ref url="http://www.securityfocus.com/bid/34094" source="BID">34094</ref>
      <ref url="http://securitytracker.com/id?1021843" source="SECTRACK">1021843</ref>
      <ref url="http://secunia.com/advisories/34254" source="SECUNIA" adv="1">34254</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5336" source="OVAL">oval:org.mitre.oval:def:5336</ref>
      <ref url="http://osvdb.org/52579" source="OSVDB">52579</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="itunes">
        <vers num="1.0" edition="-" />
        <vers num="1.0" edition="-:windows" />
        <vers num="1.0" edition="-:mac" />
        <vers num="1.1.1" edition="-" />
        <vers num="1.1.1" edition="-:windows" />
        <vers num="1.1.1" edition="-:mac" />
        <vers num="1.1.2" edition="-" />
        <vers num="1.1.2" edition="-:windows" />
        <vers num="1.1.2" edition="-:mac" />
        <vers num="2.0" edition="-" />
        <vers num="2.0" edition="-:windows" />
        <vers num="2.0" edition="-:mac" />
        <vers num="2.0.1" edition="-" />
        <vers num="2.0.1" edition="-:windows" />
        <vers num="2.0.1" edition="-:mac" />
        <vers num="2.0.2" edition="-" />
        <vers num="2.0.2" edition="-:mac" />
        <vers num="2.0.2" edition="-:windows" />
        <vers num="2.0.3" edition="-" />
        <vers num="2.0.3" edition="-:windows" />
        <vers num="2.0.3" edition="-:mac" />
        <vers num="2.0.4" edition="-" />
        <vers num="2.0.4" edition="-:windows" />
        <vers num="2.0.4" edition="-:mac" />
        <vers num="3.0" edition="" />
        <vers num="3.0" edition=":windows" />
        <vers num="3.0.1" edition="" />
        <vers num="3.0.1" edition=":windows" />
        <vers num="4.0" edition="" />
        <vers num="4.0" edition=":windows" />
        <vers num="4.0.0" edition="-" />
        <vers num="4.0.0" edition="-:mac" />
        <vers num="4.0.0" edition="-:windows" />
        <vers num="4.0.1" edition="" />
        <vers num="4.0.1" edition=":windows" />
        <vers num="4.0.1" edition="-" />
        <vers num="4.0.1" edition="-:windows" />
        <vers num="4.0.1" edition="-:mac" />
        <vers num="4.1" edition="" />
        <vers num="4.1" edition=":windows" />
        <vers num="4.1.0" edition="-" />
        <vers num="4.1.0" edition="-:windows" />
        <vers num="4.1.0" edition="-:mac" />
        <vers num="4.2" edition="" />
        <vers num="4.2" edition=":windows" />
        <vers num="4.2.0" edition="-" />
        <vers num="4.2.0" edition="-:windows" />
        <vers num="4.2.0" edition="-:mac" />
        <vers num="4.2.72" edition="" />
        <vers num="4.2.72" edition=":windows" />
        <vers num="4.5" edition="" />
        <vers num="4.5" edition=":windows" />
        <vers num="4.5.0" edition="-" />
        <vers num="4.5.0" edition="-:windows" />
        <vers num="4.5.0" edition="-:mac" />
        <vers num="4.6" edition="" />
        <vers num="4.6" edition=":windows" />
        <vers num="4.6.0" edition="-" />
        <vers num="4.6.0" edition="-:mac" />
        <vers num="4.6.0" edition="-:windows" />
        <vers num="4.7" edition="" />
        <vers num="4.7" edition=":windows" />
        <vers num="4.7.0" edition="-" />
        <vers num="4.7.0" edition="-:mac" />
        <vers num="4.7.0" edition="-:windows" />
        <vers num="4.7.1" edition="" />
        <vers num="4.7.1" edition=":windows" />
        <vers num="4.7.1" edition="-" />
        <vers num="4.7.1" edition="-:mac" />
        <vers num="4.7.1" edition="-:windows" />
        <vers num="4.7.1.30" edition="" />
        <vers num="4.7.1.30" edition=":windows" />
        <vers num="4.8" edition="" />
        <vers num="4.8" edition=":windows" />
        <vers num="4.8.0" edition="-" />
        <vers num="4.8.0" edition="-:mac" />
        <vers num="4.8.0" edition="-:windows" />
        <vers num="4.9" edition="" />
        <vers num="4.9" edition=":windows" />
        <vers num="4.9.0" edition="-" />
        <vers num="4.9.0" edition="-:windows" />
        <vers num="4.9.0" edition="-:mac" />
        <vers num="5.0" edition="" />
        <vers num="5.0" edition=":windows" />
        <vers num="5.0.0" edition="-" />
        <vers num="5.0.0" edition="-:mac" />
        <vers num="5.0.0" edition="-:windows" />
        <vers num="5.0.1" edition="" />
        <vers num="5.0.1" edition=":windows" />
        <vers num="5.0.1" edition="-" />
        <vers num="5.0.1" edition="-:mac" />
        <vers num="5.0.1" edition="-:windows" />
        <vers num="6.0" edition="" />
        <vers num="6.0" edition=":windows" />
        <vers num="6.0.0" edition="-" />
        <vers num="6.0.0" edition="-:windows" />
        <vers num="6.0.0" edition="-:mac" />
        <vers num="6.0.1" edition="" />
        <vers num="6.0.1" edition=":windows" />
        <vers num="6.0.1" edition="-" />
        <vers num="6.0.1" edition="-:mac" />
        <vers num="6.0.1" edition="-:windows" />
        <vers num="6.0.2" edition="" />
        <vers num="6.0.2" edition=":windows" />
        <vers num="6.0.2" edition="-" />
        <vers num="6.0.2" edition="-:mac" />
        <vers num="6.0.2" edition="-:windows" />
        <vers num="6.0.3" edition="" />
        <vers num="6.0.3" edition=":windows" />
        <vers num="6.0.3" edition="-" />
        <vers num="6.0.3" edition="-:mac" />
        <vers num="6.0.3" edition="-:windows" />
        <vers num="6.0.4" edition="" />
        <vers num="6.0.4" edition=":windows" />
        <vers num="6.0.4" edition="-" />
        <vers num="6.0.4" edition="-:windows" />
        <vers num="6.0.4" edition="-:mac" />
        <vers num="6.0.4.2" edition="" />
        <vers num="6.0.4.2" edition=":windows" />
        <vers num="6.0.5" edition="" />
        <vers num="6.0.5" edition=":windows" />
        <vers num="6.0.5" edition="-" />
        <vers num="6.0.5" edition="-:mac" />
        <vers num="6.0.5" edition="-:windows" />
        <vers num="7.0.0" edition="-" />
        <vers num="7.0.0" edition="-:mac" />
        <vers num="7.0.0" edition="-:windows" />
        <vers num="7.0.1" edition="-" />
        <vers num="7.0.1" edition="-:windows" />
        <vers num="7.0.1" edition="-:mac" />
        <vers num="7.0.2" edition="" />
        <vers num="7.0.2" edition=":windows" />
        <vers num="7.0.2" edition="-" />
        <vers num="7.0.2" edition="-:windows" />
        <vers num="7.0.2" edition="-:mac" />
        <vers num="7.1.0" edition="-" />
        <vers num="7.1.0" edition="-:windows" />
        <vers num="7.1.0" edition="-:mac" />
        <vers num="7.1.1" edition="-" />
        <vers num="7.1.1" edition="-:windows" />
        <vers num="7.1.1" edition="-:mac" />
        <vers num="7.2.0" edition="-" />
        <vers num="7.2.0" edition="-:windows" />
        <vers num="7.2.0" edition="-:mac" />
        <vers num="7.3.0" edition="-" />
        <vers num="7.3.0" edition="-:windows" />
        <vers num="7.3.0" edition="-:mac" />
        <vers num="7.3.1" edition="-" />
        <vers num="7.3.1" edition="-:windows" />
        <vers num="7.3.1" edition="-:mac" />
        <vers num="7.3.2" edition="" />
        <vers num="7.3.2" edition=":windows" />
        <vers num="7.3.2" edition="-" />
        <vers num="7.3.2" edition="-:mac" />
        <vers num="7.3.2" edition="-:windows" />
        <vers num="7.4" edition="" />
        <vers num="7.4" edition=":windows" />
        <vers num="7.4.0" edition="-" />
        <vers num="7.4.0" edition="-:windows" />
        <vers num="7.4.0" edition="-:mac" />
        <vers num="7.4.1" edition="" />
        <vers num="7.4.1" edition=":windows" />
        <vers num="7.4.1" edition="-" />
        <vers num="7.4.1" edition="-:mac" />
        <vers num="7.4.1" edition="-:windows" />
        <vers num="7.4.2" edition="" />
        <vers num="7.4.2" edition=":windows" />
        <vers num="7.4.2" edition="-" />
        <vers num="7.4.2" edition="-:windows" />
        <vers num="7.4.2" edition="-:mac" />
        <vers num="7.4.3" edition="" />
        <vers num="7.4.3" edition=":windows" />
        <vers num="7.5" edition="" />
        <vers num="7.5" edition=":windows" />
        <vers num="7.5.0" edition="-" />
        <vers num="7.5.0" edition="-:windows" />
        <vers num="7.5.0" edition="-:mac" />
        <vers num="7.6" edition="" />
        <vers num="7.6" edition=":windows" />
        <vers num="7.6.0" edition="-" />
        <vers num="7.6.0" edition="-:windows" />
        <vers num="7.6.0" edition="-:mac" />
        <vers num="7.6.1" edition="" />
        <vers num="7.6.1" edition=":windows" />
        <vers num="7.6.1" edition="-" />
        <vers num="7.6.1" edition="-:windows" />
        <vers num="7.6.1" edition="-:mac" />
        <vers num="7.6.2" edition="" />
        <vers num="7.6.2" edition=":windows" />
        <vers num="7.6.2" edition="-" />
        <vers num="7.6.2" edition="-:mac" />
        <vers num="7.6.2" edition="-:windows" />
        <vers num="7.7" edition="" />
        <vers num="7.7" edition=":windows" />
        <vers num="7.7.0" edition="-" />
        <vers num="7.7.0" edition="-:mac" />
        <vers num="7.7.0" edition="-:windows" />
        <vers num="7.7.1" edition="" />
        <vers num="7.7.1" edition=":windows" />
        <vers num="7.7.1" edition="-" />
        <vers num="7.7.1" edition="-:mac" />
        <vers num="7.7.1" edition="-:windows" />
        <vers prev="1" num="8.0" edition="" />
        <vers prev="1" num="8.0" edition=":windows" />
        <vers prev="1" num="8.0" edition="-" />
        <vers prev="1" num="8.0" edition="-:mac" />
        <vers num="8.0.0" edition="-" />
        <vers num="8.0.0" edition="-:mac" />
        <vers num="8.0.0" edition="-:windows" />
        <vers prev="1" num="8.0.1" edition="-" />
        <vers prev="1" num="8.0.1" edition="-:mac" />
        <vers prev="1" num="8.0.1" edition="-:windows" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0144" published="2009-05-13" name="CVE-2009-0144" modified="2009-05-16" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">CFNetwork in Apple Mac OS X 10.5 before 10.5.7 does not properly parse noncompliant Set-Cookie headers, which allows remote attackers to obtain sensitive information by sniffing the network for "secure cookies" that are sent over unencrypted HTTP connections.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-133A.html" source="CERT">TA09-133A</ref>
      <ref url="http://support.apple.com/kb/HT3549" source="CONFIRM" patch="1" adv="1">http://support.apple.com/kb/HT3549</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2009/May/msg00002.html" source="APPLE" patch="1" adv="1">APPLE-SA-2009-05-12</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/50479" source="XF">macos-cfnetwork-info-disclosure(50479)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1297" source="VUPEN">ADV-2009-1297</ref>
      <ref url="http://www.securitytracker.com/id?1022214" source="SECTRACK">1022214</ref>
      <ref url="http://www.securityfocus.com/bid/34926" source="BID">34926</ref>
      <ref url="http://secunia.com/advisories/35074" source="SECUNIA">35074</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.5.6" />
      </prod>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.5" />
        <vers num="10.5.1" />
        <vers num="10.5.2" />
        <vers num="10.5.3" />
        <vers num="10.5.4" />
        <vers num="10.5.5" />
        <vers num="10.5.6" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.5.1" />
        <vers num="10.5.2" />
        <vers num="10.5.3" />
        <vers num="10.5.4" />
        <vers num="10.5.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0145" published="2009-05-13" name="CVE-2009-0145" modified="2009-06-23" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">CoreGraphics in Apple Mac OS X 10.4.11 and 10.5 before 10.5.7, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch 1.1 through 2.2.1 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted PDF file that triggers memory corruption.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-133A.html" source="CERT">TA09-133A</ref>
      <ref url="http://support.apple.com/kb/HT3549" source="CONFIRM" patch="1" adv="1">http://support.apple.com/kb/HT3549</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2009/May/msg00002.html" source="APPLE" patch="1" adv="1">APPLE-SA-2009-05-12</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/50481" source="XF">macos-coregraphics-pdf-code-execution(50481)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1621" source="VUPEN">ADV-2009-1621</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1522" source="VUPEN">ADV-2009-1522</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1297" source="VUPEN">ADV-2009-1297</ref>
      <ref url="http://www.securitytracker.com/id?1022209" source="SECTRACK">1022209</ref>
      <ref url="http://www.securityfocus.com/bid/34926" source="BID">34926</ref>
      <ref url="http://support.apple.com/kb/HT3639" source="CONFIRM">http://support.apple.com/kb/HT3639</ref>
      <ref url="http://support.apple.com/kb/HT3613" source="CONFIRM">http://support.apple.com/kb/HT3613</ref>
      <ref url="http://secunia.com/advisories/35379" source="SECUNIA">35379</ref>
      <ref url="http://secunia.com/advisories/35074" source="SECUNIA">35074</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2009/Jun/msg00005.html" source="APPLE">APPLE-SA-2009-06-17-1</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2009/jun/msg00002.html" source="APPLE">APPLE-SA-2009-06-08-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.4.11" />
        <vers num="10.5.0" />
        <vers num="10.5.1" />
        <vers num="10.5.2" />
        <vers num="10.5.3" />
        <vers num="10.5.4" />
        <vers num="10.5.5" />
        <vers num="10.5.6" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.4.11" />
        <vers num="10.5.0" />
        <vers num="10.5.1" />
        <vers num="10.5.2" />
        <vers num="10.5.3" />
        <vers num="10.5.4" />
        <vers num="10.5.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0146" published="2009-04-23" name="CVE-2009-0146" modified="2010-12-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple buffer overflows in the JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, and other products allow remote attackers to cause a denial of service (crash) via a crafted PDF file, related to (1) JBIG2SymbolDict::setBitmap and (2) JBIG2Stream::readSymbolDictSeg.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-133A.html" source="CERT">TA09-133A</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-0430.html" source="REDHAT" patch="1">RHSA-2009:0430</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-June/msg01291.html" source="FEDORA">FEDORA-2009-6982</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-June/msg01277.html" source="FEDORA">FEDORA-2009-6973</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-July/msg00567.html" source="FEDORA">FEDORA-2009-6972</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=490612" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=490612</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1040" source="VUPEN" adv="1">ADV-2010-1040</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1621" source="VUPEN" adv="1">ADV-2009-1621</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1297" source="VUPEN" adv="1">ADV-2009-1297</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1077" source="VUPEN" adv="1">ADV-2009-1077</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1066" source="VUPEN" adv="1">ADV-2009-1066</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1065" source="VUPEN" adv="1">ADV-2009-1065</ref>
      <ref url="http://www.securitytracker.com/id?1022073" source="SECTRACK">1022073</ref>
      <ref url="http://www.securityfocus.com/bid/34568" source="BID">34568</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/502761/100/0/threaded" source="BUGTRAQ">20090417 rPSA-2009-0059-1 poppler</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/502750/100/0/threaded" source="BUGTRAQ">20090417 rPSA-2009-0061-1 cups</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-0480.html" source="REDHAT">RHSA-2009:0480</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-0431.html" source="REDHAT">RHSA-2009:0431</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-0429.html" source="REDHAT">RHSA-2009:0429</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2010:087" source="MANDRIVA">MDVSA-2010:087</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:101" source="MANDRIVA">MDVSA-2009:101</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1793" source="DEBIAN">DSA-1793</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1790" source="DEBIAN">DSA-1790</ref>
      <ref url="http://wiki.rpath.com/Advisories:rPSA-2009-0061" source="CONFIRM">http://wiki.rpath.com/Advisories:rPSA-2009-0061</ref>
      <ref url="http://wiki.rpath.com/Advisories:rPSA-2009-0059" source="CONFIRM">http://wiki.rpath.com/Advisories:rPSA-2009-0059</ref>
      <ref url="http://support.apple.com/kb/HT3639" source="CONFIRM">http://support.apple.com/kb/HT3639</ref>
      <ref url="http://support.apple.com/kb/HT3549" source="CONFIRM">http://support.apple.com/kb/HT3549</ref>
      <ref url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2009&amp;m=slackware-security.578477" source="SLACKWARE">SSA:2009-129-01</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200904-20.xml" source="GENTOO">GLSA-200904-20</ref>
      <ref url="http://secunia.com/advisories/35685" source="SECUNIA" adv="1">35685</ref>
      <ref url="http://secunia.com/advisories/35618" source="SECUNIA" adv="1">35618</ref>
      <ref url="http://secunia.com/advisories/35074" source="SECUNIA" adv="1">35074</ref>
      <ref url="http://secunia.com/advisories/35065" source="SECUNIA" adv="1">35065</ref>
      <ref url="http://secunia.com/advisories/35064" source="SECUNIA" adv="1">35064</ref>
      <ref url="http://secunia.com/advisories/35037" source="SECUNIA">35037</ref>
      <ref url="http://secunia.com/advisories/34991" source="SECUNIA" adv="1">34991</ref>
      <ref url="http://secunia.com/advisories/34963" source="SECUNIA">34963</ref>
      <ref url="http://secunia.com/advisories/34959" source="SECUNIA" adv="1">34959</ref>
      <ref url="http://secunia.com/advisories/34852" source="SECUNIA" adv="1">34852</ref>
      <ref url="http://secunia.com/advisories/34756" source="SECUNIA">34756</ref>
      <ref url="http://secunia.com/advisories/34755" source="SECUNIA" adv="1">34755</ref>
      <ref url="http://secunia.com/advisories/34481" source="SECUNIA" adv="1">34481</ref>
      <ref url="http://secunia.com/advisories/34291" source="SECUNIA" adv="1">34291</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2009-0458.html" source="REDHAT">RHSA-2009:0458</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9632" source="OVAL">oval:org.mitre.oval:def:9632</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-07/msg00002.html" source="SUSE">SUSE-SR:2009:012</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-05/msg00000.html" source="SUSE">SUSE-SR:2009:010</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-04/msg00011.html" source="SUSE">SUSE-SA:2009:024</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2009/May/msg00002.html" source="APPLE">APPLE-SA-2009-05-12</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2009/Jun/msg00005.html" source="APPLE">APPLE-SA-2009-06-17-1</ref>
      <ref url="http://bugs.gentoo.org/show_bug.cgi?id=263028" source="CONFIRM">http://bugs.gentoo.org/show_bug.cgi?id=263028</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="cups">
        <vers num="1.1" />
        <vers num="1.1.1" />
        <vers num="1.1.10" />
        <vers num="1.1.10-1" />
        <vers num="1.1.11" />
        <vers num="1.1.12" />
        <vers num="1.1.13" />
        <vers num="1.1.14" />
        <vers num="1.1.15" />
        <vers num="1.1.16" />
        <vers num="1.1.17" />
        <vers num="1.1.18" />
        <vers num="1.1.19" edition="rc1" />
        <vers num="1.1.19" edition="rc2" />
        <vers num="1.1.19" edition="rc3" />
        <vers num="1.1.19" edition="rc4" />
        <vers num="1.1.19" edition="rc5" />
        <vers num="1.1.2" />
        <vers num="1.1.20" edition="rc1" />
        <vers num="1.1.20" edition="rc2" />
        <vers num="1.1.20" edition="rc3" />
        <vers num="1.1.20" edition="rc4" />
        <vers num="1.1.20" edition="rc5" />
        <vers num="1.1.20" edition="rc6" />
        <vers num="1.1.21" edition="rc1" />
        <vers num="1.1.21" edition="rc2" />
        <vers num="1.1.22" edition="rc1" />
        <vers num="1.1.22" edition="rc2" />
        <vers num="1.1.23" edition="rc1" />
        <vers num="1.1.3" />
        <vers num="1.1.4" />
        <vers num="1.1.5" />
        <vers num="1.1.5-1" />
        <vers num="1.1.5-2" />
        <vers num="1.1.6" />
        <vers num="1.1.6-1" />
        <vers num="1.1.6-2" />
        <vers num="1.1.6-3" />
        <vers num="1.1.7" />
        <vers num="1.1.8" />
        <vers num="1.1.9" />
        <vers num="1.1.9-1" />
        <vers num="1.2.0" />
        <vers num="1.2.1" />
        <vers num="1.2.10" />
        <vers num="1.2.11" />
        <vers num="1.2.12" />
        <vers num="1.2.2" />
        <vers num="1.2.3" />
        <vers num="1.2.4" />
        <vers num="1.2.5" />
        <vers num="1.2.6" />
        <vers num="1.2.7" />
        <vers num="1.2.8" />
        <vers num="1.2.9" />
        <vers num="1.3.0" />
        <vers num="1.3.1" />
        <vers num="1.3.10" />
        <vers num="1.3.11" />
        <vers num="1.3.2" />
        <vers num="1.3.3" />
        <vers num="1.3.4" />
        <vers num="1.3.5" />
        <vers num="1.3.6" />
        <vers num="1.3.7" />
        <vers num="1.3.8" />
        <vers prev="1" num="1.3.9" />
      </prod>
      <prod vendor="foolabs" name="xpdf">
        <vers num="0.2" />
        <vers num="0.3" />
        <vers num="0.4" />
        <vers num="0.5" />
        <vers num="0.5a" />
        <vers num="0.6" />
        <vers num="0.7" />
        <vers num="0.7a" />
        <vers num="0.80" />
        <vers num="0.90" />
        <vers num="0.91" />
        <vers num="0.91a" />
        <vers num="0.91b" />
        <vers num="0.91c" />
        <vers num="0.92" />
        <vers num="0.92a" />
        <vers num="0.92b" />
        <vers num="0.92c" />
        <vers num="0.92d" />
        <vers num="0.92e" />
        <vers num="0.93" />
        <vers num="0.93a" />
        <vers num="0.93b" />
        <vers num="0.93c" />
        <vers num="1.00" />
        <vers num="1.00a" />
        <vers num="1.01" />
        <vers num="2.00" />
        <vers num="2.01" />
        <vers num="2.02" />
        <vers num="2.03" />
        <vers num="3.00" />
        <vers num="3.01" />
        <vers prev="1" num="3.02" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0147" published="2009-04-23" name="CVE-2009-0147" modified="2010-12-16" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple integer overflows in the JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, and other products allow remote attackers to cause a denial of service (crash) via a crafted PDF file, related to (1) JBIG2Stream::readSymbolDictSeg, (2) JBIG2Stream::readSymbolDictSeg, and (3) JBIG2Stream::readGenericBitmap.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-133A.html" source="CERT">TA09-133A</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-0430.html" source="REDHAT" patch="1">RHSA-2009:0430</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-June/msg01291.html" source="FEDORA">FEDORA-2009-6982</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-June/msg01277.html" source="FEDORA">FEDORA-2009-6973</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-July/msg00567.html" source="FEDORA">FEDORA-2009-6972</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=490614" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=490614</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1040" source="VUPEN" adv="1">ADV-2010-1040</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1621" source="VUPEN" adv="1">ADV-2009-1621</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1297" source="VUPEN" adv="1">ADV-2009-1297</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1077" source="VUPEN" adv="1">ADV-2009-1077</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1066" source="VUPEN" adv="1">ADV-2009-1066</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1065" source="VUPEN" adv="1">ADV-2009-1065</ref>
      <ref url="http://www.securitytracker.com/id?1022073" source="SECTRACK">1022073</ref>
      <ref url="http://www.securityfocus.com/bid/34568" source="BID">34568</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/502761/100/0/threaded" source="BUGTRAQ">20090417 rPSA-2009-0059-1 poppler</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/502750/100/0/threaded" source="BUGTRAQ">20090417 rPSA-2009-0061-1 cups</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-0480.html" source="REDHAT">RHSA-2009:0480</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-0431.html" source="REDHAT">RHSA-2009:0431</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-0429.html" source="REDHAT">RHSA-2009:0429</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2010:087" source="MANDRIVA">MDVSA-2010:087</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:101" source="MANDRIVA">MDVSA-2009:101</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1793" source="DEBIAN">DSA-1793</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1790" source="DEBIAN">DSA-1790</ref>
      <ref url="http://wiki.rpath.com/Advisories:rPSA-2009-0061" source="CONFIRM">http://wiki.rpath.com/Advisories:rPSA-2009-0061</ref>
      <ref url="http://wiki.rpath.com/Advisories:rPSA-2009-0059" source="CONFIRM">http://wiki.rpath.com/Advisories:rPSA-2009-0059</ref>
      <ref url="http://support.apple.com/kb/HT3639" source="CONFIRM">http://support.apple.com/kb/HT3639</ref>
      <ref url="http://support.apple.com/kb/HT3549" source="CONFIRM">http://support.apple.com/kb/HT3549</ref>
      <ref url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2009&amp;m=slackware-security.578477" source="SLACKWARE">SSA:2009-129-01</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200904-20.xml" source="GENTOO">GLSA-200904-20</ref>
      <ref url="http://secunia.com/advisories/35685" source="SECUNIA" adv="1">35685</ref>
      <ref url="http://secunia.com/advisories/35618" source="SECUNIA" adv="1">35618</ref>
      <ref url="http://secunia.com/advisories/35074" source="SECUNIA" adv="1">35074</ref>
      <ref url="http://secunia.com/advisories/35065" source="SECUNIA" adv="1">35065</ref>
      <ref url="http://secunia.com/advisories/35064" source="SECUNIA" adv="1">35064</ref>
      <ref url="http://secunia.com/advisories/35037" source="SECUNIA" adv="1">35037</ref>
      <ref url="http://secunia.com/advisories/34991" source="SECUNIA" adv="1">34991</ref>
      <ref url="http://secunia.com/advisories/34963" source="SECUNIA" adv="1">34963</ref>
      <ref url="http://secunia.com/advisories/34959" source="SECUNIA" adv="1">34959</ref>
      <ref url="http://secunia.com/advisories/34852" source="SECUNIA" adv="1">34852</ref>
      <ref url="http://secunia.com/advisories/34756" source="SECUNIA" adv="1">34756</ref>
      <ref url="http://secunia.com/advisories/34755" source="SECUNIA" adv="1">34755</ref>
      <ref url="http://secunia.com/advisories/34481" source="SECUNIA" adv="1">34481</ref>
      <ref url="http://secunia.com/advisories/34291" source="SECUNIA" adv="1">34291</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2009-0458.html" source="REDHAT">RHSA-2009:0458</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9941" source="OVAL">oval:org.mitre.oval:def:9941</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-07/msg00002.html" source="SUSE">SUSE-SR:2009:012</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-05/msg00000.html" source="SUSE">SUSE-SR:2009:010</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-04/msg00011.html" source="SUSE">SUSE-SA:2009:024</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2009/May/msg00002.html" source="APPLE">APPLE-SA-2009-05-12</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2009/Jun/msg00005.html" source="APPLE">APPLE-SA-2009-06-17-1</ref>
      <ref url="http://bugs.gentoo.org/show_bug.cgi?id=263028" source="CONFIRM">http://bugs.gentoo.org/show_bug.cgi?id=263028</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="cups">
        <vers num="1.1" />
        <vers num="1.1.1" />
        <vers num="1.1.10" />
        <vers num="1.1.10-1" />
        <vers num="1.1.11" />
        <vers num="1.1.12" />
        <vers num="1.1.13" />
        <vers num="1.1.14" />
        <vers num="1.1.15" />
        <vers num="1.1.16" />
        <vers num="1.1.17" />
        <vers num="1.1.18" />
        <vers num="1.1.19" edition="rc1" />
        <vers num="1.1.19" edition="rc2" />
        <vers num="1.1.19" edition="rc3" />
        <vers num="1.1.19" edition="rc4" />
        <vers num="1.1.19" edition="rc5" />
        <vers num="1.1.2" />
        <vers num="1.1.20" edition="rc1" />
        <vers num="1.1.20" edition="rc2" />
        <vers num="1.1.20" edition="rc3" />
        <vers num="1.1.20" edition="rc4" />
        <vers num="1.1.20" edition="rc5" />
        <vers num="1.1.20" edition="rc6" />
        <vers num="1.1.21" edition="rc1" />
        <vers num="1.1.21" edition="rc2" />
        <vers num="1.1.22" edition="rc1" />
        <vers num="1.1.22" edition="rc2" />
        <vers num="1.1.23" edition="rc1" />
        <vers num="1.1.3" />
        <vers num="1.1.4" />
        <vers num="1.1.5" />
        <vers num="1.1.5-1" />
        <vers num="1.1.5-2" />
        <vers num="1.1.6" />
        <vers num="1.1.6-1" />
        <vers num="1.1.6-2" />
        <vers num="1.1.6-3" />
        <vers num="1.1.7" />
        <vers num="1.1.8" />
        <vers num="1.1.9" />
        <vers num="1.1.9-1" />
        <vers num="1.2.0" />
        <vers num="1.2.1" />
        <vers num="1.2.10" />
        <vers num="1.2.11" />
        <vers num="1.2.12" />
        <vers num="1.2.2" />
        <vers num="1.2.3" />
        <vers num="1.2.4" />
        <vers num="1.2.5" />
        <vers num="1.2.6" />
        <vers num="1.2.7" />
        <vers num="1.2.8" />
        <vers num="1.2.9" />
        <vers num="1.3.0" />
        <vers num="1.3.1" />
        <vers num="1.3.10" />
        <vers num="1.3.11" />
        <vers num="1.3.2" />
        <vers num="1.3.3" />
        <vers num="1.3.4" />
        <vers num="1.3.5" />
        <vers num="1.3.6" />
        <vers num="1.3.7" />
        <vers num="1.3.8" />
        <vers prev="1" num="1.3.9" />
      </prod>
      <prod vendor="foolabs" name="xpdf">
        <vers num="0.2" />
        <vers num="0.3" />
        <vers num="0.4" />
        <vers num="0.5" />
        <vers num="0.5a" />
        <vers num="0.6" />
        <vers num="0.7" />
        <vers num="0.7a" />
        <vers num="0.80" />
        <vers num="0.90" />
        <vers num="0.91" />
        <vers num="0.91a" />
        <vers num="0.91b" />
        <vers num="0.91c" />
        <vers num="0.92" />
        <vers num="0.92a" />
        <vers num="0.92b" />
        <vers num="0.92c" />
        <vers num="0.92d" />
        <vers num="0.92e" />
        <vers num="0.93" />
        <vers num="0.93a" />
        <vers num="0.93b" />
        <vers num="0.93c" />
        <vers num="1.00" />
        <vers num="1.00a" />
        <vers num="1.01" />
        <vers num="2.00" />
        <vers num="2.01" />
        <vers num="2.02" />
        <vers num="2.03" />
        <vers num="3.00" />
        <vers num="3.01" />
        <vers prev="1" num="3.02" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0148" published="2009-05-05" name="CVE-2009-0148" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Multiple buffer overflows in Cscope before 15.7a allow remote attackers to execute arbitrary code via long strings in input such as (1) source-code tokens and (2) pathnames, related to integer overflows in some cases. NOTE: this issue exists because of an incomplete fix for CVE-2004-2541.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-133A.html" source="CERT">TA09-133A</ref>
      <ref url="http://sourceforge.net/project/shownotes.php?group_id=4664&amp;release_id=679527" source="CONFIRM" patch="1">http://sourceforge.net/project/shownotes.php?group_id=4664&amp;release_id=679527</ref>
      <ref url="http://sourceforge.net/forum/forum.php?forum_id=947983" source="CONFIRM" patch="1">http://sourceforge.net/forum/forum.php?forum_id=947983</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=490667" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=490667</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1297" source="VUPEN" adv="1">ADV-2009-1297</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1238" source="VUPEN" adv="1">ADV-2009-1238</ref>
      <ref url="http://www.securitytracker.com/id?1022218" source="SECTRACK">1022218</ref>
      <ref url="http://www.securityfocus.com/bid/34805" source="BID">34805</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-1102.html" source="REDHAT">RHSA-2009:1102</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-1101.html" source="REDHAT">RHSA-2009:1101</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2009/05/06/9" source="MLIST">[oss-security] 20090506 Re: Old cscope buffer overflow</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1806" source="DEBIAN">DSA-1806</ref>
      <ref url="http://support.apple.com/kb/HT3549" source="CONFIRM">http://support.apple.com/kb/HT3549</ref>
      <ref url="http://sourceforge.net/mailarchive/forum.php?thread_name=E1LsGx3-00015K-TN%40ddv4jf1.ch3.sourceforge.com&amp;forum_name=cscope-cvs" source="MLIST">[cscope-cvs] 20090410 CVS: cscope/src snprintf.c, NONE, 1.1 build.c, 1.14, 1.15 command.c, 1.32, 1.33 dir.c, 1.30, 1.31 display.c, 1.29, 1.30 edit.c, 1.6, 1.7 exec.c, 1.11, 1.12 find.c, 1.20, 1.21 global.h, 1.36, 1.37 main.c, 1.45, 1.46 Makefile.am, 1.12, 1.13 Makefile.in, 1.15, 1.16 vpaccess.c, 1.2, 1.3 vpfopen.c, 1.3, 1.4 vpopen.c, 1.4, 1.5</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200905-02.xml" source="GENTOO">GLSA-200905-02</ref>
      <ref url="http://secunia.com/advisories/35462" source="SECUNIA" adv="1">35462</ref>
      <ref url="http://secunia.com/advisories/35214" source="SECUNIA" adv="1">35214</ref>
      <ref url="http://secunia.com/advisories/35213" source="SECUNIA" adv="1">35213</ref>
      <ref url="http://secunia.com/advisories/35074" source="SECUNIA" adv="1">35074</ref>
      <ref url="http://secunia.com/advisories/34978" source="SECUNIA" adv="1">34978</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9633" source="OVAL">oval:org.mitre.oval:def:9633</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2009/May/msg00002.html" source="APPLE">APPLE-SA-2009-05-12</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cscope" name="cscope">
        <vers num="13.0" />
        <vers num="15.0bl2" />
        <vers num="15.1" />
        <vers num="15.3" />
        <vers num="15.4" />
        <vers num="15.5" />
        <vers num="15.6" />
        <vers num="15.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0149" published="2009-05-13" name="CVE-2009-0149" modified="2009-05-16" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="4.4" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.4" CVSS_base_score="4.4">
    <desc>
      <descript source="cve">Apple Mac OS X 10.4.11 and 10.5 before 10.5.7 allows local users to gain privileges or cause a denial of service (application crash) by attempting to mount a crafted sparse disk image that triggers memory corruption.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <local />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-133A.html" source="CERT">TA09-133A</ref>
      <ref url="http://support.apple.com/kb/HT3549" source="CONFIRM" patch="1" adv="1">http://support.apple.com/kb/HT3549</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2009/May/msg00002.html" source="APPLE" patch="1" adv="1">APPLE-SA-2009-05-12</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/50484" source="XF">macos-diskimages-code-execution-var1(50484)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1297" source="VUPEN">ADV-2009-1297</ref>
      <ref url="http://www.securitytracker.com/id?1022217" source="SECTRACK">1022217</ref>
      <ref url="http://www.securityfocus.com/bid/34942" source="BID">34942</ref>
      <ref url="http://www.securityfocus.com/bid/34926" source="BID">34926</ref>
      <ref url="http://secunia.com/advisories/35074" source="SECUNIA">35074</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.4.11" />
        <vers num="10.5.0" />
        <vers num="10.5.1" />
        <vers num="10.5.2" />
        <vers num="10.5.3" />
        <vers num="10.5.4" />
        <vers num="10.5.5" />
        <vers num="10.5.6" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.4.11" />
        <vers num="10.5.0" />
        <vers num="10.5.1" />
        <vers num="10.5.2" />
        <vers num="10.5.3" />
        <vers num="10.5.4" />
        <vers num="10.5.5" />
        <vers num="10.5.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0150" published="2009-05-13" name="CVE-2009-0150" modified="2009-05-16" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="4.4" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.4" CVSS_base_score="4.4">
    <desc>
      <descript source="cve">Stack-based buffer overflow in Apple Mac OS X 10.5 before 10.5.7 allows local users to gain privileges or cause a denial of service (application crash) by attempting to mount a crafted sparse disk image.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <local />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-133A.html" source="CERT">TA09-133A</ref>
      <ref url="http://support.apple.com/kb/HT3549" source="CONFIRM" patch="1" adv="1">http://support.apple.com/kb/HT3549</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2009/May/msg00002.html" source="APPLE" patch="1" adv="1">APPLE-SA-2009-05-12</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/50483" source="XF">macos-diskimages-bo(50483)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1297" source="VUPEN">ADV-2009-1297</ref>
      <ref url="http://www.securitytracker.com/id?1022217" source="SECTRACK">1022217</ref>
      <ref url="http://www.securityfocus.com/bid/34926" source="BID">34926</ref>
      <ref url="http://secunia.com/advisories/35074" source="SECUNIA">35074</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.5.0" />
        <vers num="10.5.1" />
        <vers num="10.5.2" />
        <vers num="10.5.3" />
        <vers num="10.5.4" />
        <vers num="10.5.5" />
        <vers num="10.5.6" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.5.0" />
        <vers num="10.5.1" />
        <vers num="10.5.2" />
        <vers num="10.5.3" />
        <vers num="10.5.4" />
        <vers num="10.5.5" />
        <vers num="10.5.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0151" published="2009-08-06" name="CVE-2009-0151" modified="2009-08-19" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">The screen saver in Dock in Apple Mac OS X 10.5 before 10.5.8 does not prevent four-finger Multi-Touch gestures, which allows physically proximate attackers to bypass locking and "manage applications or use Expose" via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-218A.html" source="CERT">TA09-218A</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/2172" source="VUPEN" patch="1" adv="1">ADV-2009-2172</ref>
      <ref url="http://www.securityfocus.com/bid/35954" source="BID" patch="1">35954</ref>
      <ref url="http://support.apple.com/kb/HT3757" source="CONFIRM" patch="1" adv="1">http://support.apple.com/kb/HT3757</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2009/Aug/msg00001.html" source="APPLE" patch="1" adv="1">APPLE-SA-2009-08-05-1</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/52421" source="XF">macosx-dock-security-bypass(52421)</ref>
      <ref url="http://secunia.com/advisories/36096" source="SECUNIA" adv="1">36096</ref>
      <ref url="http://osvdb.org/56847" source="OSVDB">56847</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.5.6" />
      </prod>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.5" />
        <vers num="10.5.0" />
        <vers num="10.5.1" />
        <vers num="10.5.2" edition="2008-002" />
        <vers num="10.5.3" />
        <vers num="10.5.4" />
        <vers num="10.5.5" />
        <vers num="10.5.6" />
        <vers num="10.5.7" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.5" />
        <vers num="10.5.0" />
        <vers num="10.5.1" />
        <vers num="10.5.2" />
        <vers num="10.5.3" />
        <vers num="10.5.4" />
        <vers num="10.5.5" />
        <vers num="10.5.6" />
        <vers num="10.5.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0152" published="2009-05-13" name="CVE-2009-0152" modified="2009-05-16" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">iChat in Apple Mac OS X 10.5 before 10.5.7 disables SSL for AOL Instant Messenger (AIM) communication in certain circumstances that are inconsistent with the Require SSL setting, which allows remote attackers to obtain sensitive information by sniffing the network.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-133A.html" source="CERT">TA09-133A</ref>
      <ref url="http://support.apple.com/kb/HT3549" source="CONFIRM" patch="1" adv="1">http://support.apple.com/kb/HT3549</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2009/May/msg00002.html" source="APPLE" patch="1" adv="1">APPLE-SA-2009-05-12</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/50487" source="XF">macos-ichat-ssl-weak-security(50487)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1297" source="VUPEN">ADV-2009-1297</ref>
      <ref url="http://www.securitytracker.com/id?1022212" source="SECTRACK">1022212</ref>
      <ref url="http://www.securityfocus.com/bid/34926" source="BID">34926</ref>
      <ref url="http://secunia.com/advisories/35074" source="SECUNIA">35074</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.5.0" />
        <vers num="10.5.1" />
        <vers num="10.5.2" />
        <vers num="10.5.3" />
        <vers num="10.5.4" />
        <vers num="10.5.5" />
        <vers num="10.5.6" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.5.0" />
        <vers num="10.5.1" />
        <vers num="10.5.2" />
        <vers num="10.5.3" />
        <vers num="10.5.4" />
        <vers num="10.5.5" />
        <vers num="10.5.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0153" published="2009-05-13" name="CVE-2009-0153" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">International Components for Unicode (ICU) 4.0, 3.6, and other 3.x versions, as used in Apple Mac OS X 10.5 before 10.5.7, iPhone OS 1.0 through 2.2.1, iPhone OS for iPod touch 1.1 through 2.2.1, Fedora 9 and 10, and possibly other operating systems, does not properly handle invalid byte sequences during Unicode conversion, which might allow remote attackers to conduct cross-site scripting (XSS) attacks.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-133A.html" source="CERT">TA09-133A</ref>
      <ref url="http://support.apple.com/kb/HT3549" source="CONFIRM" patch="1" adv="1">http://support.apple.com/kb/HT3549</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2009/May/msg00002.html" source="APPLE" patch="1" adv="1">APPLE-SA-2009-05-12</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-June/msg00478.html" source="FEDORA">FEDORA-2009-6273</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-June/msg00336.html" source="FEDORA">FEDORA-2009-6121</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=503071" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=503071</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/50488" source="XF">macos-icu-security-bypass(50488)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1621" source="VUPEN">ADV-2009-1621</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1522" source="VUPEN">ADV-2009-1522</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1297" source="VUPEN">ADV-2009-1297</ref>
      <ref url="http://www.securityfocus.com/bid/34974" source="BID">34974</ref>
      <ref url="http://www.securityfocus.com/bid/34926" source="BID">34926</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-1122.html" source="REDHAT">RHSA-2009:1122</ref>
      <ref url="http://support.apple.com/kb/HT3639" source="CONFIRM">http://support.apple.com/kb/HT3639</ref>
      <ref url="http://support.apple.com/kb/HT3613" source="CONFIRM">http://support.apple.com/kb/HT3613</ref>
      <ref url="http://secunia.com/advisories/35584" source="SECUNIA">35584</ref>
      <ref url="http://secunia.com/advisories/35498" source="SECUNIA">35498</ref>
      <ref url="http://secunia.com/advisories/35436" source="SECUNIA">35436</ref>
      <ref url="http://secunia.com/advisories/35379" source="SECUNIA">35379</ref>
      <ref url="http://secunia.com/advisories/35074" source="SECUNIA">35074</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11366" source="OVAL">oval:org.mitre.oval:def:11366</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2009/Jun/msg00005.html" source="APPLE">APPLE-SA-2009-06-17-1</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2009/jun/msg00002.html" source="APPLE">APPLE-SA-2009-06-08-1</ref>
      <ref url="http://bugs.icu-project.org/trac/ticket/5691" source="CONFIRM">http://bugs.icu-project.org/trac/ticket/5691</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.5.0" />
        <vers num="10.5.1" />
        <vers num="10.5.2" />
        <vers num="10.5.3" />
        <vers num="10.5.4" />
        <vers num="10.5.5" />
        <vers num="10.5.6" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.5.0" />
        <vers num="10.5.1" />
        <vers num="10.5.2" />
        <vers num="10.5.3" />
        <vers num="10.5.4" />
        <vers num="10.5.5" />
        <vers num="10.5.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0154" published="2009-05-13" name="CVE-2009-0154" modified="2009-05-23" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Heap-based buffer overflow in Apple Type Services (ATS) in Apple Mac OS X 10.4.11 and 10.5 before 10.5.7 allows remote attackers to execute arbitrary code via a crafted Compact Font Format (CFF) font.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-133A.html" source="CERT">TA09-133A</ref>
      <ref url="http://support.apple.com/kb/HT3549" source="CONFIRM" patch="1" adv="1">http://support.apple.com/kb/HT3549</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2009/May/msg00002.html" source="APPLE" patch="1" adv="1">APPLE-SA-2009-05-12</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/50478" source="XF">macos-ats-cff-bo(50478)</ref>
      <ref url="http://www.zerodayinitiative.com/advisories/ZDI-09-023" source="MISC">http://www.zerodayinitiative.com/advisories/ZDI-09-023</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1297" source="VUPEN">ADV-2009-1297</ref>
      <ref url="http://www.securitytracker.com/id?1022218" source="SECTRACK">1022218</ref>
      <ref url="http://www.securityfocus.com/bid/34926" source="BID">34926</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/503597/100/0/threaded" source="BUGTRAQ">20090519 ZDI-09-023: Apple OS X ATSServer Compact Font Format Parsing Memory Corruption Vulnerability</ref>
      <ref url="http://secunia.com/advisories/35074" source="SECUNIA">35074</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.4.11" />
        <vers num="10.5.0" />
        <vers num="10.5.1" />
        <vers num="10.5.2" />
        <vers num="10.5.3" />
        <vers num="10.5.4" />
        <vers num="10.5.5" />
        <vers num="10.5.6" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.4.11" />
        <vers num="10.5.0" />
        <vers num="10.5.1" />
        <vers num="10.5.2" />
        <vers num="10.5.3" />
        <vers num="10.5.4" />
        <vers num="10.5.5" />
        <vers num="10.5.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0155" published="2009-05-13" name="CVE-2009-0155" modified="2009-06-23" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Integer underflow in CoreGraphics in Apple Mac OS X 10.5 before 10.5.7, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch 1.1 through 2.2.1 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted PDF file that triggers a heap-based buffer overflow.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-133A.html" source="CERT">TA09-133A</ref>
      <ref url="http://support.apple.com/kb/HT3549" source="CONFIRM" patch="1" adv="1">http://support.apple.com/kb/HT3549</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2009/May/msg00002.html" source="APPLE" patch="1" adv="1">APPLE-SA-2009-05-12</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/50482" source="XF">macos-coregraphics-pdf-bo(50482)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1621" source="VUPEN">ADV-2009-1621</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1297" source="VUPEN">ADV-2009-1297</ref>
      <ref url="http://www.securitytracker.com/id?1022209" source="SECTRACK">1022209</ref>
      <ref url="http://www.securityfocus.com/bid/34926" source="BID">34926</ref>
      <ref url="http://support.apple.com/kb/HT3639" source="CONFIRM">http://support.apple.com/kb/HT3639</ref>
      <ref url="http://secunia.com/advisories/35074" source="SECUNIA">35074</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2009/Jun/msg00005.html" source="APPLE">APPLE-SA-2009-06-17-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.5.0" />
        <vers num="10.5.1" />
        <vers num="10.5.2" />
        <vers num="10.5.3" />
        <vers num="10.5.4" />
        <vers num="10.5.5" />
        <vers num="10.5.6" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.5.0" />
        <vers num="10.5.1" />
        <vers num="10.5.2" />
        <vers num="10.5.3" />
        <vers num="10.5.4" />
        <vers num="10.5.5" />
        <vers num="10.5.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0156" published="2009-05-13" name="CVE-2009-0156" modified="2009-05-16" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Launch Services in Apple Mac OS X 10.4.11 and 10.5 before 10.5.7 allows remote attackers to cause a denial of service (persistent Finder crash) via a crafted Mach-O executable that triggers an out-of-bounds memory read.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-133A.html" source="CERT">TA09-133A</ref>
      <ref url="http://support.apple.com/kb/HT3549" source="CONFIRM" patch="1" adv="1">http://support.apple.com/kb/HT3549</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2009/May/msg00002.html" source="APPLE" patch="1" adv="1">APPLE-SA-2009-05-12</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/50490" source="XF">macos-launchservices-dos(50490)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1297" source="VUPEN">ADV-2009-1297</ref>
      <ref url="http://www.securitytracker.com/id?1022215" source="SECTRACK">1022215</ref>
      <ref url="http://www.securityfocus.com/bid/34932" source="BID">34932</ref>
      <ref url="http://www.securityfocus.com/bid/34926" source="BID">34926</ref>
      <ref url="http://secunia.com/advisories/35074" source="SECUNIA">35074</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.4.11" />
        <vers num="10.5.0" />
        <vers num="10.5.1" />
        <vers num="10.5.2" />
        <vers num="10.5.3" />
        <vers num="10.5.4" />
        <vers num="10.5.5" />
        <vers num="10.5.6" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.4.11" />
        <vers num="10.5.0" />
        <vers num="10.5.1" />
        <vers num="10.5.2" />
        <vers num="10.5.3" />
        <vers num="10.5.4" />
        <vers num="10.5.5" />
        <vers num="10.5.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0157" published="2009-05-13" name="CVE-2009-0157" modified="2009-05-16" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Heap-based buffer overflow in CFNetwork in Apple Mac OS X 10.5 before 10.5.7 allows remote web servers to execute arbitrary code or cause a denial of service (application crash) via long HTTP headers.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-133A.html" source="CERT">TA09-133A</ref>
      <ref url="http://support.apple.com/kb/HT3549" source="CONFIRM" patch="1" adv="1">http://support.apple.com/kb/HT3549</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2009/May/msg00002.html" source="APPLE" patch="1" adv="1">APPLE-SA-2009-05-12</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/50480" source="XF">macos-cfnetwork-bo(50480)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1297" source="VUPEN">ADV-2009-1297</ref>
      <ref url="http://www.securitytracker.com/id?1022211" source="SECTRACK">1022211</ref>
      <ref url="http://www.securityfocus.com/bid/34926" source="BID">34926</ref>
      <ref url="http://secunia.com/advisories/35074" source="SECUNIA">35074</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.5.0" />
        <vers num="10.5.1" />
        <vers num="10.5.2" />
        <vers num="10.5.3" />
        <vers num="10.5.4" />
        <vers num="10.5.5" />
        <vers num="10.5.6" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.5.0" />
        <vers num="10.5.1" />
        <vers num="10.5.2" />
        <vers num="10.5.3" />
        <vers num="10.5.4" />
        <vers num="10.5.5" />
        <vers num="10.5.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0158" published="2009-05-13" name="CVE-2009-0158" modified="2009-05-16" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Stack-based buffer overflow in telnet in Apple Mac OS X 10.4.11 and 10.5 before 10.5.7 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a long hostname for a telnet server.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-133A.html" source="CERT">TA09-133A</ref>
      <ref url="http://support.apple.com/kb/HT3549" source="CONFIRM" patch="1" adv="1">http://support.apple.com/kb/HT3549</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2009/May/msg00002.html" source="APPLE" patch="1" adv="1">APPLE-SA-2009-05-12</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1297" source="VUPEN">ADV-2009-1297</ref>
      <ref url="http://www.securityfocus.com/bid/34926" source="BID">34926</ref>
      <ref url="http://secunia.com/advisories/35074" source="SECUNIA">35074</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.4.11" />
        <vers num="10.5.0" />
        <vers num="10.5.1" />
        <vers num="10.5.2" />
        <vers num="10.5.3" />
        <vers num="10.5.4" />
        <vers num="10.5.5" />
        <vers num="10.5.6" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.4.11" />
        <vers num="10.5.0" />
        <vers num="10.5.1" />
        <vers num="10.5.2" />
        <vers num="10.5.3" />
        <vers num="10.5.4" />
        <vers num="10.5.5" />
        <vers num="10.5.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0159" published="2009-04-14" name="CVE-2009-0159" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Stack-based buffer overflow in the cookedprint function in ntpq/ntpq.c in ntpq in NTP before 4.2.4p7-RC2 allows remote NTP servers to execute arbitrary code via a crafted response.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-133A.html" source="CERT">TA09-133A</ref>
      <ref url="https://support.ntp.org/bugs/show_bug.cgi?id=1144" source="CONFIRM" patch="1">https://support.ntp.org/bugs/show_bug.cgi?id=1144</ref>
      <ref url="http://www.securityfocus.com/bid/34481" source="BID" patch="1">34481</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-May/msg01449.html" source="FEDORA">FEDORA-2009-5275</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-May/msg01414.html" source="FEDORA">FEDORA-2009-5273</ref>
      <ref url="https://rhn.redhat.com/errata/RHSA-2009-1651.html" source="REDHAT">RHSA-2009:1651</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=490617" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=490617</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/49838" source="XF">ntp-cookedprint-bo(49838)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/3316" source="VUPEN" adv="1">ADV-2009-3316</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1297" source="VUPEN" adv="1">ADV-2009-1297</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0999" source="VUPEN" adv="1">ADV-2009-0999</ref>
      <ref url="http://www.vmware.com/security/advisories/VMSA-2009-0016.html" source="CONFIRM">http://www.vmware.com/security/advisories/VMSA-2009-0016.html</ref>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-777-1" source="UBUNTU">USN-777-1</ref>
      <ref url="http://www.securitytracker.com/id?1022033" source="SECTRACK">1022033</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/507985/100/0/threaded" source="BUGTRAQ">20091120 VMSA-2009-0016 VMware vCenter and ESX update release and vMA patch release address multiple security issue in third party components</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:092" source="MANDRIVA">MDVSA-2009:092</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200905-08.xml" source="GENTOO">GLSA-200905-08</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1801" source="DEBIAN">DSA-1801</ref>
      <ref url="http://support.apple.com/kb/HT3549" source="CONFIRM">http://support.apple.com/kb/HT3549</ref>
      <ref url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2009&amp;m=slackware-security.566238" source="SLACKWARE">SSA:2009-154-01</ref>
      <ref url="http://secunia.com/advisories/37471" source="SECUNIA" adv="1">37471</ref>
      <ref url="http://secunia.com/advisories/35630" source="SECUNIA" adv="1">35630</ref>
      <ref url="http://secunia.com/advisories/35416" source="SECUNIA" adv="1">35416</ref>
      <ref url="http://secunia.com/advisories/35336" source="SECUNIA" adv="1">35336</ref>
      <ref url="http://secunia.com/advisories/35308" source="SECUNIA" adv="1">35308</ref>
      <ref url="http://secunia.com/advisories/35253" source="SECUNIA" adv="1">35253</ref>
      <ref url="http://secunia.com/advisories/35169" source="SECUNIA" adv="1">35169</ref>
      <ref url="http://secunia.com/advisories/35166" source="SECUNIA" adv="1">35166</ref>
      <ref url="http://secunia.com/advisories/35138" source="SECUNIA" adv="1">35138</ref>
      <ref url="http://secunia.com/advisories/35137" source="SECUNIA" adv="1">35137</ref>
      <ref url="http://secunia.com/advisories/35074" source="SECUNIA" adv="1">35074</ref>
      <ref url="http://secunia.com/advisories/34608" source="SECUNIA" adv="1">34608</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2009-1040.html" source="REDHAT">RHSA-2009:1040</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2009-1039.html" source="REDHAT">RHSA-2009:1039</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9634" source="OVAL">oval:org.mitre.oval:def:9634</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:8665" source="OVAL">oval:org.mitre.oval:def:8665</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:8386" source="OVAL">oval:org.mitre.oval:def:8386</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5411" source="OVAL">oval:org.mitre.oval:def:5411</ref>
      <ref url="http://osvdb.org/53593" source="OSVDB">53593</ref>
      <ref url="http://ntp.bkbits.net:8080/ntp-stable/?PAGE=gnupatch&amp;REV=1.1565" source="CONFIRM">http://ntp.bkbits.net:8080/ntp-stable/?PAGE=gnupatch&amp;REV=1.1565</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-06/msg00003.html" source="SUSE">SUSE-SR:2009:011</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2009/May/msg00002.html" source="APPLE">APPLE-SA-2009-05-12</ref>
      <ref url="http://bugs.pardus.org.tr/show_bug.cgi?id=9532" source="CONFIRM">http://bugs.pardus.org.tr/show_bug.cgi?id=9532</ref>
      <ref url="ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2009-006.txt.asc" source="NETBSD">NetBSD-SA2009-006</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ntp" name="ntp">
        <vers num="4.0.72" />
        <vers num="4.0.73" />
        <vers num="4.0.90" />
        <vers num="4.0.91" />
        <vers num="4.0.92" />
        <vers num="4.0.93" />
        <vers num="4.0.94" />
        <vers num="4.0.95" />
        <vers num="4.0.96" />
        <vers num="4.0.97" />
        <vers num="4.0.98" />
        <vers num="4.0.99" />
        <vers num="4.1.0" />
        <vers num="4.1.2" />
        <vers num="4.2.0" />
        <vers num="4.2.2" />
        <vers num="4.2.2p1" />
        <vers num="4.2.2p2" />
        <vers num="4.2.2p3" />
        <vers num="4.2.2p4" />
        <vers num="4.2.4" />
        <vers num="4.2.4p0" />
        <vers num="4.2.4p1" />
        <vers num="4.2.4p2" />
        <vers num="4.2.4p3" />
        <vers num="4.2.4p4" />
        <vers num="4.2.4p5" />
        <vers num="4.2.4p6" />
        <vers prev="1" num="4.2.4p7" edition="rc1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0160" published="2009-05-13" name="CVE-2009-0160" modified="2009-05-16" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">QuickDraw Manager in Apple Mac OS X 10.4.11 and 10.5 before 10.5.7 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted PICT image that triggers memory corruption.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-133A.html" source="CERT">TA09-133A</ref>
      <ref url="http://support.apple.com/kb/HT3549" source="CONFIRM" patch="1" adv="1">http://support.apple.com/kb/HT3549</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2009/May/msg00002.html" source="APPLE" patch="1" adv="1">APPLE-SA-2009-05-12</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1297" source="VUPEN">ADV-2009-1297</ref>
      <ref url="http://www.securitytracker.com/id?1022209" source="SECTRACK">1022209</ref>
      <ref url="http://www.securityfocus.com/bid/34937" source="BID">34937</ref>
      <ref url="http://www.securityfocus.com/bid/34926" source="BID">34926</ref>
      <ref url="http://secunia.com/advisories/35074" source="SECUNIA">35074</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.4.11" />
        <vers num="10.5.0" />
        <vers num="10.5.1" />
        <vers num="10.5.2" />
        <vers num="10.5.3" />
        <vers num="10.5.4" />
        <vers num="10.5.5" />
        <vers num="10.5.6" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.4.11" />
        <vers num="10.5.0" />
        <vers num="10.5.1" />
        <vers num="10.5.2" />
        <vers num="10.5.3" />
        <vers num="10.5.4" />
        <vers num="10.5.5" />
        <vers num="10.5.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0161" published="2009-05-13" name="CVE-2009-0161" modified="2009-05-23" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:P)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">The OpenSSL::OCSP module for Ruby in Apple Mac OS X 10.5 before 10.5.7 misinterprets an unspecified invalid response as a successful OCSP certificate validation, which might allow remote attackers to spoof certificate authentication via a revoked certificate.</descript>
    </desc>
    <loss_types>
      <avail />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-133A.html" source="CERT">TA09-133A</ref>
      <ref url="http://support.apple.com/kb/HT3549" source="CONFIRM" patch="1" adv="1">http://support.apple.com/kb/HT3549</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2009/May/msg00002.html" source="APPLE" patch="1" adv="1">APPLE-SA-2009-05-12</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/50592" source="XF">macos-opensslocsp-weak-security(50592)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1297" source="VUPEN">ADV-2009-1297</ref>
      <ref url="http://www.securityfocus.com/bid/34926" source="BID">34926</ref>
      <ref url="http://secunia.com/advisories/35074" source="SECUNIA">35074</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.5.0" />
        <vers num="10.5.1" />
        <vers num="10.5.2" />
        <vers num="10.5.3" />
        <vers num="10.5.4" />
        <vers num="10.5.5" />
        <vers num="10.5.6" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.4.11" />
        <vers num="10.5.0" />
        <vers num="10.5.1" />
        <vers num="10.5.2" />
        <vers num="10.5.3" />
        <vers num="10.5.4" />
        <vers num="10.5.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0162" published="2009-05-13" name="CVE-2009-0162" modified="2009-05-16" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Safari before 3.2.3, and 4 Public Beta, on Apple Mac OS X 10.5 before 10.5.7 and Windows allows remote attackers to inject arbitrary web script or HTML via a crafted feed: URL.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-133A.html" source="CERT">TA09-133A</ref>
      <ref url="http://support.apple.com/kb/HT3549" source="CONFIRM" patch="1" adv="1">http://support.apple.com/kb/HT3549</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2009/May/msg00002.html" source="APPLE" patch="1" adv="1">APPLE-SA-2009-05-12</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2009/May/msg00001.html" source="APPLE" patch="1" adv="1">APPLE-SA-2009-05-12</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2009/May/msg00000.html" source="APPLE" patch="1" adv="1">APPLE-SA-2009-05-12</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/50476" source="XF">safari-feedurl-code-execution(50476)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1298" source="VUPEN">ADV-2009-1298</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1297" source="VUPEN">ADV-2009-1297</ref>
      <ref url="http://www.securitytracker.com/id?1022206" source="SECTRACK">1022206</ref>
      <ref url="http://www.securityfocus.com/bid/34925" source="BID">34925</ref>
      <ref url="http://support.apple.com/kb/HT3550" source="CONFIRM">http://support.apple.com/kb/HT3550</ref>
      <ref url="http://secunia.com/advisories/35074" source="SECUNIA">35074</ref>
      <ref url="http://secunia.com/advisories/35056" source="SECUNIA">35056</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="safari">
        <vers num="0.8" />
        <vers num="0.9" />
        <vers num="1.0" edition="beta" />
        <vers num="1.0" edition="beta2" />
        <vers num="1.0.0" />
        <vers num="1.0.0b1" />
        <vers num="1.0.0b2" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" edition="85.8" />
        <vers num="1.0.3" edition="85.8.1" />
        <vers num="1.1" />
        <vers num="1.1.0" />
        <vers num="1.1.1" />
        <vers num="1.2" />
        <vers num="1.2.0" />
        <vers num="1.2.1" />
        <vers num="1.2.2" />
        <vers num="1.2.3" />
        <vers num="1.2.4" />
        <vers num="1.2.5" />
        <vers num="1.3" />
        <vers num="1.3.0" />
        <vers num="1.3.1" />
        <vers num="1.3.2" edition="312.5" />
        <vers num="1.3.2" edition="312.6" />
        <vers num="2" />
        <vers num="2.0" />
        <vers num="2.0.0" />
        <vers num="2.0.1" />
        <vers num="2.0.2" />
        <vers num="2.0.3" edition="417.8" />
        <vers num="2.0.3" edition="417.9" />
        <vers num="2.0.3" edition="417.9.2" />
        <vers num="2.0.4" />
        <vers num="3" />
        <vers num="3.0" />
        <vers num="3.0.0" />
        <vers num="3.0.1" />
        <vers num="3.0.2" />
        <vers num="3.0.3" />
        <vers num="3.0.4" />
        <vers num="3.1" />
        <vers num="3.1.0" />
        <vers num="3.1.1" />
        <vers num="3.1.2" />
        <vers num="3.2" />
        <vers num="3.2.0" />
        <vers num="3.2.1" />
        <vers prev="1" num="3.2.2" />
        <vers num="4.0" edition="beta" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0163" published="2009-04-23" name="CVE-2009-0163" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Integer overflow in the TIFF image decoding routines in CUPS 1.3.9 and earlier allows remote attackers to cause a denial of service (daemon crash) and possibly execute arbitrary code via a crafted TIFF image, which is not properly handled by the (1) _cupsImageReadTIFF function in the imagetops filter and (2) imagetoraster filter, leading to a heap-based buffer overflow.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=490596" source="CONFIRM" patch="1">https://bugzilla.redhat.com/show_bug.cgi?id=490596</ref>
      <ref url="http://www.ubuntu.com/usn/usn-760-1" source="UBUNTU">USN-760-1</ref>
      <ref url="http://www.securitytracker.com/id?1022070" source="SECTRACK">1022070</ref>
      <ref url="http://www.securityfocus.com/bid/34571" source="BID">34571</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/502750/100/0/threaded" source="BUGTRAQ">20090417 rPSA-2009-0061-1 cups</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-0429.html" source="REDHAT">RHSA-2009:0429</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-0428.html" source="REDHAT">RHSA-2009:0428</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1773" source="DEBIAN">DSA-1773</ref>
      <ref url="http://www.cups.org/str.php?L3031" source="CONFIRM">http://www.cups.org/str.php?L3031</ref>
      <ref url="http://www.cups.org/articles.php?L582" source="CONFIRM">http://www.cups.org/articles.php?L582</ref>
      <ref url="http://wiki.rpath.com/Advisories:rPSA-2009-0061" source="CONFIRM">http://wiki.rpath.com/Advisories:rPSA-2009-0061</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200904-20.xml" source="GENTOO">GLSA-200904-20</ref>
      <ref url="http://secunia.com/advisories/34852" source="SECUNIA" adv="1">34852</ref>
      <ref url="http://secunia.com/advisories/34756" source="SECUNIA" adv="1">34756</ref>
      <ref url="http://secunia.com/advisories/34747" source="SECUNIA" adv="1">34747</ref>
      <ref url="http://secunia.com/advisories/34722" source="SECUNIA" adv="1">34722</ref>
      <ref url="http://secunia.com/advisories/34481" source="SECUNIA" adv="1">34481</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11546" source="OVAL">oval:org.mitre.oval:def:11546</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-04/msg00011.html" source="SUSE">SUSE-SA:2009:024</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="cups">
        <vers num="1.1" />
        <vers num="1.1.1" />
        <vers num="1.1.10" />
        <vers num="1.1.10-1" />
        <vers num="1.1.11" />
        <vers num="1.1.12" />
        <vers num="1.1.13" />
        <vers num="1.1.14" />
        <vers num="1.1.15" />
        <vers num="1.1.16" />
        <vers num="1.1.17" />
        <vers num="1.1.18" />
        <vers num="1.1.19" edition="rc1" />
        <vers num="1.1.19" edition="rc2" />
        <vers num="1.1.19" edition="rc3" />
        <vers num="1.1.19" edition="rc4" />
        <vers num="1.1.19" edition="rc5" />
        <vers num="1.1.2" />
        <vers num="1.1.20" edition="rc1" />
        <vers num="1.1.20" edition="rc2" />
        <vers num="1.1.20" edition="rc3" />
        <vers num="1.1.20" edition="rc4" />
        <vers num="1.1.20" edition="rc5" />
        <vers num="1.1.20" edition="rc6" />
        <vers num="1.1.21" edition="rc1" />
        <vers num="1.1.21" edition="rc2" />
        <vers num="1.1.22" edition="rc1" />
        <vers num="1.1.22" edition="rc2" />
        <vers num="1.1.23" edition="rc1" />
        <vers num="1.1.3" />
        <vers num="1.1.4" />
        <vers num="1.1.5" />
        <vers num="1.1.5-1" />
        <vers num="1.1.5-2" />
        <vers num="1.1.6" />
        <vers num="1.1.6-1" />
        <vers num="1.1.6-2" />
        <vers num="1.1.6-3" />
        <vers num="1.1.7" />
        <vers num="1.1.8" />
        <vers num="1.1.9" />
        <vers num="1.1.9-1" />
        <vers num="1.2" edition="b1" />
        <vers num="1.2" edition="b2" />
        <vers num="1.2" edition="rc1" />
        <vers num="1.2" edition="rc2" />
        <vers num="1.2" edition="rc3" />
        <vers num="1.2.0" />
        <vers num="1.2.1" />
        <vers num="1.2.10" />
        <vers num="1.2.11" />
        <vers num="1.2.12" />
        <vers num="1.2.2" />
        <vers num="1.2.3" />
        <vers num="1.2.4" />
        <vers num="1.2.5" />
        <vers num="1.2.6" />
        <vers num="1.2.7" />
        <vers num="1.2.8" />
        <vers num="1.2.9" />
        <vers num="1.3" edition="b1" />
        <vers num="1.3" edition="rc1" />
        <vers num="1.3" edition="rc2" />
        <vers num="1.3.0" />
        <vers num="1.3.1" />
        <vers num="1.3.2" />
        <vers num="1.3.3" />
        <vers num="1.3.4" />
        <vers num="1.3.5" />
        <vers num="1.3.6" />
        <vers num="1.3.7" />
        <vers num="1.3.8" />
        <vers prev="1" num="1.3.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0164" published="2009-04-24" name="CVE-2009-0164" modified="2009-05-16" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:P)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">The web interface for CUPS before 1.3.10 does not validate the HTTP Host header in a client request, which makes it easier for remote attackers to conduct DNS rebinding attacks.</descript>
    </desc>
    <loss_types>
      <avail />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-133A.html" source="CERT">TA09-133A</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=490597" source="CONFIRM" patch="1">https://bugzilla.redhat.com/show_bug.cgi?id=490597</ref>
      <ref url="http://www.cups.org/str.php?L3118" source="CONFIRM" patch="1" adv="1">http://www.cups.org/str.php?L3118</ref>
      <ref url="http://www.cups.org/articles.php?L582" source="CONFIRM" patch="1" adv="1">http://www.cups.org/articles.php?L582</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1297" source="VUPEN">ADV-2009-1297</ref>
      <ref url="http://www.securityfocus.com/bid/34665" source="BID">34665</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/502750/100/0/threaded" source="BUGTRAQ">20090417 rPSA-2009-0061-1 cups</ref>
      <ref url="http://wiki.rpath.com/Advisories:rPSA-2009-0061" source="CONFIRM">http://wiki.rpath.com/Advisories:rPSA-2009-0061</ref>
      <ref url="http://support.apple.com/kb/HT3549" source="CONFIRM">http://support.apple.com/kb/HT3549</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200904-20.xml" source="GENTOO">GLSA-200904-20</ref>
      <ref url="http://secunia.com/advisories/35074" source="SECUNIA">35074</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2009/May/msg00002.html" source="APPLE">APPLE-SA-2009-05-12</ref>
      <ref url="http://bugs.gentoo.org/show_bug.cgi?id=263070" source="CONFIRM">http://bugs.gentoo.org/show_bug.cgi?id=263070</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="cups">
        <vers num="1.1" />
        <vers num="1.1.1" />
        <vers num="1.1.10" />
        <vers num="1.1.10-1" />
        <vers num="1.1.11" />
        <vers num="1.1.12" />
        <vers num="1.1.13" />
        <vers num="1.1.14" />
        <vers num="1.1.15" />
        <vers num="1.1.16" />
        <vers num="1.1.17" />
        <vers num="1.1.18" />
        <vers num="1.1.19" edition="rc1" />
        <vers num="1.1.19" edition="rc2" />
        <vers num="1.1.19" edition="rc3" />
        <vers num="1.1.19" edition="rc4" />
        <vers num="1.1.19" edition="rc5" />
        <vers num="1.1.2" />
        <vers num="1.1.20" edition="rc1" />
        <vers num="1.1.20" edition="rc2" />
        <vers num="1.1.20" edition="rc3" />
        <vers num="1.1.20" edition="rc4" />
        <vers num="1.1.20" edition="rc5" />
        <vers num="1.1.20" edition="rc6" />
        <vers num="1.1.21" edition="rc1" />
        <vers num="1.1.21" edition="rc2" />
        <vers num="1.1.22" edition="rc1" />
        <vers num="1.1.22" edition="rc2" />
        <vers num="1.1.23" edition="rc1" />
        <vers num="1.1.3" />
        <vers num="1.1.4" />
        <vers num="1.1.5" />
        <vers num="1.1.5-1" />
        <vers num="1.1.5-2" />
        <vers num="1.1.6" />
        <vers num="1.1.6-1" />
        <vers num="1.1.6-2" />
        <vers num="1.1.6-3" />
        <vers num="1.1.7" />
        <vers num="1.1.8" />
        <vers num="1.1.9" />
        <vers num="1.1.9-1" />
        <vers num="1.2" edition="b1" />
        <vers num="1.2" edition="b2" />
        <vers num="1.2" edition="rc1" />
        <vers num="1.2" edition="rc2" />
        <vers num="1.2" edition="rc3" />
        <vers num="1.2.0" />
        <vers num="1.2.1" />
        <vers num="1.2.10" />
        <vers num="1.2.11" />
        <vers num="1.2.12" />
        <vers num="1.2.2" />
        <vers num="1.2.3" />
        <vers num="1.2.4" />
        <vers num="1.2.5" />
        <vers num="1.2.6" />
        <vers num="1.2.7" />
        <vers num="1.2.8" />
        <vers num="1.2.9" />
        <vers num="1.3" edition="b1" />
        <vers num="1.3" edition="rc1" />
        <vers num="1.3" edition="rc2" />
        <vers num="1.3.0" />
        <vers num="1.3.1" />
        <vers num="1.3.2" />
        <vers num="1.3.3" />
        <vers num="1.3.4" />
        <vers num="1.3.5" />
        <vers num="1.3.6" />
        <vers num="1.3.7" />
        <vers num="1.3.8" />
        <vers prev="1" num="1.3.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0165" published="2009-04-23" name="CVE-2009-0165" modified="2009-07-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Integer overflow in the JBIG2 decoder in Xpdf 3.02pl2 and earlier, as used in Poppler and other products, when running on Mac OS X, has unspecified impact, related to "g*allocn."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-133A.html" source="CERT">TA09-133A</ref>
      <ref url="http://bugs.gentoo.org/show_bug.cgi?id=263028" source="CONFIRM" patch="1">http://bugs.gentoo.org/show_bug.cgi?id=263028</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/50377" source="XF">multiple-jbig2-unspecified(50377)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1621" source="VUPEN">ADV-2009-1621</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1297" source="VUPEN">ADV-2009-1297</ref>
      <ref url="http://www.securityfocus.com/bid/34568" source="BID">34568</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:101" source="MANDRIVA">MDVSA-2009:101</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1793" source="DEBIAN">DSA-1793</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1790" source="DEBIAN">DSA-1790</ref>
      <ref url="http://support.apple.com/kb/HT3639" source="CONFIRM">http://support.apple.com/kb/HT3639</ref>
      <ref url="http://support.apple.com/kb/HT3549" source="CONFIRM">http://support.apple.com/kb/HT3549</ref>
      <ref url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2009&amp;m=slackware-security.578477" source="SLACKWARE">SSA:2009-129-01</ref>
      <ref url="http://secunia.com/advisories/35685" source="SECUNIA">35685</ref>
      <ref url="http://secunia.com/advisories/35074" source="SECUNIA">35074</ref>
      <ref url="http://secunia.com/advisories/35065" source="SECUNIA">35065</ref>
      <ref url="http://secunia.com/advisories/35037" source="SECUNIA">35037</ref>
      <ref url="http://secunia.com/advisories/34991" source="SECUNIA">34991</ref>
      <ref url="http://secunia.com/advisories/34959" source="SECUNIA">34959</ref>
      <ref url="http://secunia.com/advisories/34852" source="SECUNIA">34852</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-07/msg00002.html" source="SUSE">SUSE-SR:2009:012</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-05/msg00000.html" source="SUSE">SUSE-SR:2009:010</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-04/msg00011.html" source="SUSE">SUSE-SA:2009:024</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2009/May/msg00002.html" source="APPLE">APPLE-SA-2009-05-12</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2009/Jun/msg00005.html" source="APPLE">APPLE-SA-2009-06-17-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="foolabs" name="xpdf">
        <vers num="0.2" />
        <vers num="0.3" />
        <vers num="0.4" />
        <vers num="0.5" />
        <vers num="0.5a" />
        <vers num="0.6" />
        <vers num="0.7" />
        <vers num="0.7a" />
        <vers num="0.80" />
        <vers num="0.90" />
        <vers num="0.91" />
        <vers num="0.91a" />
        <vers num="0.91b" />
        <vers num="0.91c" />
        <vers num="0.92" />
        <vers num="0.92a" />
        <vers num="0.92b" />
        <vers num="0.92c" />
        <vers num="0.92d" />
        <vers num="0.92e" />
        <vers num="0.93" />
        <vers num="0.93a" />
        <vers num="0.93b" />
        <vers num="0.93c" />
        <vers num="1.00" />
        <vers num="1.00a" />
        <vers num="1.01" />
        <vers num="2.00" />
        <vers num="2.01" />
        <vers num="2.02" />
        <vers num="2.03" />
        <vers num="3.0.1" />
        <vers num="3.00" />
        <vers num="3.01" />
        <vers prev="1" num="3.02" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0166" published="2009-04-23" name="CVE-2009-0166" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">The JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, and other products allows remote attackers to cause a denial of service (crash) via a crafted PDF file that triggers a free of uninitialized memory.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2009/1066" source="VUPEN" patch="1" adv="1">ADV-2009-1066</ref>
      <ref url="http://www.securityfocus.com/bid/34568" source="BID" patch="1">34568</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-0480.html" source="REDHAT" patch="1">RHSA-2009:0480</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-0431.html" source="REDHAT" patch="1">RHSA-2009:0431</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-0430.html" source="REDHAT" patch="1">RHSA-2009:0430</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-0429.html" source="REDHAT" patch="1">RHSA-2009:0429</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1793" source="DEBIAN" patch="1">DSA-1793</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1790" source="DEBIAN" patch="1">DSA-1790</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2009-0458.html" source="REDHAT" patch="1">RHSA-2009:0458</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-June/msg01291.html" source="FEDORA">FEDORA-2009-6982</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-June/msg01277.html" source="FEDORA">FEDORA-2009-6973</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-July/msg00567.html" source="FEDORA">FEDORA-2009-6972</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=490625" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=490625</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1040" source="VUPEN" adv="1">ADV-2010-1040</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1077" source="VUPEN" adv="1">ADV-2009-1077</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1065" source="VUPEN" adv="1">ADV-2009-1065</ref>
      <ref url="http://www.securitytracker.com/id?1022073" source="SECTRACK">1022073</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/502750/100/0/threaded" source="BUGTRAQ">20090417 rPSA-2009-0061-1 cups</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2010:087" source="MANDRIVA">MDVSA-2010:087</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:101" source="MANDRIVA">MDVSA-2009:101</ref>
      <ref url="http://wiki.rpath.com/Advisories:rPSA-2009-0061" source="CONFIRM">http://wiki.rpath.com/Advisories:rPSA-2009-0061</ref>
      <ref url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2009&amp;m=slackware-security.578477" source="SLACKWARE">SSA:2009-129-01</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200904-20.xml" source="GENTOO">GLSA-200904-20</ref>
      <ref url="http://secunia.com/advisories/35685" source="SECUNIA" adv="1">35685</ref>
      <ref url="http://secunia.com/advisories/35618" source="SECUNIA" adv="1">35618</ref>
      <ref url="http://secunia.com/advisories/35065" source="SECUNIA" adv="1">35065</ref>
      <ref url="http://secunia.com/advisories/35064" source="SECUNIA" adv="1">35064</ref>
      <ref url="http://secunia.com/advisories/35037" source="SECUNIA" adv="1">35037</ref>
      <ref url="http://secunia.com/advisories/34991" source="SECUNIA" adv="1">34991</ref>
      <ref url="http://secunia.com/advisories/34963" source="SECUNIA" adv="1">34963</ref>
      <ref url="http://secunia.com/advisories/34959" source="SECUNIA" adv="1">34959</ref>
      <ref url="http://secunia.com/advisories/34852" source="SECUNIA" adv="1">34852</ref>
      <ref url="http://secunia.com/advisories/34756" source="SECUNIA" adv="1">34756</ref>
      <ref url="http://secunia.com/advisories/34755" source="SECUNIA" adv="1">34755</ref>
      <ref url="http://secunia.com/advisories/34481" source="SECUNIA" adv="1">34481</ref>
      <ref url="http://secunia.com/advisories/34291" source="SECUNIA" adv="1">34291</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9778" source="OVAL">oval:org.mitre.oval:def:9778</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-07/msg00002.html" source="SUSE">SUSE-SR:2009:012</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-05/msg00000.html" source="SUSE">SUSE-SR:2009:010</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-04/msg00011.html" source="SUSE">SUSE-SA:2009:024</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="cups">
        <vers num="1.1" />
        <vers num="1.1.1" />
        <vers num="1.1.10" />
        <vers num="1.1.10-1" />
        <vers num="1.1.11" />
        <vers num="1.1.12" />
        <vers num="1.1.13" />
        <vers num="1.1.14" />
        <vers num="1.1.15" />
        <vers num="1.1.16" />
        <vers num="1.1.17" />
        <vers num="1.1.18" />
        <vers num="1.1.19" edition="rc1" />
        <vers num="1.1.19" edition="rc2" />
        <vers num="1.1.19" edition="rc3" />
        <vers num="1.1.19" edition="rc4" />
        <vers num="1.1.19" edition="rc5" />
        <vers num="1.1.2" />
        <vers num="1.1.20" edition="rc1" />
        <vers num="1.1.20" edition="rc2" />
        <vers num="1.1.20" edition="rc3" />
        <vers num="1.1.20" edition="rc4" />
        <vers num="1.1.20" edition="rc5" />
        <vers num="1.1.20" edition="rc6" />
        <vers num="1.1.21" edition="rc1" />
        <vers num="1.1.21" edition="rc2" />
        <vers num="1.1.22" edition="rc1" />
        <vers num="1.1.22" edition="rc2" />
        <vers num="1.1.23" edition="rc1" />
        <vers num="1.1.3" />
        <vers num="1.1.4" />
        <vers num="1.1.5" />
        <vers num="1.1.5-1" />
        <vers num="1.1.5-2" />
        <vers num="1.1.6" />
        <vers num="1.1.6-1" />
        <vers num="1.1.6-2" />
        <vers num="1.1.6-3" />
        <vers num="1.1.7" />
        <vers num="1.1.8" />
        <vers num="1.1.9" />
        <vers num="1.1.9-1" />
        <vers num="1.2.0" />
        <vers num="1.2.1" />
        <vers num="1.2.10" />
        <vers num="1.2.11" />
        <vers num="1.2.12" />
        <vers num="1.2.2" />
        <vers num="1.2.3" />
        <vers num="1.2.4" />
        <vers num="1.2.5" />
        <vers num="1.2.6" />
        <vers num="1.2.7" />
        <vers num="1.2.8" />
        <vers num="1.2.9" />
        <vers num="1.3.0" />
        <vers num="1.3.1" />
        <vers num="1.3.10" />
        <vers num="1.3.11" />
        <vers num="1.3.2" />
        <vers num="1.3.3" />
        <vers num="1.3.4" />
        <vers num="1.3.5" />
        <vers num="1.3.6" />
        <vers num="1.3.7" />
        <vers num="1.3.8" />
        <vers prev="1" num="1.3.9" />
      </prod>
      <prod vendor="foolabs" name="xpdf">
        <vers num="0.2" />
        <vers num="0.3" />
        <vers num="0.4" />
        <vers num="0.5" />
        <vers num="0.5a" />
        <vers num="0.6" />
        <vers num="0.7" />
        <vers num="0.7a" />
        <vers num="0.80" />
        <vers num="0.90" />
        <vers num="0.91" />
        <vers num="0.91a" />
        <vers num="0.91b" />
        <vers num="0.91c" />
        <vers num="0.92" />
        <vers num="0.92a" />
        <vers num="0.92b" />
        <vers num="0.92c" />
        <vers num="0.92d" />
        <vers num="0.92e" />
        <vers num="0.93" />
        <vers num="0.93a" />
        <vers num="0.93b" />
        <vers num="0.93c" />
        <vers num="1.00" />
        <vers num="1.00a" />
        <vers num="1.01" />
        <vers num="2.00" />
        <vers num="2.01" />
        <vers num="2.02" />
        <vers num="2.03" />
        <vers num="3.00" />
        <vers num="3.01" />
        <vers prev="1" num="3.02" />
      </prod>
      <prod vendor="poppler" name="poppler">
        <vers num="0.1" />
        <vers num="0.1.1" />
        <vers num="0.1.2" />
        <vers num="0.10.0" />
        <vers num="0.10.1" />
        <vers num="0.10.2" />
        <vers num="0.10.3" />
        <vers num="0.10.4" />
        <vers prev="1" num="0.10.5" />
        <vers num="0.2.0" />
        <vers num="0.3.0" />
        <vers num="0.3.1" />
        <vers num="0.3.2" />
        <vers num="0.3.3" />
        <vers num="0.4.0" />
        <vers num="0.4.1" />
        <vers num="0.4.2" />
        <vers num="0.4.3" />
        <vers num="0.4.4" />
        <vers num="0.5.0" />
        <vers num="0.5.1" />
        <vers num="0.5.2" />
        <vers num="0.5.3" />
        <vers num="0.5.4" />
        <vers num="0.5.9" />
        <vers num="0.5.90" />
        <vers num="0.5.91" />
        <vers num="0.6.0" />
        <vers num="0.6.1" />
        <vers num="0.6.2" />
        <vers num="0.6.3" />
        <vers num="0.6.4" />
        <vers num="0.7.0" />
        <vers num="0.7.1" />
        <vers num="0.7.2" />
        <vers num="0.7.3" />
        <vers num="0.8.0" />
        <vers num="0.8.1" />
        <vers num="0.8.2" />
        <vers num="0.8.3" />
        <vers num="0.8.4" />
        <vers num="0.8.5" />
        <vers num="0.8.6" />
        <vers num="0.8.7" />
        <vers num="0.9.0" />
        <vers num="0.9.1" />
        <vers num="0.9.2" />
        <vers num="0.9.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0167" published="2009-01-16" name="CVE-2009-0167" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:N/I:N/A:C)" CVSS_score="4.7" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="3.4" CVSS_base_score="4.7">
    <desc>
      <descript source="cve">Unspecified vulnerability in lpadmin in Sun Solaris 10 and OpenSolaris snv_61 through snv_106 allows local users to cause a denial of service via unspecified vectors, related to enumeration of "wrong printers," aka a "Temporary file vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-21-139390-01-1" source="CONFIRM" patch="1" adv="1">http://sunsolve.sun.com/search/document.do?assetkey=1-21-139390-01-1</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0155" source="VUPEN">ADV-2009-0155</ref>
      <ref url="http://www.securitytracker.com/id?1021601" source="SECTRACK">1021601</ref>
      <ref url="http://www.securityfocus.com/bid/33269" source="BID">33269</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2009-026.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2009-026.htm</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-249306-1" source="SUNALERT" adv="1">249306</ref>
      <ref url="http://secunia.com/advisories/33705" source="SECUNIA">33705</ref>
      <ref url="http://secunia.com/advisories/33488" source="SECUNIA">33488</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6175" source="OVAL">oval:org.mitre.oval:def:6175</ref>
      <ref url="http://opensolaris.org/os/bug_reports/request_sponsor/" source="MISC">http://opensolaris.org/os/bug_reports/request_sponsor/</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="opensolaris">
        <vers num="snv_100" edition="" />
        <vers num="snv_100" edition=":x86" />
        <vers num="snv_100" edition=":sparc" />
        <vers num="snv_101" edition="" />
        <vers num="snv_101" edition=":x86" />
        <vers num="snv_101" edition=":sparc" />
        <vers num="snv_102" edition="" />
        <vers num="snv_102" edition=":x86" />
        <vers num="snv_102" edition=":sparc" />
        <vers num="snv_103" edition="" />
        <vers num="snv_103" edition=":sparc" />
        <vers num="snv_103" edition=":x86" />
        <vers num="snv_104" edition="" />
        <vers num="snv_104" edition=":sparc" />
        <vers num="snv_104" edition=":x86" />
        <vers num="snv_105" edition="" />
        <vers num="snv_105" edition=":x86" />
        <vers num="snv_105" edition=":sparc" />
        <vers num="snv_106" edition="" />
        <vers num="snv_106" edition=":sparc" />
        <vers num="snv_106" edition=":x86" />
        <vers num="snv_61" edition="" />
        <vers num="snv_61" edition=":sparc" />
        <vers num="snv_61" edition=":x86" />
        <vers num="snv_62" edition="" />
        <vers num="snv_62" edition=":x86" />
        <vers num="snv_62" edition=":sparc" />
        <vers num="snv_63" edition="" />
        <vers num="snv_63" edition=":sparc" />
        <vers num="snv_63" edition=":x86" />
        <vers num="snv_64" edition="" />
        <vers num="snv_64" edition=":x86" />
        <vers num="snv_64" edition=":sparc" />
        <vers num="snv_65" edition="" />
        <vers num="snv_65" edition=":sparc" />
        <vers num="snv_65" edition=":x86" />
        <vers num="snv_66" edition="" />
        <vers num="snv_66" edition=":x86" />
        <vers num="snv_66" edition=":sparc" />
        <vers num="snv_67" edition="" />
        <vers num="snv_67" edition=":sparc" />
        <vers num="snv_67" edition=":x86" />
        <vers num="snv_68" edition="" />
        <vers num="snv_68" edition=":x86" />
        <vers num="snv_68" edition=":sparc" />
        <vers num="snv_69" edition="" />
        <vers num="snv_69" edition=":x86" />
        <vers num="snv_69" edition=":sparc" />
        <vers num="snv_70" edition="" />
        <vers num="snv_70" edition=":sparc" />
        <vers num="snv_70" edition=":x86" />
        <vers num="snv_71" edition="" />
        <vers num="snv_71" edition=":sparc" />
        <vers num="snv_71" edition=":x86" />
        <vers num="snv_72" edition="" />
        <vers num="snv_72" edition=":x86" />
        <vers num="snv_72" edition=":sparc" />
        <vers num="snv_73" edition="" />
        <vers num="snv_73" edition=":sparc" />
        <vers num="snv_73" edition=":x86" />
        <vers num="snv_74" edition="" />
        <vers num="snv_74" edition=":x86" />
        <vers num="snv_74" edition=":sparc" />
        <vers num="snv_75" edition="" />
        <vers num="snv_75" edition=":x86" />
        <vers num="snv_75" edition=":sparc" />
        <vers num="snv_76" edition="" />
        <vers num="snv_76" edition=":sparc" />
        <vers num="snv_76" edition=":x86" />
        <vers num="snv_77" edition="" />
        <vers num="snv_77" edition=":sparc" />
        <vers num="snv_77" edition=":x86" />
        <vers num="snv_78" edition="" />
        <vers num="snv_78" edition=":sparc" />
        <vers num="snv_78" edition=":x86" />
        <vers num="snv_79" edition="" />
        <vers num="snv_79" edition=":x86" />
        <vers num="snv_79" edition=":sparc" />
        <vers num="snv_80" edition="" />
        <vers num="snv_80" edition=":x86" />
        <vers num="snv_80" edition=":sparc" />
        <vers num="snv_81" edition="" />
        <vers num="snv_81" edition=":x86" />
        <vers num="snv_81" edition=":sparc" />
        <vers num="snv_82" edition="" />
        <vers num="snv_82" edition=":sparc" />
        <vers num="snv_82" edition=":x86" />
        <vers num="snv_83" edition="" />
        <vers num="snv_83" edition=":sparc" />
        <vers num="snv_83" edition=":x86" />
        <vers num="snv_84" edition="" />
        <vers num="snv_84" edition=":x86" />
        <vers num="snv_84" edition=":sparc" />
        <vers num="snv_85" edition="" />
        <vers num="snv_85" edition=":sparc" />
        <vers num="snv_85" edition=":x86" />
        <vers num="snv_86" edition="" />
        <vers num="snv_86" edition=":sparc" />
        <vers num="snv_86" edition=":x86" />
        <vers num="snv_87" edition="" />
        <vers num="snv_87" edition=":sparc" />
        <vers num="snv_87" edition=":x86" />
        <vers num="snv_88" edition="" />
        <vers num="snv_88" edition=":x86" />
        <vers num="snv_88" edition=":sparc" />
        <vers num="snv_89" edition="" />
        <vers num="snv_89" edition=":x86" />
        <vers num="snv_89" edition=":sparc" />
        <vers num="snv_90" edition="" />
        <vers num="snv_90" edition=":x86" />
        <vers num="snv_90" edition=":sparc" />
        <vers num="snv_91" edition="" />
        <vers num="snv_91" edition=":x86" />
        <vers num="snv_91" edition=":sparc" />
        <vers num="snv_92" edition="" />
        <vers num="snv_92" edition=":sparc" />
        <vers num="snv_92" edition=":x86" />
        <vers num="snv_93" edition="" />
        <vers num="snv_93" edition=":sparc" />
        <vers num="snv_93" edition=":x86" />
        <vers num="snv_94" edition="" />
        <vers num="snv_94" edition=":x86" />
        <vers num="snv_94" edition=":sparc" />
        <vers num="snv_95" edition="" />
        <vers num="snv_95" edition=":sparc" />
        <vers num="snv_95" edition=":x86" />
        <vers num="snv_96" edition="" />
        <vers num="snv_96" edition=":x86" />
        <vers num="snv_96" edition=":sparc" />
        <vers num="snv_97" edition="" />
        <vers num="snv_97" edition=":x86" />
        <vers num="snv_97" edition=":sparc" />
        <vers num="snv_98" edition="" />
        <vers num="snv_98" edition=":x86" />
        <vers num="snv_98" edition=":sparc" />
        <vers num="snv_99" edition="" />
        <vers num="snv_99" edition=":sparc" />
        <vers num="snv_99" edition=":x86" />
      </prod>
      <prod vendor="sun" name="solaris">
        <vers num="10.0" edition="" />
        <vers num="10.0" edition=":x86" />
        <vers num="10.0" edition=":sparc" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0168" published="2009-01-16" name="CVE-2009-0168" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="4.9" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="3.9" CVSS_base_score="4.9">
    <desc>
      <descript source="cve">Unspecified vulnerability in ppdmgr in Sun Solaris 10 and OpenSolaris snv_61 through snv_106 allows local users to cause a denial of service via unspecified vectors, related to a failure to "include all cache files," and improper handling of temporary files.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-249306-1" source="SUNALERT" patch="1">249306</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-21-139390-01-1" source="CONFIRM" patch="1">http://sunsolve.sun.com/search/document.do?assetkey=1-21-139390-01-1</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/48143" source="XF">solaris-ppdmgr-dos(48143)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0155" source="VUPEN">ADV-2009-0155</ref>
      <ref url="http://www.securitytracker.com/id?1021601" source="SECTRACK">1021601</ref>
      <ref url="http://www.securityfocus.com/bid/33269" source="BID">33269</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2009-026.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2009-026.htm</ref>
      <ref url="http://secunia.com/advisories/33705" source="SECUNIA">33705</ref>
      <ref url="http://secunia.com/advisories/33488" source="SECUNIA">33488</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5503" source="OVAL">oval:org.mitre.oval:def:5503</ref>
      <ref url="http://opensolaris.org/os/bug_reports/request_sponsor/" source="MISC">http://opensolaris.org/os/bug_reports/request_sponsor/</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="opensolaris">
        <vers num="snv_100" edition="" />
        <vers num="snv_100" edition=":x86" />
        <vers num="snv_100" edition=":sparc" />
        <vers num="snv_101" edition="" />
        <vers num="snv_101" edition=":x86" />
        <vers num="snv_101" edition=":sparc" />
        <vers num="snv_102" edition="" />
        <vers num="snv_102" edition=":x86" />
        <vers num="snv_102" edition=":sparc" />
        <vers num="snv_103" edition="" />
        <vers num="snv_103" edition=":sparc" />
        <vers num="snv_103" edition=":x86" />
        <vers num="snv_104" edition="" />
        <vers num="snv_104" edition=":sparc" />
        <vers num="snv_104" edition=":x86" />
        <vers num="snv_105" edition="" />
        <vers num="snv_105" edition=":x86" />
        <vers num="snv_105" edition=":sparc" />
        <vers num="snv_106" edition="" />
        <vers num="snv_106" edition=":sparc" />
        <vers num="snv_106" edition=":x86" />
        <vers num="snv_61" edition="" />
        <vers num="snv_61" edition=":sparc" />
        <vers num="snv_61" edition=":x86" />
        <vers num="snv_62" edition="" />
        <vers num="snv_62" edition=":x86" />
        <vers num="snv_62" edition=":sparc" />
        <vers num="snv_63" edition="" />
        <vers num="snv_63" edition=":sparc" />
        <vers num="snv_63" edition=":x86" />
        <vers num="snv_64" edition="" />
        <vers num="snv_64" edition=":x86" />
        <vers num="snv_64" edition=":sparc" />
        <vers num="snv_65" edition="" />
        <vers num="snv_65" edition=":sparc" />
        <vers num="snv_65" edition=":x86" />
        <vers num="snv_66" edition="" />
        <vers num="snv_66" edition=":x86" />
        <vers num="snv_66" edition=":sparc" />
        <vers num="snv_67" edition="" />
        <vers num="snv_67" edition=":sparc" />
        <vers num="snv_67" edition=":x86" />
        <vers num="snv_68" edition="" />
        <vers num="snv_68" edition=":x86" />
        <vers num="snv_68" edition=":sparc" />
        <vers num="snv_69" edition="" />
        <vers num="snv_69" edition=":x86" />
        <vers num="snv_69" edition=":sparc" />
        <vers num="snv_70" edition="" />
        <vers num="snv_70" edition=":sparc" />
        <vers num="snv_70" edition=":x86" />
        <vers num="snv_71" edition="" />
        <vers num="snv_71" edition=":sparc" />
        <vers num="snv_71" edition=":x86" />
        <vers num="snv_72" edition="" />
        <vers num="snv_72" edition=":x86" />
        <vers num="snv_72" edition=":sparc" />
        <vers num="snv_73" edition="" />
        <vers num="snv_73" edition=":sparc" />
        <vers num="snv_73" edition=":x86" />
        <vers num="snv_74" edition="" />
        <vers num="snv_74" edition=":x86" />
        <vers num="snv_74" edition=":sparc" />
        <vers num="snv_75" edition="" />
        <vers num="snv_75" edition=":x86" />
        <vers num="snv_75" edition=":sparc" />
        <vers num="snv_76" edition="" />
        <vers num="snv_76" edition=":sparc" />
        <vers num="snv_76" edition=":x86" />
        <vers num="snv_77" edition="" />
        <vers num="snv_77" edition=":sparc" />
        <vers num="snv_77" edition=":x86" />
        <vers num="snv_78" edition="" />
        <vers num="snv_78" edition=":sparc" />
        <vers num="snv_78" edition=":x86" />
        <vers num="snv_79" edition="" />
        <vers num="snv_79" edition=":x86" />
        <vers num="snv_79" edition=":sparc" />
        <vers num="snv_80" edition="" />
        <vers num="snv_80" edition=":x86" />
        <vers num="snv_80" edition=":sparc" />
        <vers num="snv_81" edition="" />
        <vers num="snv_81" edition=":x86" />
        <vers num="snv_81" edition=":sparc" />
        <vers num="snv_82" edition="" />
        <vers num="snv_82" edition=":sparc" />
        <vers num="snv_82" edition=":x86" />
        <vers num="snv_83" edition="" />
        <vers num="snv_83" edition=":sparc" />
        <vers num="snv_83" edition=":x86" />
        <vers num="snv_84" edition="" />
        <vers num="snv_84" edition=":x86" />
        <vers num="snv_84" edition=":sparc" />
        <vers num="snv_85" edition="" />
        <vers num="snv_85" edition=":sparc" />
        <vers num="snv_85" edition=":x86" />
        <vers num="snv_86" edition="" />
        <vers num="snv_86" edition=":sparc" />
        <vers num="snv_86" edition=":x86" />
        <vers num="snv_87" edition="" />
        <vers num="snv_87" edition=":sparc" />
        <vers num="snv_87" edition=":x86" />
        <vers num="snv_88" edition="" />
        <vers num="snv_88" edition=":x86" />
        <vers num="snv_88" edition=":sparc" />
        <vers num="snv_89" edition="" />
        <vers num="snv_89" edition=":x86" />
        <vers num="snv_89" edition=":sparc" />
        <vers num="snv_90" edition="" />
        <vers num="snv_90" edition=":x86" />
        <vers num="snv_90" edition=":sparc" />
        <vers num="snv_91" edition="" />
        <vers num="snv_91" edition=":x86" />
        <vers num="snv_91" edition=":sparc" />
        <vers num="snv_92" edition="" />
        <vers num="snv_92" edition=":sparc" />
        <vers num="snv_92" edition=":x86" />
        <vers num="snv_93" edition="" />
        <vers num="snv_93" edition=":sparc" />
        <vers num="snv_93" edition=":x86" />
        <vers num="snv_94" edition="" />
        <vers num="snv_94" edition=":x86" />
        <vers num="snv_94" edition=":sparc" />
        <vers num="snv_95" edition="" />
        <vers num="snv_95" edition=":sparc" />
        <vers num="snv_95" edition=":x86" />
        <vers num="snv_96" edition="" />
        <vers num="snv_96" edition=":x86" />
        <vers num="snv_96" edition=":sparc" />
        <vers num="snv_97" edition="" />
        <vers num="snv_97" edition=":x86" />
        <vers num="snv_97" edition=":sparc" />
        <vers num="snv_98" edition="" />
        <vers num="snv_98" edition=":x86" />
        <vers num="snv_98" edition=":sparc" />
        <vers num="snv_99" edition="" />
        <vers num="snv_99" edition=":sparc" />
        <vers num="snv_99" edition=":x86" />
      </prod>
      <prod vendor="sun" name="solaris">
        <vers num="10" edition="" />
        <vers num="10" edition=":sparc" />
        <vers num="10" edition=":x86" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0169" published="2009-01-16" name="CVE-2009-0169" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:C/I:C/A:C)" CVSS_score="9.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.0" CVSS_base_score="9.0">
    <desc>
      <descript source="cve">Sun Java System Access Manager 7.1 allows remote authenticated sub-realm administrators to gain privileges, as demonstrated by creating the amadmin account in the sub-realm, and then logging in as amadmin in the root realm.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/33266" source="BID" patch="1">33266</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-21-126356-02-1" source="CONFIRM" patch="1" adv="1">http://sunsolve.sun.com/search/document.do?assetkey=1-21-126356-02-1</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/47944" source="XF">sun-jsam-subrealm-privilege-escalation(47944)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0157" source="VUPEN">ADV-2009-0157</ref>
      <ref url="http://www.securitytracker.com/id?1021604" source="SECTRACK">1021604</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-249106-1" source="SUNALERT" adv="1">249106</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="java_system_access_manager">
        <vers num="7.1" edition="" />
        <vers num="7.1" edition=":solaris_sparc" />
        <vers num="7.1" edition=":windows" />
        <vers num="7.1" edition=":linux" />
        <vers num="7.1" edition=":solaris_x86" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0170" published="2009-01-16" name="CVE-2009-0170" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:S/C:P/I:P/A:P)" CVSS_score="6.0" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="6.8" CVSS_base_score="6.0">
    <desc>
      <descript source="cve">Sun Java System Access Manager 6.3 2005Q1, 7 2005Q4, and 7.1 allows remote authenticated users with console privileges to discover passwords, and obtain unspecified other "access to resources," by visiting the Configuration Items component in the console.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/33265" source="BID" patch="1">33265</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-242166-1" source="SUNALERT" patch="1" adv="1">242166</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-21-126356-02-1" source="CONFIRM" patch="1" adv="1">http://sunsolve.sun.com/search/document.do?assetkey=1-21-126356-02-1</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/47942" source="XF">sun-jsam-password-info-disclosure(47942)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0156" source="VUPEN">ADV-2009-0156</ref>
      <ref url="http://www.securitytracker.com/id?1021605" source="SECTRACK">1021605</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="java_system_access_manager">
        <vers num="6.3_2005q4" />
        <vers num="7.0_2005q4" />
        <vers num="7.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0171" published="2009-01-16" name="CVE-2009-0171" modified="2011-06-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">The Sun SPARC Enterprise M4000 and M5000 Server, within a certain range of serial numbers, allows remote attackers to use the manufacturing root password, perform a root login to the eXtended System Control Facility Unit (aka XSCFU or Service Processor), and have unspecified other impact.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2009/0207" source="VUPEN" adv="1">ADV-2009-0207</ref>
      <ref url="http://www.securitytracker.com/id?1021602" source="SECTRACK">1021602</ref>
      <ref url="http://www.securityfocus.com/bid/33280" source="BID">33280</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-249126-1" source="SUNALERT" adv="1">249126</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="sparc_enterprise_server">
        <vers num="m4000" />
        <vers num="m5000" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0172" published="2009-01-16" name="CVE-2009-0172" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in IBM DB2 8 before FP17a, 9.1 before FP6a, and 9.5 before FP3a allows remote attackers to cause a denial of service (infinite loop) via a crafted CONNECT data stream.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/33258" source="BID" patch="1">33258</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg21363936" source="CONFIRM" patch="1" adv="1">http://www-01.ibm.com/support/docview.wss?uid=swg21363936</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/47931" source="XF">ibm-db2-connect-stream-dos(47931)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0137" source="VUPEN">ADV-2009-0137</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg1IZ37696" source="AIXAPAR">IZ37696</ref>
      <ref url="http://securitytracker.com/id?1021591" source="SECTRACK">1021591</ref>
      <ref url="http://secunia.com/advisories/33529" source="SECUNIA" adv="1">33529</ref>
      <ref url="ftp://ftp.software.ibm.com/ps/products/db2/fixes/english-us/aparlist/db2_v95/APARLIST.TXT" source="CONFIRM">ftp://ftp.software.ibm.com/ps/products/db2/fixes/english-us/aparlist/db2_v95/APARLIST.TXT</ref>
      <ref url="ftp://ftp.software.ibm.com/ps/products/db2/fixes/english-us/aparlist/db2_v91/APARLIST.TXT" source="CONFIRM">ftp://ftp.software.ibm.com/ps/products/db2/fixes/english-us/aparlist/db2_v91/APARLIST.TXT</ref>
      <ref url="ftp://ftp.software.ibm.com/ps/products/db2/fixes/english-us/aparlist/db2_v82/APARLIST.TXT" source="CONFIRM">ftp://ftp.software.ibm.com/ps/products/db2/fixes/english-us/aparlist/db2_v82/APARLIST.TXT</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="db2_universal_database">
        <vers num="9.1" edition="" />
        <vers num="9.1" edition=":aix" />
        <vers num="9.1" edition=":windows" />
        <vers num="9.1" edition=":hp-ux" />
        <vers num="9.1" edition=":solaris" />
        <vers num="9.1" edition=":linux" />
        <vers num="9.1" edition="fp2" />
        <vers num="9.1" edition="fp2:linux" />
        <vers num="9.1" edition="fp2:windows" />
        <vers num="9.1" edition="fp2:hp-ux" />
        <vers num="9.1" edition="fp2:aix" />
        <vers num="9.1" edition="fp2:solaris" />
        <vers num="9.1" edition="fp3" />
        <vers num="9.1" edition="fp3:hp-ux" />
        <vers num="9.1" edition="fp3:solaris" />
        <vers num="9.1" edition="fp3:aix" />
        <vers num="9.1" edition="fp4" />
        <vers num="9.1" edition="fp4:linux" />
        <vers num="9.1" edition="fp4:windows" />
        <vers num="9.1" edition="fp4:aix" />
        <vers num="9.1" edition="fp4:hp-ux" />
        <vers num="9.1" edition="fp4a" />
        <vers num="9.1" edition="fp4a:hp-ux" />
        <vers num="9.1" edition="fp4a:linux" />
        <vers num="9.1" edition="fp4a:windows" />
        <vers num="9.1" edition="ga" />
        <vers num="9.5" edition="" />
        <vers num="9.5" edition=":linux" />
        <vers num="9.5" edition=":windows" />
        <vers num="9.5" edition=":hp-ux" />
        <vers num="9.5" edition=":aix" />
        <vers num="9.5" edition=":solaris" />
        <vers num="9.5" edition="fp1" />
        <vers num="9.5" edition="fp1:windows" />
        <vers num="9.5" edition="fp1:hp-ux" />
        <vers num="9.5" edition="fp1:aix" />
        <vers num="9.5" edition="fp1:solaris" />
        <vers num="9.5" edition="fp1:linux" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0173" published="2009-01-16" name="CVE-2009-0173" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the server in IBM DB2 8 before FP17a, 9.1 before FP6a, and 9.5 before FP3a allows remote authenticated users to cause a denial of service (trap) via a crafted data stream.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg21363936" source="CONFIRM" patch="1" adv="1">http://www-01.ibm.com/support/docview.wss?uid=swg21363936</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/47934" source="XF">ibm-db2-datastream-dos(47934)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0137" source="VUPEN">ADV-2009-0137</ref>
      <ref url="http://www.securityfocus.com/bid/33258" source="BID">33258</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg1IZ39652" source="AIXAPAR">IZ39652</ref>
      <ref url="http://securitytracker.com/id?1021591" source="SECTRACK">1021591</ref>
      <ref url="http://secunia.com/advisories/33529" source="SECUNIA" adv="1">33529</ref>
      <ref url="ftp://ftp.software.ibm.com/ps/products/db2/fixes/english-us/aparlist/db2_v95/APARLIST.TXT" source="CONFIRM">ftp://ftp.software.ibm.com/ps/products/db2/fixes/english-us/aparlist/db2_v95/APARLIST.TXT</ref>
      <ref url="ftp://ftp.software.ibm.com/ps/products/db2/fixes/english-us/aparlist/db2_v91/APARLIST.TXT" source="CONFIRM">ftp://ftp.software.ibm.com/ps/products/db2/fixes/english-us/aparlist/db2_v91/APARLIST.TXT</ref>
      <ref url="ftp://ftp.software.ibm.com/ps/products/db2/fixes/english-us/aparlist/db2_v82/APARLIST.TXT" source="CONFIRM">ftp://ftp.software.ibm.com/ps/products/db2/fixes/english-us/aparlist/db2_v82/APARLIST.TXT</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="db2_universal_database">
        <vers num="9.1" edition="" />
        <vers num="9.1" edition=":aix" />
        <vers num="9.1" edition=":windows" />
        <vers num="9.1" edition=":hp-ux" />
        <vers num="9.1" edition=":solaris" />
        <vers num="9.1" edition=":linux" />
        <vers num="9.1" edition="fp2" />
        <vers num="9.1" edition="fp2:linux" />
        <vers num="9.1" edition="fp2:windows" />
        <vers num="9.1" edition="fp2:hp-ux" />
        <vers num="9.1" edition="fp2:aix" />
        <vers num="9.1" edition="fp2:solaris" />
        <vers num="9.1" edition="fp3" />
        <vers num="9.1" edition="fp3:hp-ux" />
        <vers num="9.1" edition="fp3:solaris" />
        <vers num="9.1" edition="fp3:aix" />
        <vers num="9.1" edition="fp4" />
        <vers num="9.1" edition="fp4:linux" />
        <vers num="9.1" edition="fp4:windows" />
        <vers num="9.1" edition="fp4:aix" />
        <vers num="9.1" edition="fp4:hp-ux" />
        <vers num="9.1" edition="fp4a" />
        <vers num="9.1" edition="fp4a:hp-ux" />
        <vers num="9.1" edition="fp4a:linux" />
        <vers num="9.1" edition="fp4a:windows" />
        <vers num="9.1" edition="ga" />
        <vers num="9.5" edition="" />
        <vers num="9.5" edition=":linux" />
        <vers num="9.5" edition=":windows" />
        <vers num="9.5" edition=":hp-ux" />
        <vers num="9.5" edition=":aix" />
        <vers num="9.5" edition=":solaris" />
        <vers num="9.5" edition="fp1" />
        <vers num="9.5" edition="fp1:windows" />
        <vers num="9.5" edition="fp1:hp-ux" />
        <vers num="9.5" edition="fp1:aix" />
        <vers num="9.5" edition="fp1:solaris" />
        <vers num="9.5" edition="fp1:linux" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0174" published="2009-01-20" name="CVE-2009-0174" modified="2009-01-29" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Stack-based buffer overflow in VUPlayer 2.49 allows remote attackers to execute arbitrary code via a long .asf URI in the HREF attribute of a REF element in a .asx file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/47851" source="XF">vuplayer-asx-bo(47851)</ref>
      <ref url="http://www.securityfocus.com/bid/33185" source="BID">33185</ref>
      <ref url="http://www.milw0rm.com/exploits/7715" source="MILW0RM">7715</ref>
      <ref url="http://www.milw0rm.com/exploits/7714" source="MILW0RM">7714</ref>
      <ref url="http://www.milw0rm.com/exploits/7713" source="MILW0RM">7713</ref>
      <ref url="http://www.milw0rm.com/exploits/7709" source="MILW0RM">7709</ref>
      <ref url="http://securityreason.com/securityalert/4918" source="SREASON">4918</ref>
    </refs>
    <vuln_soft>
      <prod vendor="vuplayer" name="vuplayer">
        <vers num="2.49" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0175" published="2009-01-20" name="CVE-2009-0175" modified="2009-01-29" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Heap-based buffer overflow in Heathco Software MP3 TrackMaker 1.5 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a long string in an invalid .mp3 file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/47852" source="XF">mp3trackmaker-mp3-bo(47852)</ref>
      <ref url="http://www.securityfocus.com/bid/33183" source="BID">33183</ref>
      <ref url="http://www.milw0rm.com/exploits/7708" source="MILW0RM">7708</ref>
      <ref url="http://securityreason.com/securityalert/4920" source="SREASON">4920</ref>
    </refs>
    <vuln_soft>
      <prod vendor="heathcosoft" name="mp3_trackmaker">
        <vers num="1.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0176" published="2009-01-20" name="CVE-2009-0176" modified="2009-05-18" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Multiple heap-based buffer overflows in the PDF distiller in the Attachment Service in Research in Motion (RIM) BlackBerry Enterprise Server (BES) 4.1.3 through 4.1.6, BlackBerry Professional Software 4.1.4, and BlackBerry Unite! before 1.0.3 bundle 28 allow user-assisted remote attackers to execute arbitrary code via (1) a crafted stream in a .pdf file, related to "symWidths"; or (2) a crafted data stream in a .pdf file, related to "bitmaps."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/33224" source="BID">33224</ref>
      <ref url="http://www.blackberry.com/btsc/search.do?cmd=displayKC&amp;docType=kc&amp;externalId=KB17119" source="CONFIRM" adv="1">http://www.blackberry.com/btsc/search.do?cmd=displayKC&amp;docType=kc&amp;externalId=KB17119</ref>
      <ref url="http://www.blackberry.com/btsc/search.do?cmd=displayKC&amp;docType=kc&amp;externalId=KB17118" source="CONFIRM" adv="1">http://www.blackberry.com/btsc/search.do?cmd=displayKC&amp;docType=kc&amp;externalId=KB17118</ref>
      <ref url="http://secunia.com/advisories/33534" source="SECUNIA" adv="1">33534</ref>
      <ref url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=765" source="IDEFENSE">20090113 RIM BlackBerry Enterprise Server Attachment Service PDF Distiller 'bitmaps' Heap Overflow Vulnerability</ref>
      <ref url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=764" source="IDEFENSE">20090113 RIM BlackBerry Enterprise Server Attachment Service PDF Distiller 'symWidths' Heap Overflow Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="research_in_motion_limited" name="blackberry_enterprise_server">
        <vers num="4.1.3" />
        <vers num="4.1.4" />
        <vers num="4.1.5" />
        <vers num="4.1.6" />
      </prod>
      <prod vendor="research_in_motion_limited" name="blackberry_professional_software">
        <vers num="4.1.4" />
      </prod>
      <prod vendor="research_in_motion_limited" name="blackberry_unite">
        <vers num="1.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers prev="1" num="1.0.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0177" published="2009-01-20" name="CVE-2009-0177" modified="2011-03-10" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">vmwarebase.dll, as used in the vmware-authd service (aka vmware-authd.exe), in VMware Workstation 6.5.1 build 126130, 6.5.1 and earlier; VMware Player 2.5.1 build 126130, 2.5.1 and earlier; VMware ACE 2.5.1 and earlier; VMware Server 2.0.x before 2.0.1 build 156745; and VMware Fusion before 2.0.2 build 147997 allows remote attackers to cause a denial of service (daemon crash) via a long (1) USER or (2) PASS command.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vmware.com/security/advisories/VMSA-2009-0005.html" source="CONFIRM" patch="1" adv="1">http://www.vmware.com/security/advisories/VMSA-2009-0005.html</ref>
      <ref url="http://seclists.org/fulldisclosure/2009/Apr/0036.html" source="FULLDISC" patch="1">20090403 VMSA-2009-0005 VMware Hosted products, VI Client and patches for ESX and ESXi resolve multiple security issues</ref>
      <ref url="http://lists.vmware.com/pipermail/security-announce/2009/000054.html" source="MLIST" patch="1">[security-announce] 20090403 VMSA-2009-0005 VMware Hosted products, VI Client and patches for ESX and ESXi resolve multiple security issues</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0944" source="VUPEN" adv="1">ADV-2009-0944</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0024" source="VUPEN" adv="1">ADV-2009-0024</ref>
      <ref url="http://www.securitytracker.com/id?1021512" source="SECTRACK">1021512</ref>
      <ref url="http://www.securityfocus.com/bid/34373" source="BID">34373</ref>
      <ref url="http://secunia.com/advisories/34601" source="SECUNIA" adv="1">34601</ref>
      <ref url="http://secunia.com/advisories/33372" source="SECUNIA" adv="1">33372</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6433" source="OVAL">oval:org.mitre.oval:def:6433</ref>
      <ref url="http://osvdb.org/51180" source="OSVDB">51180</ref>
      <ref url="http://milw0rm.com/exploits/7647" source="MILW0RM">7647</ref>
    </refs>
    <vuln_soft>
      <prod vendor="vmware" name="ace">
        <vers num="2.5.0" />
        <vers prev="1" num="2.5.1" />
      </prod>
      <prod vendor="vmware" name="fusion">
        <vers prev="1" num="2.0.1" />
      </prod>
      <prod vendor="vmware" name="server">
        <vers num="2.0.0" />
      </prod>
      <prod vendor="vmware" name="vmware_player">
        <vers num="1.0.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.6" />
        <vers num="1.0.7" />
        <vers num="1.0.8" />
        <vers num="1.0.9" />
        <vers num="1.05" />
        <vers num="2.0" />
        <vers num="2.0.1" />
        <vers num="2.0.2" />
        <vers num="2.0.3" />
        <vers num="2.0.4" />
        <vers num="2.0.5" />
        <vers num="2.5" />
        <vers prev="1" num="2.5.1" />
      </prod>
      <prod vendor="vmware" name="vmware_workstation">
        <vers num="4.5.3" />
        <vers num="5.0" />
        <vers num="5.5.0" />
        <vers num="5.5.1" />
        <vers num="5.5.2" />
        <vers num="5.5.3" />
        <vers num="5.5.4" />
        <vers num="5.5.5" />
        <vers num="5.5.6" />
        <vers num="5.5.7" />
        <vers num="5.5.8" />
        <vers num="6.0" />
        <vers num="6.0.1" />
        <vers num="6.0.2" />
        <vers num="6.0.3" />
        <vers num="6.0.4" />
        <vers num="6.0.5" />
        <vers num="6.5" />
        <vers prev="1" num="6.51" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0178" published="2009-01-20" name="CVE-2009-0178" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in IBM Hardware Management Console (HMC) 7 release 3.2.0 SP1 has unknown impact and attack vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/48010" source="XF">ibm-hmc-unspecified(48010)</ref>
      <ref url="http://www14.software.ibm.com/webapp/set2/subscriptions/pqvcmjd?mode=18&amp;ID=4521" source="CONFIRM">http://www14.software.ibm.com/webapp/set2/subscriptions/pqvcmjd?mode=18&amp;ID=4521</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0158" source="VUPEN">ADV-2009-0158</ref>
      <ref url="http://www.securityfocus.com/bid/33293" source="BID">33293</ref>
      <ref url="http://secunia.com/advisories/33518" source="SECUNIA" adv="1">33518</ref>
      <ref url="http://osvdb.org/51432" source="OSVDB">51432</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="hardware_management_console">
        <vers num="7.3.2.0" edition="sp1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0179" published="2009-01-20" name="CVE-2009-0179" modified="2009-09-02" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">libmikmod 3.1.11 through 3.2.0, as used by MikMod and possibly other products, allows user-assisted attackers to cause a denial of service (application crash) by loading an XM file.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-August/msg01312.html" source="FEDORA">FEDORA-2009-9112</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-August/msg01305.html" source="FEDORA">FEDORA-2009-9095</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=479833" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=479833</ref>
      <ref url="http://www.securityfocus.com/bid/33240" source="BID">33240</ref>
      <ref url="http://secunia.com/advisories/34259" source="SECUNIA">34259</ref>
      <ref url="http://openwall.com/lists/oss-security/2009/01/13/2" source="MLIST">[oss-security] 20090113 CVE Request -- libmikmod</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-03/msg00001.html" source="SUSE">SUSE-SR:2009:006</ref>
      <ref url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=476339" source="MISC">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=476339</ref>
    </refs>
    <vuln_soft>
      <prod vendor="igno_saitz" name="libmikmod">
        <vers num="3.1.10-1" />
        <vers num="3.1.10-2" />
        <vers num="3.1.10-3" />
        <vers num="3.1.10-4" />
        <vers num="3.1.10-5" />
        <vers num="3.1.11-1" />
        <vers num="3.1.11-2" />
        <vers num="3.1.11-3" />
        <vers num="3.1.11-4" />
        <vers num="3.1.11-5" />
        <vers num="3.1.11-6" />
        <vers num="3.1.12" />
        <vers num="3.1.9-1" />
        <vers num="3.1.9-2" />
        <vers num="3.1.9-3" />
        <vers num="3.1.9-4" />
        <vers num="3.1.9-5" />
        <vers num="3.1.9-6" />
        <vers num="3.2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0180" published="2009-01-20" name="CVE-2009-0180" modified="2009-01-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Certain Fedora build scripts for nfs-utils before 1.1.2-9.fc9 on Fedora 9, and before 1.1.4-6.fc10 on Fedora 10, omit TCP Wrapper support, which might allow remote attackers to bypass intended access restrictions, possibly a related issue to CVE-2008-1376.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-January/msg00526.html" source="FEDORA">FEDORA-2009-0297</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-January/msg00376.html" source="FEDORA">FEDORA-2009-0266</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=477864" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=477864</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/48058" source="XF">nfsutils-tcpwrapper-security-bypass(48058)</ref>
      <ref url="http://www.securityfocus.com/bid/33294" source="BID">33294</ref>
      <ref url="http://secunia.com/advisories/33545" source="SECUNIA" adv="1">33545</ref>
    </refs>
    <vuln_soft>
      <prod vendor="nfs" name="nfs-utils">
        <vers num="0.2" />
        <vers num="0.2.1" />
        <vers num="0.3.1" />
        <vers num="0.3.3" />
        <vers num="1.0" />
        <vers num="1.0.1" />
        <vers num="1.0.10" />
        <vers num="1.0.11" />
        <vers num="1.0.12" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.6" />
        <vers num="1.0.7" edition="pre-1" />
        <vers num="1.0.7" edition="pre-2" />
        <vers num="1.0.8" edition="rc-1" />
        <vers num="1.0.8" edition="rc-2" />
        <vers num="1.0.8" edition="rc-3" />
        <vers num="1.0.8" edition="rc-4" />
        <vers num="1.0.9" />
        <vers num="1.1.0" edition="rc-1" />
        <vers num="1.1.1" />
        <vers prev="1" num="1.1.2" />
        <vers num="1.1.3" />
        <vers prev="1" num="1.1.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0181" published="2009-01-20" name="CVE-2009-0181" modified="2009-01-29" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Buffer overflow in VUPlayer allows user-assisted attackers to have an unknown impact via a long file, as demonstrated by a file composed entirely of 'A' characters.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/48169" source="XF">vuplayer-file-bo(48169)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/499810/100/0/threaded" source="BUGTRAQ">20090106 VUPLAYER BufferOver flow POC</ref>
      <ref url="http://securityreason.com/securityalert/4921" source="SREASON">4921</ref>
    </refs>
    <vuln_soft>
      <prod vendor="vuplayer" name="vuplayer">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0182" published="2009-01-20" name="CVE-2009-0182" modified="2009-01-29" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Buffer overflow in VUPlayer 2.49 and earlier allows user-assisted attackers to execute arbitrary code via a long URL in a File line in a .pls file, as demonstrated by an http URL on a File1 line.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/48170" source="XF">vuplayer-fileline-bo(48170)</ref>
      <ref url="http://www.milw0rm.com/exploits/7695" source="MILW0RM">7695</ref>
      <ref url="http://securityreason.com/securityalert/4923" source="SREASON">4923</ref>
    </refs>
    <vuln_soft>
      <prod vendor="vuplayer" name="vuplayer">
        <vers num="0.1" />
        <vers num="0.2" />
        <vers num="0.3" />
        <vers num="0.4" />
        <vers num="0.5" />
        <vers num="0.6" />
        <vers num="0.7" />
        <vers num="0.8" />
        <vers num="0.9" />
        <vers num="1.0" />
        <vers num="1.01" />
        <vers num="1.04" />
        <vers num="1.05" />
        <vers num="1.1" />
        <vers num="1.2" />
        <vers num="1.3" />
        <vers num="1.4" />
        <vers num="1.5" />
        <vers num="1.6" />
        <vers num="1.7" />
        <vers num="1.8" />
        <vers num="1.9" />
        <vers num="2.0" />
        <vers num="2.01" />
        <vers num="2.02" />
        <vers num="2.03" />
        <vers num="2.1" />
        <vers num="2.11" />
        <vers num="2.2" />
        <vers num="2.21" />
        <vers num="2.22" />
        <vers num="2.23" />
        <vers num="2.3" />
        <vers num="2.4" />
        <vers num="2.41" />
        <vers num="2.42" />
        <vers num="2.43" />
        <vers num="2.44" />
        <vers num="2.45" />
        <vers num="2.46" />
        <vers num="2.47" />
        <vers num="2.48" />
        <vers prev="1" num="2.49" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0183" published="2009-02-03" name="CVE-2009-0183" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Stack-based buffer overflow in Remote Control Server in Free Download Manager (FDM) 2.5 Build 758 and 3.0 Build 844 allows remote attackers to execute arbitrary code via a long Authorization header in an HTTP request.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2009/0302" source="VUPEN">ADV-2009-0302</ref>
      <ref url="http://www.securityfocus.com/bid/33554" source="BID">33554</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/500604/100/0/threaded" source="BUGTRAQ">20090202 Secunia Research: Free Download Manager Remote Control Server Buffer Overflow</ref>
      <ref url="http://www.milw0rm.com/exploits/7986" source="MILW0RM">7986</ref>
      <ref url="http://secunia.com/secunia_research/2009-3/" source="MISC" adv="1">http://secunia.com/secunia_research/2009-3/</ref>
      <ref url="http://secunia.com/advisories/33524" source="SECUNIA" adv="1">33524</ref>
      <ref url="http://osvdb.org/51745" source="OSVDB">51745</ref>
    </refs>
    <vuln_soft>
      <prod vendor="free_download_manager" name="free_download_manager">
        <vers num="2.5" />
        <vers num="3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0184" published="2009-02-03" name="CVE-2009-0184" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Multiple buffer overflows in the torrent parsing implementation in Free Download Manager (FDM) 2.5 Build 758 and 3.0 Build 844 allow remote attackers to execute arbitrary code via (1) a long file name within a torrent file, (2) a long tracker URL in a torrent file, or (3) a long comment in a torrent file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2009/0302" source="VUPEN">ADV-2009-0302</ref>
      <ref url="http://www.securityfocus.com/bid/33555" source="BID">33555</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/500605/100/0/threaded" source="BUGTRAQ">20090202 Secunia Research: Free Download Manager Torrent Parsing Buffer Overflows</ref>
      <ref url="http://secunia.com/secunia_research/2009-5/" source="MISC" adv="1">http://secunia.com/secunia_research/2009-5/</ref>
      <ref url="http://secunia.com/advisories/33524" source="SECUNIA" adv="1">33524</ref>
    </refs>
    <vuln_soft>
      <prod vendor="free_download_manager" name="free_download_manager">
        <vers num="2.5" />
        <vers num="3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0185" published="2009-06-02" name="CVE-2009-0185" modified="2009-06-10" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Heap-based buffer overflow in Apple QuickTime before 7.6.2 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via crafted MS ADPCM encoded audio data in an AVI movie file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2009/1469" source="VUPEN" patch="1" adv="1">ADV-2009-1469</ref>
      <ref url="http://support.apple.com/kb/HT3591" source="CONFIRM" patch="1" adv="1">http://support.apple.com/kb/HT3591</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2009/Jun/msg00000.html" source="APPLE" patch="1" adv="1">APPLE-SA-2009-06-01-1</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/50894" source="XF">quicktime-msadpcm-bo(50894)</ref>
      <ref url="http://www.securitytracker.com/id?1022314" source="SECTRACK">1022314</ref>
      <ref url="http://www.securityfocus.com/bid/35163" source="BID">35163</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/504006/100/0/threaded" source="BUGTRAQ">20090602 Secunia Research: Apple QuickTime MS ADPCM Encoding Buffer Overflow</ref>
      <ref url="http://secunia.com/secunia_research/2009-6/" source="MISC" adv="1">http://secunia.com/secunia_research/2009-6/</ref>
      <ref url="http://secunia.com/advisories/35091" source="SECUNIA" adv="1">35091</ref>
      <ref url="http://osvdb.org/54879" source="OSVDB">54879</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="quicktime">
        <vers num="3" />
        <vers num="4.1.2" edition="-" />
        <vers num="4.1.2" edition="-:windows" />
        <vers num="4.1.2" edition="-:mac" />
        <vers num="5.0" />
        <vers num="5.0.1" edition="-" />
        <vers num="5.0.1" edition="-:windows" />
        <vers num="5.0.1" edition="-:mac" />
        <vers num="5.0.2" edition="-" />
        <vers num="5.0.2" edition="-:windows" />
        <vers num="5.0.2" edition="-:mac" />
        <vers num="6.0" edition="-" />
        <vers num="6.0" edition="-:windows" />
        <vers num="6.0.0" edition="-" />
        <vers num="6.0.0" edition="-:windows" />
        <vers num="6.0.0" edition="-:mac" />
        <vers num="6.0.1" edition="-" />
        <vers num="6.0.1" edition="-:windows" />
        <vers num="6.0.1" edition="-:mac" />
        <vers num="6.0.2" edition="-" />
        <vers num="6.0.2" edition="-:windows" />
        <vers num="6.0.2" edition="-:mac" />
        <vers num="6.1" />
        <vers num="6.1.0" edition="-" />
        <vers num="6.1.0" edition="-:mac" />
        <vers num="6.1.0" edition="-:windows" />
        <vers num="6.1.1" edition="-" />
        <vers num="6.1.1" edition="-:windows" />
        <vers num="6.1.1" edition="-:mac" />
        <vers num="6.2.0" edition="-" />
        <vers num="6.2.0" edition="-:windows" />
        <vers num="6.2.0" edition="-:mac" />
        <vers num="6.3.0" edition="-" />
        <vers num="6.3.0" edition="-:mac" />
        <vers num="6.3.0" edition="-:windows" />
        <vers num="6.4.0" edition="-" />
        <vers num="6.4.0" edition="-:mac" />
        <vers num="6.4.0" edition="-:windows" />
        <vers num="6.5" />
        <vers num="6.5.0" edition="-" />
        <vers num="6.5.0" edition="-:windows" />
        <vers num="6.5.0" edition="-:mac" />
        <vers num="6.5.1" edition="-" />
        <vers num="6.5.1" edition="-:mac" />
        <vers num="6.5.1" edition="-:windows" />
        <vers num="6.5.2" edition="-" />
        <vers num="6.5.2" edition="-:mac" />
        <vers num="6.5.2" edition="-:windows" />
        <vers num="7.0" edition="" />
        <vers num="7.0" edition=":windows" />
        <vers num="7.0" edition="-" />
        <vers num="7.0" edition="-:windows" />
        <vers num="7.0.0" edition="-" />
        <vers num="7.0.0" edition="-:windows" />
        <vers num="7.0.0" edition="-:mac" />
        <vers num="7.0.1" edition="" />
        <vers num="7.0.1" edition=":windows" />
        <vers num="7.0.1" edition="-" />
        <vers num="7.0.1" edition="-:mac" />
        <vers num="7.0.1" edition="-:windows" />
        <vers num="7.0.2" edition="" />
        <vers num="7.0.2" edition=":windows" />
        <vers num="7.0.2" edition="-" />
        <vers num="7.0.2" edition="-:windows" />
        <vers num="7.0.2" edition="-:mac" />
        <vers num="7.0.3" edition="-" />
        <vers num="7.0.3" edition="-:windows" />
        <vers num="7.0.3" edition="-:mac" />
        <vers num="7.0.4" edition="-" />
        <vers num="7.0.4" edition="-:windows" />
        <vers num="7.0.4" edition="-:mac" />
        <vers num="7.0.8" />
        <vers num="7.1" />
        <vers num="7.1.0" edition="-" />
        <vers num="7.1.0" edition="-:windows" />
        <vers num="7.1.0" edition="-:mac" />
        <vers num="7.1.1" edition="-" />
        <vers num="7.1.1" edition="-:mac" />
        <vers num="7.1.1" edition="-:windows" />
        <vers num="7.1.2" edition="-" />
        <vers num="7.1.2" edition="-:windows" />
        <vers num="7.1.2" edition="-:mac" />
        <vers num="7.1.3" edition="-" />
        <vers num="7.1.3" edition="-:mac" />
        <vers num="7.1.3" edition="-:windows" />
        <vers num="7.1.4" edition="-" />
        <vers num="7.1.4" edition="-:windows" />
        <vers num="7.1.4" edition="-:mac" />
        <vers num="7.1.5" edition="-" />
        <vers num="7.1.5" edition="-:windows" />
        <vers num="7.1.5" edition="-:mac" />
        <vers num="7.1.6" edition="-" />
        <vers num="7.1.6" edition="-:mac" />
        <vers num="7.1.6" edition="-:windows" />
        <vers num="7.2" edition="" />
        <vers num="7.2" edition=":vista" />
        <vers num="7.2.0" edition="-" />
        <vers num="7.2.0" edition="-:windows" />
        <vers num="7.2.0" edition="-:mac" />
        <vers num="7.2.1" edition="-" />
        <vers num="7.2.1" edition="-:mac" />
        <vers num="7.2.1" edition="-:windows" />
        <vers num="7.3" />
        <vers num="7.3.0" edition="-" />
        <vers num="7.3.0" edition="-:windows" />
        <vers num="7.3.0" edition="-:mac" />
        <vers num="7.3.1" edition="-" />
        <vers num="7.3.1" edition="-:windows" />
        <vers num="7.3.1" edition="-:mac" />
        <vers num="7.3.1.70" />
        <vers num="7.4" />
        <vers num="7.4.0" edition="-" />
        <vers num="7.4.0" edition="-:mac" />
        <vers num="7.4.0" edition="-:windows" />
        <vers num="7.4.1" edition="-" />
        <vers num="7.4.1" edition="-:mac" />
        <vers num="7.4.1" edition="-:windows" />
        <vers num="7.4.4" />
        <vers num="7.4.5" edition="-" />
        <vers num="7.4.5" edition="-:windows" />
        <vers num="7.4.5" edition="-:mac" />
        <vers num="7.5" />
        <vers num="7.5.0" edition="-" />
        <vers num="7.5.0" edition="-:windows" />
        <vers num="7.5.0" edition="-:mac" />
        <vers num="7.5.5" edition="-" />
        <vers num="7.5.5" edition="-:windows" />
        <vers num="7.5.5" edition="-:mac" />
        <vers num="7.6.0" />
        <vers prev="1" num="7.6.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0186" published="2009-03-04" name="CVE-2009-0186" modified="2010-04-27" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Integer overflow in libsndfile 1.0.18, as used in Winamp and other products, allows context-dependent attackers to execute arbitrary code via crafted description chunks in a CAF audio file, leading to a heap-based buffer overflow.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/49038" source="XF">libsndfile-caf-bo(49038)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0585" source="VUPEN" adv="1">ADV-2009-0585</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0584" source="VUPEN" adv="1">ADV-2009-0584</ref>
      <ref url="http://www.ubuntu.com/usn/USN-749-1" source="UBUNTU">USN-749-1</ref>
      <ref url="http://www.securitytracker.com/id?1021784" source="SECTRACK">1021784</ref>
      <ref url="http://www.securityfocus.com/bid/33963" source="BID">33963</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/501413/100/0/threaded" source="BUGTRAQ">20090303 Secunia Research: libsndfile CAF Processing Integer Overflow Vulnerability</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/501399/100/0/threaded" source="BUGTRAQ">20090303 Secunia Research: Winamp CAF Processing Integer Overflow Vulnerability</ref>
      <ref url="http://www.mega-nerd.com/libsndfile/NEWS" source="CONFIRM">http://www.mega-nerd.com/libsndfile/NEWS</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1742" source="DEBIAN">DSA-1742</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200904-16.xml" source="GENTOO">GLSA-200904-16</ref>
      <ref url="http://secunia.com/secunia_research/2009-8/" source="MISC" adv="1">http://secunia.com/secunia_research/2009-8/</ref>
      <ref url="http://secunia.com/secunia_research/2009-7/" source="MISC" adv="1">http://secunia.com/secunia_research/2009-7/</ref>
      <ref url="http://secunia.com/advisories/34791" source="SECUNIA">34791</ref>
      <ref url="http://secunia.com/advisories/34642" source="SECUNIA">34642</ref>
      <ref url="http://secunia.com/advisories/34526" source="SECUNIA">34526</ref>
      <ref url="http://secunia.com/advisories/34316" source="SECUNIA">34316</ref>
      <ref url="http://secunia.com/advisories/33981" source="SECUNIA" adv="1">33981</ref>
      <ref url="http://secunia.com/advisories/33980" source="SECUNIA" adv="1">33980</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-04/msg00003.html" source="SUSE">SUSE-SR:2009:008</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mega-nerd" name="libsndfile">
        <vers num="0.0.28" />
        <vers num="0.0.8" />
        <vers num="1.0.0" edition="rc1" />
        <vers num="1.0.0" edition="rc6" />
        <vers num="1.0.1" />
        <vers num="1.0.10" />
        <vers num="1.0.11" />
        <vers num="1.0.12" />
        <vers num="1.0.13" />
        <vers num="1.0.14" />
        <vers num="1.0.15" />
        <vers num="1.0.16" />
        <vers num="1.0.17" />
        <vers prev="1" num="1.0.18" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.5" />
        <vers num="1.0.6" />
        <vers num="1.0.7" />
        <vers num="1.0.8" />
        <vers num="1.0.9" />
      </prod>
      <prod vendor="nullsoft" name="winamp">
        <vers num="5.541" />
        <vers num="5.55" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0187" published="2009-02-26" name="CVE-2009-0187" modified="2010-04-27" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Stack-based buffer overflow in Orbit Downloader 2.8.2 and 2.8.3, and possibly other versions before 2.8.5, allows remote attackers to execute arbitrary code via a crafted HTTP URL with a long host name, which is not properly handled when constructing a "Connecting" log message.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2009/0521" source="VUPEN" patch="1" adv="1">ADV-2009-0521</ref>
      <ref url="http://www.securityfocus.com/bid/33894" source="BID" patch="1">33894</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/48932" source="XF">orbitdownloader-connecting-bo(48932)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/501220/100/0/threaded" source="BUGTRAQ">20090225 Secunia Research: Orbit Downloader Long URL Parsing Buffer Overflow</ref>
      <ref url="http://secunia.com/secunia_research/2009-9/" source="MISC" adv="1">http://secunia.com/secunia_research/2009-9/</ref>
      <ref url="http://secunia.com/advisories/33843" source="SECUNIA" adv="1">33843</ref>
      <ref url="http://osvdb.org/52294" source="OSVDB">52294</ref>
    </refs>
    <vuln_soft>
      <prod vendor="orbitdownloader" name="orbit_downloader">
        <vers num="2.8.2" />
        <vers num="2.8.3" />
        <vers num="2.8.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0188" published="2009-06-02" name="CVE-2009-0188" modified="2009-06-09" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Apple QuickTime before 7.6.2 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted movie composed of a Sorenson 3 video file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2009/1469" source="VUPEN" patch="1" adv="1">ADV-2009-1469</ref>
      <ref url="http://support.apple.com/kb/HT3591" source="CONFIRM" patch="1" adv="1">http://support.apple.com/kb/HT3591</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2009/Jun/msg00000.html" source="APPLE" patch="1" adv="1">APPLE-SA-2009-06-01-1</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/50886" source="XF">quicktime-sorensonvideo-code-execution(50886)</ref>
      <ref url="http://www.securitytracker.com/id?1022314" source="SECTRACK">1022314</ref>
      <ref url="http://www.securityfocus.com/bid/35159" source="BID">35159</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/504007/100/0/threaded" source="BUGTRAQ">20090602 Secunia Research: QuickTime Sorenson Video 3 Content Parsing Vulnerability</ref>
      <ref url="http://secunia.com/secunia_research/2009-10/" source="MISC" adv="1">http://secunia.com/secunia_research/2009-10/</ref>
      <ref url="http://secunia.com/advisories/35091" source="SECUNIA" adv="1">35091</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="quicktime">
        <vers num="3" />
        <vers num="4.1.2" edition="-" />
        <vers num="4.1.2" edition="-:windows" />
        <vers num="4.1.2" edition="-:mac" />
        <vers num="5.0" />
        <vers num="5.0.1" edition="-" />
        <vers num="5.0.1" edition="-:windows" />
        <vers num="5.0.1" edition="-:mac" />
        <vers num="5.0.2" edition="-" />
        <vers num="5.0.2" edition="-:windows" />
        <vers num="5.0.2" edition="-:mac" />
        <vers num="6.0" edition="-" />
        <vers num="6.0" edition="-:windows" />
        <vers num="6.0.0" edition="-" />
        <vers num="6.0.0" edition="-:windows" />
        <vers num="6.0.0" edition="-:mac" />
        <vers num="6.0.1" edition="-" />
        <vers num="6.0.1" edition="-:windows" />
        <vers num="6.0.1" edition="-:mac" />
        <vers num="6.0.2" edition="-" />
        <vers num="6.0.2" edition="-:windows" />
        <vers num="6.0.2" edition="-:mac" />
        <vers num="6.1" />
        <vers num="6.1.0" edition="-" />
        <vers num="6.1.0" edition="-:mac" />
        <vers num="6.1.0" edition="-:windows" />
        <vers num="6.1.1" edition="-" />
        <vers num="6.1.1" edition="-:windows" />
        <vers num="6.1.1" edition="-:mac" />
        <vers num="6.2.0" edition="-" />
        <vers num="6.2.0" edition="-:windows" />
        <vers num="6.2.0" edition="-:mac" />
        <vers num="6.3.0" edition="-" />
        <vers num="6.3.0" edition="-:mac" />
        <vers num="6.3.0" edition="-:windows" />
        <vers num="6.4.0" edition="-" />
        <vers num="6.4.0" edition="-:mac" />
        <vers num="6.4.0" edition="-:windows" />
        <vers num="6.5" />
        <vers num="6.5.0" edition="-" />
        <vers num="6.5.0" edition="-:windows" />
        <vers num="6.5.0" edition="-:mac" />
        <vers num="6.5.1" edition="-" />
        <vers num="6.5.1" edition="-:mac" />
        <vers num="6.5.1" edition="-:windows" />
        <vers num="6.5.2" edition="-" />
        <vers num="6.5.2" edition="-:mac" />
        <vers num="6.5.2" edition="-:windows" />
        <vers num="7.0" edition="" />
        <vers num="7.0" edition=":windows" />
        <vers num="7.0" edition="-" />
        <vers num="7.0" edition="-:windows" />
        <vers num="7.0.0" edition="-" />
        <vers num="7.0.0" edition="-:windows" />
        <vers num="7.0.0" edition="-:mac" />
        <vers num="7.0.1" edition="" />
        <vers num="7.0.1" edition=":windows" />
        <vers num="7.0.1" edition="-" />
        <vers num="7.0.1" edition="-:mac" />
        <vers num="7.0.1" edition="-:windows" />
        <vers num="7.0.2" edition="" />
        <vers num="7.0.2" edition=":windows" />
        <vers num="7.0.2" edition="-" />
        <vers num="7.0.2" edition="-:windows" />
        <vers num="7.0.2" edition="-:mac" />
        <vers num="7.0.3" edition="-" />
        <vers num="7.0.3" edition="-:windows" />
        <vers num="7.0.3" edition="-:mac" />
        <vers num="7.0.4" edition="-" />
        <vers num="7.0.4" edition="-:windows" />
        <vers num="7.0.4" edition="-:mac" />
        <vers num="7.0.8" />
        <vers num="7.1" />
        <vers num="7.1.0" edition="-" />
        <vers num="7.1.0" edition="-:windows" />
        <vers num="7.1.0" edition="-:mac" />
        <vers num="7.1.1" edition="-" />
        <vers num="7.1.1" edition="-:mac" />
        <vers num="7.1.1" edition="-:windows" />
        <vers num="7.1.2" edition="-" />
        <vers num="7.1.2" edition="-:windows" />
        <vers num="7.1.2" edition="-:mac" />
        <vers num="7.1.3" edition="-" />
        <vers num="7.1.3" edition="-:mac" />
        <vers num="7.1.3" edition="-:windows" />
        <vers num="7.1.4" edition="-" />
        <vers num="7.1.4" edition="-:windows" />
        <vers num="7.1.4" edition="-:mac" />
        <vers num="7.1.5" edition="-" />
        <vers num="7.1.5" edition="-:windows" />
        <vers num="7.1.5" edition="-:mac" />
        <vers num="7.1.6" edition="-" />
        <vers num="7.1.6" edition="-:mac" />
        <vers num="7.1.6" edition="-:windows" />
        <vers num="7.2" edition="" />
        <vers num="7.2" edition=":vista" />
        <vers num="7.2.0" edition="-" />
        <vers num="7.2.0" edition="-:windows" />
        <vers num="7.2.0" edition="-:mac" />
        <vers num="7.2.1" edition="-" />
        <vers num="7.2.1" edition="-:mac" />
        <vers num="7.2.1" edition="-:windows" />
        <vers num="7.3" />
        <vers num="7.3.0" edition="-" />
        <vers num="7.3.0" edition="-:windows" />
        <vers num="7.3.0" edition="-:mac" />
        <vers num="7.3.1" edition="-" />
        <vers num="7.3.1" edition="-:windows" />
        <vers num="7.3.1" edition="-:mac" />
        <vers num="7.3.1.70" />
        <vers num="7.4" />
        <vers num="7.4.0" edition="-" />
        <vers num="7.4.0" edition="-:mac" />
        <vers num="7.4.0" edition="-:windows" />
        <vers num="7.4.1" edition="-" />
        <vers num="7.4.1" edition="-:mac" />
        <vers num="7.4.1" edition="-:windows" />
        <vers num="7.4.4" />
        <vers num="7.4.5" edition="-" />
        <vers num="7.4.5" edition="-:windows" />
        <vers num="7.4.5" edition="-:mac" />
        <vers num="7.5" />
        <vers num="7.5.0" edition="-" />
        <vers num="7.5.0" edition="-:windows" />
        <vers num="7.5.0" edition="-:mac" />
        <vers num="7.5.5" edition="-" />
        <vers num="7.5.5" edition="-:windows" />
        <vers num="7.5.5" edition="-:mac" />
        <vers num="7.6.0" />
        <vers prev="1" num="7.6.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" seq="2009-0189" reject="1" published="2011-02-01" name="CVE-2009-0189" modified="2011-02-01">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2009-1012.  Reason: This candidate is a reservation duplicate of CVE-2009-1012.  Notes: All CVE users should reference CVE-2009-1012 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript>
    </desc>
    <refs />
  </entry>
  <entry type="CVE" seq="2009-0190" reject="1" published="2011-02-01" name="CVE-2009-0190" modified="2011-02-01">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2009-1016.  Reason: This candidate is a reservation duplicate of CVE-2009-1016.  Notes: All CVE users should reference CVE-2009-1016 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript>
    </desc>
    <refs />
  </entry>
  <entry type="CVE" severity="High" seq="2009-0191" published="2009-03-10" name="CVE-2009-0191" modified="2009-03-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Foxit Reader 2.3 before Build 3902 and 3.0 before Build 1506, including 3.0.2009.1301, does not properly handle a JBIG2 symbol dictionary segment with zero new symbols, which allows remote attackers to execute arbitrary code via a crafted PDF file that triggers a dereference of an uninitialized memory location.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2009/0634" source="VUPEN" patch="1" adv="1">ADV-2009-0634</ref>
      <ref url="http://www.foxitsoftware.com/pdf/reader/security.htm#Processing" source="CONFIRM" patch="1" adv="1">http://www.foxitsoftware.com/pdf/reader/security.htm#Processing</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/49135" source="XF">foxitreader-jbig2-code-execution(49135)</ref>
      <ref url="http://www.securitytracker.com/id?1021822" source="SECTRACK">1021822</ref>
      <ref url="http://www.securityfocus.com/bid/34035" source="BID">34035</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/501590/100/0/threaded" source="BUGTRAQ">20090309 Secunia Research: Foxit Reader JBIG2 Symbol Dictionary Processing Vulnerability</ref>
      <ref url="http://secunia.com/secunia_research/2009-11/" source="MISC" adv="1">http://secunia.com/secunia_research/2009-11/</ref>
      <ref url="http://secunia.com/advisories/34036" source="SECUNIA" adv="1">34036</ref>
    </refs>
    <vuln_soft>
      <prod vendor="foxitsoftware" name="foxit_reader">
        <vers num="2.3" />
        <vers num="3.0" />
        <vers num="3.0.2009.1301" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0192" published="2009-07-14" name="CVE-2009-0192" modified="2009-07-20" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Off-by-one error in the iMonitor component in Novell eDirectory 8.8 SP3, 8.8 SP3 FTF3, and possibly other versions allows remote attackers to execute arbitrary code via an HTTP request with a crafted Accept-Language header, which triggers a stack-based buffer overflow.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/51703" source="XF">edirectory-imonitor-acceptlanguage-bo(51703)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1883" source="VUPEN" adv="1">ADV-2009-1883</ref>
      <ref url="http://www.securityfocus.com/bid/35666" source="BID">35666</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/504924/100/0/threaded" source="BUGTRAQ">20090714 Secunia Research: Novell eDirectory iMonitor "Accept-Language" Buffer Overflow</ref>
      <ref url="http://www.novell.com/support/viewContent.do?externalId=3426981" source="CONFIRM">http://www.novell.com/support/viewContent.do?externalId=3426981</ref>
      <ref url="http://secunia.com/secunia_research/2009-13/" source="MISC" adv="1">http://secunia.com/secunia_research/2009-13/</ref>
      <ref url="http://secunia.com/advisories/34160" source="SECUNIA" adv="1">34160</ref>
      <ref url="http://osvdb.org/55847" source="OSVDB">55847</ref>
    </refs>
    <vuln_soft>
      <prod vendor="novell" name="edirectory">
        <vers num="8.8" edition="sp3" />
        <vers num="8.8" edition="sp3:ftf3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0193" published="2009-03-24" name="CVE-2009-0193" modified="2009-04-28" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Heap-based buffer overflow in Adobe Acrobat Reader 9 before 9.1, 8 before 8.1.4, and 7 before 7.1.1 allows remote attackers to execute arbitrary code via a PDF file with a malformed JBIG2 symbol dictionary segment, a different vulnerability than CVE-2009-1061 and CVE-2009-1062.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/34229" source="BID" patch="1">34229</ref>
      <ref url="http://www.adobe.com/support/security/bulletins/apsb09-04.html" source="CONFIRM" patch="1" adv="1">http://www.adobe.com/support/security/bulletins/apsb09-04.html</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1019" source="VUPEN" adv="1">ADV-2009-1019</ref>
      <ref url="http://www.securitytracker.com/id?1021892" source="SECTRACK">1021892</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/502155/100/0/threaded" source="BUGTRAQ">20090325 Secunia Research: Adobe Reader JBIG2 Symbol Dictionary Buffer Overflow</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-0376.html" source="REDHAT">RHSA-2009:0376</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-256788-1" source="SUNALERT">256788</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200904-17.xml" source="GENTOO">GLSA-200904-17</ref>
      <ref url="http://secunia.com/secunia_research/2009-14/" source="MISC" adv="1">http://secunia.com/secunia_research/2009-14/</ref>
      <ref url="http://secunia.com/advisories/34790" source="SECUNIA" adv="1">34790</ref>
      <ref url="http://secunia.com/advisories/34706" source="SECUNIA" adv="1">34706</ref>
      <ref url="http://secunia.com/advisories/34490" source="SECUNIA" adv="1">34490</ref>
      <ref url="http://secunia.com/advisories/34392" source="SECUNIA" adv="1">34392</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-04/msg00010.html" source="SUSE">SUSE-SR:2009:009</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-03/msg00005.html" source="SUSE">SUSE-SA:2009:014</ref>
    </refs>
    <vuln_soft>
      <prod vendor="adobe" name="acrobat">
        <vers num="7.0" />
        <vers num="7.0.1" />
        <vers num="7.0.2" />
        <vers num="7.0.3" />
        <vers num="7.0.5" />
        <vers num="7.0.7" />
        <vers num="7.0.8" />
        <vers num="7.0.9" />
        <vers prev="1" num="7.1.0" />
        <vers num="8.0" />
        <vers num="8.1" />
        <vers num="8.1.1" />
        <vers prev="1" num="8.1.2" />
        <vers prev="1" num="9.0" />
      </prod>
      <prod vendor="adobe" name="reader">
        <vers num="7.0.1" />
        <vers num="7.0.2" />
        <vers num="7.0.3" />
        <vers num="7.0.5" />
        <vers num="7.0.7" />
        <vers num="7.0.8" />
        <vers num="7.0.9" />
        <vers prev="1" num="7.1.0" />
        <vers num="8.1.1" />
        <vers prev="1" num="8.1.2" />
        <vers prev="1" num="9.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0194" published="2009-05-11" name="CVE-2009-0194" modified="2009-05-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">The domain-locking implementation in the GARMINAXCONTROL.GarminAxControl_t.1 ActiveX control in npGarmin.dll in the Garmin Communicator Plug-In 2.6.4.0 does not properly enforce the restrictions that (1) download and (2) upload requests come from a web site specified by the user, which allows remote attackers to obtain sensitive information or reconfigure Garmin GPS devices via unspecified vectors related to a "synchronisation error."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/50360" source="XF">communicator-domain-security-bypass(50360)</ref>
      <ref url="http://www.securityfocus.com/bid/34858" source="BID">34858</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/503319/100/0/threaded" source="BUGTRAQ">20090507 Secunia Research: Garmin Communicator Plug-In Domain Locking Security Bypass</ref>
      <ref url="http://securitytracker.com/id?1022173" source="SECTRACK">1022173</ref>
      <ref url="http://secunia.com/secunia_research/2009-16/" source="MISC" adv="1">http://secunia.com/secunia_research/2009-16/</ref>
      <ref url="http://secunia.com/advisories/34326" source="SECUNIA" adv="1">34326</ref>
      <ref url="http://osvdb.org/54258" source="OSVDB">54258</ref>
    </refs>
    <vuln_soft>
      <prod vendor="garmin" name="garmin_communicator_plugin">
        <vers num="2.6.4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0195" published="2009-04-23" name="CVE-2009-0195" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Heap-based buffer overflow in Xpdf 3.02pl2 and earlier, CUPS 1.3.9, and probably other products, allows remote attackers to execute arbitrary code via a PDF file with crafted JBIG2 symbol dictionary segments.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2010/1040" source="VUPEN">ADV-2010-1040</ref>
      <ref url="http://www.securityfocus.com/bid/34791" source="BID">34791</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/502762/100/0/threaded" source="BUGTRAQ">20090417 Secunia Research: Xpdf JBIG2 Symbol Dictionary Buffer Overflow Vulnerability</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/502759/100/0/threaded" source="BUGTRAQ">20090417 Secunia Research: CUPS pdftops JBIG2 Symbol Dictionary Buffer Overflow</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-0480.html" source="REDHAT">RHSA-2009:0480</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2010:087" source="MANDRIVA">MDVSA-2010:087</ref>
      <ref url="http://secunia.com/secunia_research/2009-18/" source="MISC" adv="1">http://secunia.com/secunia_research/2009-18/</ref>
      <ref url="http://secunia.com/secunia_research/2009-17/" source="MISC" adv="1">http://secunia.com/secunia_research/2009-17/</ref>
      <ref url="http://secunia.com/advisories/35064" source="SECUNIA">35064</ref>
      <ref url="http://secunia.com/advisories/34963" source="SECUNIA">34963</ref>
      <ref url="http://secunia.com/advisories/34756" source="SECUNIA">34756</ref>
      <ref url="http://secunia.com/advisories/34481" source="SECUNIA">34481</ref>
      <ref url="http://secunia.com/advisories/34291" source="SECUNIA">34291</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2009-0458.html" source="REDHAT">RHSA-2009:0458</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10076" source="OVAL">oval:org.mitre.oval:def:10076</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="cups">
        <vers num="1.3.9" />
      </prod>
      <prod vendor="foolabs" name="xpdf">
        <vers num="0.2" />
        <vers num="0.3" />
        <vers num="0.4" />
        <vers num="0.5" />
        <vers num="0.5a" />
        <vers num="0.6" />
        <vers num="0.7" />
        <vers num="0.7a" />
        <vers num="0.80" />
        <vers num="0.90" />
        <vers num="0.91" />
        <vers num="0.91a" />
        <vers num="0.91b" />
        <vers num="0.91c" />
        <vers num="0.92" />
        <vers num="0.92a" />
        <vers num="0.92b" />
        <vers num="0.92c" />
        <vers num="0.92d" />
        <vers num="0.92e" />
        <vers num="0.93" />
        <vers num="0.93a" />
        <vers num="0.93b" />
        <vers num="0.93c" />
        <vers num="1.00" />
        <vers num="1.00a" />
        <vers num="1.01" />
        <vers num="2.00" />
        <vers num="2.01" />
        <vers num="2.02" />
        <vers num="2.03" />
        <vers num="3.0.1" />
        <vers num="3.00" />
        <vers prev="1" num="3.02" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0196" published="2009-04-16" name="CVE-2009-0196" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Heap-based buffer overflow in the big2_decode_symbol_dict function (jbig2_symbol_dict.c) in the JBIG2 decoding library (jbig2dec) in Ghostscript 8.64, and probably earlier versions, allows remote attackers to execute arbitrary code via a PDF file with a JBIG2 symbol dictionary segment with a large run length value.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/34445" source="BID" patch="1">34445</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-April/msg00461.html" source="FEDORA">FEDORA-2009-3710</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-April/msg00460.html" source="FEDORA">FEDORA-2009-3709</ref>
      <ref url="https://bugzilla.redhat.com/attachment.cgi?id=337747" source="MISC">https://bugzilla.redhat.com/attachment.cgi?id=337747</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1708" source="VUPEN">ADV-2009-1708</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0983" source="VUPEN" adv="1">ADV-2009-0983</ref>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-757-1" source="UBUNTU">USN-757-1</ref>
      <ref url="http://www.securitytracker.com/id?1022029" source="SECTRACK">1022029</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/502757/100/0/threaded" source="BUGTRAQ">20090417 rPSA-2009-0060-1 ghostscript</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/502586/100/0/threaded" source="BUGTRAQ">20090409 Secunia Research: Ghostscript jbig2dec JBIG2 Processing Buffer Overflow</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-0421.html" source="REDHAT">RHSA-2009:0421</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:095" source="MANDRIVA">MDVSA-2009:095</ref>
      <ref url="http://wiki.rpath.com/Advisories:rPSA-2009-0060" source="CONFIRM">http://wiki.rpath.com/Advisories:rPSA-2009-0060</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-262288-1" source="SUNALERT">262288</ref>
      <ref url="http://secunia.com/secunia_research/2009-21/" source="MISC" adv="1">http://secunia.com/secunia_research/2009-21/</ref>
      <ref url="http://secunia.com/advisories/35569" source="SECUNIA">35569</ref>
      <ref url="http://secunia.com/advisories/35559" source="SECUNIA">35559</ref>
      <ref url="http://secunia.com/advisories/35416" source="SECUNIA">35416</ref>
      <ref url="http://secunia.com/advisories/34732" source="SECUNIA">34732</ref>
      <ref url="http://secunia.com/advisories/34729" source="SECUNIA">34729</ref>
      <ref url="http://secunia.com/advisories/34667" source="SECUNIA">34667</ref>
      <ref url="http://secunia.com/advisories/34292" source="SECUNIA" adv="1">34292</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10533" source="OVAL">oval:org.mitre.oval:def:10533</ref>
      <ref url="http://osvdb.org/53492" source="OSVDB">53492</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-06/msg00003.html" source="SUSE">SUSE-SR:2009:011</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-04/msg00010.html" source="SUSE">SUSE-SR:2009:009</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ghostscript" name="ghostscript">
        <vers num="0" />
        <vers num="5.50" />
        <vers num="7.07" />
        <vers num="8.0.1" />
        <vers num="8.15" />
        <vers num="8.15.2" />
        <vers num="8.54" />
        <vers num="8.56" />
        <vers num="8.57" />
        <vers num="8.60" />
        <vers num="8.61" />
        <vers num="8.62" />
        <vers num="8.63" />
        <vers prev="1" num="8.64" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0197" published="2009-04-09" name="CVE-2009-0197" modified="2009-04-10" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Integer overflow in the FORMATS Plugin before 4.23 for IrfanView allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a large XPM file that triggers a heap-based buffer overflow.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/49717" source="XF" patch="1">irfanview-formatsplugin-xpm-bo(49717)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0953" source="VUPEN" patch="1" adv="1">ADV-2009-0953</ref>
      <ref url="http://www.irfanview.com/plugins.htm" source="CONFIRM" patch="1">http://www.irfanview.com/plugins.htm</ref>
      <ref url="http://www.securityfocus.com/bid/34402" source="BID">34402</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/502516/100/0/threaded" source="BUGTRAQ">20090407 Secunia Research: IrfanView Formats Plug-in XPM Parsing Integer Overflow</ref>
      <ref url="http://www.osvdb.org/53323" source="OSVDB">53323</ref>
      <ref url="http://secunia.com/secunia_research/2009-20/" source="MISC" adv="1">http://secunia.com/secunia_research/2009-20/</ref>
      <ref url="http://secunia.com/advisories/34525" source="SECUNIA" adv="1">34525</ref>
    </refs>
    <vuln_soft>
      <prod vendor="irfanview" name="formats">
        <vers num="4.00" />
        <vers num="4.10" />
        <vers num="4.20" />
        <vers prev="1" num="4.22" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0198" published="2009-06-11" name="CVE-2009-0198" modified="2010-05-04" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Heap-based buffer overflow in the JBIG2 filter in Adobe Reader 7 and Acrobat 7 before 7.1.3, Adobe Reader 8 and Acrobat 8 before 8.1.6, and Adobe Reader 9 and Acrobat 9 before 9.1.2 allows remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via a crafted PDF file that contains JBIG2 text region segments with Huffman encoding.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-161A.html" source="CERT">TA09-161A</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1547" source="VUPEN" patch="1" adv="1">ADV-2009-1547</ref>
      <ref url="http://www.adobe.com/support/security/bulletins/apsb09-07.html" source="CONFIRM" patch="1" adv="1">http://www.adobe.com/support/security/bulletins/apsb09-07.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/51015" source="XF">reader-acrobat-jbig2-code-exec(51015)</ref>
      <ref url="http://www.securityfocus.com/bid/35302" source="BID">35302</ref>
      <ref url="http://www.securityfocus.com/bid/35274" source="BID">35274</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/504217/100/0/threaded" source="BUGTRAQ">20090610 Secunia Research: Adobe Reader JBIG2 Text Region Segment Buffer Overflow</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-1109.html" source="REDHAT">RHSA-2009:1109</ref>
      <ref url="http://securitytracker.com/id?1022361" source="SECTRACK">1022361</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200907-06.xml" source="GENTOO">GLSA-200907-06</ref>
      <ref url="http://secunia.com/secunia_research/2009-24/" source="MISC" adv="1">http://secunia.com/secunia_research/2009-24/</ref>
      <ref url="http://secunia.com/advisories/35734" source="SECUNIA">35734</ref>
      <ref url="http://secunia.com/advisories/35685" source="SECUNIA">35685</ref>
      <ref url="http://secunia.com/advisories/35655" source="SECUNIA">35655</ref>
      <ref url="http://secunia.com/advisories/35496" source="SECUNIA">35496</ref>
      <ref url="http://secunia.com/advisories/34580" source="SECUNIA" adv="1">34580</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-07/msg00002.html" source="SUSE">SUSE-SR:2009:012</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-07/msg00000.html" source="SUSE">SUSE-SA:2009:035</ref>
    </refs>
    <vuln_soft>
      <prod vendor="adobe" name="acrobat">
        <vers num="7.0" edition="" />
        <vers num="7.0" edition=":standard" />
        <vers num="7.0" edition=":professional" />
        <vers num="7.0.1" edition="" />
        <vers num="7.0.1" edition=":professional" />
        <vers num="7.0.1" edition=":standard" />
        <vers num="7.0.2" edition="" />
        <vers num="7.0.2" edition=":professional" />
        <vers num="7.0.2" edition=":standard" />
        <vers num="7.0.3" edition="" />
        <vers num="7.0.3" edition=":professional" />
        <vers num="7.0.3" edition=":standard" />
        <vers num="7.0.4" edition="" />
        <vers num="7.0.4" edition=":professional" />
        <vers num="7.0.4" edition=":standard" />
        <vers num="7.0.5" edition="" />
        <vers num="7.0.5" edition=":professional" />
        <vers num="7.0.5" edition=":standard" />
        <vers num="7.0.6" edition="" />
        <vers num="7.0.6" edition=":professional" />
        <vers num="7.0.6" edition=":standard" />
        <vers num="7.0.7" edition="" />
        <vers num="7.0.7" edition=":professional" />
        <vers num="7.0.7" edition=":standard" />
        <vers num="7.0.8" edition="" />
        <vers num="7.0.8" edition=":elements" />
        <vers num="7.0.8" edition=":standard" />
        <vers num="7.0.8" edition=":professional" />
        <vers num="7.0.9" edition="" />
        <vers num="7.0.9" edition=":professional" />
        <vers num="7.1" edition="" />
        <vers num="7.1" edition=":standard" />
        <vers num="7.1" edition=":professional" />
        <vers num="7.1.0" />
        <vers num="7.1.1" edition="" />
        <vers num="7.1.1" edition=":standard" />
        <vers num="8.0" edition="" />
        <vers num="8.0" edition=":professional" />
        <vers num="8.0" edition=":standard" />
        <vers num="8.1" edition="" />
        <vers num="8.1" edition=":standard" />
        <vers num="8.1.1" edition="" />
        <vers num="8.1.1" edition=":standard" />
        <vers num="8.1.1" edition=":professional" />
        <vers num="8.1.2" edition="" />
        <vers num="8.1.2" edition=":standard" />
        <vers num="8.1.2" edition=":professional" />
        <vers num="8.1.2" edition="security_update" />
        <vers num="8.1.2" edition="security_update:professional" />
        <vers num="8.1.3" edition="" />
        <vers num="8.1.3" edition=":standard" />
        <vers num="8.1.3" edition=":professional" />
        <vers num="8.1.4" edition="" />
        <vers num="8.1.4" edition=":standard" />
        <vers num="8.1.4" edition=":professional" />
        <vers num="9" />
        <vers num="9.0" edition="" />
        <vers num="9.0" edition=":standard" />
        <vers num="9.0.0" />
        <vers num="9.1" edition="" />
        <vers num="9.1" edition=":standard" />
      </prod>
      <prod vendor="adobe" name="acrobat_reader">
        <vers num="7.0" />
        <vers num="7.0.1" />
        <vers num="7.0.2" />
        <vers num="7.0.3" />
        <vers num="7.0.4" />
        <vers num="7.0.5" />
        <vers num="7.0.6" />
        <vers num="7.0.7" />
        <vers num="7.0.8" />
        <vers num="7.0.9" />
        <vers num="7.1" />
        <vers num="7.1.1" />
        <vers num="8.0" />
        <vers num="8.1" />
        <vers num="8.1.1" />
        <vers num="8.1.2" edition="security_update" />
        <vers num="8.1.3" />
        <vers num="8.1.4" />
        <vers num="8.1.5" />
        <vers num="9" />
        <vers num="9.1" />
        <vers num="9.1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0199" published="2009-09-08" name="CVE-2009-0199" modified="2009-09-29" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Heap-based buffer overflow in the VMnc media codec in vmnc.dll in VMware Movie Decoder before 6.5.3 build 185404, VMware Workstation 6.5.x before 6.5.3 build 185404, VMware Player 2.5.x before 2.5.3 build 185404, and VMware ACE 2.5.x before 2.5.3 build 185404 on Windows might allow remote attackers to execute arbitrary code via a video file with crafted dimensions (aka framebuffer parameters).</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2009/2553" source="VUPEN" patch="1" adv="1">ADV-2009-2553</ref>
      <ref url="http://www.vmware.com/security/advisories/VMSA-2009-0012.html" source="CONFIRM" patch="1" adv="1">http://www.vmware.com/security/advisories/VMSA-2009-0012.html</ref>
      <ref url="http://lists.vmware.com/pipermail/security-announce/2009/000065.html" source="MLIST" patch="1">[security-announce] 20090904 VMSA-2009-0012 VMware Movie Decoder, VMware Workstation, VMware Player, and VMware ACE resolve security issues.</ref>
      <ref url="http://www.securityfocus.com/bid/36290" source="BID">36290</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/506286/100/0/threaded" source="BUGTRAQ">20090905 VMSA-2009-0012 VMware Movie Decoder, VMware Workstation, VMware Player, and VMware ACE resolve security issues.</ref>
      <ref url="http://secunia.com/secunia_research/2009-25/" source="MISC" adv="1">http://secunia.com/secunia_research/2009-25/</ref>
      <ref url="http://secunia.com/advisories/34938" source="SECUNIA" adv="1">34938</ref>
    </refs>
    <vuln_soft>
      <prod vendor="vmware" name="ace">
        <vers num="2.5.0" />
        <vers num="2.5.1" />
        <vers num="2.5.2" />
      </prod>
      <prod vendor="vmware" name="movie_decoder">
        <vers num="6.5.3" />
      </prod>
      <prod vendor="vmware" name="player">
        <vers num="2.5" />
        <vers num="2.5.1" />
        <vers num="2.5.2" />
        <vers num="2.5.2_build_156735" />
      </prod>
      <prod vendor="vmware" name="workstation">
        <vers num="6.5" />
        <vers num="6.5.0" />
        <vers num="6.5.1" />
        <vers num="6.5.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0200" published="2009-09-02" name="CVE-2009-0200" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Integer underflow in OpenOffice.org (OOo) before 3.1.1 and StarOffice/StarSuite 7, 8, and 9 might allow remote attackers to execute arbitrary code via crafted records in the document table of a Word document, leading to a heap-based buffer overflow.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2009/2490" source="VUPEN" adv="1">ADV-2009-2490</ref>
      <ref url="http://www.securityfocus.com/bid/36200" source="BID">36200</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/506194/100/0/threaded" source="BUGTRAQ">20090901 Secunia Research: OpenOffice.org Word Document Table Parsing Integer Underflow</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2010:105" source="MANDRIVA">MDVSA-2010:105</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2010:091" source="MANDRIVA">MDVSA-2010:091</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2010:035" source="MANDRIVA">MDVSA-2010:035</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1880" source="DEBIAN">DSA-1880</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-77-1020715.1-1" source="SUNALERT">1020715</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-263508-1" source="SUNALERT">263508</ref>
      <ref url="http://secunia.com/secunia_research/2009-26/" source="MISC" adv="1">http://secunia.com/secunia_research/2009-26/</ref>
      <ref url="http://secunia.com/advisories/36750" source="SECUNIA">36750</ref>
      <ref url="http://secunia.com/advisories/35036" source="SECUNIA" adv="1">35036</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10881" source="OVAL">oval:org.mitre.oval:def:10881</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-09/msg00001.html" source="SUSE">SUSE-SR:2009:015</ref>
      <ref url="http://development.openoffice.org/releases/3.1.1.html" source="MISC">http://development.openoffice.org/releases/3.1.1.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="openoffice" name="openoffice.org">
        <vers num="1.0-ru" />
        <vers num="1.0.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3.1" />
        <vers num="1.1" edition="beta" />
        <vers num="1.1" edition="beta2" />
        <vers num="1.1" edition="rc1" />
        <vers num="1.1" edition="rc3" />
        <vers num="1.1.1" />
        <vers num="1.1.2" />
        <vers num="1.1.3" />
        <vers num="1.1.4" />
        <vers num="1.1.5" />
        <vers num="1.9.100" />
        <vers num="1.9.104" />
        <vers num="1.9.113" />
        <vers num="1.9.118" />
        <vers num="1.9.122" />
        <vers num="1.9.130" />
        <vers num="1.9.156" />
        <vers num="1.9.680" />
        <vers num="1.9.84" />
        <vers num="1.9.87" />
        <vers num="1.9.91" />
        <vers num="1.9.93" />
        <vers num="1.9.95" />
        <vers num="2.0" edition="beta2" />
        <vers num="2.0.1" />
        <vers num="2.0.2" edition="rc1" />
        <vers num="2.0.2" edition="rc2" />
        <vers num="2.0.3" />
        <vers num="2.0.4" />
        <vers num="2.1" />
        <vers num="2.1.152" />
        <vers num="2.1.154" />
        <vers num="2.2" />
        <vers num="2.2.1" />
        <vers num="2.3" />
        <vers num="2.3.1" />
        <vers num="2.4" />
        <vers num="2.4.1" edition="" />
        <vers num="2.4.1" edition=":64-bit" />
        <vers num="3.01" />
        <vers prev="1" num="3.1" />
        <vers num="605b" />
        <vers num="609" />
        <vers num="614" />
        <vers num="619" />
        <vers num="627" />
        <vers num="633" />
        <vers num="638" />
        <vers num="638c" />
        <vers num="641b" />
        <vers num="641d" />
        <vers num="643" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0201" published="2009-09-02" name="CVE-2009-0201" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Heap-based buffer overflow in OpenOffice.org (OOo) before 3.1.1 and StarOffice/StarSuite 7, 8, and 9 might allow remote attackers to execute arbitrary code via unspecified records in a crafted Word document, related to "table parsing."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2009/2490" source="VUPEN" adv="1">ADV-2009-2490</ref>
      <ref url="http://www.securitytracker.com/id?1022798" source="SECTRACK">1022798</ref>
      <ref url="http://www.securityfocus.com/bid/36200" source="BID">36200</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/506195/100/0/threaded" source="BUGTRAQ">20090901 Secunia Research: OpenOffice.org Word Document Table Parsing Buffer Overflow</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2010:105" source="MANDRIVA">MDVSA-2010:105</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2010:091" source="MANDRIVA">MDVSA-2010:091</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2010:035" source="MANDRIVA">MDVSA-2010:035</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1880" source="DEBIAN">DSA-1880</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-77-1020715.1-1" source="SUNALERT">1020715</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-263508-1" source="SUNALERT">263508</ref>
      <ref url="http://secunia.com/secunia_research/2009-27/" source="MISC" adv="1">http://secunia.com/secunia_research/2009-27/</ref>
      <ref url="http://secunia.com/advisories/36750" source="SECUNIA">36750</ref>
      <ref url="http://secunia.com/advisories/35036" source="SECUNIA" adv="1">35036</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10726" source="OVAL">oval:org.mitre.oval:def:10726</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-09/msg00001.html" source="SUSE">SUSE-SR:2009:015</ref>
      <ref url="http://development.openoffice.org/releases/3.1.1.html" source="MISC">http://development.openoffice.org/releases/3.1.1.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="openoffice" name="openoffice.org">
        <vers num="1.1.2" />
        <vers num="1.1.3" />
        <vers num="1.1.4" />
        <vers num="1.1.5" />
        <vers num="2.0" />
        <vers num="2.0.2" />
        <vers num="2.0.3" />
        <vers num="2.0.4" />
        <vers num="2.1" />
        <vers num="2.2" />
        <vers num="2.2.1" />
        <vers num="2.3" />
        <vers num="2.3.1" />
        <vers num="2.4" />
        <vers num="2.4.1" edition="" />
        <vers num="2.4.1" edition=":64-bit" />
        <vers prev="1" num="3.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0202" published="2009-06-11" name="CVE-2009-0202" modified="2009-06-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Array index error in FL21WIN.DLL in the PowerPoint Freelance Windows 2.1 Translator in Microsoft PowerPoint 2000 and 2002 allows remote attackers to execute arbitrary code via a Freelance file with unspecified "layout information" that triggers a heap-based buffer overflow.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/51034" source="XF" patch="1">ms-powerpoint-freelance-bo(51034)</ref>
      <ref url="http://www.securityfocus.com/bid/35275" source="BID">35275</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/504215/100/0/threaded" source="BUGTRAQ">20090610 Secunia Research: Microsoft PowerPoint Freelance Layout Parsing Vulnerability</ref>
      <ref url="http://www.osvdb.org/54961" source="OSVDB">54961</ref>
      <ref url="http://securitytracker.com/id?1022369" source="SECTRACK">1022369</ref>
      <ref url="http://secunia.com/secunia_research/2009-29/" source="MISC" adv="1">http://secunia.com/secunia_research/2009-29/</ref>
      <ref url="http://secunia.com/advisories/35184" source="SECUNIA" adv="1">35184</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="office_powerpoint">
        <vers num="2000" />
        <vers num="2002" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0204" published="2009-01-30" name="CVE-2009-0204" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in HP Select Access 6.1 and 6.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://marc.info/?l=bugtraq&amp;m=123324765514459&amp;w=2" source="HP" patch="1">HPSBMA02403</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/48334" source="XF">selectaccess-unspecified-xss(48334)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0296" source="VUPEN">ADV-2009-0296</ref>
      <ref url="http://www.securityfocus.com/bid/33505" source="BID">33505</ref>
      <ref url="http://securitytracker.com/id?1021641" source="SECTRACK">1021641</ref>
      <ref url="http://secunia.com/advisories/33713" source="SECUNIA" adv="1">33713</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=123324765514459&amp;w=2" source="HP">HPSBMA02403</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="select_access">
        <vers num="6.1" />
        <vers num="6.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0206" published="2009-02-08" name="CVE-2009-0206" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="4.9" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="3.9" CVSS_base_score="4.9">
    <desc>
      <descript source="cve">Unspecified vulnerability in NFS in HP ONCplus B.11.31.05 and earlier for HP-UX B.11.31 allows local users to cause a denial of service via unknown vectors.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://marc.info/?l=bugtraq&amp;m=123394068325944&amp;w=2" source="HP" patch="1" adv="1">SSRT080182</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/48556" source="XF">hpux-nfs-dos(48556)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0350" source="VUPEN">ADV-2009-0350</ref>
      <ref url="http://www.securityfocus.com/bid/33653" source="BID">33653</ref>
      <ref url="http://secunia.com/advisories/33860" source="SECUNIA" adv="1">33860</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="oncplus">
        <vers num="b.11.31_01" />
        <vers num="b.11.31_02" />
        <vers num="b.11.31_03" />
        <vers num="b.11.31_04" />
        <vers prev="1" num="b.11.31_05" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0207" published="2009-03-24" name="CVE-2009-0207" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:S/C:C/I:C/A:C)" CVSS_score="6.8" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.1" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Unspecified vulnerability in HP-UX B.11.11 running VERITAS Oracle Disk Manager (VRTSodm) 3.5, B.11.23 running VRTSodm 4.1 or VERITAS File System (VRTSvxfs) 4.1, B.11.23 running VRTSodm 5.0 or VRTSvxfs 5.0, and B.11.31 running VRTSodm 5.0 allows local users to gain root privileges via unknown vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/34226" source="BID" patch="1">34226</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=123792744311063&amp;w=2" source="HP" patch="1">SSRT080171</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=123792744311063&amp;w=2" source="HP" patch="1">SSRT080171</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/49403" source="XF">hpux-veritas-unspecified-priv-escalation(49403)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0823" source="VUPEN">ADV-2009-0823</ref>
      <ref url="http://www.securitytracker.com/id?1021891" source="SECTRACK">1021891</ref>
      <ref url="http://secunia.com/advisories/34419" source="SECUNIA">34419</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6352" source="OVAL">oval:org.mitre.oval:def:6352</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="hp-ux">
        <vers num="b.11.11" />
        <vers num="b.11.23" />
        <vers num="b.11.31" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0208" published="2009-02-26" name="CVE-2009-0208" modified="2009-02-27" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in HP Virtual Rooms Client before 7.0.1, when running on Windows, allows remote attackers to execute arbitrary code via unknown vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.info/?l=bugtraq&amp;m=123567121722181&amp;w=2" source="HP">HPSBGN02410</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=123567121722181&amp;w=2" source="HP">HPSBGN02410</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="virtual_rooms">
        <vers num="6.0" />
        <vers prev="1" num="7.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0209" published="2009-10-01" name="CVE-2009-0209" modified="2009-10-02" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">PI Server in OSIsoft PI System before 3.4.380.x does not properly use encryption in the default authentication process, which allows remote attackers to read or modify information in databases via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/506826/100/0/threaded" source="BUGTRAQ">20090930 C4 SCADA Security Advisory - OSISoft PI Server Authentication Weakness</ref>
    </refs>
    <vuln_soft>
      <prod vendor="osisoft" name="pi_server">
        <vers num="2.4" />
        <vers num="2.6" />
        <vers num="3.4.363.97" />
        <vers num="3.4.370" />
        <vers prev="1" num="3.4.375.99" edition="sp2" />
        <vers prev="1" num="3.4.375.99" edition="sp2:32bit_windows" />
        <vers prev="1" num="3.4.375.99" edition="sp2:64bit_windows" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0210" published="2009-02-08" name="CVE-2009-0210" modified="2009-02-20" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in the MLF application in AREVA e-terrahabitat 5.7 and earlier allows remote attackers to execute arbitrary commands or cause a denial of service (system crash) via unspecified vectors, aka PD28578.</descript>
    </desc>
    <sols>
      <sol source="nvd">Per http://www.kb.cert.org/vuls/id/337569 

"III. Solution 

Apply Patch Users of e-terrahabitat version 5.5, 5.6, and 5.7 should apply the e-terrahabitat_560_P20081030_SEC patch immediately."</sol>
    </sols>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/337569" source="CERT-VN">VU#337569</ref>
      <ref url="http://www.securityfocus.com/bid/33637" source="BID">33637</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/500689/100/0/threaded" source="BUGTRAQ">20090205 C4 SCADA Security Advisory - AREVA e-terrahabitat / e-terraplatform Multiple Vulnerabilities</ref>
      <ref url="http://www.scada-security.com/vulnerabilities/areva1.html" source="MISC">http://www.scada-security.com/vulnerabilities/areva1.html</ref>
      <ref url="http://secunia.com/advisories/33837" source="SECUNIA">33837</ref>
    </refs>
    <vuln_soft>
      <prod vendor="areva" name="e-terrahabitat">
        <vers num="5.5" />
        <vers num="5.6" />
        <vers prev="1" num="5.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0211" published="2009-02-08" name="CVE-2009-0211" modified="2009-02-20" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Unspecified vulnerability in the WebFGServer application in AREVA e-terrahabitat 5.7 and earlier allows remote attackers to cause a denial of service (system crash) via unknown vectors, aka PD32018.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/337569" source="CERT-VN">VU#337569</ref>
      <ref url="http://www.securityfocus.com/bid/33637" source="BID">33637</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/500689/100/0/threaded" source="BUGTRAQ">20090205 C4 SCADA Security Advisory - AREVA e-terrahabitat / e-terraplatform Multiple Vulnerabilities</ref>
      <ref url="http://www.scada-security.com/vulnerabilities/areva1.html" source="MISC">http://www.scada-security.com/vulnerabilities/areva1.html</ref>
      <ref url="http://secunia.com/advisories/33837" source="SECUNIA">33837</ref>
    </refs>
    <vuln_soft>
      <prod vendor="areva" name="e-terrahabitat">
        <vers num="5.5" />
        <vers num="5.6" />
        <vers prev="1" num="5.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0212" published="2009-02-08" name="CVE-2009-0212" modified="2009-02-20" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Unspecified vulnerability in the WebFGServer application in AREVA e-terrahabitat 5.7 and earlier allows remote attackers to cause a denial of service (system crash) via unknown vectors, aka PD32020.</descript>
    </desc>
    <sols>
      <sol source="nvd">Per http://www.kb.cert.org/vuls/id/337569 

"III. Solution

 Apply Patch Users of e-terrahabitat version 5.5, 5.6, and 5.7 should apply the e-terrahabitat_560_P20081030_SEC patch immediately."</sol>
    </sols>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/337569" source="CERT-VN">VU#337569</ref>
      <ref url="http://www.securityfocus.com/bid/33637" source="BID">33637</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/500689/100/0/threaded" source="BUGTRAQ">20090205 C4 SCADA Security Advisory - AREVA e-terrahabitat / e-terraplatform Multiple Vulnerabilities</ref>
      <ref url="http://www.scada-security.com/vulnerabilities/areva1.html" source="MISC">http://www.scada-security.com/vulnerabilities/areva1.html</ref>
      <ref url="http://secunia.com/advisories/33837" source="SECUNIA">33837</ref>
    </refs>
    <vuln_soft>
      <prod vendor="areva" name="e-terrahabitat">
        <vers num="5.5" />
        <vers num="5.6" />
        <vers prev="1" num="5.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0213" published="2009-02-08" name="CVE-2009-0213" modified="2009-02-20" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Unspecified vulnerability in the NETIO application in AREVA e-terrahabitat 5.7 and earlier allows remote attackers to cause a denial of service (system crash) via unknown vectors, aka PD32021.</descript>
    </desc>
    <sols>
      <sol source="nvd">Per http://www.kb.cert.org/vuls/id/337569


"III. Solution
Apply Patch


Users of e-terrahabitat version 5.5, 5.6, and 5.7 should apply the e-terrahabitat_560_P20081030_SEC patch immediately."</sol>
    </sols>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/337569" source="CERT-VN">VU#337569</ref>
      <ref url="http://www.securityfocus.com/bid/33637" source="BID">33637</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/500689/100/0/threaded" source="BUGTRAQ">20090205 C4 SCADA Security Advisory - AREVA e-terrahabitat / e-terraplatform Multiple Vulnerabilities</ref>
      <ref url="http://www.scada-security.com/vulnerabilities/areva1.html" source="MISC">http://www.scada-security.com/vulnerabilities/areva1.html</ref>
      <ref url="http://secunia.com/advisories/33837" source="SECUNIA">33837</ref>
    </refs>
    <vuln_soft>
      <prod vendor="areva" name="e-terrahabitat">
        <vers num="5.5" />
        <vers num="5.6" />
        <vers prev="1" num="5.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0214" published="2009-02-08" name="CVE-2009-0214" modified="2009-02-20" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:C/I:C/A:C)" CVSS_score="9.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.0" CVSS_base_score="9.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the WebFGServer application in AREVA e-terrahabitat 5.7 and earlier allows remote authenticated users to gain privileges via unknown vectors, aka PD32022.</descript>
    </desc>
    <sols>
      <sol source="nvd">Per http://www.kb.cert.org/vuls/id/337569 

"III. Solution 

Apply Patch Users of e-terrahabitat version 5.5, 5.6, and 5.7 should apply the e-terrahabitat_560_P20081030_SEC patch immediately."</sol>
    </sols>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/337569" source="CERT-VN">VU#337569</ref>
      <ref url="http://www.securityfocus.com/bid/33637" source="BID">33637</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/500689/100/0/threaded" source="BUGTRAQ">20090205 C4 SCADA Security Advisory - AREVA e-terrahabitat / e-terraplatform Multiple Vulnerabilities</ref>
      <ref url="http://www.scada-security.com/vulnerabilities/areva1.html" source="MISC">http://www.scada-security.com/vulnerabilities/areva1.html</ref>
      <ref url="http://secunia.com/advisories/33837" source="SECUNIA">33837</ref>
    </refs>
    <vuln_soft>
      <prod vendor="areva" name="e-terrahabitat">
        <vers num="5.5" />
        <vers num="5.6" />
        <vers prev="1" num="5.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0215" published="2009-03-25" name="CVE-2009-0215" modified="2009-04-02" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Stack-based buffer overflow in the GetXMLValue method in the IBM Access Support ActiveX control in IbmEgath.dll, as distributed on IBM and Lenovo computers, allows remote attackers to execute arbitrary code via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/340420" source="CERT-VN" adv="1">VU#340420</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/49409" source="XF">ibm-access-activex-bo(49409)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0824" source="VUPEN" adv="1">ADV-2009-0824</ref>
      <ref url="http://www.securityfocus.com/bid/34228" source="BID">34228</ref>
      <ref url="http://secunia.com/advisories/34470" source="SECUNIA">34470</ref>
      <ref url="http://osvdb.org/52958" source="OSVDB">52958</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="access_support_activex_control">
        <vers num="3.20.284.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0216" published="2009-02-13" name="CVE-2009-0216" modified="2009-02-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">GE Fanuc iFIX 5.0 and earlier relies on client-side authentication involving a weakly encrypted local password file, which allows remote attackers to bypass intended access restrictions and start privileged server login sessions by recovering a password or by using a modified program module.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/310355" source="CERT-VN">VU#310355</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/48691" source="XF">gefanucifix-multiple-unauth-access(48691)</ref>
      <ref url="http://www.securityfocus.com/bid/33739" source="BID">33739</ref>
      <ref url="http://www.mcgrewsecurity.com/2009/02/10/ge-fanuc-releases-info-on-ifix-vulnerabilities-vu-310355/" source="MISC">http://www.mcgrewsecurity.com/2009/02/10/ge-fanuc-releases-info-on-ifix-vulnerabilities-vu-310355/</ref>
      <ref url="http://support.gefanuc.com/support/index?page=kbchannel&amp;id=S:KB13253&amp;actp=search" source="CONFIRM" adv="1">http://support.gefanuc.com/support/index?page=kbchannel&amp;id=S:KB13253&amp;actp=search</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ge_fanuc" name="ifix">
        <vers num="2.0" />
        <vers num="2.2" />
        <vers num="2.21" />
        <vers num="2.5" />
        <vers num="2.6" />
        <vers num="3.0" />
        <vers num="3.5" />
        <vers num="4.0" />
        <vers num="4.5" />
        <vers prev="1" num="5.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0217" published="2009-07-14" name="CVE-2009-0217" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The design of the W3C XML Signature Syntax and Processing (XMLDsig) recommendation, as implemented in products including (1) the Oracle Security Developer Tools component in Oracle Application Server 10.1.2.3, 10.1.3.4, and 10.1.4.3IM; (2) the WebLogic Server component in BEA Product Suite 10.3, 10.0 MP1, 9.2 MP3, 9.1, 9.0, and 8.1 SP6; (3) Mono before 2.4.2.2; (4) XML Security Library before 1.2.12; (5) IBM WebSphere Application Server Versions 6.0 through 6.0.2.33, 6.1 through 6.1.0.23, and 7.0 through 7.0.0.1; (6) Sun JDK and JRE Update 14 and earlier; (7) Microsoft .NET Framework 3.0 through 3.0 SP2, 3.5, and 4.0; and other products uses a parameter that defines an HMAC truncation length (HMACOutputLength) but does not require a minimum for this length, which allows attackers to spoof HMAC-based signatures and bypass authentication by specifying a truncation length with a small number of bits.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA10-159B.html" source="CERT">TA10-159B</ref>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-294A.html" source="CERT">TA09-294A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/466161" source="CERT-VN">VU#466161</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1911" source="VUPEN" patch="1" adv="1">ADV-2009-1911</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1909" source="VUPEN" patch="1" adv="1">ADV-2009-1909</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1908" source="VUPEN" patch="1" adv="1">ADV-2009-1908</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1900" source="VUPEN" patch="1" adv="1">ADV-2009-1900</ref>
      <ref url="http://www.securityfocus.com/bid/35671" source="BID" patch="1">35671</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujul2009.html" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujul2009.html</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?rs=180&amp;uid=swg21384925" source="CONFIRM" patch="1" adv="1">http://www-01.ibm.com/support/docview.wss?rs=180&amp;uid=swg21384925</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?rs=180&amp;context=SSEQTP&amp;dc=D400&amp;uid=swg24023723&amp;loc=en_US&amp;cs=UTF-8&amp;lang=en&amp;rss=ct180websphere" source="AIXAPAR" patch="1" adv="1">PK80627</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?rs=180&amp;context=SSEQTP&amp;dc=D400&amp;uid=swg24023545&amp;loc=en_US&amp;cs=UTF-8&amp;lang=en&amp;rss=ct180websphere" source="AIXAPAR" patch="1" adv="1">PK80596</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-August/msg00505.html" source="FEDORA">FEDORA-2009-8473</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-August/msg00494.html" source="FEDORA">FEDORA-2009-8456</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-August/msg00325.html" source="FEDORA">FEDORA-2009-8337</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-August/msg00310.html" source="FEDORA">FEDORA-2009-8329</ref>
      <ref url="https://rhn.redhat.com/errata/RHSA-2009-1650.html" source="REDHAT">RHSA-2009:1650</ref>
      <ref url="https://rhn.redhat.com/errata/RHSA-2009-1649.html" source="REDHAT">RHSA-2009:1649</ref>
      <ref url="https://rhn.redhat.com/errata/RHSA-2009-1637.html" source="REDHAT">RHSA-2009:1637</ref>
      <ref url="https://rhn.redhat.com/errata/RHSA-2009-1636.html" source="REDHAT">RHSA-2009:1636</ref>
      <ref url="https://rhn.redhat.com/errata/RHSA-2009-1428.html" source="REDHAT">RHSA-2009:1428</ref>
      <ref url="https://rhn.redhat.com/errata/RHSA-2009-1201.html" source="REDHAT">RHSA-2009:1201</ref>
      <ref url="https://rhn.redhat.com/errata/RHSA-2009-1200.html" source="REDHAT">RHSA-2009:1200</ref>
      <ref url="https://issues.apache.org/bugzilla/show_bug.cgi?id=47527" source="CONFIRM">https://issues.apache.org/bugzilla/show_bug.cgi?id=47527</ref>
      <ref url="https://issues.apache.org/bugzilla/show_bug.cgi?id=47526" source="CONFIRM">https://issues.apache.org/bugzilla/show_bug.cgi?id=47526</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=511915" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=511915</ref>
      <ref url="http://www.w3.org/QA/2009/07/hmac_truncation_in_xml_signatu.html" source="MISC" adv="1">http://www.w3.org/QA/2009/07/hmac_truncation_in_xml_signatu.html</ref>
      <ref url="http://www.w3.org/2008/06/xmldsigcore-errata.html#e03" source="CONFIRM" adv="1">http://www.w3.org/2008/06/xmldsigcore-errata.html#e03</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0635" source="VUPEN">ADV-2010-0635</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0366" source="VUPEN">ADV-2010-0366</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/3122" source="VUPEN">ADV-2009-3122</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/2543" source="VUPEN">ADV-2009-2543</ref>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-826-1" source="UBUNTU">USN-826-1</ref>
      <ref url="http://www.ubuntu.com/usn/USN-903-1" source="UBUNTU">USN-903-1</ref>
      <ref url="http://www.securitytracker.com/id?1022661" source="SECTRACK">1022661</ref>
      <ref url="http://www.securitytracker.com/id?1022567" source="SECTRACK">1022567</ref>
      <ref url="http://www.securitytracker.com/id?1022561" source="SECTRACK">1022561</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-1694.html" source="REDHAT">RHSA-2009:1694</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuoct2009.html" source="CONFIRM">http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuoct2009.html</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujul2010.html" source="CONFIRM">http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujul2010.html</ref>
      <ref url="http://www.openoffice.org/security/cves/CVE-2009-0217.html" source="CONFIRM">http://www.openoffice.org/security/cves/CVE-2009-0217.html</ref>
      <ref url="http://www.mono-project.com/Vulnerabilities" source="CONFIRM" adv="1">http://www.mono-project.com/Vulnerabilities</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms10-041.mspx" source="MS">MS10-041</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:209" source="MANDRIVA">MDVSA-2009:209</ref>
      <ref url="http://www.kb.cert.org/vuls/id/WDON-7TY529" source="CONFIRM">http://www.kb.cert.org/vuls/id/WDON-7TY529</ref>
      <ref url="http://www.kb.cert.org/vuls/id/MAPG-7TSKXQ" source="CONFIRM">http://www.kb.cert.org/vuls/id/MAPG-7TSKXQ</ref>
      <ref url="http://www.debian.org/security/2010/dsa-1995" source="DEBIAN">DSA-1995</ref>
      <ref url="http://www.aleksey.com/xmlsec/" source="CONFIRM">http://www.aleksey.com/xmlsec/</ref>
      <ref url="http://svn.apache.org/viewvc?revision=794013&amp;view=revision" source="CONFIRM">http://svn.apache.org/viewvc?revision=794013&amp;view=revision</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-77-1020710.1-1" source="SUNALERT">1020710</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-269208-1" source="SUNALERT">269208</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-263429-1" source="SUNALERT">263429</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-21-125136-16-1" source="CONFIRM">http://sunsolve.sun.com/search/document.do?assetkey=1-21-125136-16-1</ref>
      <ref url="http://secunia.com/advisories/38921" source="SECUNIA">38921</ref>
      <ref url="http://secunia.com/advisories/38695" source="SECUNIA">38695</ref>
      <ref url="http://secunia.com/advisories/38568" source="SECUNIA">38568</ref>
      <ref url="http://secunia.com/advisories/38567" source="SECUNIA">38567</ref>
      <ref url="http://secunia.com/advisories/37841" source="SECUNIA">37841</ref>
      <ref url="http://secunia.com/advisories/37671" source="SECUNIA">37671</ref>
      <ref url="http://secunia.com/advisories/37300" source="SECUNIA">37300</ref>
      <ref url="http://secunia.com/advisories/36494" source="SECUNIA" adv="1">36494</ref>
      <ref url="http://secunia.com/advisories/36180" source="SECUNIA" adv="1">36180</ref>
      <ref url="http://secunia.com/advisories/36176" source="SECUNIA" adv="1">36176</ref>
      <ref url="http://secunia.com/advisories/36162" source="SECUNIA" adv="1">36162</ref>
      <ref url="http://secunia.com/advisories/35858" source="SECUNIA" adv="1">35858</ref>
      <ref url="http://secunia.com/advisories/35855" source="SECUNIA" adv="1">35855</ref>
      <ref url="http://secunia.com/advisories/35854" source="SECUNIA" adv="1">35854</ref>
      <ref url="http://secunia.com/advisories/35853" source="SECUNIA" adv="1">35853</ref>
      <ref url="http://secunia.com/advisories/35852" source="SECUNIA" adv="1">35852</ref>
      <ref url="http://secunia.com/advisories/35776" source="SECUNIA" adv="1">35776</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:8717" source="OVAL">oval:org.mitre.oval:def:8717</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7158" source="OVAL">oval:org.mitre.oval:def:7158</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10186" source="OVAL">oval:org.mitre.oval:def:10186</ref>
      <ref url="http://osvdb.org/55907" source="OSVDB">55907</ref>
      <ref url="http://osvdb.org/55895" source="OSVDB">55895</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=125787273209737&amp;w=2" source="HP">HPSBUX02476</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=125787273209737&amp;w=2" source="HP">HPSBUX02476</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-03/msg00005.html" source="SUSE">SUSE-SA:2010:017</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-11/msg00002.html" source="SUSE">SUSE-SA:2009:053</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2009/Sep/msg00000.html" source="APPLE">APPLE-SA-2009-09-03-1</ref>
      <ref url="http://git.gnome.org/cgit/xmlsec/patch/?id=34b349675af9f72eb822837a8772cc1ead7115c7" source="CONFIRM">http://git.gnome.org/cgit/xmlsec/patch/?id=34b349675af9f72eb822837a8772cc1ead7115c7</ref>
      <ref url="http://git.gnome.org/cgit/xmlsec/commit/?id=34b349675af9f72eb822837a8772cc1ead7115c7" source="CONFIRM">http://git.gnome.org/cgit/xmlsec/commit/?id=34b349675af9f72eb822837a8772cc1ead7115c7</ref>
      <ref url="http://blogs.sun.com/security/entry/cert_vulnerability_note_vu_466161" source="CONFIRM">http://blogs.sun.com/security/entry/cert_vulnerability_note_vu_466161</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="websphere_application_server">
        <vers num="6.0" />
        <vers num="6.0.0.1" />
        <vers num="6.0.0.2" />
        <vers num="6.0.0.3" />
        <vers num="6.0.1" />
        <vers num="6.0.1.1" />
        <vers num="6.0.1.11" />
        <vers num="6.0.1.13" />
        <vers num="6.0.1.15" />
        <vers num="6.0.1.17" />
        <vers num="6.0.1.2" />
        <vers num="6.0.1.3" />
        <vers num="6.0.1.5" />
        <vers num="6.0.1.7" />
        <vers num="6.0.1.9" />
        <vers num="6.0.2" edition="" />
        <vers num="6.0.2" edition=":fp17" />
        <vers num="6.0.2.1" />
        <vers num="6.0.2.10" />
        <vers num="6.0.2.11" />
        <vers num="6.0.2.12" />
        <vers num="6.0.2.13" />
        <vers num="6.0.2.14" />
        <vers num="6.0.2.15" />
        <vers num="6.0.2.16" />
        <vers num="6.0.2.17" />
        <vers num="6.0.2.18" />
        <vers num="6.0.2.19" />
        <vers num="6.0.2.2" />
        <vers num="6.0.2.20" />
        <vers num="6.0.2.21" />
        <vers num="6.0.2.22" />
        <vers num="6.0.2.23" />
        <vers num="6.0.2.24" />
        <vers num="6.0.2.25" />
        <vers num="6.0.2.28" />
        <vers num="6.0.2.29" />
        <vers num="6.0.2.3" />
        <vers num="6.0.2.30" />
        <vers num="6.0.2.31" />
        <vers num="6.0.2.32" />
        <vers num="6.0.2.33" />
        <vers num="6.1" />
        <vers num="6.1.0" />
        <vers num="6.1.0.0" />
        <vers num="6.1.0.1" />
        <vers num="6.1.0.10" />
        <vers num="6.1.0.11" />
        <vers num="6.1.0.12" />
        <vers num="6.1.0.13" />
        <vers num="6.1.0.14" />
        <vers num="6.1.0.15" />
        <vers num="6.1.0.16" />
        <vers num="6.1.0.17" />
        <vers num="6.1.0.18" />
        <vers num="6.1.0.19" />
        <vers num="6.1.0.2" />
        <vers num="6.1.0.20" />
        <vers num="6.1.0.21" />
        <vers num="6.1.0.22" />
        <vers num="6.1.0.23" />
        <vers num="6.1.0.3" />
        <vers num="6.1.0.4" />
        <vers num="6.1.0.5" />
        <vers num="6.1.0.6" />
        <vers num="6.1.0.7" />
        <vers num="6.1.0.8" />
        <vers num="6.1.0.9" />
        <vers num="7.0" />
        <vers num="7.0.0.1" />
      </prod>
      <prod vendor="mono_project" name="mono">
        <vers num="1.2.1" />
        <vers num="1.2.2" />
        <vers num="1.2.3" />
        <vers num="1.2.4" />
        <vers num="1.2.5" />
        <vers num="1.2.6" />
        <vers num="1.9" />
        <vers num="2.0" />
      </prod>
      <prod vendor="oracle" name="application_server">
        <vers num="10.1.2.3" />
        <vers num="10.1.3.4" />
        <vers num="10.1.4.3im" />
      </prod>
      <prod vendor="oracle" name="bea_product_suite">
        <vers num="10.0" edition="mp1" />
        <vers num="10.3" />
        <vers num="8.1" edition="sp6" />
        <vers num="9.0" />
        <vers num="9.1" />
        <vers num="9.2" edition="mp3" />
      </prod>
      <prod vendor="oracle" name="weblogic_server_component">
        <vers num="10.0" edition="mp1" />
        <vers num="10.3" />
        <vers num="8.1" edition="sp6" />
        <vers num="9.0" />
        <vers num="9.1" />
        <vers num="9.2" edition="mp3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0218" published="2009-04-13" name="CVE-2009-0218" modified="2009-04-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Insecure method vulnerability in Particle Software IntraLaunch Application Launcher ActiveX control in IntraLaunch.ocx, as used in LDRA TBbrowse and possibly other products, allows remote attackers to execute arbitrary code via unknown vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/WDON-7Q4RZN" source="MISC">http://www.kb.cert.org/vuls/id/WDON-7Q4RZN</ref>
      <ref url="http://www.kb.cert.org/vuls/id/MAPG-7PYRP4" source="CONFIRM">http://www.kb.cert.org/vuls/id/MAPG-7PYRP4</ref>
      <ref url="http://www.kb.cert.org/vuls/id/908801" source="CERT-VN">VU#908801</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/49684" source="XF">intralaunch-activex-code-execution(49684)</ref>
      <ref url="http://www.securityfocus.com/bid/34395" source="BID">34395</ref>
    </refs>
    <vuln_soft>
      <prod vendor="particlesoftware" name="intralaunch">
        <vers num="-" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0219" published="2009-01-20" name="CVE-2009-0219" modified="2009-02-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">The PDF distiller in the Attachment Service in Research in Motion (RIM) BlackBerry Enterprise Server (BES) 4.1.3 through 4.1.6, BlackBerry Professional Software 4.1.4, and BlackBerry Unite! before 1.0.3 bundle 28 performs delete operations on uninitialized pointers, which allows user-assisted remote attackers to execute arbitrary code via a crafted data stream in a .pdf file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securitytracker.com/id?1021559" source="SECTRACK">1021559</ref>
      <ref url="http://www.securityfocus.com/bid/33250" source="BID">33250</ref>
      <ref url="http://www.blackberry.com/btsc/search.do?cmd=displayKC&amp;docType=kc&amp;externalId=KB17119" source="CONFIRM" adv="1">http://www.blackberry.com/btsc/search.do?cmd=displayKC&amp;docType=kc&amp;externalId=KB17119</ref>
      <ref url="http://www.blackberry.com/btsc/search.do?cmd=displayKC&amp;docType=kc&amp;externalId=KB17118" source="CONFIRM" adv="1">http://www.blackberry.com/btsc/search.do?cmd=displayKC&amp;docType=kc&amp;externalId=KB17118</ref>
      <ref url="http://secunia.com/advisories/33534" source="SECUNIA" adv="1">33534</ref>
      <ref url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=766" source="IDEFENSE">20090113 RIM BlackBerry Enterprise Server Attachment Service PDF Distiller Uninitialized Memory Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="research_in_motion_limited" name="blackberry_enterprise_server">
        <vers num="4.1.3" />
        <vers num="4.1.4" />
        <vers num="4.1.5" />
        <vers num="4.1.6" />
      </prod>
      <prod vendor="research_in_motion_limited" name="blackberry_professional_software">
        <vers num="4.1.4" />
      </prod>
      <prod vendor="research_in_motion_limited" name="blackberry_unite">
        <vers num="1.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers prev="1" num="1.0.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0220" published="2009-05-12" name="CVE-2009-0220" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Multiple stack-based buffer overflows in the PowerPoint 4.0 importer (PP4X32.DLL) in Microsoft Office PowerPoint 2000 SP3, 2002 SP3, and 2003 SP3 allow remote attackers to execute arbitrary code via crafted formatting data for paragraphs in a file that uses a PowerPoint 4.0 native file format, related to (1) an incorrect calculation from a record header, or (2) an interget that is used to specify the number of bytes to copy, aka "Legacy File Format Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-132A.html" source="CERT">TA09-132A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS09-017.mspx" source="MS" patch="1" adv="1">MS09-017</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1290" source="VUPEN" adv="1">ADV-2009-1290</ref>
      <ref url="http://www.securitytracker.com/id?1022205" source="SECTRACK">1022205</ref>
      <ref url="http://www.securityfocus.com/bid/34833" source="BID">34833</ref>
      <ref url="http://secunia.com/advisories/32428" source="SECUNIA" adv="1">32428</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5610" source="OVAL">oval:org.mitre.oval:def:5610</ref>
      <ref url="http://osvdb.org/54386" source="OSVDB">54386</ref>
      <ref url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=790" source="IDEFENSE">20090512 Microsoft PowerPoint PPT 4.0 Importer Multiple Stack Buffer Overflow Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="office_powerpoint">
        <vers num="2000" edition="sp3" />
        <vers num="2002" edition="sp3" />
        <vers num="2003" edition="sp3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0221" published="2009-05-12" name="CVE-2009-0221" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Integer overflow in Microsoft Office PowerPoint 2002 SP3 and 2003 SP3 allows remote attackers to execute arbitrary code via a PowerPoint file containing a crafted record type for "collaboration information for different slides" that contains a field that specifies a large number of records, which triggers an under-allocated buffer and a heap-based buffer overflow, aka "Integer Overflow Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-132A.html" source="CERT">TA09-132A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS09-017.mspx" source="MS" patch="1" adv="1">MS09-017</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1290" source="VUPEN">ADV-2009-1290</ref>
      <ref url="http://www.securitytracker.com/id?1022205" source="SECTRACK">1022205</ref>
      <ref url="http://www.securityfocus.com/bid/34835" source="BID">34835</ref>
      <ref url="http://secunia.com/advisories/32428" source="SECUNIA">32428</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6127" source="OVAL">oval:org.mitre.oval:def:6127</ref>
      <ref url="http://osvdb.org/54394" source="OSVDB">54394</ref>
      <ref url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=796" source="IDEFENSE">20090512 Microsoft PowerPoint Integer Overflow Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="office_powerpoint">
        <vers num="2002" edition="sp3" />
        <vers num="2003" edition="sp3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0222" published="2009-05-12" name="CVE-2009-0222" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Microsoft Office PowerPoint 2000 SP3, 2002 SP3, and 2003 SP3 allows remote attackers to execute arbitrary code via crafted sound data in a file that uses a PowerPoint 4.0 native file format, leading to a "pointer overwrite" and memory corruption, aka "Legacy File Format Vulnerability," a different vulnerability than CVE-2009-0223, CVE-2009-0226, CVE-2009-0227, and CVE-2009-1137.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-132A.html" source="CERT">TA09-132A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS09-017.mspx" source="MS" patch="1" adv="1">MS09-017</ref>
      <ref url="http://www.vupen.com/exploits/Microsoft_PowerPoint_Pointer_Overwrite_Code_Execution_Exploit_MS09_017_1290123.php" source="MISC" adv="1">http://www.vupen.com/exploits/Microsoft_PowerPoint_Pointer_Overwrite_Code_Execution_Exploit_MS09_017_1290123.php</ref>
      <ref url="http://www.vupen.com/exploits/Microsoft_PowerPoint_Memory_Corruption_Code_Execution_Exploit_MS09_017_1290124.php" source="MISC" adv="1">http://www.vupen.com/exploits/Microsoft_PowerPoint_Memory_Corruption_Code_Execution_Exploit_MS09_017_1290124.php</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1290" source="VUPEN">ADV-2009-1290</ref>
      <ref url="http://www.securitytracker.com/id?1022205" source="SECTRACK">1022205</ref>
      <ref url="http://www.securityfocus.com/bid/34831" source="BID">34831</ref>
      <ref url="http://secunia.com/advisories/32428" source="SECUNIA">32428</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6143" source="OVAL">oval:org.mitre.oval:def:6143</ref>
      <ref url="http://osvdb.org/54382" source="OSVDB">54382</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="office_powerpoint">
        <vers num="2000" edition="sp3" />
        <vers num="2002" edition="sp3" />
        <vers num="2003" edition="sp3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0223" published="2009-05-12" name="CVE-2009-0223" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Microsoft Office PowerPoint 2000 SP3, 2002 SP3, and 2003 SP3 allows remote attackers to execute arbitrary code via crafted sound data in a file that uses a PowerPoint 4.0 native file format, leading to memory corruption, aka "Legacy File Format Vulnerability," a different vulnerability than CVE-2009-0222, CVE-2009-0226, CVE-2009-0227, and CVE-2009-1137.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-132A.html" source="CERT">TA09-132A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS09-017.mspx" source="MS" patch="1" adv="1">MS09-017</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1290" source="VUPEN">ADV-2009-1290</ref>
      <ref url="http://www.securitytracker.com/id?1022205" source="SECTRACK">1022205</ref>
      <ref url="http://www.securityfocus.com/bid/34834" source="BID">34834</ref>
      <ref url="http://secunia.com/advisories/32428" source="SECUNIA">32428</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6269" source="OVAL">oval:org.mitre.oval:def:6269</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="office_powerpoint">
        <vers num="2000" edition="sp3" />
        <vers num="2002" edition="sp3" />
        <vers num="2003" edition="sp3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0224" published="2009-05-12" name="CVE-2009-0224" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Microsoft Office PowerPoint 2000 SP3, 2002 SP3, 2003 SP3, and 2007 SP1 and SP2; PowerPoint Viewer 2003 and 2007 SP1 and SP2; PowerPoint in Microsoft Office 2004 for Mac and 2008 for Mac; Open XML File Format Converter for Mac; Microsoft Works 8.5 and 9.0; and Microsoft Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2 do not properly validate PowerPoint files, which allows remote attackers to execute arbitrary code via multiple crafted BuildList records that include ChartBuild containers, which triggers memory corruption, aka "Memory Corruption Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-132A.html" source="CERT">TA09-132A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS09-017.mspx" source="MS" patch="1" adv="1">MS09-017</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1290" source="VUPEN">ADV-2009-1290</ref>
      <ref url="http://www.securitytracker.com/id?1022205" source="SECTRACK">1022205</ref>
      <ref url="http://www.securityfocus.com/bid/34879" source="BID">34879</ref>
      <ref url="http://secunia.com/advisories/32428" source="SECUNIA">32428</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6023" source="OVAL">oval:org.mitre.oval:def:6023</ref>
      <ref url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=793" source="IDEFENSE">20090512 Microsoft PowerPoint Build List Memory Corruption Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="compatibility_pack_word_excel_powerpoint">
        <vers num="2007" edition="sp1" />
      </prod>
      <prod vendor="microsoft" name="office_compatibility_pack_for_word_excel_ppt_2007">
        <vers num="" edition=":sp1" />
        <vers num="" edition="sp2" />
      </prod>
      <prod vendor="microsoft" name="office_powerpoint">
        <vers num="2000" edition="sp3" />
        <vers num="2002" edition="sp3" />
        <vers num="2003" edition="sp3" />
        <vers num="2007" edition="sp1" />
      </prod>
      <prod vendor="microsoft" name="office_powerpoint_viewer">
        <vers num="2003" />
        <vers num="2007" edition="sp1" />
        <vers num="2007" edition="sp2" />
      </prod>
      <prod vendor="microsoft" name="open_xml_file_format_converter">
        <vers num="" edition=":mac" />
      </prod>
      <prod vendor="microsoft" name="powerpoint">
        <vers num="2004" edition="" />
        <vers num="2004" edition=":mac" />
        <vers num="2008" edition="" />
        <vers num="2008" edition=":mac" />
      </prod>
      <prod vendor="microsoft" name="works">
        <vers num="8.5" />
        <vers num="9.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0225" published="2009-05-12" name="CVE-2009-0225" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Microsoft Office PowerPoint 2002 SP3 allows remote attackers to execute arbitrary code via crafted sound data in a file that uses a PowerPoint 95 native file format, leading to improper "array indexing" and memory corruption, aka "PP7 Memory Corruption Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-132A.html" source="CERT">TA09-132A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS09-017.mspx" source="MS" patch="1" adv="1">MS09-017</ref>
      <ref url="http://www.vupen.com/exploits/Microsoft_PowerPoint_Array_Indexing_Code_Execution_Exploit_MS09_017_1290125.php" source="MISC" adv="1">http://www.vupen.com/exploits/Microsoft_PowerPoint_Array_Indexing_Code_Execution_Exploit_MS09_017_1290125.php</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1290" source="VUPEN">ADV-2009-1290</ref>
      <ref url="http://www.securitytracker.com/id?1022205" source="SECTRACK">1022205</ref>
      <ref url="http://www.securityfocus.com/bid/34880" source="BID">34880</ref>
      <ref url="http://secunia.com/advisories/32428" source="SECUNIA">32428</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5526" source="OVAL">oval:org.mitre.oval:def:5526</ref>
      <ref url="http://osvdb.org/54388" source="OSVDB">54388</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="office_powerpoint">
        <vers num="2002" edition="sp3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0226" published="2009-05-12" name="CVE-2009-0226" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Stack-based buffer overflow in the PowerPoint 4.2 conversion filter in Microsoft Office PowerPoint 2000 SP3, 2002 SP3, and 2003 SP3 allows remote attackers to execute arbitrary code via a long string in sound data in a file that uses a PowerPoint 4.0 native file format, leading to memory corruption, aka "Legacy File Format Vulnerability," a different vulnerability than CVE-2009-0222, CVE-2009-0223, CVE-2009-0227, and CVE-2009-1137.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-132A.html" source="CERT">TA09-132A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS09-017.mspx" source="MS" patch="1" adv="1">MS09-017</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1290" source="VUPEN" adv="1">ADV-2009-1290</ref>
      <ref url="http://www.securitytracker.com/id?1022205" source="SECTRACK">1022205</ref>
      <ref url="http://www.securityfocus.com/bid/34881" source="BID">34881</ref>
      <ref url="http://secunia.com/advisories/32428" source="SECUNIA" adv="1">32428</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6106" source="OVAL">oval:org.mitre.oval:def:6106</ref>
      <ref url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=789" source="IDEFENSE">20090512 Microsoft PowerPoint 4.2 Conversion Filter Stack Overflow</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="office_powerpoint">
        <vers num="2000" edition="sp3" />
        <vers num="2002" edition="sp3" />
        <vers num="2003" edition="sp3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0227" published="2009-05-12" name="CVE-2009-0227" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Stack-based buffer overflow in the PowerPoint 4.2 conversion filter (PP4X32.DLL) in Microsoft Office PowerPoint 2000 SP3, 2002 SP3, and 2003 SP3 allows remote attackers to execute arbitrary code via a large number of structures in sound data in a file that uses a PowerPoint 4.0 native file format, leading to memory corruption, aka "Legacy File Format Vulnerability," a different vulnerability than CVE-2009-0222, CVE-2009-0223, CVE-2009-0226, and CVE-2009-1137.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-132A.html" source="CERT">TA09-132A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS09-017.mspx" source="MS" patch="1" adv="1">MS09-017</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1290" source="VUPEN" adv="1">ADV-2009-1290</ref>
      <ref url="http://www.securitytracker.com/id?1022205" source="SECTRACK">1022205</ref>
      <ref url="http://www.securityfocus.com/bid/34882" source="BID">34882</ref>
      <ref url="http://secunia.com/advisories/32428" source="SECUNIA" adv="1">32428</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6239" source="OVAL">oval:org.mitre.oval:def:6239</ref>
      <ref url="http://osvdb.org/54384" source="OSVDB">54384</ref>
      <ref url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=787" source="IDEFENSE">20090512 Microsoft PowerPoint 4.2 Conversion Filter Stack Buffer Overflow Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="office_powerpoint">
        <vers num="2000" edition="sp3" />
        <vers num="2002" edition="sp3" />
        <vers num="2003" edition="sp3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0228" published="2009-06-10" name="CVE-2009-0228" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Stack-based buffer overflow in the EnumeratePrintShares function in Windows Print Spooler Service (win32spl.dll) in Microsoft Windows 2000 SP4 allows remote printer servers to execute arbitrary code via a a crafted ShareName in a response to an RPC request, related to "printing data structures," aka "Buffer Overflow in Print Spooler Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-160A.html" source="CERT">TA09-160A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS09-022.mspx" source="MS" patch="1" adv="1">MS09-022</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1541" source="VUPEN">ADV-2009-1541</ref>
      <ref url="http://www.securitytracker.com/id?1022352" source="SECTRACK">1022352</ref>
      <ref url="http://www.securityfocus.com/bid/35206" source="BID">35206</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2009-217.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2009-217.htm</ref>
      <ref url="http://secunia.com/advisories/35365" source="SECUNIA">35365</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6317" source="OVAL">oval:org.mitre.oval:def:6317</ref>
      <ref url="http://osvdb.org/54932" source="OSVDB">54932</ref>
      <ref url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=806" source="IDEFENSE">20090609 Microsoft Windows 2000 Print Spooler Remote Stack Buffer Overflow Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition="sp4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0229" published="2009-06-10" name="CVE-2009-0229" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:N/A:N)" CVSS_score="4.9" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="3.9" CVSS_base_score="4.9">
    <desc>
      <descript source="cve">The Windows Printing Service in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 SP2 allows local users to read arbitrary files via a crafted separator page, aka "Print Spooler Read File Vulnerability."</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-160A.html" source="CERT">TA09-160A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS09-022.mspx" source="MS" patch="1" adv="1">MS09-022</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1541" source="VUPEN">ADV-2009-1541</ref>
      <ref url="http://www.securitytracker.com/id?1022352" source="SECTRACK">1022352</ref>
      <ref url="http://www.securityfocus.com/bid/35208" source="BID">35208</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2009-217.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2009-217.htm</ref>
      <ref url="http://secunia.com/advisories/35365" source="SECUNIA">35365</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5815" source="OVAL">oval:org.mitre.oval:def:5815</ref>
      <ref url="http://osvdb.org/54933" source="OSVDB">54933</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="sp4" />
      </prod>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="sp2" edition="" />
        <vers num="sp2" edition=":itanium" />
        <vers num="sp2" edition=":x64" />
      </prod>
      <prod vendor="microsoft" name="windows_server_2008">
        <vers num="" edition=":x64" />
        <vers num="-" edition="sp2" />
        <vers num="-" edition="sp2:itanium" />
        <vers num="-" edition="x32" />
        <vers num="sp2" edition="x32" />
        <vers num="sp2" edition="x64" />
      </prod>
      <prod vendor="microsoft" name="windows_vista">
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:x64" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:x64" />
        <vers num="gold" />
        <vers num="sp1" />
        <vers num="sp2" />
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="-" edition="sp2" />
        <vers num="-" edition="sp2:x64" />
        <vers num="sp2" />
        <vers num="sp3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0230" published="2009-06-10" name="CVE-2009-0230" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:C/I:C/A:C)" CVSS_score="9.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.0" CVSS_base_score="9.0">
    <desc>
      <descript source="cve">The Windows Print Spooler in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 SP2 allows remote authenticated users to gain privileges via a crafted RPC message that triggers loading of a DLL file from an arbitrary directory, aka "Print Spooler Load Library Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-160A.html" source="CERT">TA09-160A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS09-022.mspx" source="MS" patch="1" adv="1">MS09-022</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1541" source="VUPEN">ADV-2009-1541</ref>
      <ref url="http://www.securitytracker.com/id?1022352" source="SECTRACK">1022352</ref>
      <ref url="http://www.securityfocus.com/bid/35209" source="BID">35209</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2009-217.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2009-217.htm</ref>
      <ref url="http://secunia.com/advisories/35365" source="SECUNIA">35365</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6287" source="OVAL">oval:org.mitre.oval:def:6287</ref>
      <ref url="http://osvdb.org/54934" source="OSVDB">54934</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition="sp4" />
      </prod>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:itanium" />
        <vers num="" edition="sp2:x64" />
      </prod>
      <prod vendor="microsoft" name="windows_server">
        <vers num="2008" edition="" />
        <vers num="2008" edition=":" />
        <vers num="2008" edition="::itanium" />
        <vers num="2008" edition=":sp2" />
        <vers num="2008" edition=":sp2:itanium" />
      </prod>
      <prod vendor="microsoft" name="windows_server_2008">
        <vers num="" edition=":x64" />
        <vers num="" edition=":x32" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:x32" />
        <vers num="-" edition="sp2" />
        <vers num="-" edition="sp2:x64" />
      </prod>
      <prod vendor="microsoft" name="windows_vista">
        <vers num="" edition=":x64" />
        <vers num="" edition="sp1" />
        <vers num="" edition="sp2" />
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:x64" />
        <vers num="" edition="sp3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0231" published="2009-07-15" name="CVE-2009-0231" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">The Embedded OpenType (EOT) Font Engine (T2EMBED.DLL) in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 allows remote attackers to execute arbitrary code via a crafted name table in a data record that triggers an integer truncation and a heap-based buffer overflow, aka "Embedded OpenType Font Heap Overflow Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-195A.html" source="CERT">TA09-195A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS09-029.mspx" source="MS" patch="1" adv="1">MS09-029</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1887" source="VUPEN" adv="1">ADV-2009-1887</ref>
      <ref url="http://www.securitytracker.com/id?1022543" source="SECTRACK">1022543</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5457" source="OVAL">oval:org.mitre.oval:def:5457</ref>
      <ref url="http://osvdb.org/55842" source="OSVDB">55842</ref>
      <ref url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=811" source="IDEFENSE">20090714 Microsoft Embedded OpenType Font Engine (T2EMBED.DLL) Heap Buffer Overflow Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition="sp4" />
      </prod>
      <prod vendor="microsoft" name="windows_server_2003">
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:itanium" />
        <vers num="" edition="sp2:x64" />
      </prod>
      <prod vendor="microsoft" name="windows_server_2008">
        <vers num="" edition=":itanium" />
        <vers num="" edition=":x64" />
        <vers num="" edition=":x32" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:x64" />
        <vers num="" edition="sp2:x32" />
        <vers num="-" edition="sp2" />
        <vers num="-" edition="sp2:itanium" />
      </prod>
      <prod vendor="microsoft" name="windows_vista">
        <vers num="" edition=":x64" />
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:x64" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:x64" />
        <vers num="-" edition="sp1" />
        <vers num="-" edition="sp2" />
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:professional_x64" />
        <vers num="" edition="sp3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0232" published="2009-07-15" name="CVE-2009-0232" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Integer overflow in the Embedded OpenType (EOT) Font Engine in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 allows remote attackers to execute arbitrary code via a crafted name table, aka "Embedded OpenType Font Integer Overflow Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-195A.html" source="CERT">TA09-195A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS09-029.mspx" source="MS" patch="1" adv="1">MS09-029</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1887" source="VUPEN">ADV-2009-1887</ref>
      <ref url="http://www.securitytracker.com/id?1022543" source="SECTRACK">1022543</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5678" source="OVAL">oval:org.mitre.oval:def:5678</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition="sp4" />
      </prod>
      <prod vendor="microsoft" name="windows_server_2003">
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:itanium" />
        <vers num="" edition="sp2:x64" />
      </prod>
      <prod vendor="microsoft" name="windows_server_2008">
        <vers num="" edition=":itanium" />
        <vers num="" edition=":x64" />
        <vers num="" edition=":x32" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:x64" />
        <vers num="" edition="sp2:x32" />
        <vers num="-" edition="sp2" />
        <vers num="-" edition="sp2:itanium" />
      </prod>
      <prod vendor="microsoft" name="windows_vista">
        <vers num="" edition=":x64" />
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:x64" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:x64" />
        <vers num="-" edition="sp1" />
        <vers num="-" edition="sp2" />
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:professional_x64" />
        <vers num="" edition="sp3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0233" published="2009-03-11" name="CVE-2009-0233" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:P)" CVSS_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_base_score="5.8">
    <desc>
      <descript source="cve">The DNS Resolver Cache Service (aka DNSCache) in Windows DNS Server in Microsoft Windows 2000 SP4, Server 2003 SP1 and SP2, and Server 2008, when dynamic updates are enabled, does not reuse cached DNS responses in all applicable situations, which makes it easier for remote attackers to predict transaction IDs and poison caches by simultaneously sending crafted DNS queries and responses, aka "DNS Server Query Validation Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-069A.html" source="CERT">TA09-069A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS09-008.mspx" source="MS" patch="1" adv="1">MS09-008</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0661" source="VUPEN">ADV-2009-0661</ref>
      <ref url="http://www.securitytracker.com/id?1021831" source="SECTRACK">1021831</ref>
      <ref url="http://www.securityfocus.com/bid/33982" source="BID">33982</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2009-083.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2009-083.htm</ref>
      <ref url="http://secunia.com/advisories/34217" source="SECUNIA">34217</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6228" source="OVAL">oval:org.mitre.oval:def:6228</ref>
      <ref url="http://osvdb.org/52517" source="OSVDB">52517</ref>
      <ref url="http://blogs.technet.com/srd/archive/2009/03/13/ms09-008-dns-and-wins-server-security-update-in-more-detail.aspx" source="CONFIRM">http://blogs.technet.com/srd/archive/2009/03/13/ms09-008-dns-and-wins-server-security-update-in-more-detail.aspx</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition="sp4" />
      </prod>
      <prod vendor="microsoft" name="windows_server_2003">
        <vers num="" edition=":x64" />
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:itanium" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:itanium" />
        <vers num="" edition="sp2:x64" />
      </prod>
      <prod vendor="microsoft" name="windows_server_2008">
        <vers num="" edition=":x64" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0234" published="2009-03-11" name="CVE-2009-0234" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:P)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">The DNS Resolver Cache Service (aka DNSCache) in Windows DNS Server in Microsoft Windows 2000 SP4, Server 2003 SP1 and SP2, and Server 2008 does not properly cache crafted DNS responses, which makes it easier for remote attackers to predict transaction IDs and poison caches by sending many crafted DNS queries that trigger "unnecessary lookups," aka "DNS Server Response Validation Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-069A.html" source="CERT">TA09-069A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/319331" source="CERT-VN">VU#319331</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS09-008.mspx" source="MS" patch="1" adv="1">MS09-008</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0661" source="VUPEN">ADV-2009-0661</ref>
      <ref url="http://www.securitytracker.com/id?1021831" source="SECTRACK">1021831</ref>
      <ref url="http://www.securityfocus.com/bid/33988" source="BID">33988</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2009-083.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2009-083.htm</ref>
      <ref url="http://secunia.com/advisories/34217" source="SECUNIA">34217</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5715" source="OVAL">oval:org.mitre.oval:def:5715</ref>
      <ref url="http://osvdb.org/52518" source="OSVDB">52518</ref>
      <ref url="http://blogs.technet.com/srd/archive/2009/03/13/ms09-008-dns-and-wins-server-security-update-in-more-detail.aspx" source="CONFIRM">http://blogs.technet.com/srd/archive/2009/03/13/ms09-008-dns-and-wins-server-security-update-in-more-detail.aspx</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition="sp4" />
      </prod>
      <prod vendor="microsoft" name="windows_server_2003">
        <vers num="" edition=":x64" />
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:itanium" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:itanium" />
        <vers num="" edition="sp2:x64" />
      </prod>
      <prod vendor="microsoft" name="windows_server_2008">
        <vers num="" edition=":x64" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0235" published="2009-04-15" name="CVE-2009-0235" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Stack-based buffer overflow in the Word 97 text converter in WordPad in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP1 and SP2 allows remote attackers to execute arbitrary code via a crafted Word 97 file that triggers memory corruption, related to use of inconsistent integer data sizes for an unspecified length field, aka "WordPad Word 97 Text Converter Stack Overflow Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-104A.html" source="CERT">TA09-104A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS09-010.mspx" source="MS" patch="1" adv="1">MS09-010</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1024" source="VUPEN">ADV-2009-1024</ref>
      <ref url="http://www.securitytracker.com/id?1022043" source="SECTRACK">1022043</ref>
      <ref url="http://www.securityfocus.com/bid/34470" source="BID">34470</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5893" source="OVAL">oval:org.mitre.oval:def:5893</ref>
      <ref url="http://osvdb.org/53664" source="OSVDB">53664</ref>
      <ref url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=783" source="IDEFENSE">20090414 Microsoft WordPad Word97 Converter Stack Buffer Overflow Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition="sp4" />
      </prod>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="" edition="sp1" />
        <vers num="" edition="sp2" />
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition="sp2" />
        <vers num="" edition="sp3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0237" published="2009-04-15" name="CVE-2009-0237" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in cookieauth.dll in the HTML forms authentication component in Microsoft Forefront Threat Management Gateway, Medium Business Edition (TMG MBE); and Internet Security and Acceleration (ISA) Server 2006, 2006 Supportability Update, and 2006 SP1; allows remote attackers to inject arbitrary web script or HTML via "authentication input" to this component, aka "Cross-Site Scripting Vulnerability."</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-104A.html" source="CERT">TA09-104A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS09-016.mspx" source="MS" patch="1" adv="1">MS09-016</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1030" source="VUPEN">ADV-2009-1030</ref>
      <ref url="http://www.securitytracker.com/id?1022046" source="SECTRACK">1022046</ref>
      <ref url="http://secunia.com/advisories/34687" source="SECUNIA">34687</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5771" source="OVAL">oval:org.mitre.oval:def:5771</ref>
      <ref url="http://osvdb.org/53637" source="OSVDB">53637</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="forefront_threat_management_gateway">
        <vers num="-" edition="-" />
        <vers num="-" edition="-:medium_business" />
      </prod>
      <prod vendor="microsoft" name="internet_security_and_acceleration_server">
        <vers num="2004" edition="sp3" />
        <vers num="2004" edition="sp3:enterprise" />
        <vers num="2004" edition="sp3:standard" />
        <vers num="2006" edition="sp1" />
        <vers num="2006" edition="supportability" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0238" published="2009-02-25" name="CVE-2009-0238" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Microsoft Office Excel 2000 SP3, 2002 SP3, 2003 SP3, and 2007 SP1; Excel Viewer 2003 Gold and SP3; Excel Viewer; Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1; and Excel in Microsoft Office 2004 and 2008 for Mac allow remote attackers to execute arbitrary code via a crafted Excel document that triggers an access attempt on an invalid object, as exploited in the wild in February 2009 by Trojan.Mdropper.AC.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-104A.html" source="CERT">TA09-104A</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/48875" source="XF">ms-excel-unspecified-code-execution(48875)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1023" source="VUPEN">ADV-2009-1023</ref>
      <ref url="http://www.symantec.com/business/security_response/writeup.jsp?docid=2009-022310-4202-99" source="MISC">http://www.symantec.com/business/security_response/writeup.jsp?docid=2009-022310-4202-99</ref>
      <ref url="http://www.securityfocus.com/bid/33870" source="BID">33870</ref>
      <ref url="http://www.microsoft.com/technet/security/bulletin/ms09-009.mspx" source="MS">MS09-009</ref>
      <ref url="http://www.microsoft.com/technet/security/advisory/968272.mspx" source="CONFIRM" adv="1">http://www.microsoft.com/technet/security/advisory/968272.mspx</ref>
      <ref url="http://securitytracker.com/id?1021744" source="SECTRACK">1021744</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5968" source="OVAL">oval:org.mitre.oval:def:5968</ref>
      <ref url="http://isc.sans.org/diary.html?storyid=5923" source="MISC">http://isc.sans.org/diary.html?storyid=5923</ref>
      <ref url="http://blogs.zdnet.com/security/?p=2658" source="MISC">http://blogs.zdnet.com/security/?p=2658</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="excel">
        <vers num="2004" edition="" />
        <vers num="2004" edition=":mac" />
      </prod>
      <prod vendor="microsoft" name="excel_viewer">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="office">
        <vers num="2008" edition="" />
        <vers num="2008" edition=":mac" />
      </prod>
      <prod vendor="microsoft" name="office_compatibility_pack">
        <vers num="2007" edition="sp1" />
      </prod>
      <prod vendor="microsoft" name="office_excel">
        <vers num="2000" edition="sp3" />
        <vers num="2002" edition="sp3" />
        <vers num="2003" edition="sp3" />
        <vers num="2007" edition="sp1" />
      </prod>
      <prod vendor="microsoft" name="office_excel_viewer">
        <vers num="2003" edition="gold" />
        <vers num="2003" edition="sp3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0239" published="2009-06-10" name="CVE-2009-0239" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Windows Search 4.0 for Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 allows user-assisted remote attackers to inject arbitrary web script or HTML via a crafted file that appears in a preview in a search result, aka "Script Execution in Windows Search Vulnerability."</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-160A.html" source="CERT">TA09-160A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS09-023.mspx" source="MS" patch="1" adv="1">MS09-023</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1542" source="VUPEN">ADV-2009-1542</ref>
      <ref url="http://www.securitytracker.com/id?1022353" source="SECTRACK">1022353</ref>
      <ref url="http://secunia.com/advisories/35366" source="SECUNIA">35366</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5428" source="OVAL">oval:org.mitre.oval:def:5428</ref>
      <ref url="http://osvdb.org/54935" source="OSVDB">54935</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_search">
        <vers num="4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2009-0240" published="2009-01-20" name="CVE-2009-0240" modified="2011-09-12" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:S/C:P/I:N/A:N)" CVSS_score="3.5" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="6.8" CVSS_base_score="3.5">
    <desc>
      <descript source="cve">listing.php in WebSVN 2.0 and possibly 1.7 beta, when using an SVN authz file, allows remote authenticated users to read changelogs or diffs for restricted projects via a modified repname parameter.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/48171" source="XF">websvn-listing-information-disclosure(48171)</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2009/01/18/2" source="MLIST">[oss-security] 20090118 CVE request: WebSVN</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200903-20.xml" source="GENTOO">GLSA-200903-20</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1725" source="DEBIAN">DSA-1725</ref>
      <ref url="http://secunia.com/advisories/34191" source="SECUNIA">34191</ref>
      <ref url="http://secunia.com/advisories/33945" source="SECUNIA">33945</ref>
      <ref url="http://secunia.com/advisories/32338" source="SECUNIA" adv="1">32338</ref>
      <ref url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=512191" source="CONFIRM">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=512191</ref>
    </refs>
    <vuln_soft>
      <prod vendor="tigris" name="websvn">
        <vers num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0241" published="2009-01-21" name="CVE-2009-0241" modified="2009-06-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Stack-based buffer overflow in the process_path function in gmetad/server.c in Ganglia 3.1.1 allows remote attackers to cause a denial of service (crash) via a request to the gmetad service with a long pathname.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/33299" source="BID">33299</ref>
      <ref url="http://www.mail-archive.com/ganglia-developers@lists.sourceforge.net/msg04929.html" source="MLIST">[Ganglia-developers] 20090113 patches for: [Sec] Gmetad server BoF and network overload + [Feature] multiple requests per conn on interactive port</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200903-22.xml" source="GENTOO">GLSA-200903-22</ref>
      <ref url="http://secunia.com/advisories/35416" source="SECUNIA">35416</ref>
      <ref url="http://secunia.com/advisories/34228" source="SECUNIA">34228</ref>
      <ref url="http://secunia.com/advisories/33506" source="SECUNIA" adv="1">33506</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-06/msg00003.html" source="SUSE">SUSE-SR:2009:011</ref>
      <ref url="http://bugzilla.ganglia.info/cgi-bin/bugzilla/show_bug.cgi?id=223" source="MISC">http://bugzilla.ganglia.info/cgi-bin/bugzilla/show_bug.cgi?id=223</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ganglia" name="ganglia">
        <vers num="3.1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" seq="2009-0242" reject="1" published="2009-01-21" name="CVE-2009-0242" modified="2009-02-05">
    <desc>
      <descript source="cve">** REJECT **  gmetad in Ganglia 3.1.1, when supporting multiple requests per connection on an interactive port, allows remote attackers to cause a denial of service via a request to the gmetad service with a path does not exist, which causes Ganglia to (1) perform excessive CPU computation and (2) send the entire tree, which consumes network bandwidth.  NOTE: the vendor and original researcher have disputed this issue, since legitimate requests can generate the same amount of resource consumption.  CVE concurs with the dispute, so this identifier should not be used.</descript>
    </desc>
    <refs />
  </entry>
  <entry type="CVE" severity="High" seq="2009-0243" published="2009-01-21" name="CVE-2009-0243" modified="2009-01-29" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Microsoft Windows does not properly enforce the Autorun and NoDriveTypeAutoRun registry values, which allows physically proximate attackers to execute arbitrary code by (1) inserting CD-ROM media, (2) inserting DVD media, (3) connecting a USB device, and (4) connecting a Firewire device; (5) allows user-assisted remote attackers to execute arbitrary code by mapping a network drive; and allows user-assisted attackers to execute arbitrary code by clicking on (6) an icon under My Computer\Devices with Removable Storage and (7) an option in an AutoPlay dialog, related to the Autorun.inf file.  NOTE: vectors 1 and 3 on Vista are already covered by CVE-2008-0951.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-020A.html" source="CERT">TA09-020A</ref>
      <ref url="http://www.securitytracker.com/id?1021629" source="SECTRACK">1021629</ref>
      <ref url="http://isc.sans.org/diary.html?storyid=5695" source="MISC">http://isc.sans.org/diary.html?storyid=5695</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition="sp4" />
      </prod>
      <prod vendor="microsoft" name="windows_server_2003">
        <vers num="" edition=":x64" />
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:itanium" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:itanium" />
        <vers num="" edition="sp2:x64" />
      </prod>
      <prod vendor="microsoft" name="windows_server_2008">
        <vers num="" edition=":itanium" />
        <vers num="" edition=":x64" />
        <vers num="" edition=":x32" />
      </prod>
      <prod vendor="microsoft" name="windows_vista">
        <vers num="" edition=":x64" />
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:x64" />
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition=":professional_x64" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:professional_x64" />
        <vers num="" edition="sp3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0244" published="2009-01-21" name="CVE-2009-0244" modified="2009-02-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:S/C:C/I:C/A:C)" CVSS_score="8.5" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="6.8" CVSS_base_score="8.5">
    <desc>
      <descript source="cve">Directory traversal vulnerability in the OBEX FTP Service in the Microsoft Bluetooth stack in Windows Mobile 6 Professional, and probably Windows Mobile 5.0 for Pocket PC and 5.0 for Pocket PC Phone Edition, allows remote authenticated users to list arbitrary directories, and create or read arbitrary files, via a .. (dot dot) in a pathname.  NOTE: this can be leveraged for code execution by writing to a Startup folder.</descript>
    </desc>
    <impacts>
      <impact source="nvd">per: http://www.seguridadmobile.com/windows-mobile/windows-mobile-security/Microsoft-Bluetooth-Stack-Directory-Traversal.html

"Non vulnerable products: Windows Mobile devices 5.0 and 6 not using Microsoft Bluetooth Stack (for example: ASUS P525, ASUS P535, ... using Widcomm/Broadcom Bluetooth Stack)"</impact>
    </impacts>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/48124" source="XF">winmobile-obexftp-directory-traversal(48124)</ref>
      <ref url="http://www.seguridadmobile.com/windows-mobile/windows-mobile-security/Microsoft-Bluetooth-Stack-Directory-Traversal.html" source="MISC">http://www.seguridadmobile.com/windows-mobile/windows-mobile-security/Microsoft-Bluetooth-Stack-Directory-Traversal.html</ref>
      <ref url="http://www.securityfocus.com/bid/33359" source="BID">33359</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/500199/100/0/threaded" source="BUGTRAQ">20090119 Microsoft Bluetooth Stack OBEX Directory Traversal</ref>
      <ref url="http://securityreason.com/securityalert/4938" source="SREASON">4938</ref>
      <ref url="http://secunia.com/advisories/33598" source="SECUNIA">33598</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_mobile">
        <vers num="5.0" edition="" />
        <vers num="5.0" edition=":pocket_pc" />
        <vers num="5.0" edition=":smartphone" />
        <vers num="6.0" edition="" />
        <vers num="6.0" edition=":standard" />
        <vers num="6.0" edition=":pro" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0245" published="2009-01-21" name="CVE-2009-0245" modified="2009-01-22" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Usagi Project MyNETS 1.2.0.1 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different issue than CVE-2008-4629.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://usagi-project.org/PRESS/archives/57" source="CONFIRM" patch="1" adv="1">http://usagi-project.org/PRESS/archives/57</ref>
      <ref url="http://www.securityfocus.com/bid/33145" source="BID">33145</ref>
      <ref url="http://secunia.com/advisories/33409" source="SECUNIA" adv="1">33409</ref>
      <ref url="http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-000001.html" source="JVNDB">JVNDB-2009-000001</ref>
      <ref url="http://jvn.jp/en/jp/JVN36802959/index.html" source="JVN">JVN#36802959</ref>
    </refs>
    <vuln_soft>
      <prod vendor="usagi" name="mynets">
        <vers num="1.0.0" />
        <vers num="1.0.1" />
        <vers num="1.1.0" />
        <vers num="1.2.0" />
        <vers prev="1" num="1.2.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0246" published="2009-01-22" name="CVE-2009-0246" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Stack-based buffer overflow in easyHDR PRO 1.60.2 allows user-assisted attackers to execute arbitrary code via an invalid Radiance RGBE (aka .hdr) file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/48119" source="XF">easyhdrpro-hdr-bo(48119)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0190" source="VUPEN">ADV-2009-0190</ref>
      <ref url="http://www.securityfocus.com/bid/33363" source="BID">33363</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/500192/100/0/threaded" source="BUGTRAQ">20090120 Secunia Research: EasyHDR Pro Radiance RGBE Buffer Overflow</ref>
      <ref url="http://securityreason.com/securityalert/4941" source="SREASON">4941</ref>
      <ref url="http://secunia.com/secunia_research/2008-61/" source="MISC" adv="1">http://secunia.com/secunia_research/2008-61/</ref>
      <ref url="http://secunia.com/advisories/33468" source="SECUNIA" adv="1">33468</ref>
      <ref url="http://osvdb.org/51609" source="OSVDB">51609</ref>
      <ref url="http://easyhdr.com/version.php" source="CONFIRM" adv="1">http://easyhdr.com/version.php</ref>
    </refs>
    <vuln_soft>
      <prod vendor="easyhdr" name="easyhdr">
        <vers num="1.60.2" edition="" />
        <vers num="1.60.2" edition=":pro" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0247" published="2009-01-22" name="CVE-2009-0247" modified="2009-01-22" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">The server for 53KF Web IM 2009 Home, Professional, and Enterprise editions relies on client-side protection mechanisms against cross-site scripting (XSS), which allows remote attackers to conduct XSS attacks by using a modified client to send a crafted IM message, related to the msg variable.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/48096" source="XF">53kfwebim-msg-xss(48096)</ref>
      <ref url="http://www.securityfocus.com/bid/33341" source="BID">33341</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/500169/100/0/threaded" source="BUGTRAQ">20090119 53KF Web IM 2009 Cross-Site Scripting Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="53kf" name="web_im_2009">
        <vers num="_nil_" edition="enterprise" />
        <vers num="_nil_" edition="home" />
        <vers num="_nil_" edition="professional" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0248" published="2009-01-22" name="CVE-2009-0248" modified="2009-01-22" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in rankup.asp in Katy Whitton RankEm allows remote attackers to inject arbitrary web script or HTML via the siteID parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/48072" source="XF">rankem-siteid-xss(48072)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/48071" source="XF">rankem-rankup-xss(48071)</ref>
      <ref url="http://www.securityfocus.com/bid/33324" source="BID">33324</ref>
      <ref url="http://www.milw0rm.com/exploits/7805" source="MILW0RM">7805</ref>
    </refs>
    <vuln_soft>
      <prod vendor="katywhitton" name="rankem">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0249" published="2009-01-22" name="CVE-2009-0249" modified="2009-01-22" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Katy Whitton RankEm stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing credentials via a direct request for database/topsites.mdb.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/48070" source="XF">rankem-topsites-information-disclosure(48070)</ref>
      <ref url="http://www.milw0rm.com/exploits/7805" source="MILW0RM">7805</ref>
    </refs>
    <vuln_soft>
      <prod vendor="katywhitton" name="rankem">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0250" published="2009-01-22" name="CVE-2009-0250" modified="2009-01-29" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Ryneezy phoSheezy 0.2 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the file containing the administrator's password hash via a direct request for config/password.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/48056" source="XF">phosheezy-configpassword-info-disclosure(48056)</ref>
      <ref url="http://www.milw0rm.com/exploits/7780" source="MILW0RM">7780</ref>
      <ref url="http://securityreason.com/securityalert/4935" source="SREASON">4935</ref>
      <ref url="http://secunia.com/advisories/33531" source="SECUNIA" adv="1">33531</ref>
      <ref url="http://osvdb.org/51411" source="OSVDB">51411</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ryneezy" name="phosheezy">
        <vers num="0.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0251" published="2009-01-22" name="CVE-2009-0251" modified="2009-01-29" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)" CVSS_score="6.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.0" CVSS_base_score="6.5">
    <desc>
      <descript source="cve">Static code injection vulnerability in admin.php in Ryneezy phoSheezy 0.2 allows remote authenticated administrators to inject arbitrary PHP code into config/footer via the footer parameter.  NOTE: this can be exploited by unauthenticated attackers by leveraging CVE-2009-0250. NOTE: some of these details are obtained from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.milw0rm.com/exploits/7780" source="MILW0RM">7780</ref>
      <ref url="http://securityreason.com/securityalert/4935" source="SREASON">4935</ref>
      <ref url="http://secunia.com/advisories/33531" source="SECUNIA" adv="1">33531</ref>
      <ref url="http://osvdb.org/51412" source="OSVDB">51412</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ryneezy" name="phosheezy">
        <vers num="0.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0252" published="2009-01-22" name="CVE-2009-0252" modified="2009-02-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in default.asp in Enthrallweb eReservations allow remote attackers to execute arbitrary SQL commands via the (1) Login parameter (aka username field) or the (2) Password parameter (aka password field).  NOTE: some of these details are obtained from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/48062" source="XF">ereservations-login-sql-injection(48062)</ref>
      <ref url="http://www.securityfocus.com/bid/33321" source="BID">33321</ref>
      <ref url="http://www.milw0rm.com/exploits/7801" source="MILW0RM">7801</ref>
      <ref url="http://secunia.com/advisories/33578" source="SECUNIA" adv="1">33578</ref>
      <ref url="http://osvdb.org/51456" source="OSVDB">51456</ref>
    </refs>
    <vuln_soft>
      <prod vendor="enthrallweb" name="ereservations">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0253" published="2009-01-22" name="CVE-2009-0253" modified="2009-01-29" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Mozilla Firefox 3.0.5 allows remote attackers to trick a user into visiting an arbitrary URL via an onclick action that moves a crafted element to the current mouse position, related to a "Status Bar Obfuscation" and "Clickjacking" attack.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/48212" source="XF">firefox-onclickaction-click-hijacking(48212)</ref>
      <ref url="http://www.milw0rm.com/exploits/7842" source="MILW0RM">7842</ref>
      <ref url="http://securityreason.com/securityalert/4936" source="SREASON">4936</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="3.0.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0254" published="2009-01-22" name="CVE-2009-0254" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Stack-based buffer overflow in easyHDR PRO 1.60.2 allows user-assisted attackers to execute arbitrary code via an invalid Flexible Image Transport System (FITS) file.  NOTE: some of these details are obtained from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2009/0190" source="VUPEN">ADV-2009-0190</ref>
      <ref url="http://www.securityfocus.com/bid/33363" source="BID">33363</ref>
      <ref url="http://secunia.com/advisories/33468" source="SECUNIA" adv="1">33468</ref>
      <ref url="http://osvdb.org/51608" source="OSVDB">51608</ref>
      <ref url="http://easyhdr.com/version.php" source="CONFIRM" adv="1">http://easyhdr.com/version.php</ref>
    </refs>
    <vuln_soft>
      <prod vendor="easyhdr" name="easyhdr">
        <vers num="1.60.2" edition="" />
        <vers num="1.60.2" edition=":pro" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0255" published="2009-01-22" name="CVE-2009-0255" modified="2009-01-29" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The System extension Install tool in TYPO3 4.0.0 through 4.0.9, 4.1.0 through 4.1.7, and 4.2.0 through 4.2.3 creates the encryption key with an insufficiently random seed, which makes it easier for attackers to crack the key.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/48132" source="XF">typo3-installtool-weak-security(48132)</ref>
      <ref url="http://www.securityfocus.com/bid/33376" source="BID">33376</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1711" source="DEBIAN">DSA-1711</ref>
      <ref url="http://typo3.org/teams/security/security-bulletins/typo3-sa-2009-001/" source="CONFIRM" adv="1">http://typo3.org/teams/security/security-bulletins/typo3-sa-2009-001/</ref>
      <ref url="http://secunia.com/advisories/33679" source="SECUNIA" adv="1">33679</ref>
      <ref url="http://secunia.com/advisories/33617" source="SECUNIA" adv="1">33617</ref>
    </refs>
    <vuln_soft>
      <prod vendor="typo3" name="typo3">
        <vers num="4.0" />
        <vers num="4.0.1" />
        <vers num="4.0.2" />
        <vers num="4.0.3" />
        <vers num="4.0.4" />
        <vers num="4.0.5" />
        <vers num="4.0.6" />
        <vers num="4.0.7" />
        <vers num="4.0.8" />
        <vers num="4.0.9" />
        <vers num="4.1.0" edition="beta1" />
        <vers num="4.1.0" edition="rc1" />
        <vers num="4.1.1" />
        <vers num="4.1.2" />
        <vers num="4.1.3" />
        <vers num="4.1.4" />
        <vers num="4.1.5" />
        <vers num="4.1.6" />
        <vers num="4.1.7" />
        <vers num="4.2.0" />
        <vers num="4.2.1" />
        <vers num="4.2.2" />
        <vers num="4.2.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0256" published="2009-01-22" name="CVE-2009-0256" modified="2009-01-29" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Session fixation vulnerability in the authentication library in TYPO3 4.0.0 through 4.0.9, 4.1.0 through 4.1.7, and 4.2.0 through 4.2.3 allows remote attackers to hijack web sessions via unspecified vectors related to (1) frontend and (2) backend authentication.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/48133" source="XF">typo3-library-session-hijacking(48133)</ref>
      <ref url="http://www.securityfocus.com/bid/33376" source="BID">33376</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1711" source="DEBIAN">DSA-1711</ref>
      <ref url="http://typo3.org/teams/security/security-bulletins/typo3-sa-2009-001/" source="CONFIRM" adv="1">http://typo3.org/teams/security/security-bulletins/typo3-sa-2009-001/</ref>
      <ref url="http://secunia.com/advisories/33679" source="SECUNIA">33679</ref>
      <ref url="http://secunia.com/advisories/33617" source="SECUNIA" adv="1">33617</ref>
    </refs>
    <vuln_soft>
      <prod vendor="typo3" name="typo3">
        <vers num="4.0" />
        <vers num="4.0.1" />
        <vers num="4.0.2" />
        <vers num="4.0.3" />
        <vers num="4.0.4" />
        <vers num="4.0.5" />
        <vers num="4.0.6" />
        <vers num="4.0.7" />
        <vers num="4.0.8" />
        <vers num="4.0.9" />
        <vers num="4.1.0" edition="beta1" />
        <vers num="4.1.0" edition="rc1" />
        <vers num="4.1.1" />
        <vers num="4.1.2" />
        <vers num="4.1.3" />
        <vers num="4.1.4" />
        <vers num="4.1.5" />
        <vers num="4.1.6" />
        <vers num="4.1.7" />
        <vers num="4.2.0" />
        <vers num="4.2.1" />
        <vers num="4.2.2" />
        <vers num="4.2.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0257" published="2009-01-22" name="CVE-2009-0257" modified="2009-01-29" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in TYPO3 4.0.0 through 4.0.9, 4.1.0 through 4.1.7, and 4.2.0 through 4.2.3 allow remote attackers to inject arbitrary web script or HTML via the (1) name and (2) content of indexed files to the (a) Indexed Search Engine (indexed_search) system extension; (b) unspecified test scripts in the ADOdb system extension; and (c) unspecified vectors in the Workspace module.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/48137" source="XF">typo3-adodb-xss(48137)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/48136" source="XF">typo3-workspace-xss(48136)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/48135" source="XF">typo3-indexedsearchengine-xss(48135)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/48133" source="XF">typo3-library-session-hijacking(48133)</ref>
      <ref url="http://www.securityfocus.com/bid/33376" source="BID">33376</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1711" source="DEBIAN">DSA-1711</ref>
      <ref url="http://typo3.org/teams/security/security-bulletins/typo3-sa-2009-001/" source="CONFIRM" adv="1">http://typo3.org/teams/security/security-bulletins/typo3-sa-2009-001/</ref>
      <ref url="http://secunia.com/advisories/33679" source="SECUNIA">33679</ref>
      <ref url="http://secunia.com/advisories/33617" source="SECUNIA" adv="1">33617</ref>
    </refs>
    <vuln_soft>
      <prod vendor="typo3" name="typo3">
        <vers num="4.0" />
        <vers num="4.0.1" />
        <vers num="4.0.2" />
        <vers num="4.0.3" />
        <vers num="4.0.4" />
        <vers num="4.0.5" />
        <vers num="4.0.6" />
        <vers num="4.0.7" />
        <vers num="4.0.8" />
        <vers num="4.0.9" />
        <vers num="4.1.0" edition="beta1" />
        <vers num="4.1.0" edition="rc1" />
        <vers num="4.1.1" />
        <vers num="4.1.2" />
        <vers num="4.1.3" />
        <vers num="4.1.4" />
        <vers num="4.1.5" />
        <vers num="4.1.6" />
        <vers num="4.1.7" />
        <vers num="4.2.0" />
        <vers num="4.2.1" />
        <vers num="4.2.2" />
        <vers num="4.2.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0258" published="2009-01-22" name="CVE-2009-0258" modified="2009-02-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">The Indexed Search Engine (indexed_search) system extension in TYPO3 4.0.0 through 4.0.9, 4.1.0 through 4.1.7, and 4.2.0 through 4.2.3 allows remote attackers to execute arbitrary commands via a crafted filename containing shell metacharacters, which is not properly handled by the command-line indexer.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/48138" source="XF">typo3-indexedsearch-command-execution(48138)</ref>
      <ref url="http://www.securityfocus.com/bid/33376" source="BID">33376</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2009/01/23/4" source="MLIST">[oss-security] 20090123 Re: CVE id request: typo3 SA-2009-001</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1711" source="DEBIAN">DSA-1711</ref>
      <ref url="http://typo3.org/teams/security/security-bulletins/typo3-sa-2009-001/" source="CONFIRM" adv="1">http://typo3.org/teams/security/security-bulletins/typo3-sa-2009-001/</ref>
      <ref url="http://secunia.com/advisories/33679" source="SECUNIA">33679</ref>
      <ref url="http://secunia.com/advisories/33617" source="SECUNIA" adv="1">33617</ref>
    </refs>
    <vuln_soft>
      <prod vendor="typo3" name="typo3">
        <vers num="4.0" />
        <vers num="4.0.1" />
        <vers num="4.0.2" />
        <vers num="4.0.3" />
        <vers num="4.0.4" />
        <vers num="4.0.5" />
        <vers num="4.0.6" />
        <vers num="4.0.7" />
        <vers num="4.0.8" />
        <vers num="4.0.9" />
        <vers num="4.1.0" edition="beta1" />
        <vers num="4.1.0" edition="rc1" />
        <vers num="4.1.1" />
        <vers num="4.1.2" />
        <vers num="4.1.3" />
        <vers num="4.1.4" />
        <vers num="4.1.5" />
        <vers num="4.1.6" />
        <vers num="4.1.7" />
        <vers num="4.2.0" />
        <vers num="4.2.1" />
        <vers num="4.2.2" />
        <vers num="4.2.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0259" published="2009-01-22" name="CVE-2009-0259" modified="2009-04-10" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">The Word processor in OpenOffice.org 1.1.2 through 1.1.5 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted (1) .doc, (2) .wri, or (3) .rtf Word 97 file that triggers memory corruption, as exploited in the wild in December 2008, as demonstrated by 2008-crash.doc.rar, and a similar issue to CVE-2008-4841.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/48213" source="XF">openoffice-wordprocessor-code-execution(48213)</ref>
      <ref url="http://www.securityfocus.com/bid/33383" source="BID">33383</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2009/01/21/9" source="MLIST">[oss-security] 20090121 CVE Request -- openoffice.org (CVE-2008-4841)</ref>
      <ref url="http://www.milw0rm.com/exploits/6560" source="MILW0RM">6560</ref>
      <ref url="http://milw0rm.com/sploits/2008-crash.doc.rar" source="MISC">http://milw0rm.com/sploits/2008-crash.doc.rar</ref>
    </refs>
    <vuln_soft>
      <prod vendor="openoffice" name="openoffice.org">
        <vers num="1.1.2" />
        <vers num="1.1.3" />
        <vers num="1.1.4" />
        <vers num="1.1.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0260" published="2009-01-23" name="CVE-2009-0260" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in action/AttachFile.py in MoinMoin before 1.8.1 allow remote attackers to inject arbitrary web script or HTML via an AttachFile action to the WikiSandBox component with (1) the rename parameter or (2) the drawing parameter (aka the basename variable).</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/33365" source="BID" patch="1">33365</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/48126" source="XF">moinmoin-attachfilepy-xss(48126)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0195" source="VUPEN">ADV-2009-0195</ref>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-716-1" source="UBUNTU">USN-716-1</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/500197/100/0/threaded" source="BUGTRAQ">20090120 MoinMoin Wiki Engine XSS Vulnerability</ref>
      <ref url="http://secunia.com/advisories/33755" source="SECUNIA">33755</ref>
      <ref url="http://secunia.com/advisories/33716" source="SECUNIA">33716</ref>
      <ref url="http://secunia.com/advisories/33593" source="SECUNIA" adv="1">33593</ref>
      <ref url="http://osvdb.org/51485" source="OSVDB">51485</ref>
      <ref url="http://moinmo.in/SecurityFixes#moin1.8.1" source="CONFIRM">http://moinmo.in/SecurityFixes#moin1.8.1</ref>
      <ref url="http://lists.debian.org/debian-security-announce/2009/msg00023.html" source="DEBIAN">DSA-1715</ref>
      <ref url="http://hg.moinmo.in/moin/1.8/rev/8cb4d34ccbc1" source="CONFIRM">http://hg.moinmo.in/moin/1.8/rev/8cb4d34ccbc1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="moinmoin" name="moinmoin">
        <vers num="0.1" />
        <vers num="0.10" />
        <vers num="0.11" />
        <vers num="0.2" />
        <vers num="0.3" />
        <vers num="0.7" />
        <vers num="0.8" />
        <vers num="0.9" />
        <vers num="1.0" />
        <vers num="1.1" />
        <vers num="1.2" />
        <vers num="1.2.1" />
        <vers num="1.2.2" />
        <vers num="1.5.0" />
        <vers num="1.5.1" />
        <vers num="1.5.2" />
        <vers num="1.5.3" />
        <vers num="1.5.3_rc1" />
        <vers num="1.5.3_rc2" />
        <vers num="1.5.4" />
        <vers num="1.5.5" />
        <vers num="1.5.5_rc1" />
        <vers num="1.5.5a" />
        <vers num="1.5.6" />
        <vers num="1.5.7" />
        <vers num="1.5.8" />
        <vers num="1.6" />
        <vers num="1.6.0" />
        <vers num="1.6.1" />
        <vers num="1.6.2" />
        <vers num="1.6.3" />
        <vers num="1.7.0" />
        <vers num="1.7.1" />
        <vers num="1.7.2" />
        <vers num="1.7.3" />
        <vers prev="1" num="1.8.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0261" published="2009-01-23" name="CVE-2009-0261" modified="2009-01-29" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Stack-based buffer overflow in EffectMatrix Total Video Player 1.31 allows user-assisted attackers to execute arbitrary code via a Skins\DefaultSkin\DefaultSkin.ini file with a large ColumnHeaderSpan value.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/48140" source="XF">totalvideoplayer-defaultskin-bo(48140)</ref>
      <ref url="http://www.securityfocus.com/bid/33373" source="BID">33373</ref>
      <ref url="http://www.milw0rm.com/exploits/7839" source="MILW0RM">7839</ref>
    </refs>
    <vuln_soft>
      <prod vendor="effectmatrix" name="total_video_player">
        <vers num="1.31" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0262" published="2009-01-23" name="CVE-2009-0262" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Stack-based buffer overflow in Triologic Media Player 7 and 8.0.0.0 allows user-assisted remote attackers to execute arbitrary code via a long string in a .m3u playlist file.  NOTE: some of these details are obtained from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2009/0097" source="VUPEN">ADV-2009-0097</ref>
      <ref url="http://www.securityfocus.com/bid/33221" source="BID">33221</ref>
      <ref url="http://secunia.com/advisories/33496" source="SECUNIA">33496</ref>
      <ref url="http://milw0rm.com/exploits/7737" source="MILW0RM">7737</ref>
    </refs>
    <vuln_soft>
      <prod vendor="trilogic" name="media_player">
        <vers num="7" />
        <vers num="8.0.0.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0263" published="2009-01-23" name="CVE-2009-0263" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Multiple buffer overflows in Winamp 5.541 and earlier allow remote attackers to cause a denial of service and possibly execute arbitrary code via (1) a large Common Chunk (COMM) header value in an AIFF file and (2) a large invalid value in an MP3 file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2009/0113" source="VUPEN">ADV-2009-0113</ref>
      <ref url="http://www.securityfocus.com/bid/33226" source="BID">33226</ref>
      <ref url="http://secunia.com/advisories/33478" source="SECUNIA">33478</ref>
      <ref url="http://milw0rm.com/exploits/7742" source="MILW0RM">7742</ref>
    </refs>
    <vuln_soft>
      <prod vendor="nullsoft" name="winamp">
        <vers num="2.0" />
        <vers num="2.10" />
        <vers num="2.24" />
        <vers num="2.4" />
        <vers num="2.50" />
        <vers num="2.5e" />
        <vers num="2.60" edition="" />
        <vers num="2.60" edition=":lite" />
        <vers num="2.60" edition=":full" />
        <vers num="2.61" edition="" />
        <vers num="2.61" edition=":full" />
        <vers num="2.62" edition="" />
        <vers num="2.62" edition=":standard" />
        <vers num="2.64" edition="" />
        <vers num="2.64" edition=":standard" />
        <vers num="2.65" />
        <vers num="2.6x" />
        <vers num="2.70" edition="" />
        <vers num="2.70" edition=":full" />
        <vers num="2.71" />
        <vers num="2.72" />
        <vers num="2.73" edition="" />
        <vers num="2.73" edition=":full" />
        <vers num="2.74" />
        <vers num="2.75" />
        <vers num="2.76" />
        <vers num="2.77" />
        <vers num="2.78" />
        <vers num="2.79" />
        <vers num="2.7x" />
        <vers num="2.80" />
        <vers num="2.81" />
        <vers num="2.90" />
        <vers num="2.91" />
        <vers num="2.95" />
        <vers num="3.0" />
        <vers num="3.1" />
        <vers num="5.0" />
        <vers num="5.0.1" />
        <vers num="5.0.2" />
        <vers num="5.01" />
        <vers num="5.02" />
        <vers num="5.03" />
        <vers num="5.03a" />
        <vers num="5.04" />
        <vers num="5.05" />
        <vers num="5.06" />
        <vers num="5.07" />
        <vers num="5.08" edition="c" />
        <vers num="5.08" edition="d" />
        <vers num="5.08" edition="e" />
        <vers num="5.08c" />
        <vers num="5.08d" />
        <vers num="5.08e" />
        <vers num="5.09" />
        <vers num="5.091" />
        <vers num="5.093" />
        <vers num="5.094" />
        <vers num="5.1" />
        <vers num="5.11" />
        <vers num="5.111" />
        <vers num="5.112" />
        <vers num="5.12" />
        <vers num="5.13" />
        <vers num="5.2" />
        <vers num="5.21" />
        <vers num="5.22" />
        <vers num="5.23" />
        <vers num="5.24" />
        <vers num="5.3" />
        <vers num="5.31" />
        <vers num="5.32" />
        <vers num="5.33" />
        <vers num="5.34" />
        <vers num="5.35" />
        <vers num="5.36" />
        <vers num="5.5" />
        <vers num="5.51" />
        <vers num="5.52" />
        <vers num="5.53" />
        <vers num="5.54" />
        <vers prev="1" num="5.541" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0264" published="2009-01-26" name="CVE-2009-0264" modified="2009-02-12" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in the Registry Setting Tool in Fujitsu SystemcastWizard Lite 2.0A, 2.0, 1.9, and earlier has unknown impact and attack vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.fujitsu.com/global/services/computing/server/primequest/products/os/windows-server-2008-2.html" source="CONFIRM" patch="1" adv="1">http://www.fujitsu.com/global/services/computing/server/primequest/products/os/windows-server-2008-2.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/48315" source="XF">systemcast-registrytool-bo(48315)</ref>
      <ref url="http://www.securityfocus.com/bid/33644" source="BID">33644</ref>
    </refs>
    <vuln_soft>
      <prod vendor="fujitsu" name="systemcastwizard_lite">
        <vers num="1.7" />
        <vers num="1.8" />
        <vers num="1.8a" />
        <vers num="1.9" />
        <vers num="2.0" />
        <vers prev="1" num="2.0a" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0265" published="2009-01-26" name="CVE-2009-0265" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Internet Systems Consortium (ISC) BIND 9.6.0 and earlier does not properly check the return value from the OpenSSL EVP_VerifyFinal function, which allows remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature, a similar vulnerability to CVE-2008-5077 and CVE-2009-0025.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="https://www.isc.org/node/373" source="CONFIRM" adv="1">https://www.isc.org/node/373</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0043" source="VUPEN">ADV-2009-0043</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:037" source="MANDRIVA">MDVSA-2009:037</ref>
      <ref url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2009&amp;m=slackware-security.540362" source="SLACKWARE">SSA:2009-014-02</ref>
      <ref url="http://secunia.com/advisories/33559" source="SECUNIA" adv="1">33559</ref>
      <ref url="http://groups.google.com/group/comp.protocols.dns.bind/browse_thread/thread/49ef622c8329fd33" source="MISC">http://groups.google.com/group/comp.protocols.dns.bind/browse_thread/thread/49ef622c8329fd33</ref>
    </refs>
    <vuln_soft>
      <prod vendor="isc" name="bind">
        <vers num="4" />
        <vers num="4.9" />
        <vers num="4.9.10" />
        <vers num="4.9.2" />
        <vers num="4.9.3" />
        <vers num="4.9.4" />
        <vers num="4.9.5" edition="p1" />
        <vers num="4.9.6" />
        <vers num="4.9.7" />
        <vers num="4.9.8" />
        <vers num="4.9.9" />
        <vers num="8" />
        <vers num="8.1" />
        <vers num="8.1.1" />
        <vers num="8.1.2" />
        <vers num="8.2" edition="p1" />
        <vers num="8.2.1" />
        <vers num="8.2.2" edition="p1" />
        <vers num="8.2.2" edition="p2" />
        <vers num="8.2.2" edition="p3" />
        <vers num="8.2.2" edition="p4" />
        <vers num="8.2.2" edition="p5" />
        <vers num="8.2.2" edition="p6" />
        <vers num="8.2.2" edition="p7" />
        <vers num="8.2.3" />
        <vers num="8.2.3_t1a" />
        <vers num="8.2.3_t9b" />
        <vers num="8.2.4" />
        <vers num="8.2.5" />
        <vers num="8.2.6" />
        <vers num="8.2.7" />
        <vers num="8.3.0" />
        <vers num="8.3.1" />
        <vers num="8.3.2" />
        <vers num="8.3.3" />
        <vers num="8.3.4" />
        <vers num="8.3.5" />
        <vers num="8.3.6" />
        <vers num="8.4" />
        <vers num="8.4.1" />
        <vers num="8.4.4" />
        <vers num="8.4.5" />
        <vers num="8.4.7" />
        <vers num="9.0" />
        <vers num="9.0.1" />
        <vers num="9.1" />
        <vers num="9.1.1" />
        <vers num="9.1.2" />
        <vers num="9.1.3" />
        <vers num="9.2" />
        <vers num="9.2.0" />
        <vers num="9.2.1" />
        <vers num="9.2.2" edition="p3" />
        <vers num="9.2.3" />
        <vers num="9.2.4" />
        <vers num="9.2.5" />
        <vers num="9.2.6" />
        <vers num="9.2.7" />
        <vers num="9.2.9" />
        <vers num="9.3" />
        <vers num="9.3.0" />
        <vers num="9.3.1" />
        <vers num="9.3.2" />
        <vers num="9.3.3" />
        <vers num="9.3.5-p2-w1" edition="windows" />
        <vers num="9.4" />
        <vers num="9.4.0" edition="rc1" />
        <vers num="9.4.0a1" />
        <vers num="9.4.0a2" />
        <vers num="9.4.0a3" />
        <vers num="9.4.0a4" />
        <vers num="9.4.0a5" />
        <vers num="9.4.0a6" />
        <vers num="9.4.0b1" />
        <vers num="9.4.0b2" />
        <vers num="9.4.0b3" />
        <vers num="9.4.0b4" />
        <vers num="9.4.1" />
        <vers num="9.4.2" />
        <vers num="9.4.3" edition="rc1" />
        <vers num="9.4.3b1" />
        <vers num="9.4.3b2" />
        <vers num="9.4.3b3" />
        <vers num="9.5.0" edition="rc1" />
        <vers num="9.5.0-p1" />
        <vers num="9.5.0-p2" />
        <vers num="9.5.0-p2-w1" />
        <vers num="9.5.0-p2-w2" />
        <vers num="9.5.0a5" />
        <vers num="9.5.0a6" />
        <vers num="9.5.0a7" />
        <vers num="9.5.0b1" />
        <vers num="9.5.0b2" />
        <vers num="9.5.0b3" />
        <vers num="9.5.1" edition="rc1" />
        <vers num="9.5.1" edition="rc2" />
        <vers num="9.5.1b1" />
        <vers num="9.5.1b2" />
        <vers num="9.5.1b3" />
        <vers prev="1" num="9.6.0" edition="p1" />
        <vers prev="1" num="9.6.0" edition="rc1" />
        <vers prev="1" num="9.6.0" edition="rc2" />
        <vers num="9.6.0a1" />
        <vers num="9.6.0b1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0266" published="2009-01-26" name="CVE-2009-0266" modified="2009-01-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Stack-based buffer overflow in Triologic Media Player 8.0.0.0 allows user-assisted remote attackers to execute arbitrary code via a long string in a .m3l playlist file.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/33496" source="SECUNIA" adv="1">33496</ref>
    </refs>
    <vuln_soft>
      <prod vendor="trilogic" name="media_player">
        <vers num="8.0.0.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0267" published="2009-01-26" name="CVE-2009-0267" modified="2009-03-04" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">libike in Sun Solaris 9 and 10, and OpenSolaris before snv_100, does not properly check packets, which allows remote attackers to cause a denial of service (in.iked daemon crash) via an unspecified IKE packet, a different vulnerability than CVE-2007-2989.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/33407" source="BID" patch="1">33407</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-247406-1" source="SUNALERT" patch="1" adv="1">247406</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-21-113451-15-1" source="CONFIRM" patch="1">http://sunsolve.sun.com/search/document.do?assetkey=1-21-113451-15-1</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/48178" source="XF">sun-solaris-libike-dos(48178)</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2009-032.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2009-032.htm</ref>
      <ref url="http://secunia.com/advisories/33702" source="SECUNIA">33702</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6116" source="OVAL">oval:org.mitre.oval:def:6116</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="opensolaris">
        <vers num="snv_01" edition="" />
        <vers num="snv_01" edition=":sparc" />
        <vers num="snv_01" edition=":x86" />
        <vers num="snv_02" edition="" />
        <vers num="snv_02" edition=":sparc" />
        <vers num="snv_02" edition=":x86" />
        <vers num="snv_03" edition="" />
        <vers num="snv_03" edition=":x86" />
        <vers num="snv_03" edition=":sparc" />
        <vers num="snv_04" edition="" />
        <vers num="snv_04" edition=":x86" />
        <vers num="snv_04" edition=":sparc" />
        <vers num="snv_05" edition="" />
        <vers num="snv_05" edition=":sparc" />
        <vers num="snv_05" edition=":x86" />
        <vers num="snv_06" edition="" />
        <vers num="snv_06" edition=":sparc" />
        <vers num="snv_06" edition=":x86" />
        <vers num="snv_07" edition="" />
        <vers num="snv_07" edition=":sparc" />
        <vers num="snv_07" edition=":x86" />
        <vers num="snv_08" edition="" />
        <vers num="snv_08" edition=":x86" />
        <vers num="snv_08" edition=":sparc" />
        <vers num="snv_09" edition="" />
        <vers num="snv_09" edition=":sparc" />
        <vers num="snv_09" edition=":x86" />
        <vers num="snv_10" edition="" />
        <vers num="snv_10" edition=":x86" />
        <vers num="snv_10" edition=":sparc" />
        <vers num="snv_11" edition="" />
        <vers num="snv_11" edition=":sparc" />
        <vers num="snv_12" edition="" />
        <vers num="snv_12" edition=":sparc" />
        <vers num="snv_13" edition="" />
        <vers num="snv_13" edition=":sparc" />
        <vers num="snv_14" edition="" />
        <vers num="snv_14" edition=":sparc" />
        <vers num="snv_15" edition="" />
        <vers num="snv_15" edition=":sparc" />
        <vers num="snv_16" edition="" />
        <vers num="snv_16" edition=":sparc" />
        <vers num="snv_17" edition="" />
        <vers num="snv_17" edition=":sparc" />
        <vers num="snv_18" edition="" />
        <vers num="snv_18" edition=":sparc" />
        <vers num="snv_19" edition="" />
        <vers num="snv_19" edition=":sparc" />
        <vers num="snv_20" edition="" />
        <vers num="snv_20" edition=":sparc" />
        <vers num="snv_21" edition="" />
        <vers num="snv_21" edition=":x86" />
        <vers num="snv_21" edition=":sparc" />
        <vers num="snv_22" edition="" />
        <vers num="snv_22" edition=":sparc" />
        <vers num="snv_22" edition=":x86" />
        <vers num="snv_23" edition="" />
        <vers num="snv_23" edition=":sparc" />
        <vers num="snv_23" edition=":x86" />
        <vers num="snv_24" edition="" />
        <vers num="snv_24" edition=":sparc" />
        <vers num="snv_24" edition=":x86" />
        <vers num="snv_25" edition="" />
        <vers num="snv_25" edition=":sparc" />
        <vers num="snv_25" edition=":x86" />
        <vers num="snv_26" edition="" />
        <vers num="snv_26" edition=":sparc" />
        <vers num="snv_26" edition=":x86" />
        <vers num="snv_27" edition="" />
        <vers num="snv_27" edition=":sparc" />
        <vers num="snv_27" edition=":x86" />
        <vers num="snv_28" edition="" />
        <vers num="snv_28" edition=":sparc" />
        <vers num="snv_28" edition=":x86" />
        <vers num="snv_29" edition="" />
        <vers num="snv_29" edition=":x86" />
        <vers num="snv_29" edition=":sparc" />
        <vers num="snv_30" edition="" />
        <vers num="snv_30" edition=":sparc" />
        <vers num="snv_30" edition=":x86" />
        <vers num="snv_31" edition="" />
        <vers num="snv_31" edition=":sparc" />
        <vers num="snv_31" edition=":x86" />
        <vers num="snv_32" edition="" />
        <vers num="snv_32" edition=":x86" />
        <vers num="snv_32" edition=":sparc" />
        <vers num="snv_33" edition="" />
        <vers num="snv_33" edition=":x86" />
        <vers num="snv_33" edition=":sparc" />
        <vers num="snv_34" edition="" />
        <vers num="snv_34" edition=":sparc" />
        <vers num="snv_34" edition=":x86" />
        <vers num="snv_35" edition="" />
        <vers num="snv_35" edition=":sparc" />
        <vers num="snv_35" edition=":x86" />
        <vers num="snv_36" edition="" />
        <vers num="snv_36" edition=":sparc" />
        <vers num="snv_36" edition=":x86" />
        <vers num="snv_37" edition="" />
        <vers num="snv_37" edition=":sparc" />
        <vers num="snv_37" edition=":x86" />
        <vers num="snv_38" edition="" />
        <vers num="snv_38" edition=":sparc" />
        <vers num="snv_38" edition=":x86" />
        <vers num="snv_39" edition="" />
        <vers num="snv_39" edition=":sparc" />
        <vers num="snv_39" edition=":x86" />
        <vers num="snv_40" edition="" />
        <vers num="snv_40" edition=":x86" />
        <vers num="snv_40" edition=":sparc" />
        <vers num="snv_41" edition="" />
        <vers num="snv_41" edition=":sparc" />
        <vers num="snv_41" edition=":x86" />
        <vers num="snv_42" edition="" />
        <vers num="snv_42" edition=":x86" />
        <vers num="snv_42" edition=":sparc" />
        <vers num="snv_43" edition="" />
        <vers num="snv_43" edition=":sparc" />
        <vers num="snv_43" edition=":x86" />
        <vers num="snv_44" edition="" />
        <vers num="snv_44" edition=":x86" />
        <vers num="snv_44" edition=":sparc" />
        <vers num="snv_45" edition="" />
        <vers num="snv_45" edition=":x86" />
        <vers num="snv_45" edition=":sparc" />
        <vers num="snv_46" edition="" />
        <vers num="snv_46" edition=":sparc" />
        <vers num="snv_46" edition=":x86" />
        <vers num="snv_47" edition="" />
        <vers num="snv_47" edition=":x86" />
        <vers num="snv_47" edition=":sparc" />
        <vers num="snv_48" edition="" />
        <vers num="snv_48" edition=":sparc" />
        <vers num="snv_48" edition=":x86" />
        <vers num="snv_49" edition="" />
        <vers num="snv_49" edition=":sparc" />
        <vers num="snv_49" edition=":x86" />
        <vers num="snv_50" edition="" />
        <vers num="snv_50" edition=":sparc" />
        <vers num="snv_50" edition=":x86" />
        <vers num="snv_51" edition="" />
        <vers num="snv_51" edition=":x86" />
        <vers num="snv_51" edition=":sparc" />
        <vers num="snv_52" edition="" />
        <vers num="snv_52" edition=":x86" />
        <vers num="snv_52" edition=":sparc" />
        <vers num="snv_53" edition="" />
        <vers num="snv_53" edition=":sparc" />
        <vers num="snv_53" edition=":x86" />
        <vers num="snv_54" edition="" />
        <vers num="snv_54" edition=":sparc" />
        <vers num="snv_54" edition=":x86" />
        <vers num="snv_55" edition="" />
        <vers num="snv_55" edition=":sparc" />
        <vers num="snv_55" edition=":x86" />
        <vers num="snv_56" edition="" />
        <vers num="snv_56" edition=":x86" />
        <vers num="snv_56" edition=":sparc" />
        <vers num="snv_57" edition="" />
        <vers num="snv_57" edition=":x86" />
        <vers num="snv_57" edition=":sparc" />
        <vers num="snv_58" edition="" />
        <vers num="snv_58" edition=":sparc" />
        <vers num="snv_58" edition=":x86" />
        <vers num="snv_59" edition="" />
        <vers num="snv_59" edition=":sparc" />
        <vers num="snv_59" edition=":x86" />
        <vers num="snv_60" edition="" />
        <vers num="snv_60" edition=":x86" />
        <vers num="snv_60" edition=":sparc" />
        <vers num="snv_61" edition="" />
        <vers num="snv_61" edition=":sparc" />
        <vers num="snv_61" edition=":x86" />
        <vers num="snv_62" edition="" />
        <vers num="snv_62" edition=":x86" />
        <vers num="snv_62" edition=":sparc" />
        <vers num="snv_63" edition="" />
        <vers num="snv_63" edition=":x86" />
        <vers num="snv_63" edition=":sparc" />
        <vers num="snv_64" edition="" />
        <vers num="snv_64" edition=":x86" />
        <vers num="snv_64" edition=":sparc" />
        <vers num="snv_65" edition="" />
        <vers num="snv_65" edition=":sparc" />
        <vers num="snv_65" edition=":x86" />
        <vers num="snv_66" edition="" />
        <vers num="snv_66" edition=":x86" />
        <vers num="snv_66" edition=":sparc" />
        <vers num="snv_67" edition="" />
        <vers num="snv_67" edition=":sparc" />
        <vers num="snv_67" edition=":x86" />
        <vers num="snv_68" edition="" />
        <vers num="snv_68" edition=":x86" />
        <vers num="snv_68" edition=":sparc" />
        <vers num="snv_69" edition="" />
        <vers num="snv_69" edition=":sparc" />
        <vers num="snv_69" edition=":x86" />
        <vers num="snv_70" edition="" />
        <vers num="snv_70" edition=":sparc" />
        <vers num="snv_70" edition=":x86" />
        <vers num="snv_71" edition="" />
        <vers num="snv_71" edition=":sparc" />
        <vers num="snv_71" edition=":x86" />
        <vers num="snv_72" edition="" />
        <vers num="snv_72" edition=":x86" />
        <vers num="snv_72" edition=":sparc" />
        <vers num="snv_73" edition="" />
        <vers num="snv_73" edition=":x86" />
        <vers num="snv_73" edition=":sparc" />
        <vers num="snv_74" edition="" />
        <vers num="snv_74" edition=":x86" />
        <vers num="snv_74" edition=":sparc" />
        <vers num="snv_75" edition="" />
        <vers num="snv_75" edition=":x86" />
        <vers num="snv_75" edition=":sparc" />
        <vers num="snv_76" edition="" />
        <vers num="snv_76" edition=":sparc" />
        <vers num="snv_76" edition=":x86" />
        <vers num="snv_77" edition="" />
        <vers num="snv_77" edition=":sparc" />
        <vers num="snv_77" edition=":x86" />
        <vers num="snv_78" edition="" />
        <vers num="snv_78" edition=":sparc" />
        <vers num="snv_78" edition=":x86" />
        <vers num="snv_79" edition="" />
        <vers num="snv_79" edition=":x86" />
        <vers num="snv_79" edition=":sparc" />
        <vers num="snv_80" edition="" />
        <vers num="snv_80" edition=":x86" />
        <vers num="snv_80" edition=":sparc" />
        <vers num="snv_81" edition="" />
        <vers num="snv_81" edition=":x86" />
        <vers num="snv_81" edition=":sparc" />
        <vers num="snv_82" edition="" />
        <vers num="snv_82" edition=":x86" />
        <vers num="snv_82" edition=":sparc" />
        <vers num="snv_83" edition="" />
        <vers num="snv_83" edition=":sparc" />
        <vers num="snv_83" edition=":x86" />
        <vers num="snv_84" edition="" />
        <vers num="snv_84" edition=":x86" />
        <vers num="snv_84" edition=":sparc" />
        <vers num="snv_85" edition="" />
        <vers num="snv_85" edition=":sparc" />
        <vers num="snv_85" edition=":x86" />
        <vers num="snv_86" edition="" />
        <vers num="snv_86" edition=":sparc" />
        <vers num="snv_86" edition=":x86" />
        <vers num="snv_87" edition="" />
        <vers num="snv_87" edition=":sparc" />
        <vers num="snv_87" edition=":x86" />
        <vers num="snv_88" edition="" />
        <vers num="snv_88" edition=":x86" />
        <vers num="snv_88" edition=":sparc" />
        <vers num="snv_89" edition="" />
        <vers num="snv_89" edition=":x86" />
        <vers num="snv_89" edition=":sparc" />
        <vers num="snv_90" edition="" />
        <vers num="snv_90" edition=":sparc" />
        <vers num="snv_90" edition=":x86" />
        <vers num="snv_91" edition="" />
        <vers num="snv_91" edition=":x86" />
        <vers num="snv_91" edition=":sparc" />
        <vers num="snv_92" edition="" />
        <vers num="snv_92" edition=":x86" />
        <vers num="snv_92" edition=":sparc" />
        <vers num="snv_93" edition="" />
        <vers num="snv_93" edition=":sparc" />
        <vers num="snv_93" edition=":x86" />
        <vers num="snv_94" edition="" />
        <vers num="snv_94" edition=":x86" />
        <vers num="snv_94" edition=":sparc" />
        <vers num="snv_95" edition="" />
        <vers num="snv_95" edition=":x86" />
        <vers num="snv_95" edition=":sparc" />
        <vers num="snv_96" edition="" />
        <vers num="snv_96" edition=":sparc" />
        <vers num="snv_96" edition=":x86" />
        <vers num="snv_97" edition="" />
        <vers num="snv_97" edition=":x86" />
        <vers num="snv_97" edition=":sparc" />
        <vers num="snv_98" edition="" />
        <vers num="snv_98" edition=":x86" />
        <vers num="snv_98" edition=":sparc" />
        <vers prev="1" num="snv_99" edition="" />
        <vers prev="1" num="snv_99" edition=":sparc" />
        <vers prev="1" num="snv_99" edition=":x86" />
      </prod>
      <prod vendor="sun" name="solaris">
        <vers num="10" edition="" />
        <vers num="10" edition=":sparc" />
        <vers num="10" edition=":x86" />
        <vers num="9" edition="" />
        <vers num="9" edition=":sparc" />
        <vers num="9" edition=":x86" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0268" published="2009-01-26" name="CVE-2009-0268" modified="2009-03-04" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="4.9" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="3.9" CVSS_base_score="4.9">
    <desc>
      <descript source="cve">Race condition in the pseudo-terminal (aka pty) driver module in Sun Solaris 8 through 10, and OpenSolaris before snv_103, allows local users to cause a denial of service (panic) via unspecified vectors related to lack of "properly sequenced code" in ptc and ptsl.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/33406" source="BID" patch="1">33406</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-249586-1" source="SUNALERT" patch="1" adv="1">249586</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-21-113685-07-1" source="CONFIRM" patch="1">http://sunsolve.sun.com/search/document.do?assetkey=1-21-113685-07-1</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/48179" source="XF">solaris-pseudo-terminal-dos(48179)</ref>
      <ref url="http://www.securitytracker.com/id?1021640" source="SECTRACK">1021640</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2009-034.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2009-034.htm</ref>
      <ref url="http://secunia.com/advisories/33708" source="SECUNIA">33708</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6061" source="OVAL">oval:org.mitre.oval:def:6061</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="opensolaris">
        <vers num="snv_01" edition="" />
        <vers num="snv_01" edition=":sparc" />
        <vers num="snv_01" edition=":x86" />
        <vers num="snv_02" edition="" />
        <vers num="snv_02" edition=":sparc" />
        <vers num="snv_02" edition=":x86" />
        <vers num="snv_03" edition="" />
        <vers num="snv_03" edition=":x86" />
        <vers num="snv_03" edition=":sparc" />
        <vers num="snv_04" edition="" />
        <vers num="snv_04" edition=":x86" />
        <vers num="snv_04" edition=":sparc" />
        <vers num="snv_05" edition="" />
        <vers num="snv_05" edition=":sparc" />
        <vers num="snv_05" edition=":x86" />
        <vers num="snv_06" edition="" />
        <vers num="snv_06" edition=":sparc" />
        <vers num="snv_06" edition=":x86" />
        <vers num="snv_07" edition="" />
        <vers num="snv_07" edition=":sparc" />
        <vers num="snv_07" edition=":x86" />
        <vers num="snv_08" edition="" />
        <vers num="snv_08" edition=":x86" />
        <vers num="snv_08" edition=":sparc" />
        <vers num="snv_09" edition="" />
        <vers num="snv_09" edition=":x86" />
        <vers num="snv_09" edition=":sparc" />
        <vers num="snv_10" edition="" />
        <vers num="snv_10" edition=":x86" />
        <vers num="snv_10" edition=":sparc" />
        <vers num="snv_100" edition="" />
        <vers num="snv_100" edition=":sparc" />
        <vers num="snv_100" edition=":x86" />
        <vers num="snv_101" edition="" />
        <vers num="snv_101" edition=":x86" />
        <vers num="snv_101" edition=":sparc" />
        <vers prev="1" num="snv_102" edition="" />
        <vers prev="1" num="snv_102" edition=":sparc" />
        <vers prev="1" num="snv_102" edition=":x86" />
        <vers num="snv_11" edition="" />
        <vers num="snv_11" edition=":x86" />
        <vers num="snv_11" edition=":sparc" />
        <vers num="snv_12" edition="" />
        <vers num="snv_12" edition=":x86" />
        <vers num="snv_12" edition=":sparc" />
        <vers num="snv_13" edition="" />
        <vers num="snv_13" edition=":x86" />
        <vers num="snv_13" edition=":sparc" />
        <vers num="snv_14" edition="" />
        <vers num="snv_14" edition=":sparc" />
        <vers num="snv_14" edition=":x86" />
        <vers num="snv_15" edition="" />
        <vers num="snv_15" edition=":x86" />
        <vers num="snv_15" edition=":sparc" />
        <vers num="snv_16" edition="" />
        <vers num="snv_16" edition=":sparc" />
        <vers num="snv_16" edition=":x86" />
        <vers num="snv_17" edition="" />
        <vers num="snv_17" edition=":x86" />
        <vers num="snv_17" edition=":sparc" />
        <vers num="snv_18" edition="" />
        <vers num="snv_18" edition=":x86" />
        <vers num="snv_18" edition=":sparc" />
        <vers num="snv_19" edition="" />
        <vers num="snv_19" edition=":sparc" />
        <vers num="snv_19" edition=":x86" />
        <vers num="snv_20" edition="" />
        <vers num="snv_20" edition=":x86" />
        <vers num="snv_20" edition=":sparc" />
        <vers num="snv_21" edition="" />
        <vers num="snv_21" edition=":sparc" />
        <vers num="snv_21" edition=":x86" />
        <vers num="snv_22" edition="" />
        <vers num="snv_22" edition=":sparc" />
        <vers num="snv_22" edition=":x86" />
        <vers num="snv_23" edition="" />
        <vers num="snv_23" edition=":sparc" />
        <vers num="snv_23" edition=":x86" />
        <vers num="snv_24" edition="" />
        <vers num="snv_24" edition=":sparc" />
        <vers num="snv_24" edition=":x86" />
        <vers num="snv_25" edition="" />
        <vers num="snv_25" edition=":x86" />
        <vers num="snv_25" edition=":sparc" />
        <vers num="snv_26" edition="" />
        <vers num="snv_26" edition=":x86" />
        <vers num="snv_26" edition=":sparc" />
        <vers num="snv_27" edition="" />
        <vers num="snv_27" edition=":sparc" />
        <vers num="snv_27" edition=":x86" />
        <vers num="snv_28" edition="" />
        <vers num="snv_28" edition=":x86" />
        <vers num="snv_28" edition=":sparc" />
        <vers num="snv_29" edition="" />
        <vers num="snv_29" edition=":x86" />
        <vers num="snv_29" edition=":sparc" />
        <vers num="snv_30" edition="" />
        <vers num="snv_30" edition=":sparc" />
        <vers num="snv_30" edition=":x86" />
        <vers num="snv_31" edition="" />
        <vers num="snv_31" edition=":sparc" />
        <vers num="snv_31" edition=":x86" />
        <vers num="snv_32" edition="" />
        <vers num="snv_32" edition=":x86" />
        <vers num="snv_32" edition=":sparc" />
        <vers num="snv_33" edition="" />
        <vers num="snv_33" edition=":x86" />
        <vers num="snv_33" edition=":sparc" />
        <vers num="snv_34" edition="" />
        <vers num="snv_34" edition=":sparc" />
        <vers num="snv_34" edition=":x86" />
        <vers num="snv_35" edition="" />
        <vers num="snv_35" edition=":sparc" />
        <vers num="snv_35" edition=":x86" />
        <vers num="snv_36" edition="" />
        <vers num="snv_36" edition=":x86" />
        <vers num="snv_36" edition=":sparc" />
        <vers num="snv_37" edition="" />
        <vers num="snv_37" edition=":sparc" />
        <vers num="snv_37" edition=":x86" />
        <vers num="snv_38" edition="" />
        <vers num="snv_38" edition=":sparc" />
        <vers num="snv_38" edition=":x86" />
        <vers num="snv_39" edition="" />
        <vers num="snv_39" edition=":sparc" />
        <vers num="snv_39" edition=":x86" />
        <vers num="snv_40" edition="" />
        <vers num="snv_40" edition=":sparc" />
        <vers num="snv_40" edition=":x86" />
        <vers num="snv_41" edition="" />
        <vers num="snv_41" edition=":sparc" />
        <vers num="snv_41" edition=":x86" />
        <vers num="snv_42" edition="" />
        <vers num="snv_42" edition=":x86" />
        <vers num="snv_42" edition=":sparc" />
        <vers num="snv_43" edition="" />
        <vers num="snv_43" edition=":sparc" />
        <vers num="snv_43" edition=":x86" />
        <vers num="snv_44" edition="" />
        <vers num="snv_44" edition=":x86" />
        <vers num="snv_44" edition=":sparc" />
        <vers num="snv_45" edition="" />
        <vers num="snv_45" edition=":x86" />
        <vers num="snv_45" edition=":sparc" />
        <vers num="snv_46" edition="" />
        <vers num="snv_46" edition=":x86" />
        <vers num="snv_46" edition=":sparc" />
        <vers num="snv_47" edition="" />
        <vers num="snv_47" edition=":x86" />
        <vers num="snv_47" edition=":sparc" />
        <vers num="snv_48" edition="" />
        <vers num="snv_48" edition=":sparc" />
        <vers num="snv_48" edition=":x86" />
        <vers num="snv_49" edition="" />
        <vers num="snv_49" edition=":sparc" />
        <vers num="snv_49" edition=":x86" />
        <vers num="snv_50" edition="" />
        <vers num="snv_50" edition=":sparc" />
        <vers num="snv_50" edition=":x86" />
        <vers num="snv_51" edition="" />
        <vers num="snv_51" edition=":sparc" />
        <vers num="snv_51" edition=":x86" />
        <vers num="snv_52" edition="" />
        <vers num="snv_52" edition=":sparc" />
        <vers num="snv_52" edition=":x86" />
        <vers num="snv_53" edition="" />
        <vers num="snv_53" edition=":sparc" />
        <vers num="snv_53" edition=":x86" />
        <vers num="snv_54" edition="" />
        <vers num="snv_54" edition=":x86" />
        <vers num="snv_54" edition=":sparc" />
        <vers num="snv_55" edition="" />
        <vers num="snv_55" edition=":sparc" />
        <vers num="snv_55" edition=":x86" />
        <vers num="snv_56" edition="" />
        <vers num="snv_56" edition=":x86" />
        <vers num="snv_56" edition=":sparc" />
        <vers num="snv_57" edition="" />
        <vers num="snv_57" edition=":x86" />
        <vers num="snv_57" edition=":sparc" />
        <vers num="snv_58" edition="" />
        <vers num="snv_58" edition=":sparc" />
        <vers num="snv_58" edition=":x86" />
        <vers num="snv_59" edition="" />
        <vers num="snv_59" edition=":sparc" />
        <vers num="snv_59" edition=":x86" />
        <vers num="snv_60" edition="" />
        <vers num="snv_60" edition=":x86" />
        <vers num="snv_60" edition=":sparc" />
        <vers num="snv_61" edition="" />
        <vers num="snv_61" edition=":sparc" />
        <vers num="snv_61" edition=":x86" />
        <vers num="snv_62" edition="" />
        <vers num="snv_62" edition=":x86" />
        <vers num="snv_62" edition=":sparc" />
        <vers num="snv_63" edition="" />
        <vers num="snv_63" edition=":sparc" />
        <vers num="snv_63" edition=":x86" />
        <vers num="snv_64" edition="" />
        <vers num="snv_64" edition=":x86" />
        <vers num="snv_64" edition=":sparc" />
        <vers num="snv_65" edition="" />
        <vers num="snv_65" edition=":x86" />
        <vers num="snv_65" edition=":sparc" />
        <vers num="snv_66" edition="" />
        <vers num="snv_66" edition=":x86" />
        <vers num="snv_66" edition=":sparc" />
        <vers num="snv_67" edition="" />
        <vers num="snv_67" edition=":sparc" />
        <vers num="snv_67" edition=":x86" />
        <vers num="snv_68" edition="" />
        <vers num="snv_68" edition=":x86" />
        <vers num="snv_68" edition=":sparc" />
        <vers num="snv_69" edition="" />
        <vers num="snv_69" edition=":sparc" />
        <vers num="snv_69" edition=":x86" />
        <vers num="snv_70" edition="" />
        <vers num="snv_70" edition=":sparc" />
        <vers num="snv_70" edition=":x86" />
        <vers num="snv_71" edition="" />
        <vers num="snv_71" edition=":x86" />
        <vers num="snv_71" edition=":sparc" />
        <vers num="snv_72" edition="" />
        <vers num="snv_72" edition=":x86" />
        <vers num="snv_72" edition=":sparc" />
        <vers num="snv_73" edition="" />
        <vers num="snv_73" edition=":x86" />
        <vers num="snv_73" edition=":sparc" />
        <vers num="snv_74" edition="" />
        <vers num="snv_74" edition=":sparc" />
        <vers num="snv_74" edition=":x86" />
        <vers num="snv_75" edition="" />
        <vers num="snv_75" edition=":sparc" />
        <vers num="snv_75" edition=":x86" />
        <vers num="snv_76" edition="" />
        <vers num="snv_76" edition=":x86" />
        <vers num="snv_76" edition=":sparc" />
        <vers num="snv_77" edition="" />
        <vers num="snv_77" edition=":sparc" />
        <vers num="snv_77" edition=":x86" />
        <vers num="snv_78" edition="" />
        <vers num="snv_78" edition=":sparc" />
        <vers num="snv_78" edition=":x86" />
        <vers num="snv_79" edition="" />
        <vers num="snv_79" edition=":x86" />
        <vers num="snv_79" edition=":sparc" />
        <vers num="snv_80" edition="" />
        <vers num="snv_80" edition=":x86" />
        <vers num="snv_80" edition=":sparc" />
        <vers num="snv_81" edition="" />
        <vers num="snv_81" edition=":x86" />
        <vers num="snv_81" edition=":sparc" />
        <vers num="snv_82" edition="" />
        <vers num="snv_82" edition=":x86" />
        <vers num="snv_82" edition=":sparc" />
        <vers num="snv_83" edition="" />
        <vers num="snv_83" edition=":x86" />
        <vers num="snv_83" edition=":sparc" />
        <vers num="snv_84" edition="" />
        <vers num="snv_84" edition=":x86" />
        <vers num="snv_84" edition=":sparc" />
        <vers num="snv_85" edition="" />
        <vers num="snv_85" edition=":x86" />
        <vers num="snv_85" edition=":sparc" />
        <vers num="snv_86" edition="" />
        <vers num="snv_86" edition=":sparc" />
        <vers num="snv_86" edition=":x86" />
        <vers num="snv_87" edition="" />
        <vers num="snv_87" edition=":sparc" />
        <vers num="snv_87" edition=":x86" />
        <vers num="snv_88" edition="" />
        <vers num="snv_88" edition=":x86" />
        <vers num="snv_88" edition=":sparc" />
        <vers num="snv_89" edition="" />
        <vers num="snv_89" edition=":x86" />
        <vers num="snv_89" edition=":sparc" />
        <vers num="snv_90" edition="" />
        <vers num="snv_90" edition=":sparc" />
        <vers num="snv_90" edition=":x86" />
        <vers num="snv_91" edition="" />
        <vers num="snv_91" edition=":sparc" />
        <vers num="snv_91" edition=":x86" />
        <vers num="snv_92" edition="" />
        <vers num="snv_92" edition=":sparc" />
        <vers num="snv_92" edition=":x86" />
        <vers num="snv_93" edition="" />
        <vers num="snv_93" edition=":sparc" />
        <vers num="snv_93" edition=":x86" />
        <vers num="snv_94" edition="" />
        <vers num="snv_94" edition=":x86" />
        <vers num="snv_94" edition=":sparc" />
        <vers num="snv_95" edition="" />
        <vers num="snv_95" edition=":x86" />
        <vers num="snv_95" edition=":sparc" />
        <vers num="snv_96" edition="" />
        <vers num="snv_96" edition=":sparc" />
        <vers num="snv_96" edition=":x86" />
        <vers num="snv_97" edition="" />
        <vers num="snv_97" edition=":x86" />
        <vers num="snv_97" edition=":sparc" />
        <vers num="snv_98" edition="" />
        <vers num="snv_98" edition=":sparc" />
        <vers num="snv_98" edition=":x86" />
        <vers num="snv_99" edition="" />
        <vers num="snv_99" edition=":sparc" />
        <vers num="snv_99" edition=":x86" />
      </prod>
      <prod vendor="sun" name="solaris">
        <vers num="10" edition="" />
        <vers num="10" edition=":sparc" />
        <vers num="10" edition=":x86" />
        <vers num="8" edition="" />
        <vers num="8" edition=":sparc" />
        <vers num="8" edition=":x86" />
        <vers num="9" edition="" />
        <vers num="9" edition=":x86" />
        <vers num="9" edition=":sparc" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0269" published="2009-01-26" name="CVE-2009-0269" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="4.9" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="3.9" CVSS_base_score="4.9">
    <desc>
      <descript source="cve">fs/ecryptfs/inode.c in the eCryptfs subsystem in the Linux kernel before 2.6.28.1 allows local users to cause a denial of service (fault or memory corruption), or possibly have unspecified other impact, via a readlink call that results in an error, leading to use of a -1 return value as an array index.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/33412" source="BID" patch="1">33412</ref>
      <ref url="https://lists.launchpad.net/ecryptfs-devel/msg00011.html" source="MLIST">[ecryptfs-devel] 20081222 Re: [PATCH, v5] eCryptfs: check readlink result was not an error before using it</ref>
      <ref url="https://lists.launchpad.net/ecryptfs-devel/msg00010.html" source="MLIST">[ecryptfs-devel] 20081222 Re: [PATCH, v5] eCryptfs: check readlink result was not an error before using it</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/48188" source="XF">linux-kernel-readlink-bo(48188)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/3316" source="VUPEN">ADV-2009-3316</ref>
      <ref url="http://www.vmware.com/security/advisories/VMSA-2009-0016.html" source="CONFIRM">http://www.vmware.com/security/advisories/VMSA-2009-0016.html</ref>
      <ref url="http://www.ubuntu.com/usn/usn-751-1" source="UBUNTU">USN-751-1</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/507985/100/0/threaded" source="BUGTRAQ">20091120 VMSA-2009-0016 VMware vCenter and ESX update release and vMA patch release address multiple security issue in third party components</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-0360.html" source="REDHAT">RHSA-2009:0360</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-0326.html" source="REDHAT">RHSA-2009:0326</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:118" source="MANDRIVA">MDVSA-2009:118</ref>
      <ref url="http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.28.1" source="CONFIRM">http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.28.1</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1787" source="DEBIAN">DSA-1787</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1749" source="DEBIAN">DSA-1749</ref>
      <ref url="http://secunia.com/advisories/37471" source="SECUNIA">37471</ref>
      <ref url="http://secunia.com/advisories/35394" source="SECUNIA">35394</ref>
      <ref url="http://secunia.com/advisories/35390" source="SECUNIA">35390</ref>
      <ref url="http://secunia.com/advisories/34981" source="SECUNIA">34981</ref>
      <ref url="http://secunia.com/advisories/34502" source="SECUNIA">34502</ref>
      <ref url="http://secunia.com/advisories/34394" source="SECUNIA">34394</ref>
      <ref url="http://secunia.com/advisories/33758" source="SECUNIA">33758</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:8944" source="OVAL">oval:org.mitre.oval:def:8944</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:8169" source="OVAL">oval:org.mitre.oval:def:8169</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-06/msg00001.html" source="SUSE">SUSE-SA:2009:031</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-06/msg00000.html" source="SUSE">SUSE-SA:2009:030</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-02/msg00003.html" source="SUSE">SUSE-SA:2009:010</ref>
      <ref url="http://git.kernel.org/?p=linux/kernel/git/stable/linux-2.6.27.y.git;a=commit;h=a17d5232de7b53d34229de79ec22f4bb04adb7e4" source="CONFIRM">http://git.kernel.org/?p=linux/kernel/git/stable/linux-2.6.27.y.git;a=commit;h=a17d5232de7b53d34229de79ec22f4bb04adb7e4</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="kernel">
        <vers num="2.2.27" />
        <vers num="2.4.36" />
        <vers num="2.4.36.1" />
        <vers num="2.4.36.2" />
        <vers num="2.4.36.3" />
        <vers num="2.4.36.4" />
        <vers num="2.4.36.5" />
        <vers num="2.4.36.6" />
        <vers num="2.6" />
        <vers num="2.6.18" edition="rc1" />
        <vers num="2.6.18" edition="rc2" />
        <vers num="2.6.18" edition="rc3" />
        <vers num="2.6.18" edition="rc4" />
        <vers num="2.6.18" edition="rc5" />
        <vers num="2.6.18" edition="rc6" />
        <vers num="2.6.18" edition="rc7" />
        <vers num="2.6.19.4" />
        <vers num="2.6.19.5" />
        <vers num="2.6.19.6" />
        <vers num="2.6.19.7" />
        <vers num="2.6.20.16" />
        <vers num="2.6.20.17" />
        <vers num="2.6.20.18" />
        <vers num="2.6.20.19" />
        <vers num="2.6.20.20" />
        <vers num="2.6.20.21" />
        <vers num="2.6.21.5" />
        <vers num="2.6.21.6" />
        <vers num="2.6.21.7" />
        <vers num="2.6.22" />
        <vers num="2.6.22.1" />
        <vers num="2.6.22.10" />
        <vers num="2.6.22.11" />
        <vers num="2.6.22.12" />
        <vers num="2.6.22.13" />
        <vers num="2.6.22.14" />
        <vers num="2.6.22.15" />
        <vers num="2.6.22.17" />
        <vers num="2.6.22.18" />
        <vers num="2.6.22.19" />
        <vers num="2.6.22.2" />
        <vers num="2.6.22.20" />
        <vers num="2.6.22.21" />
        <vers num="2.6.22.22" />
        <vers num="2.6.22.8" />
        <vers num="2.6.22.9" />
        <vers num="2.6.22_rc1" />
        <vers num="2.6.22_rc7" />
        <vers num="2.6.23" />
        <vers num="2.6.23.10" />
        <vers num="2.6.23.11" />
        <vers num="2.6.23.12" />
        <vers num="2.6.23.13" />
        <vers num="2.6.23.15" />
        <vers num="2.6.23.16" />
        <vers num="2.6.23.17" />
        <vers num="2.6.23.8" />
        <vers num="2.6.23.9" />
        <vers num="2.6.23_rc1" />
        <vers num="2.6.24" />
        <vers num="2.6.24.1" />
        <vers num="2.6.24.2" />
        <vers num="2.6.24.3" />
        <vers num="2.6.24.4" />
        <vers num="2.6.24.5" />
        <vers num="2.6.24.6" />
        <vers num="2.6.24.7" />
        <vers num="2.6.24_rc1" />
        <vers num="2.6.24_rc4" />
        <vers num="2.6.24_rc5" />
        <vers num="2.6.25" edition="" />
        <vers num="2.6.25" edition=":x86_64" />
        <vers num="2.6.25.1" edition="" />
        <vers num="2.6.25.1" edition=":x86_64" />
        <vers num="2.6.25.10" edition="" />
        <vers num="2.6.25.10" edition=":x86_64" />
        <vers num="2.6.25.11" edition="" />
        <vers num="2.6.25.11" edition=":x86_64" />
        <vers num="2.6.25.12" edition="" />
        <vers num="2.6.25.12" edition=":x86_64" />
        <vers num="2.6.25.13" />
        <vers num="2.6.25.14" />
        <vers num="2.6.25.15" />
        <vers num="2.6.25.16" />
        <vers num="2.6.25.17" />
        <vers num="2.6.25.2" edition="" />
        <vers num="2.6.25.2" edition=":x86_64" />
        <vers num="2.6.25.3" edition="" />
        <vers num="2.6.25.3" edition=":x86_64" />
        <vers num="2.6.25.4" edition="" />
        <vers num="2.6.25.4" edition=":x86_64" />
        <vers num="2.6.25.5" edition="" />
        <vers num="2.6.25.5" edition=":x86_64" />
        <vers num="2.6.25.6" edition="" />
        <vers num="2.6.25.6" edition=":x86_64" />
        <vers num="2.6.25.7" edition="" />
        <vers num="2.6.25.7" edition=":x86_64" />
        <vers num="2.6.25.8" edition="" />
        <vers num="2.6.25.8" edition=":x86_64" />
        <vers num="2.6.25.9" edition="" />
        <vers num="2.6.25.9" edition=":x86_64" />
        <vers num="2.6.26" />
        <vers num="2.6.26.1" />
        <vers num="2.6.26.2" />
        <vers num="2.6.26.3" />
        <vers num="2.6.26.4" />
        <vers num="2.6.26.5" />
        <vers num="2.6.27" />
        <vers prev="1" num="2.6.28" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0270" published="2009-01-26" name="CVE-2009-0270" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Stack-based buffer overflow in PXEService.exe in Fujitsu SystemcastWizard Lite 2.0A, 2.0, 1.9, and earlier allows remote attackers to execute arbitrary code via a large PXE protocol request in a UDP packet.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.fujitsu.com/global/services/computing/server/primequest/products/os/windows-server-2008-2.html" source="CONFIRM" patch="1" adv="1">http://www.fujitsu.com/global/services/computing/server/primequest/products/os/windows-server-2008-2.html</ref>
      <ref url="http://www.wintercore.com/advisories/advisory_W010109.html" source="MISC">http://www.wintercore.com/advisories/advisory_W010109.html</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0176" source="VUPEN">ADV-2009-0176</ref>
      <ref url="http://www.securityfocus.com/bid/33342" source="BID">33342</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/500172/100/0/threaded" source="BUGTRAQ">20090119 [Wintercore Research ] Fujitsu SystemcastWizard Lite PXEService Remote Buffer Overflow.</ref>
      <ref url="http://secunia.com/advisories/33594" source="SECUNIA" adv="1">33594</ref>
      <ref url="http://osvdb.org/51486" source="OSVDB">51486</ref>
    </refs>
    <vuln_soft>
      <prod vendor="fujitsu" name="systemcastwizard_lite">
        <vers num="1.7" />
        <vers num="1.8" />
        <vers num="1.8a" />
        <vers num="1.9" />
        <vers num="2.0" />
        <vers prev="1" num="2.0a" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0271" published="2009-01-26" name="CVE-2009-0271" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in the TFTP service in Fujitsu SystemcastWizard Lite 2.0A, 2.0, 1.9, and earlier allows remote attackers to read arbitrary files via directory traversal sequences in unspecified vectors.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/33344" source="BID" patch="1">33344</ref>
      <ref url="http://www.fujitsu.com/global/services/computing/server/primequest/products/os/windows-server-2008-2.html" source="CONFIRM" patch="1" adv="1">http://www.fujitsu.com/global/services/computing/server/primequest/products/os/windows-server-2008-2.html</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0176" source="VUPEN">ADV-2009-0176</ref>
      <ref url="http://secunia.com/advisories/33594" source="SECUNIA" adv="1">33594</ref>
      <ref url="http://osvdb.org/51487" source="OSVDB">51487</ref>
    </refs>
    <vuln_soft>
      <prod vendor="fujitsu" name="systemcastwizard_lite">
        <vers num="1.7" />
        <vers num="1.8" />
        <vers num="1.8a" />
        <vers num="1.9" />
        <vers num="2.0" />
        <vers num="2.0a" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0272" published="2009-02-02" name="CVE-2009-0272" modified="2009-02-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site request forgery (CSRF) vulnerability in Novell GroupWise WebAccess 6.5x, 7.0, 7.01, 7.02x, 7.03, 7.03HP1a, and 8.0 allows remote attackers to insert e-mail forwarding rules, and modify unspecified other configuration settings, as arbitrary users via unknown vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/500569/100/0/threaded" source="BUGTRAQ">20090130 PR08-21: Cross-site Request Forgery (CSRF) on Novell GroupWise WebAccess allows email theft and other attacks</ref>
      <ref url="http://www.procheckup.com/vulnerability_manager/vulnerabilities/pr08-21" source="MISC">http://www.procheckup.com/vulnerability_manager/vulnerabilities/pr08-21</ref>
      <ref url="http://www.novell.com/support/search.do?usemicrosite=true&amp;searchString=7002319" source="CONFIRM" adv="1">http://www.novell.com/support/search.do?usemicrosite=true&amp;searchString=7002319</ref>
      <ref url="http://secunia.com/advisories/33744" source="SECUNIA">33744</ref>
    </refs>
    <vuln_soft>
      <prod vendor="novell" name="groupwise">
        <vers num="6.5" />
        <vers num="7.0" />
        <vers num="7.01" />
        <vers num="7.02x" />
        <vers num="7.03" edition="hp1a" />
        <vers num="8.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0273" published="2009-02-02" name="CVE-2009-0273" modified="2009-02-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Novell GroupWise WebAccess 6.5x, 7.0, 7.01, 7.02x, 7.03, 7.03HP1a, and 8.0 allow remote attackers to inject arbitrary web script or HTML via the (1) User.id and (2) Library.queryText parameters to gw/webacc, and other vectors involving (3) HTML e-mail and (4) HTML attachments.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/33541" source="BID">33541</ref>
      <ref url="http://www.securityfocus.com/bid/33537" source="BID">33537</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/500575/100/0/threaded" source="BUGTRAQ">20090130 PR08-23: XSS on Novell GroupWise WebAccess</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/500572/100/0/threaded" source="BUGTRAQ">20090130 PR08-22: Persistent XSS on Novell GroupWise WebAccess</ref>
      <ref url="http://www.procheckup.com/vulnerability_manager/vulnerabilities/pr08-23" source="MISC">http://www.procheckup.com/vulnerability_manager/vulnerabilities/pr08-23</ref>
      <ref url="http://www.procheckup.com/vulnerability_manager/vulnerabilities/pr08-22" source="MISC">http://www.procheckup.com/vulnerability_manager/vulnerabilities/pr08-22</ref>
      <ref url="http://www.novell.com/support/search.do?usemicrosite=true&amp;searchString=7002321" source="CONFIRM" adv="1">http://www.novell.com/support/search.do?usemicrosite=true&amp;searchString=7002321</ref>
      <ref url="http://www.novell.com/support/search.do?usemicrosite=true&amp;searchString=7002320" source="CONFIRM" adv="1">http://www.novell.com/support/search.do?usemicrosite=true&amp;searchString=7002320</ref>
      <ref url="http://secunia.com/advisories/33744" source="SECUNIA">33744</ref>
    </refs>
    <vuln_soft>
      <prod vendor="novell" name="groupwise">
        <vers num="6.5" />
        <vers num="7.0" />
        <vers num="7.01" />
        <vers num="7.02x" />
        <vers num="7.03" edition="hp1a" />
        <vers num="8.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0274" published="2009-02-03" name="CVE-2009-0274" modified="2009-02-03" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in WebAccess in Novell GroupWise 6.5, 7.0, 7.01, 7.02x, 7.03, 7.03HP1a, and 8.0 might allow remote attackers to obtain sensitive information via a crafted URL, related to conversion of POST requests to GET requests.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/33559" source="BID">33559</ref>
      <ref url="http://www.novell.com/support/viewContent.do?externalId=7002322" source="CONFIRM" adv="1">http://www.novell.com/support/viewContent.do?externalId=7002322</ref>
      <ref url="http://secunia.com/advisories/33744" source="SECUNIA" adv="1">33744</ref>
    </refs>
    <vuln_soft>
      <prod vendor="novell" name="groupwise">
        <vers num="6.5" />
        <vers num="7.0" />
        <vers num="7.01" />
        <vers num="7.02x" />
        <vers num="7.03" edition="hp1a" />
        <vers num="8.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0275" published="2009-01-26" name="CVE-2009-0275" modified="2009-01-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)" CVSS_score="6.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.0" CVSS_base_score="6.5">
    <desc>
      <descript source="cve">Static code injection vulnerability in admin.php in Ryneezy phoSheezy 0.2 allows remote authenticated administrators to inject arbitrary PHP code into config/header via the header parameter.  NOTE: this can be exploited by unauthenticated attackers by leveraging CVE-2009-0250. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.osvdb.org/51412" source="OSVDB">51412</ref>
      <ref url="http://secunia.com/advisories/33531" source="SECUNIA">33531</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ryneezy" name="phosheezy">
        <vers num="0.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0276" published="2009-02-03" name="CVE-2009-0276" modified="2009-02-04" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Cross-domain vulnerability in the V8 JavaScript engine in Google Chrome before 1.0.154.46 allows remote attackers to bypass the Same Origin Policy via a crafted script that accesses another frame and reads its full URL and possibly other sensitive information, or modifies the URL of this frame.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://src.chromium.org/viewvc/chrome?view=rev&amp;revision=8524" source="CONFIRM">http://src.chromium.org/viewvc/chrome?view=rev&amp;revision=8524</ref>
      <ref url="http://sites.google.com/a/chromium.org/dev/getting-involved/dev-channel/release-notes" source="CONFIRM">http://sites.google.com/a/chromium.org/dev/getting-involved/dev-channel/release-notes</ref>
      <ref url="http://secunia.com/advisories/33754" source="SECUNIA" adv="1">33754</ref>
      <ref url="http://googlechromereleases.blogspot.com/2009/01/stable-beta-update-yahoo-mail-and.html" source="CONFIRM" adv="1">http://googlechromereleases.blogspot.com/2009/01/stable-beta-update-yahoo-mail-and.html</ref>
      <ref url="http://codereview.chromium.org/18531" source="CONFIRM">http://codereview.chromium.org/18531</ref>
    </refs>
    <vuln_soft>
      <prod vendor="google" name="chrome">
        <vers num="0.2.152.1" />
        <vers num="0.2.153.1" />
        <vers num="0.3.154.0" />
        <vers num="0.3.154.3" />
        <vers num="0.4.154.18" />
        <vers num="0.4.154.22" />
        <vers num="0.4.154.31" />
        <vers num="0.4.154.33" />
        <vers num="1.0.154.36" />
        <vers num="1.0.154.39" />
        <vers num="1.0.154.42" />
        <vers prev="1" num="1.0.154.43" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0277" published="2009-01-26" name="CVE-2009-0277" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Unspecified vulnerability in the kernel in OpenSolaris snv_100 through snv_102 on the Sun UltraSPARC T2 and T2+ sun4v platforms allows local users to cause a denial of service (panic) via unknown vectors.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-250066-1" source="SUNALERT" patch="1" adv="1">250066</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/48164" source="XF">solaris-ultrasparct2-dos(48164)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0209" source="VUPEN">ADV-2009-0209</ref>
      <ref url="http://www.securityfocus.com/bid/33398" source="BID">33398</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="opensolaris">
        <vers num="snv_100" edition="" />
        <vers num="snv_100" edition=":sparc" />
        <vers num="snv_101" edition="" />
        <vers num="snv_101" edition=":sparc" />
        <vers num="snv_102" edition="" />
        <vers num="snv_102" edition=":sparc" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0278" published="2009-01-26" name="CVE-2009-0278" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Sun Java System Application Server (AS) 8.1 and 8.2 allows remote attackers to read the Web Application configuration files in the (1) WEB-INF or (2) META-INF directory via a malformed request.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-245446-1" source="SUNALERT" patch="1" adv="1">245446</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-21-119166-35-1" source="CONFIRM" patch="1">http://sunsolve.sun.com/search/document.do?assetkey=1-21-119166-35-1</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/48161" source="XF">javasystem-webinf-metainf-info-disclosure(48161)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0208" source="VUPEN">ADV-2009-0208</ref>
      <ref url="http://www.securityfocus.com/bid/33397" source="BID">33397</ref>
      <ref url="http://secunia.com/advisories/33725" source="SECUNIA">33725</ref>
      <ref url="http://osvdb.org/51604" source="OSVDB">51604</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="java_system_application_server">
        <vers num="8.1" edition="" />
        <vers num="8.1" edition=":linux" />
        <vers num="8.1" edition=":x86" />
        <vers num="8.1" edition=":sparc" />
        <vers num="8.1" edition=":windows" />
        <vers num="8.2" edition="" />
        <vers num="8.2" edition=":x86" />
        <vers num="8.2" edition=":windows" />
        <vers num="8.2" edition=":sparc" />
        <vers num="8.2" edition=":linux" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0279" published="2009-01-27" name="CVE-2009-0279" modified="2009-01-27" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in comentar.php in Pardal CMS 0.2.0 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/48175" source="XF">pardalcms-comentar-sql-injection(48175)</ref>
      <ref url="http://www.securityfocus.com/bid/33404" source="BID">33404</ref>
      <ref url="http://www.milw0rm.com/exploits/7851" source="MILW0RM">7851</ref>
    </refs>
    <vuln_soft>
      <prod vendor="pardalcms" name="pardalcms">
        <vers num="0.01b" />
        <vers num="0.01c" />
        <vers num="0.1.1" />
        <vers num="0.1.2" />
        <vers num="0.1.3" />
        <vers num="0.1a" />
        <vers prev="1" num="0.2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0280" published="2009-01-27" name="CVE-2009-0280" modified="2009-01-27" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Asp Project Management 1.0 allows remote attackers to bypass authentication and gain administrative access by setting the crypt cookie to 1.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/48172" source="XF">aspproject-cookie-security-bypass(48172)</ref>
      <ref url="http://www.securityfocus.com/bid/33401" source="BID">33401</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/500292/100/0/threaded" source="BUGTRAQ">20090122 Asp-project Cookie Handling</ref>
      <ref url="http://www.milw0rm.com/exploits/7850" source="MILW0RM">7850</ref>
    </refs>
    <vuln_soft>
      <prod vendor="asp-project" name="asp-project">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0281" published="2009-01-27" name="CVE-2009-0281" modified="2009-01-27" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in login.aspx in WarHound Walking Club allows remote attackers to execute arbitrary SQL commands via the (1) username and (2) password parameters.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/48061" source="XF">walkingclub-login-sql-injection(48061)</ref>
      <ref url="http://www.securityfocus.com/bid/33317" source="BID">33317</ref>
      <ref url="http://www.milw0rm.com/exploits/7802" source="MILW0RM">7802</ref>
    </refs>
    <vuln_soft>
      <prod vendor="warhound" name="walking_club">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0282" published="2009-01-27" name="CVE-2009-0282" modified="2010-12-29" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Integer overflow in Ralink Technology USB wireless adapter (RT73) 3.08 for Windows, and other wireless card drivers including rt2400, rt2500, rt2570, and rt61, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a Probe Request packet with a long SSID, possibly related to an integer signedness error.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/33340" source="BID">33340</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/500168/100/0/threaded" source="BUGTRAQ">20090118 Ralinktech wireless cards drivers vulnerability</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1714" source="DEBIAN">DSA-1714</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1713" source="DEBIAN">DSA-1713</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1712" source="DEBIAN">DSA-1712</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200907-08.xml" source="GENTOO">GLSA-200907-08</ref>
      <ref url="http://secunia.com/advisories/35743" source="SECUNIA" adv="1">35743</ref>
      <ref url="http://secunia.com/advisories/33699" source="SECUNIA" adv="1">33699</ref>
      <ref url="http://secunia.com/advisories/33592" source="SECUNIA" adv="1">33592</ref>
      <ref url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=512995" source="MISC">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=512995</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ralinktech" name="rt73">
        <vers num="3.08" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0283" published="2009-01-27" name="CVE-2009-0283" modified="2009-02-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in err.asp in Oblog allows remote attackers to inject arbitrary web script or HTML via the message parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/33416" source="BID">33416</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/500397/100/0/threaded" source="BUGTRAQ">20090124 Re: Oblog XSS valnerability</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/500349/100/0/threaded" source="BUGTRAQ">20090123 Oblog XSS valnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="aobosoft" name="oblog">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0284" published="2009-01-27" name="CVE-2009-0284" modified="2009-06-03" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in category.php in Flax Article Manager 1.1 allows remote attackers to execute arbitrary SQL commands via the cat_id parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/33422" source="BID">33422</ref>
      <ref url="http://www.milw0rm.com/exploits/7862" source="MILW0RM">7862</ref>
      <ref url="http://www.flaxweb.com/products/articles" source="CONFIRM">http://www.flaxweb.com/products/articles</ref>
      <ref url="http://secunia.com/advisories/33625" source="SECUNIA" adv="1">33625</ref>
    </refs>
    <vuln_soft>
      <prod vendor="flaxweb" name="flax_article_manager">
        <vers num="1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0285" published="2009-01-27" name="CVE-2009-0285" modified="2009-01-27" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in error.asp in BBSXP 5.13 and earlier allows remote attackers to inject arbitrary web script or HTML via the message parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/48187" source="XF">bbsxp-error-xss(48187)</ref>
      <ref url="http://www.securityfocus.com/bid/33411" source="BID">33411</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/500336/100/0/threaded" source="BUGTRAQ">20090123 BBSxp Xss vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bbsxp" name="bbsxp">
        <vers prev="1" num="5.13" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2009-0286" published="2009-01-27" name="CVE-2009-0286" modified="2009-02-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:N/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Directory traversal vulnerability in upgrade/index.php in OpenGoo 1.1, when register_globals is enabled and magic_quotes_gpc is disabled, allows remote attackers to read arbitrary files via a .. (dot dot) in the form_data[script_class] parameter.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/33421" source="BID">33421</ref>
      <ref url="http://www.milw0rm.com/exploits/7863" source="MILW0RM">7863</ref>
      <ref url="http://osvdb.org/51635" source="OSVDB">51635</ref>
    </refs>
    <vuln_soft>
      <prod vendor="opengoo" name="opengoo">
        <vers num="1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0287" published="2009-01-27" name="CVE-2009-0287" modified="2009-02-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in lib/patUser.php in KEEP Toolkit before 2.5.1 allows remote attackers to execute arbitrary SQL commands via the (1) username and (2) password.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/33425" source="BID" patch="1">33425</ref>
      <ref url="http://sourceforge.net/project/shownotes.php?release_id=655845&amp;group_id=227492" source="CONFIRM" patch="1" adv="1">http://sourceforge.net/project/shownotes.php?release_id=655845&amp;group_id=227492</ref>
      <ref url="http://secunia.com/advisories/33652" source="SECUNIA" adv="1">33652</ref>
      <ref url="http://osvdb.org/51623" source="OSVDB">51623</ref>
      <ref url="http://keeptoolkit.svn.sourceforge.net/viewvc/keeptoolkit?view=rev&amp;revision=56" source="CONFIRM">http://keeptoolkit.svn.sourceforge.net/viewvc/keeptoolkit?view=rev&amp;revision=56</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0288" published="2009-01-27" name="CVE-2009-0288" modified="2009-01-27" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in k23productions TFTPUtil GUI 1.2.0 and 1.3.0 allows remote attackers to read arbitrary files outside the TFTP root directory via directory traversal sequences in a GET request.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/33287" source="BID" patch="1">33287</ref>
      <ref url="http://sourceforge.net/forum/forum.php?forum_id=894598" source="CONFIRM" patch="1">http://sourceforge.net/forum/forum.php?forum_id=894598</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/48019" source="XF">tftputil-tftpget-directory-traversal(48019)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/500106/100/0/threaded" source="BUGTRAQ">20090115 TFTPUtil GUI TFTP Directory Traversal</ref>
      <ref url="http://www.princeofnigeria.org/blogs/index.php/2009/01/14/tftputil-gui-tftp-directory-traversal" source="MISC">http://www.princeofnigeria.org/blogs/index.php/2009/01/14/tftputil-gui-tftp-directory-traversal</ref>
      <ref url="http://secunia.com/advisories/33561" source="SECUNIA" adv="1">33561</ref>
    </refs>
    <vuln_soft>
      <prod vendor="windows_tftp_utility" name="tftputil">
        <vers num="1.2.0" />
        <vers num="1.3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0289" published="2009-01-27" name="CVE-2009-0289" modified="2009-01-27" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">k23productions TFTPUtil GUI 1.2.0 and 1.3.0 allows remote attackers to cause a denial of service (service crash) via a long filename in a crafted request.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/33289" source="BID" patch="1">33289</ref>
      <ref url="http://sourceforge.net/forum/forum.php?forum_id=894598" source="MISC" patch="1">http://sourceforge.net/forum/forum.php?forum_id=894598</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/500107/100/0/threaded" source="BUGTRAQ">20090115 TFTPUtil GUI TFTP Server Denial of Service Vulnerability</ref>
      <ref url="http://www.princeofnigeria.org/blogs/index.php/2009/01/14/tftputil-gui-tftp-server-denial-of-servi?blog=1" source="MISC">http://www.princeofnigeria.org/blogs/index.php/2009/01/14/tftputil-gui-tftp-server-denial-of-servi?blog=1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="windows_tftp_utility" name="tftputil">
        <vers num="1.2.0" />
        <vers num="1.3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0290" published="2009-01-27" name="CVE-2009-0290" modified="2009-01-27" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Directory traversal vulnerability in common.php in SIR GNUBoard 4.31.03 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the g4_path parameter.  NOTE: in some environments, this can be leveraged for remote code execution via a data: URI or a UNC share pathname.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/48015" source="XF">gnuboard-common-file-include(48015)</ref>
      <ref url="http://www.securityfocus.com/bid/33304" source="BID">33304</ref>
      <ref url="http://www.milw0rm.com/exploits/7792" source="MILW0RM">7792</ref>
      <ref url="http://secunia.com/advisories/33564" source="SECUNIA" adv="1">33564</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sir" name="gnuboard">
        <vers num="4.31.03" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0291" published="2009-01-27" name="CVE-2009-0291" modified="2009-02-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Directory traversal vulnerability in fc.php in OpenX 2.6.3 allows remote attackers to include and execute arbitrary files via a .. (dot dot) in the MAX_type parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/33458" source="BID">33458</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/500411/100/0/threaded" source="BUGTRAQ">20090127 OpenX 2.6.3 - Local File Inclusion</ref>
      <ref url="http://www.milw0rm.com/exploits/7883" source="MILW0RM">7883</ref>
    </refs>
    <vuln_soft>
      <prod vendor="openx" name="openx">
        <vers num="2.6.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0292" published="2009-01-27" name="CVE-2009-0292" modified="2009-02-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in show_cat2.php in SHOP-INET 4 allows remote attackers to execute arbitrary SQL commands via the grid parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.milw0rm.com/exploits/7874" source="MILW0RM">7874</ref>
      <ref url="http://secunia.com/advisories/33660" source="SECUNIA" adv="1">33660</ref>
      <ref url="http://osvdb.org/51615" source="OSVDB">51615</ref>
    </refs>
    <vuln_soft>
      <prod vendor="shop-inet" name="shop-inet">
        <vers num="4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0293" published="2009-01-27" name="CVE-2009-0293" modified="2009-02-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in profile_view.php in Wazzum Dating Software, possibly 2.0, allows remote attackers to execute arbitrary SQL commands via the userid parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/33461" source="BID">33461</ref>
      <ref url="http://www.milw0rm.com/exploits/7877" source="MILW0RM">7877</ref>
      <ref url="http://secunia.com/advisories/33654" source="SECUNIA" adv="1">33654</ref>
      <ref url="http://osvdb.org/51625" source="OSVDB">51625</ref>
    </refs>
    <vuln_soft>
      <prod vendor="wazzum" name="wazzum_dating_software">
        <vers num="_nil_" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0294" published="2009-01-27" name="CVE-2009-0294" modified="2009-01-29" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple PHP remote file inclusion vulnerabilities in WB News 2.0.1, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the config[installdir] parameter to (1) search.php, (2) archive.php, (3) comments.php, and (4) news.php; (5) News.php, (6) SendFriend.php, (7) Archive.php, and (8) Comments.php in base/; and possibly other components, different vectors than CVE-2007-1288.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/33434" source="BID">33434</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/500398/100/0/threaded" source="BUGTRAQ">20090125 WB News v2.0.X Remote File include ..</ref>
      <ref url="http://secunia.com/advisories/33691" source="SECUNIA" adv="1">33691</ref>
    </refs>
    <vuln_soft>
      <prod vendor="webmobo" name="wbnews">
        <vers num="2.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0295" published="2009-01-27" name="CVE-2009-0295" modified="2009-02-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">SQL injection vulnerability in index.php in Information Technology Light Poll Information (ITLPoll) 2.7 Stable 2, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the id parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/33452" source="BID">33452</ref>
      <ref url="http://www.milw0rm.com/exploits/7867" source="MILW0RM">7867</ref>
      <ref url="http://secunia.com/advisories/33666" source="SECUNIA" adv="1">33666</ref>
      <ref url="http://osvdb.org/51616" source="OSVDB">51616</ref>
    </refs>
    <vuln_soft>
      <prod vendor="itlpoll" name="itpoll">
        <vers num="2.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0296" published="2009-01-27" name="CVE-2009-0296" modified="2009-02-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in shop_display_products.php in Script Toko Online 5.01 allows remote attackers to execute arbitrary SQL commands via the cat_id parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.milw0rm.com/exploits/7873" source="MILW0RM">7873</ref>
      <ref url="http://secunia.com/advisories/33661" source="SECUNIA" adv="1">33661</ref>
      <ref url="http://osvdb.org/51630" source="OSVDB">51630</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gempar" name="script_toko_online">
        <vers num="5.01" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0297" published="2009-01-27" name="CVE-2009-0297" modified="2009-02-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in login_check.asp in ClickAuction allows remote attackers to execute arbitrary SQL commands via the (1) txtEmail and (2) txtPassword parameters.  NOTE: some of these details are obtained from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.milw0rm.com/exploits/7880" source="MILW0RM">7880</ref>
      <ref url="http://secunia.com/advisories/33647" source="SECUNIA" adv="1">33647</ref>
      <ref url="http://osvdb.org/51626" source="OSVDB">51626</ref>
    </refs>
    <vuln_soft>
      <prod vendor="clicktech" name="clickauction">
        <vers num="_nil_" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0298" published="2009-01-27" name="CVE-2009-0298" modified="2009-01-29" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Heap-based buffer overflow in MW6 Technologies Barcode ActiveX control (Barcode.MW6Barcode.1, Barcode.dll) 3.0.0.1 allows remote attackers to execute arbitrary code via a long Supplement property.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/33451" source="BID">33451</ref>
      <ref url="http://www.milw0rm.com/exploits/7869" source="MILW0RM">7869</ref>
      <ref url="http://secunia.com/advisories/33663" source="SECUNIA" adv="1">33663</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mw6_technologies" name="barcode_activex">
        <vers num="3.0.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0299" published="2009-01-27" name="CVE-2009-0299" modified="2009-10-03" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in index.php in Groone GLinks 2.1 allows remote attackers to execute arbitrary SQL commands via the cat parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/33460" source="BID">33460</ref>
      <ref url="http://www.milw0rm.com/exploits/9236" source="MILW0RM">9236</ref>
      <ref url="http://www.milw0rm.com/exploits/7878" source="MILW0RM">7878</ref>
      <ref url="http://secunia.com/advisories/33649" source="SECUNIA" adv="1">33649</ref>
      <ref url="http://osvdb.org/51628" source="OSVDB">51628</ref>
    </refs>
    <vuln_soft>
      <prod vendor="groonesworld" name="glinks">
        <vers num="2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" seq="2009-0300" reject="1" published="2009-01-27" name="CVE-2009-0300" modified="2009-01-29">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2006-2636.  Reason: This candidate is a duplicate of CVE-2006-2636.  Notes: All CVE users should reference CVE-2006-2636 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript>
    </desc>
    <refs />
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0301" published="2009-01-27" name="CVE-2009-0301" modified="2009-01-28" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple insecure method vulnerabilities in the FlexCell.Grid ActiveX control (FlexCell.ocx) in FlexCell Grid Control 5.6.9 allow remote attackers to create and overwrite arbitrary files via the (1) SaveFile and (2) ExportToXML methods.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/33453" source="BID">33453</ref>
      <ref url="http://www.milw0rm.com/exploits/7868" source="MILW0RM">7868</ref>
      <ref url="http://secunia.com/advisories/33664" source="SECUNIA" adv="1">33664</ref>
    </refs>
    <vuln_soft>
      <prod vendor="grid2000" name="flexcell_grid_control">
        <vers num="5.6.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0302" published="2009-01-27" name="CVE-2009-0302" modified="2009-02-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:S/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">SQL injection vulnerability in the Downloads 8.0 module for PHP-Nuke, when register_globals is enabled and magic_quotes_gpc is disabled, allows remote authenticated users to execute arbitrary SQL commands via the url parameter in the Add operation to modules.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/48186" source="XF">downloads-module-sql-injection(48186)</ref>
      <ref url="http://www.securityfocus.com/bid/33410" source="BID">33410</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/500335/100/0/threaded" source="BUGTRAQ">20090123 PHP-Nuke 8.0 Downloads Blind Sql Injection</ref>
      <ref url="http://osvdb.org/51633" source="OSVDB">51633</ref>
    </refs>
    <vuln_soft>
      <prod vendor="php-nuke" name="downloads_module">
        <vers num="8.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0303" published="2009-01-27" name="CVE-2009-0303" modified="2009-01-28" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Web Help Desk before 9.1.18 allows remote attackers to inject arbitrary web script or HTML via vectors related to "encoded JavaScript" and Helpdesk.woa.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/33429" source="BID">33429</ref>
      <ref url="http://updates.webhelpdesk.com/weblog/updates/StableReleases/2009/01/23/911812309.html" source="CONFIRM" adv="1">http://updates.webhelpdesk.com/weblog/updates/StableReleases/2009/01/23/911812309.html</ref>
      <ref url="http://secunia.com/advisories/33651" source="SECUNIA" adv="1">33651</ref>
    </refs>
    <vuln_soft>
      <prod vendor="webhelpdesk" name="web_help_desk">
        <vers num="8.0.20" />
        <vers num="8.0.21" />
        <vers num="8.0.22" />
        <vers num="8.2.0" />
        <vers num="8.2.0.1" />
        <vers num="8.2.0.10" />
        <vers num="8.2.0.2" />
        <vers num="8.2.0.3" />
        <vers num="8.2.0.4" />
        <vers num="8.2.0.5" />
        <vers num="8.2.0.6" />
        <vers num="8.2.0.7" />
        <vers num="8.2.0.8" />
        <vers num="8.2.0.9" />
        <vers num="8.2.1.1" />
        <vers num="8.2.1.2" />
        <vers num="8.2.1.3" />
        <vers num="8.2.1.4" />
        <vers num="8.2.1.5" />
        <vers num="8.2.2" />
        <vers num="8.2.3" />
        <vers num="8.2.3.1" />
        <vers num="8.2.3.2" />
        <vers num="8.2.3.3" />
        <vers num="8.2.3.4" />
        <vers num="8.2.4" />
        <vers num="8.2.4.1" />
        <vers num="8.2.4.2" />
        <vers num="8.2.4.3" />
        <vers num="8.3.0.1" />
        <vers num="8.3.0.2" />
        <vers num="8.3.0.3" />
        <vers num="8.3.0.4" />
        <vers num="8.3.0.5" />
        <vers num="8.3.1" />
        <vers num="8.3.1.1" />
        <vers num="8.3.1.2" />
        <vers num="8.3.1.3" />
        <vers num="8.3.2" />
        <vers num="8.3.3" />
        <vers num="8.3.3.1" />
        <vers num="8.3.3.2" />
        <vers num="8.3.3.3" />
        <vers num="8.3.3.4" />
        <vers num="8.3.4.0" />
        <vers num="8.3.4.1" />
        <vers num="8.3.4.2" />
        <vers num="8.3.5.1" />
        <vers num="8.3.5.2" />
        <vers num="8.3.5.3" />
        <vers num="8.3.5.4" />
        <vers num="8.3.5.5" />
        <vers num="8.3.5.6" />
        <vers num="8.3.6" />
        <vers num="8.3.6.1" />
        <vers num="8.4.1.0" />
        <vers num="8.4.1.1" />
        <vers num="8.4.1.2" />
        <vers num="8.4.1.3" />
        <vers num="8.4.1.4" />
        <vers num="8.4.1.5" />
        <vers num="8.4.1.6" />
        <vers num="8.4.1.7" />
        <vers num="8.4.1.8" />
        <vers num="8.4.1.9" />
        <vers num="8.4.2.0" />
        <vers num="8.4.2.1" />
        <vers num="8.4.2.2" />
        <vers num="8.4.2.3" />
        <vers num="8.4.3.0" />
        <vers num="8.4.3.1" />
        <vers num="8.4.3.2" />
        <vers num="8.4.3.3" />
        <vers num="8.4.3.4" />
        <vers num="8.4.3.5" />
        <vers num="8.4.3.6" />
        <vers num="8.4.3.7" />
        <vers num="8.4.4" />
        <vers num="8.4.5" />
        <vers num="8.4.5.1" />
        <vers num="8.4.5.2" />
        <vers num="8.4.6.0" />
        <vers num="8.4.6.1" />
        <vers num="8.4.6.10" />
        <vers num="8.4.6.2" />
        <vers num="8.4.6.3" />
        <vers num="8.4.6.4" />
        <vers num="8.4.6.5" />
        <vers num="8.4.6.6" />
        <vers num="8.4.6.7" />
        <vers num="8.4.6.8" />
        <vers num="9.1.0" />
        <vers num="9.1.1" />
        <vers num="9.1.10" />
        <vers num="9.1.11" />
        <vers num="9.1.12" />
        <vers num="9.1.13" />
        <vers num="9.1.14" />
        <vers num="9.1.15" />
        <vers num="9.1.16" />
        <vers prev="1" num="9.1.17" />
        <vers num="9.1.2" />
        <vers num="9.1.4" />
        <vers num="9.1.5" />
        <vers num="9.1.6" />
        <vers num="9.1.7" />
        <vers num="9.1.8" />
        <vers num="9.1.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0304" published="2009-01-27" name="CVE-2009-0304" modified="2012-02-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">The kernel in Sun Solaris 10 and 11 snv_101b, and OpenSolaris before snv_108, allows remote attackers to cause a denial of service (system crash) via a crafted IPv6 packet, related to an "insufficient validation security vulnerability," as demonstrated by SunOSipv6.c.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/48208" source="XF">sun-solaris-ipv6packets-dos(48208)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0232" source="VUPEN" adv="1">ADV-2009-0232</ref>
      <ref url="http://www.securityfocus.com/bid/33435" source="BID">33435</ref>
      <ref url="http://www.milw0rm.com/exploits/7865" source="MILW0RM">7865</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-251006-1" source="SUNALERT" adv="1">251006</ref>
      <ref url="http://securitytracker.com/id?1021635" source="SECTRACK">1021635</ref>
      <ref url="http://secunia.com/advisories/33605" source="SECUNIA" adv="1">33605</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2009-January/067709.html" source="FULLDISC">20090126 Solaris Devs Are Smoking Pot</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="opensolaris">
        <vers num="snv_01" edition="" />
        <vers num="snv_01" edition=":sparc" />
        <vers num="snv_01" edition=":x86" />
        <vers num="snv_02" edition="" />
        <vers num="snv_02" edition=":sparc" />
        <vers num="snv_02" edition=":x86" />
        <vers num="snv_03" edition="" />
        <vers num="snv_03" edition=":x86" />
        <vers num="snv_03" edition=":sparc" />
        <vers num="snv_04" edition="" />
        <vers num="snv_04" edition=":x86" />
        <vers num="snv_04" edition=":sparc" />
        <vers num="snv_05" edition="" />
        <vers num="snv_05" edition=":sparc" />
        <vers num="snv_05" edition=":x86" />
        <vers num="snv_06" edition="" />
        <vers num="snv_06" edition=":sparc" />
        <vers num="snv_06" edition=":x86" />
        <vers num="snv_07" edition="" />
        <vers num="snv_07" edition=":sparc" />
        <vers num="snv_07" edition=":x86" />
        <vers num="snv_08" edition="" />
        <vers num="snv_08" edition=":x86" />
        <vers num="snv_08" edition=":sparc" />
        <vers num="snv_09" edition="" />
        <vers num="snv_09" edition=":x86" />
        <vers num="snv_09" edition=":sparc" />
        <vers num="snv_10" edition="" />
        <vers num="snv_10" edition=":x86" />
        <vers num="snv_10" edition=":sparc" />
        <vers num="snv_100" edition="" />
        <vers num="snv_100" edition=":sparc" />
        <vers num="snv_100" edition=":x86" />
        <vers num="snv_101" edition="" />
        <vers num="snv_101" edition=":x86" />
        <vers num="snv_101" edition=":sparc" />
        <vers num="snv_101b" />
        <vers num="snv_102" edition="" />
        <vers num="snv_102" edition=":sparc" />
        <vers num="snv_102" edition=":x86" />
        <vers num="snv_103" edition="" />
        <vers num="snv_103" edition=":x86" />
        <vers num="snv_103" edition=":sparc" />
        <vers num="snv_104" edition="" />
        <vers num="snv_104" edition=":x86" />
        <vers num="snv_104" edition=":sparc" />
        <vers num="snv_105" edition="" />
        <vers num="snv_105" edition=":x86" />
        <vers num="snv_105" edition=":sparc" />
        <vers num="snv_106" edition="" />
        <vers num="snv_106" edition=":sparc" />
        <vers num="snv_106" edition=":x86" />
        <vers prev="1" num="snv_107" edition="" />
        <vers prev="1" num="snv_107" edition=":x86" />
        <vers prev="1" num="snv_107" edition=":sparc" />
        <vers num="snv_11" edition="" />
        <vers num="snv_11" edition=":x86" />
        <vers num="snv_11" edition=":sparc" />
        <vers num="snv_12" edition="" />
        <vers num="snv_12" edition=":x86" />
        <vers num="snv_12" edition=":sparc" />
        <vers num="snv_13" edition="" />
        <vers num="snv_13" edition=":x86" />
        <vers num="snv_13" edition=":sparc" />
        <vers num="snv_14" edition="" />
        <vers num="snv_14" edition=":sparc" />
        <vers num="snv_14" edition=":x86" />
        <vers num="snv_15" edition="" />
        <vers num="snv_15" edition=":x86" />
        <vers num="snv_15" edition=":sparc" />
        <vers num="snv_16" edition="" />
        <vers num="snv_16" edition=":sparc" />
        <vers num="snv_16" edition=":x86" />
        <vers num="snv_17" edition="" />
        <vers num="snv_17" edition=":x86" />
        <vers num="snv_17" edition=":sparc" />
        <vers num="snv_18" edition="" />
        <vers num="snv_18" edition=":x86" />
        <vers num="snv_18" edition=":sparc" />
        <vers num="snv_19" edition="" />
        <vers num="snv_19" edition=":sparc" />
        <vers num="snv_19" edition=":x86" />
        <vers num="snv_20" edition="" />
        <vers num="snv_20" edition=":x86" />
        <vers num="snv_20" edition=":sparc" />
        <vers num="snv_21" edition="" />
        <vers num="snv_21" edition=":sparc" />
        <vers num="snv_21" edition=":x86" />
        <vers num="snv_22" edition="" />
        <vers num="snv_22" edition=":sparc" />
        <vers num="snv_22" edition=":x86" />
        <vers num="snv_23" edition="" />
        <vers num="snv_23" edition=":sparc" />
        <vers num="snv_23" edition=":x86" />
        <vers num="snv_24" edition="" />
        <vers num="snv_24" edition=":sparc" />
        <vers num="snv_24" edition=":x86" />
        <vers num="snv_25" edition="" />
        <vers num="snv_25" edition=":x86" />
        <vers num="snv_25" edition=":sparc" />
        <vers num="snv_26" edition="" />
        <vers num="snv_26" edition=":x86" />
        <vers num="snv_26" edition=":sparc" />
        <vers num="snv_27" edition="" />
        <vers num="snv_27" edition=":sparc" />
        <vers num="snv_27" edition=":x86" />
        <vers num="snv_28" edition="" />
        <vers num="snv_28" edition=":x86" />
        <vers num="snv_28" edition=":sparc" />
        <vers num="snv_29" edition="" />
        <vers num="snv_29" edition=":x86" />
        <vers num="snv_29" edition=":sparc" />
        <vers num="snv_30" edition="" />
        <vers num="snv_30" edition=":sparc" />
        <vers num="snv_30" edition=":x86" />
        <vers num="snv_31" edition="" />
        <vers num="snv_31" edition=":sparc" />
        <vers num="snv_31" edition=":x86" />
        <vers num="snv_32" edition="" />
        <vers num="snv_32" edition=":x86" />
        <vers num="snv_32" edition=":sparc" />
        <vers num="snv_33" edition="" />
        <vers num="snv_33" edition=":x86" />
        <vers num="snv_33" edition=":sparc" />
        <vers num="snv_34" edition="" />
        <vers num="snv_34" edition=":sparc" />
        <vers num="snv_34" edition=":x86" />
        <vers num="snv_35" edition="" />
        <vers num="snv_35" edition=":sparc" />
        <vers num="snv_35" edition=":x86" />
        <vers num="snv_36" edition="" />
        <vers num="snv_36" edition=":x86" />
        <vers num="snv_36" edition=":sparc" />
        <vers num="snv_37" edition="" />
        <vers num="snv_37" edition=":sparc" />
        <vers num="snv_37" edition=":x86" />
        <vers num="snv_38" edition="" />
        <vers num="snv_38" edition=":sparc" />
        <vers num="snv_38" edition=":x86" />
        <vers num="snv_39" edition="" />
        <vers num="snv_39" edition=":sparc" />
        <vers num="snv_39" edition=":x86" />
        <vers num="snv_40" edition="" />
        <vers num="snv_40" edition=":sparc" />
        <vers num="snv_40" edition=":x86" />
        <vers num="snv_41" edition="" />
        <vers num="snv_41" edition=":sparc" />
        <vers num="snv_41" edition=":x86" />
        <vers num="snv_42" edition="" />
        <vers num="snv_42" edition=":x86" />
        <vers num="snv_42" edition=":sparc" />
        <vers num="snv_43" edition="" />
        <vers num="snv_43" edition=":sparc" />
        <vers num="snv_43" edition=":x86" />
        <vers num="snv_44" edition="" />
        <vers num="snv_44" edition=":x86" />
        <vers num="snv_44" edition=":sparc" />
        <vers num="snv_45" edition="" />
        <vers num="snv_45" edition=":x86" />
        <vers num="snv_45" edition=":sparc" />
        <vers num="snv_46" edition="" />
        <vers num="snv_46" edition=":x86" />
        <vers num="snv_46" edition=":sparc" />
        <vers num="snv_47" edition="" />
        <vers num="snv_47" edition=":x86" />
        <vers num="snv_47" edition=":sparc" />
        <vers num="snv_48" edition="" />
        <vers num="snv_48" edition=":sparc" />
        <vers num="snv_48" edition=":x86" />
        <vers num="snv_49" edition="" />
        <vers num="snv_49" edition=":sparc" />
        <vers num="snv_49" edition=":x86" />
        <vers num="snv_50" edition="" />
        <vers num="snv_50" edition=":sparc" />
        <vers num="snv_50" edition=":x86" />
        <vers num="snv_51" edition="" />
        <vers num="snv_51" edition=":sparc" />
        <vers num="snv_51" edition=":x86" />
        <vers num="snv_52" edition="" />
        <vers num="snv_52" edition=":sparc" />
        <vers num="snv_52" edition=":x86" />
        <vers num="snv_53" edition="" />
        <vers num="snv_53" edition=":sparc" />
        <vers num="snv_53" edition=":x86" />
        <vers num="snv_54" edition="" />
        <vers num="snv_54" edition=":x86" />
        <vers num="snv_54" edition=":sparc" />
        <vers num="snv_55" edition="" />
        <vers num="snv_55" edition=":sparc" />
        <vers num="snv_55" edition=":x86" />
        <vers num="snv_56" edition="" />
        <vers num="snv_56" edition=":x86" />
        <vers num="snv_56" edition=":sparc" />
        <vers num="snv_57" edition="" />
        <vers num="snv_57" edition=":x86" />
        <vers num="snv_57" edition=":sparc" />
        <vers num="snv_58" edition="" />
        <vers num="snv_58" edition=":sparc" />
        <vers num="snv_58" edition=":x86" />
        <vers num="snv_59" edition="" />
        <vers num="snv_59" edition=":sparc" />
        <vers num="snv_59" edition=":x86" />
        <vers num="snv_60" edition="" />
        <vers num="snv_60" edition=":x86" />
        <vers num="snv_60" edition=":sparc" />
        <vers num="snv_61" edition="" />
        <vers num="snv_61" edition=":sparc" />
        <vers num="snv_61" edition=":x86" />
        <vers num="snv_62" edition="" />
        <vers num="snv_62" edition=":x86" />
        <vers num="snv_62" edition=":sparc" />
        <vers num="snv_63" edition="" />
        <vers num="snv_63" edition=":sparc" />
        <vers num="snv_63" edition=":x86" />
        <vers num="snv_64" edition="" />
        <vers num="snv_64" edition=":x86" />
        <vers num="snv_64" edition=":sparc" />
        <vers num="snv_65" edition="" />
        <vers num="snv_65" edition=":x86" />
        <vers num="snv_65" edition=":sparc" />
        <vers num="snv_66" edition="" />
        <vers num="snv_66" edition=":x86" />
        <vers num="snv_66" edition=":sparc" />
        <vers num="snv_67" edition="" />
        <vers num="snv_67" edition=":sparc" />
        <vers num="snv_67" edition=":x86" />
        <vers num="snv_68" edition="" />
        <vers num="snv_68" edition=":x86" />
        <vers num="snv_68" edition=":sparc" />
        <vers num="snv_69" edition="" />
        <vers num="snv_69" edition=":sparc" />
        <vers num="snv_69" edition=":x86" />
        <vers num="snv_70" edition="" />
        <vers num="snv_70" edition=":sparc" />
        <vers num="snv_70" edition=":x86" />
        <vers num="snv_71" edition="" />
        <vers num="snv_71" edition=":x86" />
        <vers num="snv_71" edition=":sparc" />
        <vers num="snv_72" edition="" />
        <vers num="snv_72" edition=":x86" />
        <vers num="snv_72" edition=":sparc" />
        <vers num="snv_73" edition="" />
        <vers num="snv_73" edition=":x86" />
        <vers num="snv_73" edition=":sparc" />
        <vers num="snv_74" edition="" />
        <vers num="snv_74" edition=":sparc" />
        <vers num="snv_74" edition=":x86" />
        <vers num="snv_75" edition="" />
        <vers num="snv_75" edition=":sparc" />
        <vers num="snv_75" edition=":x86" />
        <vers num="snv_76" edition="" />
        <vers num="snv_76" edition=":x86" />
        <vers num="snv_76" edition=":sparc" />
        <vers num="snv_77" edition="" />
        <vers num="snv_77" edition=":sparc" />
        <vers num="snv_77" edition=":x86" />
        <vers num="snv_78" edition="" />
        <vers num="snv_78" edition=":sparc" />
        <vers num="snv_78" edition=":x86" />
        <vers num="snv_79" edition="" />
        <vers num="snv_79" edition=":x86" />
        <vers num="snv_79" edition=":sparc" />
        <vers num="snv_80" edition="" />
        <vers num="snv_80" edition=":x86" />
        <vers num="snv_80" edition=":sparc" />
        <vers num="snv_81" edition="" />
        <vers num="snv_81" edition=":x86" />
        <vers num="snv_81" edition=":sparc" />
        <vers num="snv_82" edition="" />
        <vers num="snv_82" edition=":x86" />
        <vers num="snv_82" edition=":sparc" />
        <vers num="snv_83" edition="" />
        <vers num="snv_83" edition=":x86" />
        <vers num="snv_83" edition=":sparc" />
        <vers num="snv_84" edition="" />
        <vers num="snv_84" edition=":x86" />
        <vers num="snv_84" edition=":sparc" />
        <vers num="snv_85" edition="" />
        <vers num="snv_85" edition=":x86" />
        <vers num="snv_85" edition=":sparc" />
        <vers num="snv_86" edition="" />
        <vers num="snv_86" edition=":sparc" />
        <vers num="snv_86" edition=":x86" />
        <vers num="snv_87" edition="" />
        <vers num="snv_87" edition=":sparc" />
        <vers num="snv_87" edition=":x86" />
        <vers num="snv_88" edition="" />
        <vers num="snv_88" edition=":x86" />
        <vers num="snv_88" edition=":sparc" />
        <vers num="snv_89" edition="" />
        <vers num="snv_89" edition=":x86" />
        <vers num="snv_89" edition=":sparc" />
        <vers num="snv_90" edition="" />
        <vers num="snv_90" edition=":sparc" />
        <vers num="snv_90" edition=":x86" />
        <vers num="snv_91" edition="" />
        <vers num="snv_91" edition=":sparc" />
        <vers num="snv_91" edition=":x86" />
        <vers num="snv_92" edition="" />
        <vers num="snv_92" edition=":sparc" />
        <vers num="snv_92" edition=":x86" />
        <vers num="snv_93" edition="" />
        <vers num="snv_93" edition=":sparc" />
        <vers num="snv_93" edition=":x86" />
        <vers num="snv_94" edition="" />
        <vers num="snv_94" edition=":x86" />
        <vers num="snv_94" edition=":sparc" />
        <vers num="snv_95" edition="" />
        <vers num="snv_95" edition=":x86" />
        <vers num="snv_95" edition=":sparc" />
        <vers num="snv_96" edition="" />
        <vers num="snv_96" edition=":sparc" />
        <vers num="snv_96" edition=":x86" />
        <vers num="snv_97" edition="" />
        <vers num="snv_97" edition=":x86" />
        <vers num="snv_97" edition=":sparc" />
        <vers num="snv_98" edition="" />
        <vers num="snv_98" edition=":sparc" />
        <vers num="snv_98" edition=":x86" />
        <vers num="snv_99" edition="" />
        <vers num="snv_99" edition=":sparc" />
        <vers num="snv_99" edition=":x86" />
      </prod>
      <prod vendor="sun" name="solaris">
        <vers num="10" edition="" />
        <vers num="10" edition=":sparc" />
        <vers num="10" edition=":x86" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0305" published="2009-02-10" name="CVE-2009-0305" modified="2009-02-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Multiple stack-based buffer overflows in the Research in Motion RIM AxLoader ActiveX control in AxLoader.ocx and AxLoader.dll in BlackBerry Application Web Loader 1.0 allow remote attackers to execute arbitrary code via unspecified use of the (1) load or (2) loadJad method.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/131100" source="CERT-VN">VU#131100</ref>
      <ref url="http://blackberry.com/btsc/KB16248" source="CONFIRM" patch="1" adv="1">http://blackberry.com/btsc/KB16248</ref>
      <ref url="http://www.securityfocus.com/bid/33663" source="BID">33663</ref>
      <ref url="http://www.microsoft.com/technet/security/advisory/960715.mspx" source="CONFIRM">http://www.microsoft.com/technet/security/advisory/960715.mspx</ref>
      <ref url="http://secunia.com/advisories/33847" source="SECUNIA" adv="1">33847</ref>
      <ref url="http://osvdb.org/51833" source="OSVDB">51833</ref>
    </refs>
    <vuln_soft>
      <prod vendor="research_in_motion_limited" name="blackberry_application_web_loader">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0306" published="2009-11-04" name="CVE-2009-0306" modified="2009-11-12" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Buffer overflow in the IBM Lotus Notes Intellisync ActiveX control in lnresobject.dll in BlackBerry Desktop Manager in Research In Motion (RIM) BlackBerry Desktop Software before 5.0.1 allows remote attackers to execute arbitrary code via a crafted web page.  NOTE: some of these details are obtained from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2009/3133" source="VUPEN" patch="1" adv="1">ADV-2009-3133</ref>
      <ref url="http://www.blackberry.com/btsc/search.do?cmd=displayKC&amp;docType=kc&amp;externalId=KB19701" source="CONFIRM" patch="1" adv="1">http://www.blackberry.com/btsc/search.do?cmd=displayKC&amp;docType=kc&amp;externalId=KB19701</ref>
      <ref url="http://www.securityfocus.com/bid/36903" source="BID">36903</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="lotus_notes_intellisync">
        <vers num="" />
      </prod>
      <prod vendor="rim" name="blackberry_desktop_software">
        <vers prev="1" num="5.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0307" published="2009-04-22" name="CVE-2009-0307" modified="2009-04-28" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the "Customize Statistics Page" (admin/statistics/ConfigureStatistics) in the MDS Connection Service in Research in Motion (RIM) BlackBerry Enterprise Server (BES) before 4.1.6 MR5 allows remote attackers to inject arbitrary web script or HTML via the (1) customDate, (2) interval, (3) lastCustomInterval, (4) lastIntervalLength, (5) nextCustomInterval, (6) nextIntervalLength, (7) action, (8) delIntervalIndex, (9) addStatIndex, (10) delStatIndex, and (11) referenceTime parameters.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2009/1090" source="VUPEN">ADV-2009-1090</ref>
      <ref url="http://www.securitytracker.com/id?1022081" source="SECTRACK">1022081</ref>
      <ref url="http://www.securityfocus.com/bid/34573" source="BID">34573</ref>
      <ref url="http://www.blackberry.com/btsc/dynamickc.do?externalId=KB17969&amp;sliceID=1&amp;command=show&amp;forward=nonthreadedKC&amp;kcId=KB17969" source="CONFIRM" adv="1">http://www.blackberry.com/btsc/dynamickc.do?externalId=KB17969&amp;sliceID=1&amp;command=show&amp;forward=nonthreadedKC&amp;kcId=KB17969</ref>
      <ref url="http://secunia.com/advisories/34740" source="SECUNIA" adv="1">34740</ref>
      <ref url="http://osvdb.org/53772" source="OSVDB">53772</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2009-04/0170.html" source="FULLDISC">20090417 ERNW Security Advisory 01-2009: XSS in Blackberries Mobile Data Service Connection Service</ref>
    </refs>
    <vuln_soft>
      <prod vendor="rim" name="blackberry_enterprise_server">
        <vers num="4.0" edition="sp3" />
        <vers num="4.0.3" />
        <vers num="4.1" edition="sp3" />
        <vers num="4.1.3" />
        <vers num="4.1.4" />
        <vers num="4.1.5" />
        <vers prev="1" num="4.1.6" edition="mr4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0310" published="2009-02-18" name="CVE-2009-0310" modified="2009-03-13" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in SUSE blinux (aka sbl) in SUSE openSUSE 10.3 through 11.0 has unknown impact and attack vectors related to "incoming data and authentication-strings."</descript>
      <descript source="nvd">Following information confirms LOCAL Access Vector reported in Hyperlink Record 1058524:

http://xforce.iss.net/xforce/xfdb/48797

The SUSE blinux (sbl) package is vulnerable to a buffer overflow. By sending a specially-crafted request, a local attacker could overflow a buffer and execute arbitrary code on the system or cause the application to crash.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/48797" source="XF">suse-blinux-bo(48797)</ref>
      <ref url="http://www.securityfocus.com/bid/33794" source="BID">33794</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-02/msg00002.html" source="SUSE" adv="1">SUSE-SR:2009:004</ref>
    </refs>
    <vuln_soft>
      <prod vendor="novell" name="opensuse">
        <vers num="10.3" />
        <vers num="11.0" />
      </prod>
      <prod vendor="opensuse" name="opensuse">
        <vers num="10.3" />
        <vers num="11.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0311" published="2009-01-27" name="CVE-2009-0311" modified="2009-01-28" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">The Backbone service (ftbackbone.exe) in EMC AutoStart before 5.3 SP2 allows remote attackers to execute arbitrary code via a packet with a crafted value that is dereferenced as a function pointer.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://zerodayinitiative.com/advisories/ZDI-09-009/" source="MISC">http://zerodayinitiative.com/advisories/ZDI-09-009/</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/48197" source="XF">autostart-backbone-code-execution(48197)</ref>
      <ref url="http://www.securitytracker.com/id?1021636" source="SECTRACK">1021636</ref>
      <ref url="http://www.securityfocus.com/bid/33415" source="BID">33415</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/500350/100/0/threaded" source="BUGTRAQ">20090123 ZDI-09-009: EMC AutoStart Backbone Engine Trusted Pointer Code Execution Vulnerability</ref>
      <ref url="http://secunia.com/advisories/33667" source="SECUNIA" adv="1">33667</ref>
      <ref url="http://osvdb.org/51566" source="OSVDB">51566</ref>
    </refs>
    <vuln_soft>
      <prod vendor="emc" name="autostart">
        <vers prev="1" num="5.3" edition="sp1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0312" published="2009-01-27" name="CVE-2009-0312" modified="2009-02-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the antispam feature (security/antispam.py) in MoinMoin 1.7 and 1.8.1 allows remote attackers to inject arbitrary web script or HTML via crafted, disallowed content.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/48306" source="XF">moinmoin-antispam-xss(48306)</ref>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-716-1" source="UBUNTU">USN-716-1</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2009/01/27/4" source="MLIST">[oss-security] 20090127 CVE Request: MoinMoin</ref>
      <ref url="http://secunia.com/advisories/33755" source="SECUNIA">33755</ref>
      <ref url="http://secunia.com/advisories/33716" source="SECUNIA">33716</ref>
      <ref url="http://osvdb.org/51632" source="OSVDB">51632</ref>
      <ref url="http://moinmo.in/SecurityFixes#moin1.8.1" source="CONFIRM" adv="1">http://moinmo.in/SecurityFixes#moin1.8.1</ref>
      <ref url="http://lists.debian.org/debian-security-announce/2009/msg00023.html" source="DEBIAN">DSA-1715</ref>
      <ref url="http://hg.moinmo.in/moin/1.8/rev/89b91bf87dad" source="CONFIRM">http://hg.moinmo.in/moin/1.8/rev/89b91bf87dad</ref>
      <ref url="http://hg.moinmo.in/moin/1.7/rev/89b91bf87dad" source="CONFIRM">http://hg.moinmo.in/moin/1.7/rev/89b91bf87dad</ref>
    </refs>
    <vuln_soft>
      <prod vendor="moinmoin" name="moinmoin">
        <vers num="1.7.0" />
        <vers num="1.8.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0313" published="2009-01-27" name="CVE-2009-0313" modified="2009-02-20" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="6.9" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.4" CVSS_base_score="6.9">
    <desc>
      <descript source="cve">winetricks before 20081223 allows local users to overwrite arbitrary files via a symlink attack on the x_showmenu.txt temporary file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/48320" source="XF">winetricks-xshowmenu-symlink(48320)</ref>
      <ref url="http://www.securityfocus.com/bid/33474" source="BID">33474</ref>
      <ref url="http://osvdb.org/51619" source="OSVDB">51619</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-02/msg00002.html" source="SUSE">SUSE-SR:2009:004</ref>
      <ref url="http://code.google.com/p/winezeug/source/detail?r=253" source="CONFIRM">http://code.google.com/p/winezeug/source/detail?r=253</ref>
    </refs>
    <vuln_soft>
      <prod vendor="kegel" name="winetricks">
        <vers num="20081127" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0314" published="2009-01-28" name="CVE-2009-0314" modified="2011-09-12" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="6.9" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.4" CVSS_base_score="6.9">
    <desc>
      <descript source="cve">Untrusted search path vulnerability in the Python module in gedit allows local users to execute arbitrary code via a Trojan horse Python file in the current working directory, related to a vulnerability in the PySys_SetArgv function (CVE-2008-5983).</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-January/msg01195.html" source="FEDORA">FEDORA-2009-1189</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=481556" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=481556</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/48271" source="XF">gedit-pysyssetargv-privilege-escalation(48271)</ref>
      <ref url="http://www.securityfocus.com/bid/33445" source="BID">33445</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2009/01/26/2" source="MLIST">[oss-security] 20090126 CVE request -- Python &lt; 2.6 PySys_SetArgv issues (epiphany, csound, dia, eog, gedit, xchat, vim, nautilus-python, Gnumeric)</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:039" source="MANDRIVA">MDVSA-2009:039</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200903-41.xml" source="GENTOO">GLSA-200903-41</ref>
      <ref url="http://secunia.com/advisories/34522" source="SECUNIA">34522</ref>
      <ref url="http://secunia.com/advisories/33769" source="SECUNIA">33769</ref>
      <ref url="http://secunia.com/advisories/33759" source="SECUNIA">33759</ref>
      <ref url="http://bugzilla.gnome.org/show_bug.cgi?id=569214" source="MISC">http://bugzilla.gnome.org/show_bug.cgi?id=569214</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gnome" name="gedit">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0315" published="2009-01-28" name="CVE-2009-0315" modified="2009-03-06" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="6.9" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.4" CVSS_base_score="6.9">
    <desc>
      <descript source="cve">Untrusted search path vulnerability in the Python module in xchat allows local users to execute arbitrary code via a Trojan horse Python file in the current working directory, related to a vulnerability in the PySys_SetArgv function (CVE-2008-5983).</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=481560" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=481560</ref>
      <ref url="http://www.securityfocus.com/bid/33444" source="BID">33444</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2009/01/26/2" source="MLIST">[oss-security] 20090126 CVE request -- Python &lt; 2.6 PySys_SetArgv issues (epiphany, csound, dia, eog, gedit, xchat, vim, nautilus-python, Gnumeric)</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:059" source="MANDRIVA">MDVSA-2009:059</ref>
    </refs>
    <vuln_soft>
      <prod vendor="xchat" name="xchat">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0316" published="2009-01-28" name="CVE-2009-0316" modified="2010-04-01" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="6.9" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.4" CVSS_base_score="6.9">
    <desc>
      <descript source="cve">Untrusted search path vulnerability in src/if_python.c in the Python interface in Vim before 7.2.045 allows local users to execute arbitrary code via a Trojan horse Python file in the current working directory, related to a vulnerability in the PySys_SetArgv function (CVE-2008-5983), as demonstrated by an erroneous search path for plugin/bike.vim in bicyclerepair.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="https://svn.pardus.org.tr/pardus/2008/applications/editors/vim/files/official/7.2.045" source="CONFIRM">https://svn.pardus.org.tr/pardus/2008/applications/editors/vim/files/official/7.2.045</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=481565" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=481565</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/48275" source="XF">vim-pysyssetargv-privilege-escalation(48275)</ref>
      <ref url="http://www.securityfocus.com/bid/33447" source="BID">33447</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2009/01/26/2" source="MLIST">[oss-security] 20090126 CVE request -- Python &lt; 2.6 PySys_SetArgv issues (epiphany, csound, dia, eog, gedit, xchat, vim, nautilus-python, Gnumeric)</ref>
      <ref url="http://www.nabble.com/Bug-484305%3A-bicyclerepair%3A-bike.vim-imports-untrusted-python-files-from-cwd-td18848099.html" source="MLIST">[debian-bugs-rc] 20080805 Bug#484305: bicyclerepair: bike.vim imports untrusted python files from cwd</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:047" source="MANDRIVA">MDVSA-2009:047</ref>
      <ref url="http://support.apple.com/kb/HT4077" source="CONFIRM">http://support.apple.com/kb/HT4077</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Mar/msg00001.html" source="APPLE">APPLE-SA-2010-03-29-1</ref>
      <ref url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=493937" source="CONFIRM">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=493937</ref>
      <ref url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=484305" source="MISC">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=484305</ref>
    </refs>
    <vuln_soft>
      <prod vendor="vim" name="vim">
        <vers num="1.0" />
        <vers num="1.22" />
        <vers num="3.0" />
        <vers num="4.0" />
        <vers num="5.0" />
        <vers num="5.1" />
        <vers num="5.2" />
        <vers num="5.3" />
        <vers num="5.4" />
        <vers num="5.5" />
        <vers num="5.6" />
        <vers num="5.7" />
        <vers num="5.8" />
        <vers num="6.0" />
        <vers num="6.1" />
        <vers num="6.2" />
        <vers num="6.3" />
        <vers num="6.4" />
        <vers num="7.0" />
        <vers num="7.1" />
        <vers prev="1" num="7.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0317" published="2009-01-28" name="CVE-2009-0317" modified="2009-02-05" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="6.9" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.4" CVSS_base_score="6.9">
    <desc>
      <descript source="cve">Untrusted search path vulnerability in the Python language bindings for Nautilus (nautilus-python) allows local users to execute arbitrary code via a Trojan horse Python file in the current working directory, related to a vulnerability in the PySys_SetArgv function (CVE-2008-5983).</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=481570" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=481570</ref>
      <ref url="http://www.securityfocus.com/bid/33442" source="BID">33442</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2009/01/26/2" source="MLIST">[oss-security] 20090126 CVE request -- Python &lt; 2.6 PySys_SetArgv issues (epiphany, csound, dia, eog, gedit, xchat, vim, nautilus-python, Gnumeric)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gnome" name="nautilus-python">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0318" published="2009-01-28" name="CVE-2009-0318" modified="2009-04-16" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="6.9" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.4" CVSS_base_score="6.9">
    <desc>
      <descript source="cve">Untrusted search path vulnerability in the GObject Python interpreter wrapper in Gnumeric allows local users to execute arbitrary code via a Trojan horse Python file in the current working directory, related to a vulnerability in the PySys_SetArgv function (CVE-2008-5983).</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-February/msg00211.html" source="FEDORA">FEDORA-2009-1295</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=481572" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=481572</ref>
      <ref url="http://www.securityfocus.com/bid/33438" source="BID">33438</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2009/01/26/2" source="MLIST">[oss-security] 20090126 CVE request -- Python &lt; 2.6 PySys_SetArgv issues (epiphany, csound, dia, eog, gedit, xchat, vim, nautilus-python, Gnumeric)</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:043" source="MANDRIVA">MDVSA-2009:043</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200904-03.xml" source="GENTOO">GLSA-200904-03</ref>
      <ref url="http://secunia.com/advisories/33823" source="SECUNIA">33823</ref>
      <ref url="http://secunia.com/advisories/33707" source="SECUNIA">33707</ref>
      <ref url="http://bugzilla.gnome.org/show_bug.cgi?id=569648" source="CONFIRM">http://bugzilla.gnome.org/show_bug.cgi?id=569648</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gnome" name="gnumeric">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0319" published="2009-01-28" name="CVE-2009-0319" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="6.9" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.4" CVSS_base_score="6.9">
    <desc>
      <descript source="cve">Unspecified vulnerability in the autofs module in the kernel in Sun Solaris 8 through 10, and OpenSolaris before snv_108, allows local users to cause a denial of service (autofs mount outage) or possibly gain privileges via vectors related to "xdr processing problems."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-249966-1" source="SUNALERT" patch="1" adv="1">249966</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-21-128624-09-1" source="CONFIRM" patch="1">http://sunsolve.sun.com/search/document.do?assetkey=1-21-128624-09-1</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/48234" source="XF">solaris-autofs-code-execution(48234)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0363" source="VUPEN">ADV-2009-0363</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0256" source="VUPEN">ADV-2009-0256</ref>
      <ref url="http://www.securitytracker.com/id?1021644" source="SECTRACK">1021644</ref>
      <ref url="http://www.securityfocus.com/bid/33459" source="BID">33459</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2009-041.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2009-041.htm</ref>
      <ref url="http://secunia.com/advisories/33665" source="SECUNIA">33665</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5977" source="OVAL">oval:org.mitre.oval:def:5977</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="opensolaris">
        <vers num="snv_01" edition="" />
        <vers num="snv_01" edition=":sparc" />
        <vers num="snv_01" edition=":x86" />
        <vers num="snv_02" edition="" />
        <vers num="snv_02" edition=":sparc" />
        <vers num="snv_02" edition=":x86" />
        <vers num="snv_03" edition="" />
        <vers num="snv_03" edition=":x86" />
        <vers num="snv_03" edition=":sparc" />
        <vers num="snv_04" edition="" />
        <vers num="snv_04" edition=":x86" />
        <vers num="snv_04" edition=":sparc" />
        <vers num="snv_05" edition="" />
        <vers num="snv_05" edition=":sparc" />
        <vers num="snv_05" edition=":x86" />
        <vers num="snv_06" edition="" />
        <vers num="snv_06" edition=":sparc" />
        <vers num="snv_06" edition=":x86" />
        <vers num="snv_07" edition="" />
        <vers num="snv_07" edition=":sparc" />
        <vers num="snv_07" edition=":x86" />
        <vers num="snv_08" edition="" />
        <vers num="snv_08" edition=":x86" />
        <vers num="snv_08" edition=":sparc" />
        <vers num="snv_09" edition="" />
        <vers num="snv_09" edition=":x86" />
        <vers num="snv_09" edition=":sparc" />
        <vers num="snv_10" edition="" />
        <vers num="snv_10" edition=":x86" />
        <vers num="snv_10" edition=":sparc" />
        <vers num="snv_100" edition="" />
        <vers num="snv_100" edition=":sparc" />
        <vers num="snv_100" edition=":x86" />
        <vers num="snv_101" edition="" />
        <vers num="snv_101" edition=":x86" />
        <vers num="snv_101" edition=":sparc" />
        <vers num="snv_102" edition="" />
        <vers num="snv_102" edition=":sparc" />
        <vers num="snv_102" edition=":x86" />
        <vers num="snv_103" edition="" />
        <vers num="snv_103" edition=":x86" />
        <vers num="snv_103" edition=":sparc" />
        <vers num="snv_104" edition="" />
        <vers num="snv_104" edition=":x86" />
        <vers num="snv_104" edition=":sparc" />
        <vers num="snv_105" edition="" />
        <vers num="snv_105" edition=":x86" />
        <vers num="snv_105" edition=":sparc" />
        <vers num="snv_106" edition="" />
        <vers num="snv_106" edition=":sparc" />
        <vers num="snv_106" edition=":x86" />
        <vers prev="1" num="snv_107" edition="" />
        <vers prev="1" num="snv_107" edition=":x86" />
        <vers prev="1" num="snv_107" edition=":sparc" />
        <vers num="snv_11" edition="" />
        <vers num="snv_11" edition=":sparc" />
        <vers num="snv_12" edition="" />
        <vers num="snv_12" edition=":sparc" />
        <vers num="snv_13" edition="" />
        <vers num="snv_13" edition=":sparc" />
        <vers num="snv_14" edition="" />
        <vers num="snv_14" edition=":sparc" />
        <vers num="snv_15" edition="" />
        <vers num="snv_15" edition=":sparc" />
        <vers num="snv_16" edition="" />
        <vers num="snv_16" edition=":sparc" />
        <vers num="snv_17" edition="" />
        <vers num="snv_17" edition=":sparc" />
        <vers num="snv_18" edition="" />
        <vers num="snv_18" edition=":sparc" />
        <vers num="snv_19" edition="" />
        <vers num="snv_19" edition=":sparc" />
        <vers num="snv_20" edition="" />
        <vers num="snv_20" edition=":sparc" />
        <vers num="snv_21" edition="" />
        <vers num="snv_21" edition=":sparc" />
        <vers num="snv_21" edition=":x86" />
        <vers num="snv_22" edition="" />
        <vers num="snv_22" edition=":sparc" />
        <vers num="snv_22" edition=":x86" />
        <vers num="snv_23" edition="" />
        <vers num="snv_23" edition=":sparc" />
        <vers num="snv_23" edition=":x86" />
        <vers num="snv_24" edition="" />
        <vers num="snv_24" edition=":sparc" />
        <vers num="snv_24" edition=":x86" />
        <vers num="snv_25" edition="" />
        <vers num="snv_25" edition=":x86" />
        <vers num="snv_25" edition=":sparc" />
        <vers num="snv_26" edition="" />
        <vers num="snv_26" edition=":x86" />
        <vers num="snv_26" edition=":sparc" />
        <vers num="snv_27" edition="" />
        <vers num="snv_27" edition=":sparc" />
        <vers num="snv_27" edition=":x86" />
        <vers num="snv_28" edition="" />
        <vers num="snv_28" edition=":x86" />
        <vers num="snv_28" edition=":sparc" />
        <vers num="snv_29" edition="" />
        <vers num="snv_29" edition=":x86" />
        <vers num="snv_29" edition=":sparc" />
        <vers num="snv_30" edition="" />
        <vers num="snv_30" edition=":sparc" />
        <vers num="snv_30" edition=":x86" />
        <vers num="snv_31" edition="" />
        <vers num="snv_31" edition=":sparc" />
        <vers num="snv_31" edition=":x86" />
        <vers num="snv_32" edition="" />
        <vers num="snv_32" edition=":x86" />
        <vers num="snv_32" edition=":sparc" />
        <vers num="snv_33" edition="" />
        <vers num="snv_33" edition=":x86" />
        <vers num="snv_33" edition=":sparc" />
        <vers num="snv_34" edition="" />
        <vers num="snv_34" edition=":sparc" />
        <vers num="snv_34" edition=":x86" />
        <vers num="snv_35" edition="" />
        <vers num="snv_35" edition=":sparc" />
        <vers num="snv_35" edition=":x86" />
        <vers num="snv_36" edition="" />
        <vers num="snv_36" edition=":x86" />
        <vers num="snv_36" edition=":sparc" />
        <vers num="snv_37" edition="" />
        <vers num="snv_37" edition=":sparc" />
        <vers num="snv_37" edition=":x86" />
        <vers num="snv_38" edition="" />
        <vers num="snv_38" edition=":sparc" />
        <vers num="snv_38" edition=":x86" />
        <vers num="snv_39" edition="" />
        <vers num="snv_39" edition=":sparc" />
        <vers num="snv_39" edition=":x86" />
        <vers num="snv_40" edition="" />
        <vers num="snv_40" edition=":sparc" />
        <vers num="snv_40" edition=":x86" />
        <vers num="snv_41" edition="" />
        <vers num="snv_41" edition=":sparc" />
        <vers num="snv_41" edition=":x86" />
        <vers num="snv_42" edition="" />
        <vers num="snv_42" edition=":x86" />
        <vers num="snv_42" edition=":sparc" />
        <vers num="snv_43" edition="" />
        <vers num="snv_43" edition=":sparc" />
        <vers num="snv_43" edition=":x86" />
        <vers num="snv_44" edition="" />
        <vers num="snv_44" edition=":x86" />
        <vers num="snv_44" edition=":sparc" />
        <vers num="snv_45" edition="" />
        <vers num="snv_45" edition=":x86" />
        <vers num="snv_45" edition=":sparc" />
        <vers num="snv_46" edition="" />
        <vers num="snv_46" edition=":x86" />
        <vers num="snv_46" edition=":sparc" />
        <vers num="snv_47" edition="" />
        <vers num="snv_47" edition=":x86" />
        <vers num="snv_47" edition=":sparc" />
        <vers num="snv_48" edition="" />
        <vers num="snv_48" edition=":sparc" />
        <vers num="snv_48" edition=":x86" />
        <vers num="snv_49" edition="" />
        <vers num="snv_49" edition=":sparc" />
        <vers num="snv_49" edition=":x86" />
        <vers num="snv_50" edition="" />
        <vers num="snv_50" edition=":sparc" />
        <vers num="snv_50" edition=":x86" />
        <vers num="snv_51" edition="" />
        <vers num="snv_51" edition=":sparc" />
        <vers num="snv_51" edition=":x86" />
        <vers num="snv_52" edition="" />
        <vers num="snv_52" edition=":sparc" />
        <vers num="snv_52" edition=":x86" />
        <vers num="snv_53" edition="" />
        <vers num="snv_53" edition=":sparc" />
        <vers num="snv_53" edition=":x86" />
        <vers num="snv_54" edition="" />
        <vers num="snv_54" edition=":x86" />
        <vers num="snv_54" edition=":sparc" />
        <vers num="snv_55" edition="" />
        <vers num="snv_55" edition=":sparc" />
        <vers num="snv_55" edition=":x86" />
        <vers num="snv_56" edition="" />
        <vers num="snv_56" edition=":x86" />
        <vers num="snv_56" edition=":sparc" />
        <vers num="snv_57" edition="" />
        <vers num="snv_57" edition=":x86" />
        <vers num="snv_57" edition=":sparc" />
        <vers num="snv_58" edition="" />
        <vers num="snv_58" edition=":sparc" />
        <vers num="snv_58" edition=":x86" />
        <vers num="snv_59" edition="" />
        <vers num="snv_59" edition=":sparc" />
        <vers num="snv_59" edition=":x86" />
        <vers num="snv_60" edition="" />
        <vers num="snv_60" edition=":x86" />
        <vers num="snv_60" edition=":sparc" />
        <vers num="snv_61" edition="" />
        <vers num="snv_61" edition=":sparc" />
        <vers num="snv_61" edition=":x86" />
        <vers num="snv_62" edition="" />
        <vers num="snv_62" edition=":x86" />
        <vers num="snv_62" edition=":sparc" />
        <vers num="snv_63" edition="" />
        <vers num="snv_63" edition=":sparc" />
        <vers num="snv_63" edition=":x86" />
        <vers num="snv_64" edition="" />
        <vers num="snv_64" edition=":x86" />
        <vers num="snv_64" edition=":sparc" />
        <vers num="snv_65" edition="" />
        <vers num="snv_65" edition=":x86" />
        <vers num="snv_65" edition=":sparc" />
        <vers num="snv_66" edition="" />
        <vers num="snv_66" edition=":x86" />
        <vers num="snv_66" edition=":sparc" />
        <vers num="snv_67" edition="" />
        <vers num="snv_67" edition=":sparc" />
        <vers num="snv_67" edition=":x86" />
        <vers num="snv_68" edition="" />
        <vers num="snv_68" edition=":x86" />
        <vers num="snv_68" edition=":sparc" />
        <vers num="snv_69" edition="" />
        <vers num="snv_69" edition=":sparc" />
        <vers num="snv_69" edition=":x86" />
        <vers num="snv_70" edition="" />
        <vers num="snv_70" edition=":sparc" />
        <vers num="snv_70" edition=":x86" />
        <vers num="snv_71" edition="" />
        <vers num="snv_71" edition=":x86" />
        <vers num="snv_71" edition=":sparc" />
        <vers num="snv_72" edition="" />
        <vers num="snv_72" edition=":x86" />
        <vers num="snv_72" edition=":sparc" />
        <vers num="snv_73" edition="" />
        <vers num="snv_73" edition=":x86" />
        <vers num="snv_73" edition=":sparc" />
        <vers num="snv_74" edition="" />
        <vers num="snv_74" edition=":sparc" />
        <vers num="snv_74" edition=":x86" />
        <vers num="snv_75" edition="" />
        <vers num="snv_75" edition=":sparc" />
        <vers num="snv_75" edition=":x86" />
        <vers num="snv_76" edition="" />
        <vers num="snv_76" edition=":x86" />
        <vers num="snv_76" edition=":sparc" />
        <vers num="snv_77" edition="" />
        <vers num="snv_77" edition=":sparc" />
        <vers num="snv_77" edition=":x86" />
        <vers num="snv_78" edition="" />
        <vers num="snv_78" edition=":sparc" />
        <vers num="snv_78" edition=":x86" />
        <vers num="snv_79" edition="" />
        <vers num="snv_79" edition=":x86" />
        <vers num="snv_79" edition=":sparc" />
        <vers num="snv_80" edition="" />
        <vers num="snv_80" edition=":x86" />
        <vers num="snv_80" edition=":sparc" />
        <vers num="snv_81" edition="" />
        <vers num="snv_81" edition=":x86" />
        <vers num="snv_81" edition=":sparc" />
        <vers num="snv_82" edition="" />
        <vers num="snv_82" edition=":x86" />
        <vers num="snv_82" edition=":sparc" />
        <vers num="snv_83" edition="" />
        <vers num="snv_83" edition=":x86" />
        <vers num="snv_83" edition=":sparc" />
        <vers num="snv_84" edition="" />
        <vers num="snv_84" edition=":x86" />
        <vers num="snv_84" edition=":sparc" />
        <vers num="snv_85" edition="" />
        <vers num="snv_85" edition=":x86" />
        <vers num="snv_85" edition=":sparc" />
        <vers num="snv_86" edition="" />
        <vers num="snv_86" edition=":sparc" />
        <vers num="snv_86" edition=":x86" />
        <vers num="snv_87" edition="" />
        <vers num="snv_87" edition=":sparc" />
        <vers num="snv_87" edition=":x86" />
        <vers num="snv_88" edition="" />
        <vers num="snv_88" edition=":x86" />
        <vers num="snv_88" edition=":sparc" />
        <vers num="snv_89" edition="" />
        <vers num="snv_89" edition=":x86" />
        <vers num="snv_89" edition=":sparc" />
        <vers num="snv_90" edition="" />
        <vers num="snv_90" edition=":sparc" />
        <vers num="snv_90" edition=":x86" />
        <vers num="snv_91" edition="" />
        <vers num="snv_91" edition=":sparc" />
        <vers num="snv_91" edition=":x86" />
        <vers num="snv_92" edition="" />
        <vers num="snv_92" edition=":sparc" />
        <vers num="snv_92" edition=":x86" />
        <vers num="snv_93" edition="" />
        <vers num="snv_93" edition=":sparc" />
        <vers num="snv_93" edition=":x86" />
        <vers num="snv_94" edition="" />
        <vers num="snv_94" edition=":x86" />
        <vers num="snv_94" edition=":sparc" />
        <vers num="snv_95" edition="" />
        <vers num="snv_95" edition=":x86" />
        <vers num="snv_95" edition=":sparc" />
        <vers num="snv_96" edition="" />
        <vers num="snv_96" edition=":sparc" />
        <vers num="snv_96" edition=":x86" />
        <vers num="snv_97" edition="" />
        <vers num="snv_97" edition=":x86" />
        <vers num="snv_97" edition=":sparc" />
        <vers num="snv_98" edition="" />
        <vers num="snv_98" edition=":sparc" />
        <vers num="snv_98" edition=":x86" />
        <vers num="snv_99" edition="" />
        <vers num="snv_99" edition=":sparc" />
        <vers num="snv_99" edition=":x86" />
      </prod>
      <prod vendor="sun" name="solaris">
        <vers num="10" edition="" />
        <vers num="10" edition=":sparc" />
        <vers num="10" edition=":x86" />
        <vers num="8" edition="" />
        <vers num="8" edition=":sparc" />
        <vers num="8" edition=":x86" />
        <vers num="9" edition="" />
        <vers num="9" edition=":x86" />
        <vers num="9" edition=":sparc" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0320" published="2009-01-28" name="CVE-2009-0320" modified="2009-01-29" CVSS_version="2.0" CVSS_vector="(AV:L/AC:H/Au:N/C:C/I:N/A:N)" CVSS_score="4.0" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="1.9" CVSS_base_score="4.0">
    <desc>
      <descript source="cve">Microsoft Windows XP, Server 2003 and 2008, and Vista exposes I/O activity measurements of all processes, which allows local users to obtain sensitive information, as demonstrated by reading the I/O Other Bytes column in Task Manager (aka taskmgr.exe) to estimate the number of characters that a different user entered at a runas.exe password prompt, related to a "benchmarking attack."</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/33440" source="BID">33440</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/500393/100/0/threaded" source="BUGTRAQ">20090124 Benchmarking attacks and major security weakness on all recent Windows versions up to Windows 200</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_server_2003">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="windows_server_2008">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="windows_vista">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0321" published="2009-01-28" name="CVE-2009-0321" modified="2009-03-04" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Apple Safari 3.2.1 (aka AppVer 3.525.27.1) on Windows allows remote attackers to cause a denial of service (infinite loop or access violation) via a link to an http URI in which the authority (aka hostname) portion is either a (1) . (dot) or (2) .. (dot dot) sequence.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/48284" source="XF">safari-httpuri-dos(48284)</ref>
      <ref url="http://www.securityfocus.com/bid/33481" source="BID">33481</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6091" source="OVAL">oval:org.mitre.oval:def:6091</ref>
      <ref url="http://lostmon.blogspot.com/2009/01/safari-for-windows-321-remote-http-uri.html" source="MISC">http://lostmon.blogspot.com/2009/01/safari-for-windows-321-remote-http-uri.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="safari">
        <vers num="3.2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0322" published="2009-01-28" name="CVE-2009-0322" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="4.9" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="3.9" CVSS_base_score="4.9">
    <desc>
      <descript source="cve">drivers/firmware/dell_rbu.c in the Linux kernel before 2.6.27.13, and 2.6.28.x before 2.6.28.2, allows local users to cause a denial of service (system crash) via a read system call that specifies zero bytes from the (1) image_type or (2) packet_size file in /sys/devices/platform/dell_rbu/.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/33428" source="BID" patch="1">33428</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/3316" source="VUPEN">ADV-2009-3316</ref>
      <ref url="http://www.vmware.com/security/advisories/VMSA-2009-0016.html" source="CONFIRM">http://www.vmware.com/security/advisories/VMSA-2009-0016.html</ref>
      <ref url="http://www.ubuntu.com/usn/usn-751-1" source="UBUNTU">USN-751-1</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/507985/100/0/threaded" source="BUGTRAQ">20091120 VMSA-2009-0016 VMware vCenter and ESX update release and vMA patch release address multiple security issue in third party components</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-0360.html" source="REDHAT">RHSA-2009:0360</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-0331.html" source="REDHAT">RHSA-2009:0331</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-0326.html" source="REDHAT">RHSA-2009:0326</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1794" source="DEBIAN">DSA-1794</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1787" source="DEBIAN">DSA-1787</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1749" source="DEBIAN">DSA-1749</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2009-114.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2009-114.htm</ref>
      <ref url="http://secunia.com/advisories/37471" source="SECUNIA">37471</ref>
      <ref url="http://secunia.com/advisories/35394" source="SECUNIA">35394</ref>
      <ref url="http://secunia.com/advisories/35390" source="SECUNIA">35390</ref>
      <ref url="http://secunia.com/advisories/35011" source="SECUNIA">35011</ref>
      <ref url="http://secunia.com/advisories/34981" source="SECUNIA">34981</ref>
      <ref url="http://secunia.com/advisories/34762" source="SECUNIA">34762</ref>
      <ref url="http://secunia.com/advisories/34680" source="SECUNIA">34680</ref>
      <ref url="http://secunia.com/advisories/34502" source="SECUNIA">34502</ref>
      <ref url="http://secunia.com/advisories/34394" source="SECUNIA">34394</ref>
      <ref url="http://secunia.com/advisories/34252" source="SECUNIA">34252</ref>
      <ref url="http://secunia.com/advisories/33758" source="SECUNIA">33758</ref>
      <ref url="http://secunia.com/advisories/33656" source="SECUNIA" adv="1">33656</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7734" source="OVAL">oval:org.mitre.oval:def:7734</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10163" source="OVAL">oval:org.mitre.oval:def:10163</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-06/msg00001.html" source="SUSE">SUSE-SA:2009:031</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-06/msg00000.html" source="SUSE">SUSE-SA:2009:030</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-02/msg00003.html" source="SUSE">SUSE-SA:2009:010</ref>
      <ref url="http://kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.28.2" source="CONFIRM">http://kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.28.2</ref>
      <ref url="http://kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.27.13" source="CONFIRM">http://kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.27.13</ref>
      <ref url="http://git.kernel.org/?p=linux/kernel/git/stable/linux-2.6.27.y.git;a=commit;h=81156928f8fe31621e467490b9d441c0285998c3" source="CONFIRM">http://git.kernel.org/?p=linux/kernel/git/stable/linux-2.6.27.y.git;a=commit;h=81156928f8fe31621e467490b9d441c0285998c3</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="kernel">
        <vers num="2.6" />
        <vers num="2.6.0" />
        <vers num="2.6.1" />
        <vers num="2.6.10" />
        <vers num="2.6.11" />
        <vers num="2.6.11.1" />
        <vers num="2.6.11.10" />
        <vers num="2.6.11.11" />
        <vers num="2.6.11.12" />
        <vers num="2.6.11.2" />
        <vers num="2.6.11.3" />
        <vers num="2.6.11.4" />
        <vers num="2.6.11.5" />
        <vers num="2.6.11.6" />
        <vers num="2.6.11.7" />
        <vers num="2.6.11.8" />
        <vers num="2.6.11.9" />
        <vers num="2.6.12" />
        <vers num="2.6.12.1" />
        <vers num="2.6.12.2" />
        <vers num="2.6.12.3" />
        <vers num="2.6.12.4" />
        <vers num="2.6.12.5" />
        <vers num="2.6.12.6" />
        <vers num="2.6.13" />
        <vers num="2.6.13.1" />
        <vers num="2.6.13.2" />
        <vers num="2.6.13.3" />
        <vers num="2.6.13.4" />
        <vers num="2.6.13.5" />
        <vers num="2.6.14" />
        <vers num="2.6.14.1" />
        <vers num="2.6.14.2" />
        <vers num="2.6.14.3" />
        <vers num="2.6.14.4" />
        <vers num="2.6.14.5" />
        <vers num="2.6.14.6" />
        <vers num="2.6.14.7" />
        <vers num="2.6.15" />
        <vers num="2.6.15.1" />
        <vers num="2.6.15.2" />
        <vers num="2.6.15.3" />
        <vers num="2.6.15.4" />
        <vers num="2.6.15.5" />
        <vers num="2.6.15.6" />
        <vers num="2.6.15.7" />
        <vers num="2.6.16" />
        <vers num="2.6.16.1" />
        <vers num="2.6.16.10" />
        <vers num="2.6.16.11" />
        <vers num="2.6.16.12" />
        <vers num="2.6.16.13" />
        <vers num="2.6.16.14" />
        <vers num="2.6.16.15" />
        <vers num="2.6.16.16" />
        <vers num="2.6.16.17" />
        <vers num="2.6.16.18" />
        <vers num="2.6.16.19" />
        <vers num="2.6.16.2" />
        <vers num="2.6.16.20" />
        <vers num="2.6.16.21" />
        <vers num="2.6.16.22" />
        <vers num="2.6.16.23" />
        <vers num="2.6.16.24" />
        <vers num="2.6.16.25" />
        <vers num="2.6.16.26" />
        <vers num="2.6.16.27" />
        <vers num="2.6.16.28" />
        <vers num="2.6.16.29" />
        <vers num="2.6.16.3" />
        <vers num="2.6.16.30" />
        <vers num="2.6.16.31" />
        <vers num="2.6.16.32" />
        <vers num="2.6.16.33" />
        <vers num="2.6.16.34" />
        <vers num="2.6.16.35" />
        <vers num="2.6.16.36" />
        <vers num="2.6.16.37" />
        <vers num="2.6.16.38" />
        <vers num="2.6.16.39" />
        <vers num="2.6.16.4" />
        <vers num="2.6.16.40" />
        <vers num="2.6.16.41" />
        <vers num="2.6.16.42" />
        <vers num="2.6.16.43" />
        <vers num="2.6.16.44" />
        <vers num="2.6.16.45" />
        <vers num="2.6.16.46" />
        <vers num="2.6.16.47" />
        <vers num="2.6.16.48" />
        <vers num="2.6.16.49" />
        <vers num="2.6.16.5" />
        <vers num="2.6.16.50" />
        <vers num="2.6.16.51" />
        <vers num="2.6.16.52" />
        <vers num="2.6.16.53" />
        <vers num="2.6.16.54" />
        <vers num="2.6.16.55" />
        <vers num="2.6.16.56" />
        <vers num="2.6.16.57" />
        <vers num="2.6.16.58" />
        <vers num="2.6.16.59" />
        <vers num="2.6.16.6" />
        <vers num="2.6.16.60" />
        <vers num="2.6.16.61" />
        <vers num="2.6.16.62" />
        <vers num="2.6.16.7" />
        <vers num="2.6.16.8" />
        <vers num="2.6.16.9" />
        <vers num="2.6.17" />
        <vers num="2.6.17.1" />
        <vers num="2.6.17.10" />
        <vers num="2.6.17.11" />
        <vers num="2.6.17.12" />
        <vers num="2.6.17.13" />
        <vers num="2.6.17.14" />
        <vers num="2.6.17.2" />
        <vers num="2.6.17.3" />
        <vers num="2.6.17.4" />
        <vers num="2.6.17.5" />
        <vers num="2.6.17.6" />
        <vers num="2.6.17.7" />
        <vers num="2.6.17.8" />
        <vers num="2.6.17.9" />
        <vers num="2.6.18" edition="rc1" />
        <vers num="2.6.18" edition="rc2" />
        <vers num="2.6.18" edition="rc3" />
        <vers num="2.6.18" edition="rc4" />
        <vers num="2.6.18" edition="rc5" />
        <vers num="2.6.18" edition="rc6" />
        <vers num="2.6.18" edition="rc7" />
        <vers num="2.6.18.1" />
        <vers num="2.6.18.2" />
        <vers num="2.6.18.3" />
        <vers num="2.6.18.4" />
        <vers num="2.6.18.5" />
        <vers num="2.6.18.6" />
        <vers num="2.6.18.7" />
        <vers num="2.6.18.8" />
        <vers num="2.6.19" />
        <vers num="2.6.19.1" />
        <vers num="2.6.19.2" />
        <vers num="2.6.19.3" />
        <vers num="2.6.19.4" />
        <vers num="2.6.19.5" />
        <vers num="2.6.19.6" />
        <vers num="2.6.19.7" />
        <vers num="2.6.2" />
        <vers num="2.6.20" />
        <vers num="2.6.20.1" />
        <vers num="2.6.20.10" />
        <vers num="2.6.20.11" />
        <vers num="2.6.20.12" />
        <vers num="2.6.20.13" />
        <vers num="2.6.20.14" />
        <vers num="2.6.20.15" />
        <vers num="2.6.20.16" />
        <vers num="2.6.20.17" />
        <vers num="2.6.20.18" />
        <vers num="2.6.20.19" />
        <vers num="2.6.20.2" />
        <vers num="2.6.20.20" />
        <vers num="2.6.20.21" />
        <vers num="2.6.20.3" />
        <vers num="2.6.20.4" />
        <vers num="2.6.20.5" />
        <vers num="2.6.20.6" />
        <vers num="2.6.20.7" />
        <vers num="2.6.20.8" />
        <vers num="2.6.20.9" />
        <vers num="2.6.21" />
        <vers num="2.6.21.1" />
        <vers num="2.6.21.2" />
        <vers num="2.6.21.3" />
        <vers num="2.6.21.4" />
        <vers num="2.6.21.5" />
        <vers num="2.6.21.6" />
        <vers num="2.6.21.7" />
        <vers num="2.6.22" />
        <vers num="2.6.22.1" />
        <vers num="2.6.22.10" />
        <vers num="2.6.22.11" />
        <vers num="2.6.22.12" />
        <vers num="2.6.22.13" />
        <vers num="2.6.22.14" />
        <vers num="2.6.22.15" />
        <vers num="2.6.22.16" />
        <vers num="2.6.22.17" />
        <vers num="2.6.22.18" />
        <vers num="2.6.22.19" />
        <vers num="2.6.22.2" />
        <vers num="2.6.22.20" />
        <vers num="2.6.22.21" />
        <vers num="2.6.22.22" />
        <vers num="2.6.22.3" />
        <vers num="2.6.22.4" />
        <vers num="2.6.22.5" />
        <vers num="2.6.22.6" />
        <vers num="2.6.22.7" />
        <vers num="2.6.22.8" />
        <vers num="2.6.22.9" />
        <vers num="2.6.23" edition="rc1" />
        <vers num="2.6.23" edition="rc2" />
        <vers num="2.6.23.1" />
        <vers num="2.6.23.10" />
        <vers num="2.6.23.11" />
        <vers num="2.6.23.12" />
        <vers num="2.6.23.13" />
        <vers num="2.6.23.14" />
        <vers num="2.6.23.15" />
        <vers num="2.6.23.16" />
        <vers num="2.6.23.17" />
        <vers num="2.6.23.2" />
        <vers num="2.6.23.3" />
        <vers num="2.6.23.4" />
        <vers num="2.6.23.5" />
        <vers num="2.6.23.6" />
        <vers num="2.6.23.7" />
        <vers num="2.6.23.8" />
        <vers num="2.6.23.9" />
        <vers num="2.6.24" edition="rc1" />
        <vers num="2.6.24" edition="rc2" />
        <vers num="2.6.24" edition="rc3" />
        <vers num="2.6.24" edition="rc4" />
        <vers num="2.6.24" edition="rc5" />
        <vers num="2.6.24.1" />
        <vers num="2.6.24.2" />
        <vers num="2.6.24.3" />
        <vers num="2.6.24.4" />
        <vers num="2.6.24.5" />
        <vers num="2.6.24.6" />
        <vers num="2.6.24.7" />
        <vers num="2.6.25" />
        <vers num="2.6.25.1" />
        <vers num="2.6.25.10" />
        <vers num="2.6.25.11" />
        <vers num="2.6.25.12" />
        <vers num="2.6.25.13" />
        <vers num="2.6.25.14" />
        <vers num="2.6.25.15" />
        <vers num="2.6.25.16" />
        <vers num="2.6.25.17" />
        <vers num="2.6.25.18" />
        <vers num="2.6.25.19" />
        <vers num="2.6.25.2" />
        <vers num="2.6.25.20" />
        <vers num="2.6.25.3" />
        <vers num="2.6.25.4" />
        <vers num="2.6.25.5" />
        <vers num="2.6.25.6" />
        <vers num="2.6.25.7" />
        <vers num="2.6.25.8" />
        <vers num="2.6.25.9" />
        <vers num="2.6.26" />
        <vers num="2.6.26.1" />
        <vers num="2.6.26.2" />
        <vers num="2.6.26.3" />
        <vers num="2.6.26.4" />
        <vers num="2.6.26.5" />
        <vers num="2.6.26.6" />
        <vers num="2.6.26.7" />
        <vers num="2.6.26.8" />
        <vers num="2.6.27" />
        <vers num="2.6.27.1" />
        <vers num="2.6.27.10" />
        <vers num="2.6.27.11" />
        <vers prev="1" num="2.6.27.12" />
        <vers num="2.6.27.2" />
        <vers num="2.6.27.3" />
        <vers num="2.6.27.4" />
        <vers num="2.6.27.5" />
        <vers num="2.6.27.6" />
        <vers num="2.6.27.7" />
        <vers num="2.6.27.8" />
        <vers num="2.6.27.9" />
        <vers num="2.6.28" />
        <vers prev="1" num="2.6.28.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0323" published="2009-01-28" name="CVE-2009-0323" modified="2009-02-10" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Multiple stack-based buffer overflows in W3C Amaya Web Browser 10.0 and 11.0 allow remote attackers to execute arbitrary code via (1) a long type parameter in an input tag, which is not properly handled by the EndOfXmlAttributeValue function; (2) an "HTML GI" in a start tag, which is not properly handled by the ProcessStartGI function; and unspecified vectors in (3) html2thot.c and (4) xml2thot.c, related to the msgBuffer variable.  NOTE: these are different vectors than CVE-2008-6005.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/48325" source="XF">amaya-html-tags-bo(48325)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/500492/100/0/threaded" source="BUGTRAQ">20090128 CORE-2008-1211: Amaya web editor XML and HTML parser vulnerabilities</ref>
      <ref url="http://www.milw0rm.com/exploits/7902" source="MILW0RM">7902</ref>
      <ref url="http://www.coresecurity.com/content/amaya-buffer-overflows" source="MISC">http://www.coresecurity.com/content/amaya-buffer-overflows</ref>
    </refs>
    <vuln_soft>
      <prod vendor="w3" name="amaya">
        <vers num="0.9" />
        <vers num="0.95b" />
        <vers num="1.0" />
        <vers num="1.0a" />
        <vers num="1.1" />
        <vers num="1.1a" />
        <vers num="1.1c" />
        <vers num="1.2" />
        <vers num="1.2a" />
        <vers num="1.3" />
        <vers num="1.3a" />
        <vers num="1.3b" />
        <vers num="1.4" />
        <vers num="1.4a" />
        <vers num="10.0" />
        <vers prev="1" num="11.0" />
        <vers num="2.0" />
        <vers num="2.1" />
        <vers num="2.2" />
        <vers num="2.3" />
        <vers num="2.4" />
        <vers num="3.0" />
        <vers num="3.1" />
        <vers num="3.2" />
        <vers num="3.2.1" />
        <vers num="4.0" />
        <vers num="4.1" />
        <vers num="4.2" />
        <vers num="4.2.1" />
        <vers num="4.3" />
        <vers num="4.3.1" />
        <vers num="4.3.2" />
        <vers num="5.0" />
        <vers num="5.1" />
        <vers num="5.2" />
        <vers num="5.3" />
        <vers num="6.0" />
        <vers num="6.1" />
        <vers num="6.2" />
        <vers num="6.3" />
        <vers num="6.4" />
        <vers num="7.0" />
        <vers num="7.1" />
        <vers num="7.2" />
        <vers num="8.0" />
        <vers num="8.1" />
        <vers num="8.1a" />
        <vers num="8.1b" />
        <vers num="8.2" />
        <vers num="8.3" />
        <vers num="8.4" />
        <vers num="8.5" />
        <vers num="8.52" />
        <vers num="8.6" />
        <vers num="8.7" />
        <vers num="8.7.1" />
        <vers num="8.7.2" />
        <vers num="8.8.1" />
        <vers num="8.8.3" />
        <vers num="8.8.4" />
        <vers num="8.8.5" />
        <vers num="9.0" />
        <vers num="9.1" />
        <vers num="9.2.1" />
        <vers num="9.3" />
        <vers num="9.4" />
        <vers num="9.5" />
        <vers num="9.52" />
        <vers num="9.53" />
        <vers num="9.54" />
        <vers num="9.55" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0324" published="2009-01-29" name="CVE-2009-0324" modified="2009-01-29" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in BibCiter 1.4 allow remote attackers to execute arbitrary SQL commands via the (1) idp parameter to reports/projects.php, the (2) idc parameter to reports/contacts.php, and the (3) idu parameter to reports/users.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/48080" source="XF">bibciter-projects-sql-injection(48080)</ref>
      <ref url="http://www.securityfocus.com/bid/33329" source="BID">33329</ref>
      <ref url="http://www.milw0rm.com/exploits/7814" source="MILW0RM">7814</ref>
      <ref url="http://secunia.com/advisories/33555" source="SECUNIA" adv="1">33555</ref>
      <ref url="http://bibciter.sourceforge.net/?p=35" source="CONFIRM" adv="1">http://bibciter.sourceforge.net/?p=35</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bibciter" name="bibciter">
        <vers num="1.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0325" published="2009-01-29" name="CVE-2009-0325" modified="2009-01-29" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Directory traversal vulnerability in entries/index.php in Ninja Blog 4.8, when magic_quotes_gpc is disabled, allows remote attackers to read arbitrary files via a .. (dot dot) in the cat parameter.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="https://www.push55.co.uk/poclibrary/ninjadesignscouk-1.txt" source="MISC">https://www.push55.co.uk/poclibrary/ninjadesignscouk-1.txt</ref>
      <ref url="http://www.securityfocus.com/bid/33351" source="BID">33351</ref>
      <ref url="http://www.push55.co.uk/index.php?s=ad&amp;id=6" source="MISC">http://www.push55.co.uk/index.php?s=ad&amp;id=6</ref>
      <ref url="http://www.milw0rm.com/exploits/7831" source="MILW0RM">7831</ref>
      <ref url="http://secunia.com/advisories/33573" source="SECUNIA" adv="1">33573</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ninjadesigns" name="ninja_blog">
        <vers num="4.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0326" published="2009-01-29" name="CVE-2009-0326" modified="2009-01-29" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in login.php in Dark Age CMS 0.2c beta allows remote attackers to execute arbitrary SQL commands via the (1) username and (2) password parameters.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/48095" source="XF">darkagecms-login-sql-injection(48095)</ref>
      <ref url="http://www.securityfocus.com/bid/33271" source="BID">33271</ref>
    </refs>
    <vuln_soft>
      <prod vendor="dark_age_cms" name="dark_age_cms">
        <vers num="0.2c" edition="beta" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0327" published="2009-01-29" name="CVE-2009-0327" modified="2009-01-29" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in readbible.php in Free Bible Search PHP Script 1.0 allows remote attackers to execute arbitrary SQL commands via the version parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.seraphimtech.net/repository/Changes.txt" source="CONFIRM">http://www.seraphimtech.net/repository/Changes.txt</ref>
      <ref url="http://www.securityfocus.com/bid/33301" source="BID">33301</ref>
      <ref url="http://www.milw0rm.com/exploits/7798" source="MILW0RM">7798</ref>
      <ref url="http://secunia.com/advisories/33595" source="SECUNIA" adv="1">33595</ref>
      <ref url="http://freshmeat.net/projects/freebiblesearch/?branch_id=77256&amp;release_id=292446" source="MISC">http://freshmeat.net/projects/freebiblesearch/?branch_id=77256&amp;release_id=292446</ref>
    </refs>
    <vuln_soft>
      <prod vendor="seraphimtech" name="free_bible_search_php_script">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0328" published="2009-01-29" name="CVE-2009-0328" modified="2009-01-29" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">ROBS-PROJECTS Digital Sales IPN (aka DS-IPN.NET or DS-IPN Paypal Shop) stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file containing user credentials via a direct request for Database/Sales.mdb.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/48082" source="XF">digitalsales-sales-information-disclosure(48082)</ref>
      <ref url="http://www.milw0rm.com/exploits/7816" source="MILW0RM">7816</ref>
      <ref url="http://secunia.com/advisories/33602" source="SECUNIA" adv="1">33602</ref>
    </refs>
    <vuln_soft>
      <prod vendor="robs-projects" name="digital_sales_ipn">
        <vers num="_nil_" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0329" published="2009-01-29" name="CVE-2009-0329" modified="2009-01-29" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in the PcCookBook (com_pccookbook) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the recipe_id parameter in a viewrecipe action to index.php, a different vector than CVE-2008-0844.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/48088" source="XF">pccookbook-recipeid-sql-injection(48088)</ref>
      <ref url="http://www.securityfocus.com/bid/33346" source="BID">33346</ref>
      <ref url="http://www.milw0rm.com/exploits/7824" source="MILW0RM">7824</ref>
    </refs>
    <vuln_soft>
      <prod vendor="joomla" name="com_pccookbook">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0330" published="2009-01-29" name="CVE-2009-0330" modified="2009-01-29" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Directory traversal vulnerability in index.php in Simple Content Management System (SCMS) 1 allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the p parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/48081" source="XF">scms-index-file-include(48081)</ref>
      <ref url="http://www.securityfocus.com/bid/33330" source="BID">33330</ref>
      <ref url="http://www.milw0rm.com/exploits/7818" source="MILW0RM">7818</ref>
      <ref url="http://secunia.com/advisories/33608" source="SECUNIA" adv="1">33608</ref>
    </refs>
    <vuln_soft>
      <prod vendor="wss-pro" name="scms">
        <vers num="1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0331" published="2009-01-29" name="CVE-2009-0331" modified="2009-01-30" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:N/A:N)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Directory traversal vulnerability in gallery/comment.php in Enhanced Simple PHP Gallery (ESPG) 1.72 allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter.  NOTE: the vulnerability may be in my little homepage Comment script. If so, then this should not be treated as a vulnerability in ESPG.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/48087" source="XF">espg-comment-directory-traversal(48087)</ref>
      <ref url="http://www.securityfocus.com/bid/33335" source="BID">33335</ref>
      <ref url="http://www.milw0rm.com/exploits/7819" source="MILW0RM">7819</ref>
    </refs>
    <vuln_soft>
      <prod vendor="quirm" name="espg">
        <vers num="1.72" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0332" published="2009-01-29" name="CVE-2009-0332" modified="2009-01-30" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in AV Book Library before 1.1 allow remote attackers to execute arbitrary SQL commands via unspecified parameters to (1) admin/edit.php, (2) admin/add.php, (3) lib/book_search.php, and possibly other components.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/48084" source="XF">avbook-edit-sql-injection(48084)</ref>
      <ref url="http://sourceforge.net/tracker/index.php?func=detail&amp;aid=2219743&amp;group_id=209711&amp;atid=1010816" source="CONFIRM">http://sourceforge.net/tracker/index.php?func=detail&amp;aid=2219743&amp;group_id=209711&amp;atid=1010816</ref>
      <ref url="http://sourceforge.net/project/shownotes.php?release_id=654214" source="CONFIRM">http://sourceforge.net/project/shownotes.php?release_id=654214</ref>
      <ref url="http://secunia.com/advisories/33583" source="SECUNIA" adv="1">33583</ref>
    </refs>
    <vuln_soft>
      <prod vendor="avbooklibrary" name="avbooklibrary">
        <vers num="1.0.0" />
        <vers num="1.0.1" />
        <vers prev="1" num="1.0.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0333" published="2009-01-29" name="CVE-2009-0333" modified="2009-01-29" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in the WebAmoeba (WA) Ticket System (com_waticketsystem) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter in a category action to index.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/33353" source="BID">33353</ref>
      <ref url="http://secunia.com/advisories/33577" source="SECUNIA" adv="1">33577</ref>
      <ref url="http://milw0rm.com/exploits/7833" source="MILW0RM">7833</ref>
    </refs>
    <vuln_soft>
      <prod vendor="joomla" name="com_waticketsystem">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0334" published="2009-01-29" name="CVE-2009-0334" modified="2009-01-30" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in index.asp in Katy Whitton BlogIt! allows remote attackers to execute arbitrary SQL commands via the day parameter in an archive action.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/48074" source="XF">blogit-index-sql-injection(48074)</ref>
      <ref url="http://www.securityfocus.com/bid/33325" source="BID">33325</ref>
      <ref url="http://www.milw0rm.com/exploits/7806" source="MILW0RM">7806</ref>
      <ref url="http://secunia.com/advisories/33572" source="SECUNIA" adv="1">33572</ref>
    </refs>
    <vuln_soft>
      <prod vendor="katywhitton" name="blogit!">
        <vers num="_nil_" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0335" published="2009-01-29" name="CVE-2009-0335" modified="2009-01-29" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in index.asp in Katy Whitton BlogIt! allows remote attackers to inject arbitrary web script or HTML via the view parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/48073" source="XF">blogit-index-xss(48073)</ref>
      <ref url="http://www.securityfocus.com/bid/33325" source="BID">33325</ref>
      <ref url="http://www.milw0rm.com/exploits/7806" source="MILW0RM">7806</ref>
      <ref url="http://secunia.com/advisories/33572" source="SECUNIA" adv="1">33572</ref>
    </refs>
    <vuln_soft>
      <prod vendor="katywhitton" name="blogit!">
        <vers num="_nil_" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0336" published="2009-01-29" name="CVE-2009-0336" modified="2009-01-29" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Katy Whitton BlogIt! stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file containing user credentials via a direct request for database/Blog.mdb.  NOTE: some of these details are obtained from third party information.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/48075" source="XF">blogit-blog-information-disclosure(48075)</ref>
      <ref url="http://www.milw0rm.com/exploits/7806" source="MILW0RM">7806</ref>
    </refs>
    <vuln_soft>
      <prod vendor="katywhitton" name="blogit!">
        <vers num="_nil_" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0337" published="2009-01-29" name="CVE-2009-0337" modified="2009-01-29" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in index.asp in Katy Whitton BlogIt! allows remote attackers to execute arbitrary SQL commands via the (1) month and (2) year parameters.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.milw0rm.com/exploits/7806" source="MILW0RM">7806</ref>
      <ref url="http://secunia.com/advisories/33572" source="SECUNIA" adv="1">33572</ref>
    </refs>
    <vuln_soft>
      <prod vendor="katywhitton" name="blogit!">
        <vers num="_nil_" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0338" published="2009-01-29" name="CVE-2009-0338" modified="2009-01-29" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in inc_webblogmanager.asp in DMXReady Blog Manager allows remote attackers to inject arbitrary web script or HTML via the CategoryID parameter in a refer action.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/48053" source="XF">blogmanager-incwebblogmanager-xss(48053)</ref>
      <ref url="http://www.securityfocus.com/bid/33314" source="BID">33314</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/500146/100/0/threaded" source="BUGTRAQ">20090116 DMXReady Blog Manager (SQL/XSS)</ref>
      <ref url="http://secunia.com/advisories/33601" source="SECUNIA" adv="1">33601</ref>
      <ref url="http://dmxready.helpserve.com/index.php?_m=news&amp;_a=viewnews&amp;newsid=12" source="MISC" adv="1">http://dmxready.helpserve.com/index.php?_m=news&amp;_a=viewnews&amp;newsid=12</ref>
    </refs>
    <vuln_soft>
      <prod vendor="dmxready" name="blog_manager">
        <vers num="_nil" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0339" published="2009-01-29" name="CVE-2009-0339" modified="2009-01-30" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in inc_webblogmanager.asp in DMXReady Blog Manager allows remote attackers to execute arbitrary SQL commands via the itemID parameter in a view action.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/48054" source="XF">blogmanager-incwebblogmanager-sql-injection(48054)</ref>
      <ref url="http://www.securityfocus.com/bid/33314" source="BID">33314</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/500146/100/0/threaded" source="BUGTRAQ">20090116 DMXReady Blog Manager (SQL/XSS)</ref>
      <ref url="http://secunia.com/advisories/33601" source="SECUNIA" adv="1">33601</ref>
      <ref url="http://dmxready.helpserve.com/index.php?_m=news&amp;_a=viewnews&amp;newsid=12" source="MISC" adv="1">http://dmxready.helpserve.com/index.php?_m=news&amp;_a=viewnews&amp;newsid=12</ref>
    </refs>
    <vuln_soft>
      <prod vendor="dmxready" name="blog_manager">
        <vers num="_nil_" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0340" published="2009-01-29" name="CVE-2009-0340" modified="2009-01-29" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple directory traversal vulnerabilities in Simple PHP Newsletter 1.5 allow remote attackers to read arbitrary files via a .. (dot dot) in the olang parameter to (1) mail.php and (2) mailbar.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/48089" source="XF">simplephpnewsletter-mail-file-include(48089)</ref>
      <ref url="http://www.securityfocus.com/bid/33327" source="BID">33327</ref>
      <ref url="http://www.milw0rm.com/exploits/7813" source="MILW0RM">7813</ref>
    </refs>
    <vuln_soft>
      <prod vendor="quirm" name="simple_php_newsletter">
        <vers num="1.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0341" published="2009-01-29" name="CVE-2009-0341" modified="2009-02-20" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">The shell32 module in Microsoft Internet Explorer 7.0 on Windows XP SP3 might allow remote attackers to execute arbitrary code via a long VALUE attribute in an INPUT element, possibly related to a stack consumption vulnerability.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/33494" source="BID">33494</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/500472/100/0/threaded" source="BUGTRAQ">20090128 Internet explorer 7.0 stack overflow</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="internet_explorer">
        <vers num="7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0342" published="2009-01-29" name="CVE-2009-0342" modified="2009-01-30" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Niels Provos Systrace before 1.6f on the x86_64 Linux platform allows local users to bypass intended access restrictions by making a 64-bit syscall with a syscall number that corresponds to a policy-compliant 32-bit syscall.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/33417" source="BID">33417</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/500377/100/0/threaded" source="BUGTRAQ">20090123 Problems with syscall filtering technologies on Linux</ref>
      <ref url="http://www.citi.umich.edu/u/provos/systrace/" source="CONFIRM">http://www.citi.umich.edu/u/provos/systrace/</ref>
      <ref url="http://scarybeastsecurity.blogspot.com/2009/01/bypassing-syscall-filtering.html" source="MISC">http://scarybeastsecurity.blogspot.com/2009/01/bypassing-syscall-filtering.html</ref>
      <ref url="http://scary.beasts.org/security/CESA-2009-001.html" source="MISC">http://scary.beasts.org/security/CESA-2009-001.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="provos" name="systrace">
        <vers num="1.1" />
        <vers num="1.2" />
        <vers num="1.3" />
        <vers num="1.4" />
        <vers num="1.5" />
        <vers num="1.6" />
        <vers num="1.6a" />
        <vers num="1.6b" />
        <vers num="1.6c" />
        <vers num="1.6d" />
        <vers prev="1" num="1.6e" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0343" published="2009-01-29" name="CVE-2009-0343" modified="2009-01-30" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Niels Provos Systrace 1.6f and earlier on the x86_64 Linux platform allows local users to bypass intended access restrictions by making a 32-bit syscall with a syscall number that corresponds to a policy-compliant 64-bit syscall, related to race conditions that occur in monitoring 64-bit processes.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/33417" source="BID">33417</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/500377/100/0/threaded" source="BUGTRAQ">20090123 Problems with syscall filtering technologies on Linux</ref>
      <ref url="http://www.citi.umich.edu/u/provos/systrace/" source="MISC">http://www.citi.umich.edu/u/provos/systrace/</ref>
      <ref url="http://scarybeastsecurity.blogspot.com/2009/01/bypassing-syscall-filtering.html" source="MISC">http://scarybeastsecurity.blogspot.com/2009/01/bypassing-syscall-filtering.html</ref>
      <ref url="http://scary.beasts.org/security/CESA-2009-001.html" source="MISC">http://scary.beasts.org/security/CESA-2009-001.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="niels_provos" name="systrace">
        <vers num="1.1" />
        <vers num="1.2" />
        <vers num="1.3" />
        <vers num="1.4" />
        <vers num="1.5" />
        <vers num="1.6" />
        <vers num="1.6a" />
        <vers num="1.6b" />
        <vers num="1.6c" />
        <vers num="1.6d" />
        <vers prev="1" num="1.6e" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0344" published="2009-01-29" name="CVE-2009-0344" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Embedded Lights Out Manager (ELOM) on the Sun Fire X2100 M2 and X2200 M2 x86 platforms before SP/BMC firmware 3.20 allows remote attackers to obtain privileged ELOM login access or execute arbitrary Service Processor (SP) commands via unknown vectors, aka Bug ID 6633175, a different vulnerability than CVE-2007-5717.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-239886-1" source="SUNALERT" patch="1" adv="1">239886</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/48329" source="XF">sunfire-elom-unauth-access(48329)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0281" source="VUPEN">ADV-2009-0281</ref>
      <ref url="http://www.securitytracker.com/id?1021646" source="SECTRACK">1021646</ref>
      <ref url="http://www.securityfocus.com/bid/33506" source="BID">33506</ref>
      <ref url="http://secunia.com/advisories/33726" source="SECUNIA">33726</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="fire_x2100_m2">
        <vers prev="1" num="3.19" edition="_nil_" />
        <vers prev="1" num="3.19" edition="_nil_:x86" />
      </prod>
      <prod vendor="sun" name="fire_x2200_m2">
        <vers prev="1" num="2.19" edition="_nil_" />
        <vers prev="1" num="2.19" edition="_nil_:x86" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0345" published="2009-01-29" name="CVE-2009-0345" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Embedded Lights Out Manager (ELOM) on the Sun Fire X2100 M2 and X2200 M2 x86 platforms before SP/BMC firmware 3.20 allows remote attackers to obtain privileged ELOM login access or execute arbitrary Service Processor (SP) commands via unknown vectors, aka Bug ID 6648082, a different vulnerability than CVE-2007-5717.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-239886-1" source="SUNALERT" patch="1" adv="1">239886</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/48329" source="XF">sunfire-elom-unauth-access(48329)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0281" source="VUPEN">ADV-2009-0281</ref>
      <ref url="http://www.securitytracker.com/id?1021646" source="SECTRACK">1021646</ref>
      <ref url="http://www.securityfocus.com/bid/33506" source="BID">33506</ref>
      <ref url="http://secunia.com/advisories/33726" source="SECUNIA">33726</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="fire_x2100_m2">
        <vers prev="1" num="3.19" edition="_nil_" />
        <vers prev="1" num="3.19" edition="_nil_:x86" />
      </prod>
      <prod vendor="sun" name="fire_x2200_m2">
        <vers prev="1" num="2.19" edition="_nil_" />
        <vers prev="1" num="2.19" edition="_nil_:x86" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0346" published="2009-01-29" name="CVE-2009-0346" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="4.9" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="3.9" CVSS_base_score="4.9">
    <desc>
      <descript source="cve">The IP-in-IP packet processing implementation in the IPsec and IP stacks in the kernel in Sun Solaris 9 and 10, and OpenSolaris snv_01 though snv_85, allows local users to cause a denial of service (panic) via a self-encapsulated packet that lacks IPsec protection.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-240086-1" source="SUNALERT" patch="1" adv="1">240086</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-21-114344-38-1" source="CONFIRM" patch="1">http://sunsolve.sun.com/search/document.do?assetkey=1-21-114344-38-1</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/48328" source="XF">solaris-ipinip-dos(48328)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0365" source="VUPEN">ADV-2009-0365</ref>
      <ref url="http://www.securityfocus.com/bid/33504" source="BID">33504</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2009-043.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2009-043.htm</ref>
      <ref url="http://secunia.com/advisories/33727" source="SECUNIA">33727</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6088" source="OVAL">oval:org.mitre.oval:def:6088</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="opensolaris">
        <vers num="snv_01" edition="" />
        <vers num="snv_01" edition=":sparc" />
        <vers num="snv_01" edition=":x86" />
        <vers num="snv_02" edition="" />
        <vers num="snv_02" edition=":sparc" />
        <vers num="snv_02" edition=":x86" />
        <vers num="snv_03" edition="" />
        <vers num="snv_03" edition=":x86" />
        <vers num="snv_03" edition=":sparc" />
        <vers num="snv_04" edition="" />
        <vers num="snv_04" edition=":x86" />
        <vers num="snv_04" edition=":sparc" />
        <vers num="snv_05" edition="" />
        <vers num="snv_05" edition=":sparc" />
        <vers num="snv_05" edition=":x86" />
        <vers num="snv_06" edition="" />
        <vers num="snv_06" edition=":sparc" />
        <vers num="snv_06" edition=":x86" />
        <vers num="snv_07" edition="" />
        <vers num="snv_07" edition=":sparc" />
        <vers num="snv_07" edition=":x86" />
        <vers num="snv_08" edition="" />
        <vers num="snv_08" edition=":x86" />
        <vers num="snv_08" edition=":sparc" />
        <vers num="snv_09" edition="" />
        <vers num="snv_09" edition=":sparc" />
        <vers num="snv_09" edition=":x86" />
        <vers num="snv_10" edition="" />
        <vers num="snv_10" edition=":x86" />
        <vers num="snv_10" edition=":sparc" />
        <vers num="snv_100" edition="" />
        <vers num="snv_100" edition=":x86" />
        <vers num="snv_100" edition=":sparc" />
        <vers num="snv_101" edition="" />
        <vers num="snv_101" edition=":x86" />
        <vers num="snv_101" edition=":sparc" />
        <vers num="snv_102" edition="" />
        <vers num="snv_102" edition=":x86" />
        <vers num="snv_102" edition=":sparc" />
        <vers num="snv_103" edition="" />
        <vers num="snv_103" edition=":sparc" />
        <vers num="snv_103" edition=":x86" />
        <vers num="snv_104" edition="" />
        <vers num="snv_104" edition=":x86" />
        <vers num="snv_104" edition=":sparc" />
        <vers num="snv_105" edition="" />
        <vers num="snv_105" edition=":x86" />
        <vers num="snv_105" edition=":sparc" />
        <vers num="snv_106" edition="" />
        <vers num="snv_106" edition=":sparc" />
        <vers num="snv_106" edition=":x86" />
        <vers num="snv_107" edition="" />
        <vers num="snv_107" edition=":sparc" />
        <vers num="snv_107" edition=":x86" />
        <vers num="snv_11" edition="" />
        <vers num="snv_11" edition=":x86" />
        <vers num="snv_11" edition=":sparc" />
        <vers num="snv_12" edition="" />
        <vers num="snv_12" edition=":x86" />
        <vers num="snv_12" edition=":sparc" />
        <vers num="snv_13" edition="" />
        <vers num="snv_13" edition=":x86" />
        <vers num="snv_13" edition=":sparc" />
        <vers num="snv_14" edition="" />
        <vers num="snv_14" edition=":x86" />
        <vers num="snv_14" edition=":sparc" />
        <vers num="snv_15" edition="" />
        <vers num="snv_15" edition=":x86" />
        <vers num="snv_15" edition=":sparc" />
        <vers num="snv_16" edition="" />
        <vers num="snv_16" edition=":sparc" />
        <vers num="snv_16" edition=":x86" />
        <vers num="snv_17" edition="" />
        <vers num="snv_17" edition=":x86" />
        <vers num="snv_17" edition=":sparc" />
        <vers num="snv_18" edition="" />
        <vers num="snv_18" edition=":x86" />
        <vers num="snv_18" edition=":sparc" />
        <vers num="snv_19" edition="" />
        <vers num="snv_19" edition=":sparc" />
        <vers num="snv_19" edition=":x86" />
        <vers num="snv_20" edition="" />
        <vers num="snv_20" edition=":x86" />
        <vers num="snv_20" edition=":sparc" />
        <vers num="snv_21" edition="" />
        <vers num="snv_21" edition=":x86" />
        <vers num="snv_21" edition=":sparc" />
        <vers num="snv_22" edition="" />
        <vers num="snv_22" edition=":sparc" />
        <vers num="snv_22" edition=":x86" />
        <vers num="snv_23" edition="" />
        <vers num="snv_23" edition=":sparc" />
        <vers num="snv_23" edition=":x86" />
        <vers num="snv_24" edition="" />
        <vers num="snv_24" edition=":sparc" />
        <vers num="snv_24" edition=":x86" />
        <vers num="snv_25" edition="" />
        <vers num="snv_25" edition=":sparc" />
        <vers num="snv_25" edition=":x86" />
        <vers num="snv_26" edition="" />
        <vers num="snv_26" edition=":sparc" />
        <vers num="snv_26" edition=":x86" />
        <vers num="snv_27" edition="" />
        <vers num="snv_27" edition=":sparc" />
        <vers num="snv_27" edition=":x86" />
        <vers num="snv_28" edition="" />
        <vers num="snv_28" edition=":sparc" />
        <vers num="snv_28" edition=":x86" />
        <vers num="snv_29" edition="" />
        <vers num="snv_29" edition=":x86" />
        <vers num="snv_29" edition=":sparc" />
        <vers num="snv_30" edition="" />
        <vers num="snv_30" edition=":sparc" />
        <vers num="snv_30" edition=":x86" />
        <vers num="snv_31" edition="" />
        <vers num="snv_31" edition=":sparc" />
        <vers num="snv_31" edition=":x86" />
        <vers num="snv_32" edition="" />
        <vers num="snv_32" edition=":x86" />
        <vers num="snv_32" edition=":sparc" />
        <vers num="snv_33" edition="" />
        <vers num="snv_33" edition=":x86" />
        <vers num="snv_33" edition=":sparc" />
        <vers num="snv_34" edition="" />
        <vers num="snv_34" edition=":sparc" />
        <vers num="snv_34" edition=":x86" />
        <vers num="snv_35" edition="" />
        <vers num="snv_35" edition=":sparc" />
        <vers num="snv_35" edition=":x86" />
        <vers num="snv_36" edition="" />
        <vers num="snv_36" edition=":sparc" />
        <vers num="snv_36" edition=":x86" />
        <vers num="snv_37" edition="" />
        <vers num="snv_37" edition=":sparc" />
        <vers num="snv_37" edition=":x86" />
        <vers num="snv_38" edition="" />
        <vers num="snv_38" edition=":sparc" />
        <vers num="snv_38" edition=":x86" />
        <vers num="snv_39" edition="" />
        <vers num="snv_39" edition=":sparc" />
        <vers num="snv_39" edition=":x86" />
        <vers num="snv_40" edition="" />
        <vers num="snv_40" edition=":x86" />
        <vers num="snv_40" edition=":sparc" />
        <vers num="snv_41" edition="" />
        <vers num="snv_41" edition=":sparc" />
        <vers num="snv_41" edition=":x86" />
        <vers num="snv_42" edition="" />
        <vers num="snv_42" edition=":x86" />
        <vers num="snv_42" edition=":sparc" />
        <vers num="snv_43" edition="" />
        <vers num="snv_43" edition=":sparc" />
        <vers num="snv_43" edition=":x86" />
        <vers num="snv_44" edition="" />
        <vers num="snv_44" edition=":x86" />
        <vers num="snv_44" edition=":sparc" />
        <vers num="snv_45" edition="" />
        <vers num="snv_45" edition=":x86" />
        <vers num="snv_45" edition=":sparc" />
        <vers num="snv_46" edition="" />
        <vers num="snv_46" edition=":sparc" />
        <vers num="snv_46" edition=":x86" />
        <vers num="snv_47" edition="" />
        <vers num="snv_47" edition=":x86" />
        <vers num="snv_47" edition=":sparc" />
        <vers num="snv_48" edition="" />
        <vers num="snv_48" edition=":sparc" />
        <vers num="snv_48" edition=":x86" />
        <vers num="snv_49" edition="" />
        <vers num="snv_49" edition=":sparc" />
        <vers num="snv_49" edition=":x86" />
        <vers num="snv_50" edition="" />
        <vers num="snv_50" edition=":sparc" />
        <vers num="snv_50" edition=":x86" />
        <vers num="snv_51" edition="" />
        <vers num="snv_51" edition=":x86" />
        <vers num="snv_51" edition=":sparc" />
        <vers num="snv_52" edition="" />
        <vers num="snv_52" edition=":x86" />
        <vers num="snv_52" edition=":sparc" />
        <vers num="snv_53" edition="" />
        <vers num="snv_53" edition=":sparc" />
        <vers num="snv_53" edition=":x86" />
        <vers num="snv_54" edition="" />
        <vers num="snv_54" edition=":sparc" />
        <vers num="snv_54" edition=":x86" />
        <vers num="snv_55" edition="" />
        <vers num="snv_55" edition=":sparc" />
        <vers num="snv_55" edition=":x86" />
        <vers num="snv_56" edition="" />
        <vers num="snv_56" edition=":x86" />
        <vers num="snv_56" edition=":sparc" />
        <vers num="snv_57" edition="" />
        <vers num="snv_57" edition=":x86" />
        <vers num="snv_57" edition=":sparc" />
        <vers num="snv_58" edition="" />
        <vers num="snv_58" edition=":sparc" />
        <vers num="snv_58" edition=":x86" />
        <vers num="snv_59" edition="" />
        <vers num="snv_59" edition=":sparc" />
        <vers num="snv_59" edition=":x86" />
        <vers num="snv_60" edition="" />
        <vers num="snv_60" edition=":x86" />
        <vers num="snv_60" edition=":sparc" />
        <vers num="snv_61" edition="" />
        <vers num="snv_61" edition=":sparc" />
        <vers num="snv_61" edition=":x86" />
        <vers num="snv_62" edition="" />
        <vers num="snv_62" edition=":x86" />
        <vers num="snv_62" edition=":sparc" />
        <vers num="snv_63" edition="" />
        <vers num="snv_63" edition=":x86" />
        <vers num="snv_63" edition=":sparc" />
        <vers num="snv_64" edition="" />
        <vers num="snv_64" edition=":x86" />
        <vers num="snv_64" edition=":sparc" />
        <vers num="snv_65" edition="" />
        <vers num="snv_65" edition=":sparc" />
        <vers num="snv_65" edition=":x86" />
        <vers num="snv_66" edition="" />
        <vers num="snv_66" edition=":x86" />
        <vers num="snv_66" edition=":sparc" />
        <vers num="snv_67" edition="" />
        <vers num="snv_67" edition=":sparc" />
        <vers num="snv_67" edition=":x86" />
        <vers num="snv_68" edition="" />
        <vers num="snv_68" edition=":x86" />
        <vers num="snv_68" edition=":sparc" />
        <vers num="snv_69" edition="" />
        <vers num="snv_69" edition=":sparc" />
        <vers num="snv_69" edition=":x86" />
        <vers num="snv_70" edition="" />
        <vers num="snv_70" edition=":sparc" />
        <vers num="snv_70" edition=":x86" />
        <vers num="snv_71" edition="" />
        <vers num="snv_71" edition=":sparc" />
        <vers num="snv_71" edition=":x86" />
        <vers num="snv_72" edition="" />
        <vers num="snv_72" edition=":x86" />
        <vers num="snv_72" edition=":sparc" />
        <vers num="snv_73" edition="" />
        <vers num="snv_73" edition=":x86" />
        <vers num="snv_73" edition=":sparc" />
        <vers num="snv_74" edition="" />
        <vers num="snv_74" edition=":x86" />
        <vers num="snv_74" edition=":sparc" />
        <vers num="snv_75" edition="" />
        <vers num="snv_75" edition=":x86" />
        <vers num="snv_75" edition=":sparc" />
        <vers num="snv_76" edition="" />
        <vers num="snv_76" edition=":sparc" />
        <vers num="snv_76" edition=":x86" />
        <vers num="snv_77" edition="" />
        <vers num="snv_77" edition=":sparc" />
        <vers num="snv_77" edition=":x86" />
        <vers num="snv_78" edition="" />
        <vers num="snv_78" edition=":sparc" />
        <vers num="snv_78" edition=":x86" />
        <vers num="snv_79" edition="" />
        <vers num="snv_79" edition=":x86" />
        <vers num="snv_79" edition=":sparc" />
        <vers num="snv_80" edition="" />
        <vers num="snv_80" edition=":x86" />
        <vers num="snv_80" edition=":sparc" />
        <vers num="snv_81" edition="" />
        <vers num="snv_81" edition=":x86" />
        <vers num="snv_81" edition=":sparc" />
        <vers num="snv_82" edition="" />
        <vers num="snv_82" edition=":x86" />
        <vers num="snv_82" edition=":sparc" />
        <vers num="snv_83" edition="" />
        <vers num="snv_83" edition=":sparc" />
        <vers num="snv_83" edition=":x86" />
        <vers num="snv_84" edition="" />
        <vers num="snv_84" edition=":x86" />
        <vers num="snv_84" edition=":sparc" />
        <vers num="snv_85" edition="" />
        <vers num="snv_85" edition=":sparc" />
        <vers num="snv_85" edition=":x86" />
      </prod>
      <prod vendor="sun" name="solaris">
        <vers num="10" edition="" />
        <vers num="10" edition=":sparc" />
        <vers num="10" edition=":x86" />
        <vers num="9" edition="" />
        <vers num="9" edition=":sparc" />
        <vers num="9" edition=":x86" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0347" published="2009-01-29" name="CVE-2009-0347" modified="2009-02-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:P)" CVSS_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_base_score="5.8">
    <desc>
      <descript source="cve">Open redirect vulnerability in cs.html in the Autonomy (formerly Verity) Ultraseek search engine allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via the url parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/202753" source="CERT-VN">VU#202753</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/48336" source="XF">ultraseek-cs-phishing(48336)</ref>
      <ref url="http://www.ultraseek.com/forums/thread.jspa?messageID=9818" source="MISC">http://www.ultraseek.com/forums/thread.jspa?messageID=9818</ref>
      <ref url="http://www.securityfocus.com/bid/33500" source="BID">33500</ref>
      <ref url="http://sunbeltblog.blogspot.com/2009/01/constant-stream-of-ultraseek-redirects.html" source="MISC">http://sunbeltblog.blogspot.com/2009/01/constant-stream-of-ultraseek-redirects.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="autonomy" name="ultraseek">
        <vers num="_nil_" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0348" published="2009-01-29" name="CVE-2009-0348" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The login module in Sun Java System Access Manager 6 2005Q1 (aka 6.3), 7 2005Q4 (aka 7.0), and 7.1 responds differently to a failed login attempt depending on whether the user account exists, which allows remote attackers to enumerate valid usernames.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-242026-1" source="SUNALERT" patch="1" adv="1">242026</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-21-119465-15-1" source="CONFIRM" patch="1">http://sunsolve.sun.com/search/document.do?assetkey=1-21-119465-15-1</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/48283" source="XF">sun-jsam-username-info-disclosure(48283)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0269" source="VUPEN">ADV-2009-0269</ref>
      <ref url="http://www.securityfocus.com/bid/33489" source="BID">33489</ref>
      <ref url="http://secunia.com/advisories/33688" source="SECUNIA" adv="1">33688</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="java_system_access_manager">
        <vers num="6.3_2005q1" edition="" />
        <vers num="6.3_2005q1" edition=":solaris_10_sparc" />
        <vers num="6.3_2005q1" edition=":solaris_8_windows" />
        <vers num="6.3_2005q1" edition=":solaris_8_linux" />
        <vers num="6.3_2005q1" edition=":solaris_9_linux" />
        <vers num="6.3_2005q1" edition=":solaris_9_sparc" />
        <vers num="6.3_2005q1" edition=":solaris_10_linux" />
        <vers num="6.3_2005q1" edition=":solaris_8_x86" />
        <vers num="6.3_2005q1" edition=":solaris_10_x86" />
        <vers num="6.3_2005q1" edition=":solaris_10_windows" />
        <vers num="6.3_2005q1" edition=":solaris_9_x86" />
        <vers num="6.3_2005q1" edition=":solaris_8_sparc" />
        <vers num="6.3_2005q1" edition=":solaris_9_windows" />
        <vers num="7.1" edition="" />
        <vers num="7.1" edition=":solaris_9_sparc" />
        <vers num="7.1" edition=":solaris_10_linux" />
        <vers num="7.1" edition=":solaris_8_x86" />
        <vers num="7.1" edition=":solaris_10_x86" />
        <vers num="7.1" edition=":solaris_10_sparc" />
        <vers num="7.1" edition=":solaris_9_linux" />
        <vers num="7.1" edition=":solaris_8_windows" />
        <vers num="7.1" edition=":solaris_10_windows" />
        <vers num="7.1" edition=":solaris_8_sparc" />
        <vers num="7.1" edition=":solaris_9_windows" />
        <vers num="7.1" edition=":solaris_8_linux" />
        <vers num="7.1" edition=":solaris_9_x86" />
        <vers num="7_2005q4" edition="" />
        <vers num="7_2005q4" edition=":solaris_9_x86" />
        <vers num="7_2005q4" edition=":solaris_8_x86" />
        <vers num="7_2005q4" edition=":solaris_10_linux" />
        <vers num="7_2005q4" edition=":solaris_10_windows" />
        <vers num="7_2005q4" edition=":solaris_10_sparc" />
        <vers num="7_2005q4" edition=":solaris_9_windows" />
        <vers num="7_2005q4" edition=":solaris_10_x86" />
        <vers num="7_2005q4" edition=":solaris_8_sparc" />
        <vers num="7_2005q4" edition=":solaris_9_sparc" />
        <vers num="7_2005q4" edition=":solaris_8_windows" />
        <vers num="7_2005q4" edition=":solaris_9_linux" />
        <vers num="7_2005q4" edition=":solaris_8_linux" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0349" published="2009-01-29" name="CVE-2009-0349" modified="2009-01-30" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Stack-based buffer overflow in FTPShell Server 4.3 allows user-assisted remote attackers to cause a denial of service (persistent daemon crash) and possibly execute arbitrary code via a long string in a licensing key (aka .key) file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.milw0rm.com/exploits/7852" source="MILW0RM">7852</ref>
      <ref url="http://secunia.com/advisories/33597" source="SECUNIA" adv="1">33597</ref>
      <ref url="http://osvdb.org/51510" source="OSVDB">51510</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ftpshell" name="ftpshell_server">
        <vers num="4.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0350" published="2009-01-29" name="CVE-2009-0350" modified="2009-01-30" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Stack-based buffer overflow in Merak Media Player 3.2 allows remote attackers to execute arbitrary code via a long string in a .m3u playlist file, related to the status bar icon's tooltip.  NOTE: some of these details are obtained from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.milw0rm.com/exploits/7857" source="MILW0RM">7857</ref>
      <ref url="http://secunia.com/advisories/33645" source="SECUNIA" adv="1">33645</ref>
      <ref url="http://osvdb.org/51565" source="OSVDB">51565</ref>
    </refs>
    <vuln_soft>
      <prod vendor="merak" name="media_player">
        <vers num="3.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0351" published="2009-01-29" name="CVE-2009-0351" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:C/I:C/A:C)" CVSS_score="9.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.0" CVSS_base_score="9.0">
    <desc>
      <descript source="cve">Stack-based buffer overflow in WFTPSRV.exe in WinFTP 2.3.0 allows remote authenticated users to execute arbitrary code via a long LIST argument beginning with an * (asterisk) character.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/48263" source="XF">winftp-list-bo(48263)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0254" source="VUPEN">ADV-2009-0254</ref>
      <ref url="http://www.securityfocus.com/bid/33454" source="BID">33454</ref>
      <ref url="http://www.milw0rm.com/exploits/7875" source="MILW0RM">7875</ref>
    </refs>
    <vuln_soft>
      <prod vendor="wftpserver" name="winftp_ftp_server">
        <vers num="2.3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0352" published="2009-02-04" name="CVE-2009-0352" modified="2011-09-12" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Multiple unspecified vulnerabilities in Mozilla Firefox 3.x before 3.0.6, Thunderbird before 2.0.0.21, and SeaMonkey before 1.1.15 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to the layout engine and destruction of arbitrary layout objects by the nsViewManager::Composite function.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-March/msg01077.html" source="FEDORA">FEDORA-2009-3101</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-March/msg00771.html" source="FEDORA">FEDORA-2009-2884</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-March/msg00769.html" source="FEDORA">FEDORA-2009-2882</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-February/msg00240.html" source="FEDORA">FEDORA-2009-1399</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=461027" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=461027</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=449006" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=449006</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=437142" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=437142</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=431705" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=431705</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=422301" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=422301</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=422283" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=422283</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=421839" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=421839</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=420697" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=420697</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=416461" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=416461</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=401042" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=401042</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=331088" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=331088</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0313" source="VUPEN">ADV-2009-0313</ref>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-741-1" source="UBUNTU">USN-741-1</ref>
      <ref url="http://www.ubuntu.com/usn/usn-717-1" source="UBUNTU">USN-717-1</ref>
      <ref url="http://www.securitytracker.com/id?1021663" source="SECTRACK">1021663</ref>
      <ref url="http://www.securityfocus.com/bid/33598" source="BID">33598</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-0258.html" source="REDHAT">RHSA-2009:0258</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-0257.html" source="REDHAT">RHSA-2009:0257</ref>
      <ref url="http://www.mozilla.org/security/announce/2009/mfsa2009-01.html" source="CONFIRM" adv="1">http://www.mozilla.org/security/announce/2009/mfsa2009-01.html</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:083" source="MANDRIVA">MDVSA-2009:083</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:044" source="MANDRIVA">MDVSA-2009:044</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1830" source="DEBIAN">DSA-1830</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2009-040.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2009-040.htm</ref>
      <ref url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2009&amp;m=slackware-security.433952" source="SLACKWARE">SSA:2009-083-03</ref>
      <ref url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2009&amp;m=slackware-security.405420" source="SLACKWARE">SSA:2009-083-02</ref>
      <ref url="http://secunia.com/advisories/34527" source="SECUNIA">34527</ref>
      <ref url="http://secunia.com/advisories/34464" source="SECUNIA">34464</ref>
      <ref url="http://secunia.com/advisories/34462" source="SECUNIA">34462</ref>
      <ref url="http://secunia.com/advisories/34417" source="SECUNIA">34417</ref>
      <ref url="http://secunia.com/advisories/34387" source="SECUNIA">34387</ref>
      <ref url="http://secunia.com/advisories/34324" source="SECUNIA">34324</ref>
      <ref url="http://secunia.com/advisories/33869" source="SECUNIA">33869</ref>
      <ref url="http://secunia.com/advisories/33846" source="SECUNIA">33846</ref>
      <ref url="http://secunia.com/advisories/33841" source="SECUNIA">33841</ref>
      <ref url="http://secunia.com/advisories/33831" source="SECUNIA">33831</ref>
      <ref url="http://secunia.com/advisories/33816" source="SECUNIA">33816</ref>
      <ref url="http://secunia.com/advisories/33809" source="SECUNIA">33809</ref>
      <ref url="http://secunia.com/advisories/33808" source="SECUNIA">33808</ref>
      <ref url="http://secunia.com/advisories/33802" source="SECUNIA">33802</ref>
      <ref url="http://secunia.com/advisories/33799" source="SECUNIA">33799</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2009-0256.html" source="REDHAT">RHSA-2009:0256</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10699" source="OVAL">oval:org.mitre.oval:def:10699</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-04/msg00009.html" source="SUSE">SUSE-SA:2009:023</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-02/msg00001.html" source="SUSE">SUSE-SA:2009:009</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="3.0" />
        <vers num="3.0.1" />
        <vers num="3.0.2" />
        <vers num="3.0.3" />
        <vers num="3.0.4" />
        <vers num="3.0.5" />
      </prod>
      <prod vendor="mozilla" name="seamonkey">
        <vers num="1.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.5" />
        <vers num="1.0.6" />
        <vers num="1.0.7" />
        <vers num="1.0.8" />
        <vers num="1.0.9" />
        <vers num="1.1" edition="alpha" />
        <vers num="1.1" edition="beta" />
        <vers num="1.1.1" />
        <vers num="1.1.10" />
        <vers num="1.1.11" />
        <vers num="1.1.12" />
        <vers prev="1" num="1.1.13" />
        <vers num="1.1.2" />
        <vers num="1.1.3" />
        <vers num="1.1.4" />
        <vers num="1.1.5" />
        <vers num="1.1.6" />
        <vers num="1.1.7" />
        <vers num="1.1.8" />
        <vers num="1.1.9" />
      </prod>
      <prod vendor="mozilla" name="thunderbird">
        <vers num="1.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.5" edition="beta" />
        <vers num="1.0.6" />
        <vers num="1.0.7" />
        <vers num="1.0.8" />
        <vers num="1.5" edition="beta2" />
        <vers num="1.5.0.1" />
        <vers num="1.5.0.10" />
        <vers num="1.5.0.11" />
        <vers num="1.5.0.12" />
        <vers num="1.5.0.13" />
        <vers num="1.5.0.14" />
        <vers num="1.5.0.2" />
        <vers num="1.5.0.3" />
        <vers num="1.5.0.4" />
        <vers num="1.5.0.5" />
        <vers num="1.5.0.6" />
        <vers num="1.5.0.7" />
        <vers num="1.5.0.8" />
        <vers num="1.5.0.9" />
        <vers num="1.5.1" />
        <vers num="1.5.2" />
        <vers num="2.0.0.0" />
        <vers num="2.0.0.12" />
        <vers num="2.0.0.14" />
        <vers num="2.0.0.16" />
        <vers num="2.0.0.17" />
        <vers num="2.0.0.18" />
        <vers prev="1" num="2.0.0.19" />
        <vers num="2.0.0.4" />
        <vers num="2.0.0.5" />
        <vers num="2.0.0.6" />
        <vers num="2.0.0.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0353" published="2009-02-04" name="CVE-2009-0353" modified="2011-09-12" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in Mozilla Firefox 3.x before 3.0.6, Thunderbird before 2.0.0.21, and SeaMonkey before 1.1.15 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to the JavaScript engine.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-March/msg01077.html" source="FEDORA">FEDORA-2009-3101</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-March/msg00771.html" source="FEDORA">FEDORA-2009-2884</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-March/msg00769.html" source="FEDORA">FEDORA-2009-2882</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-February/msg00240.html" source="FEDORA">FEDORA-2009-1399</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=452913" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=452913</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0313" source="VUPEN">ADV-2009-0313</ref>
      <ref url="http://www.ubuntu.com/usn/usn-717-1" source="UBUNTU">USN-717-1</ref>
      <ref url="http://www.securitytracker.com/id?1021663" source="SECTRACK">1021663</ref>
      <ref url="http://www.securityfocus.com/bid/33598" source="BID">33598</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-0258.html" source="REDHAT">RHSA-2009:0258</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-0257.html" source="REDHAT">RHSA-2009:0257</ref>
      <ref url="http://www.mozilla.org/security/announce/2009/mfsa2009-01.html" source="CONFIRM" adv="1">http://www.mozilla.org/security/announce/2009/mfsa2009-01.html</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:083" source="MANDRIVA">MDVSA-2009:083</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:044" source="MANDRIVA">MDVSA-2009:044</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1830" source="DEBIAN">DSA-1830</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2009-040.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2009-040.htm</ref>
      <ref url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2009&amp;m=slackware-security.433952" source="SLACKWARE">SSA:2009-083-03</ref>
      <ref url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2009&amp;m=slackware-security.405420" source="SLACKWARE">SSA:2009-083-02</ref>
      <ref url="http://secunia.com/advisories/34527" source="SECUNIA">34527</ref>
      <ref url="http://secunia.com/advisories/34464" source="SECUNIA">34464</ref>
      <ref url="http://secunia.com/advisories/34462" source="SECUNIA">34462</ref>
      <ref url="http://secunia.com/advisories/34417" source="SECUNIA">34417</ref>
      <ref url="http://secunia.com/advisories/34324" source="SECUNIA">34324</ref>
      <ref url="http://secunia.com/advisories/33869" source="SECUNIA">33869</ref>
      <ref url="http://secunia.com/advisories/33846" source="SECUNIA">33846</ref>
      <ref url="http://secunia.com/advisories/33841" source="SECUNIA">33841</ref>
      <ref url="http://secunia.com/advisories/33831" source="SECUNIA">33831</ref>
      <ref url="http://secunia.com/advisories/33816" source="SECUNIA">33816</ref>
      <ref url="http://secunia.com/advisories/33809" source="SECUNIA">33809</ref>
      <ref url="http://secunia.com/advisories/33808" source="SECUNIA">33808</ref>
      <ref url="http://secunia.com/advisories/33802" source="SECUNIA">33802</ref>
      <ref url="http://secunia.com/advisories/33799" source="SECUNIA">33799</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2009-0256.html" source="REDHAT">RHSA-2009:0256</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11193" source="OVAL">oval:org.mitre.oval:def:11193</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-04/msg00009.html" source="SUSE">SUSE-SA:2009:023</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-02/msg00001.html" source="SUSE">SUSE-SA:2009:009</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="3.0" />
        <vers num="3.0.1" />
        <vers num="3.0.2" />
        <vers num="3.0.3" />
        <vers num="3.0.4" />
        <vers num="3.0.5" />
      </prod>
      <prod vendor="mozilla" name="seamonkey">
        <vers num="1.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.5" />
        <vers num="1.0.6" />
        <vers num="1.0.7" />
        <vers num="1.0.8" />
        <vers num="1.0.9" />
        <vers num="1.1" edition="alpha" />
        <vers num="1.1" edition="beta" />
        <vers num="1.1.1" />
        <vers num="1.1.10" />
        <vers num="1.1.11" />
        <vers num="1.1.12" />
        <vers prev="1" num="1.1.13" />
        <vers num="1.1.2" />
        <vers num="1.1.3" />
        <vers num="1.1.4" />
        <vers num="1.1.5" />
        <vers num="1.1.6" />
        <vers num="1.1.7" />
        <vers num="1.1.8" />
        <vers num="1.1.9" />
      </prod>
      <prod vendor="mozilla" name="thunderbird">
        <vers num="1.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.5" edition="beta" />
        <vers num="1.0.6" />
        <vers num="1.0.7" />
        <vers num="1.0.8" />
        <vers num="1.5" edition="beta2" />
        <vers num="1.5.0.1" />
        <vers num="1.5.0.10" />
        <vers num="1.5.0.11" />
        <vers num="1.5.0.12" />
        <vers num="1.5.0.13" />
        <vers num="1.5.0.14" />
        <vers num="1.5.0.2" />
        <vers num="1.5.0.3" />
        <vers num="1.5.0.4" />
        <vers num="1.5.0.5" />
        <vers num="1.5.0.6" />
        <vers num="1.5.0.7" />
        <vers num="1.5.0.8" />
        <vers num="1.5.0.9" />
        <vers num="1.5.1" />
        <vers num="1.5.2" />
        <vers num="2.0.0.0" />
        <vers num="2.0.0.12" />
        <vers num="2.0.0.14" />
        <vers num="2.0.0.16" />
        <vers num="2.0.0.17" />
        <vers num="2.0.0.18" />
        <vers prev="1" num="2.0.0.19" />
        <vers num="2.0.0.4" />
        <vers num="2.0.0.5" />
        <vers num="2.0.0.6" />
        <vers num="2.0.0.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2009-0354" published="2009-02-04" name="CVE-2009-0354" modified="2011-09-12" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Cross-domain vulnerability in js/src/jsobj.cpp in Mozilla Firefox 3.x before 3.0.6 allows remote attackers to bypass the Same Origin Policy, and access the properties of an arbitrary window and conduct cross-site scripting (XSS) attacks, via vectors involving a chrome XBL method and the window.eval function.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-February/msg00240.html" source="FEDORA">FEDORA-2009-1399</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=468581" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=468581</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0313" source="VUPEN">ADV-2009-0313</ref>
      <ref url="http://www.ubuntu.com/usn/usn-717-1" source="UBUNTU">USN-717-1</ref>
      <ref url="http://www.securitytracker.com/id?1021664" source="SECTRACK">1021664</ref>
      <ref url="http://www.securityfocus.com/bid/33598" source="BID">33598</ref>
      <ref url="http://www.mozilla.org/security/announce/2009/mfsa2009-02.html" source="CONFIRM" adv="1">http://www.mozilla.org/security/announce/2009/mfsa2009-02.html</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:044" source="MANDRIVA">MDVSA-2009:044</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2009-040.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2009-040.htm</ref>
      <ref url="http://secunia.com/advisories/33869" source="SECUNIA">33869</ref>
      <ref url="http://secunia.com/advisories/33846" source="SECUNIA">33846</ref>
      <ref url="http://secunia.com/advisories/33841" source="SECUNIA">33841</ref>
      <ref url="http://secunia.com/advisories/33831" source="SECUNIA">33831</ref>
      <ref url="http://secunia.com/advisories/33809" source="SECUNIA">33809</ref>
      <ref url="http://secunia.com/advisories/33799" source="SECUNIA">33799</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2009-0256.html" source="REDHAT">RHSA-2009:0256</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9796" source="OVAL">oval:org.mitre.oval:def:9796</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-02/msg00001.html" source="SUSE">SUSE-SA:2009:009</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="3.0" edition="alpha" />
        <vers num="3.0" edition="beta2" />
        <vers num="3.0" edition="beta5" />
        <vers num="3.0.1" />
        <vers num="3.0.2" />
        <vers num="3.0.3" />
        <vers num="3.0.4" />
        <vers num="3.0.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0355" published="2009-02-04" name="CVE-2009-0355" modified="2011-09-12" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:N/A:N)" CVSS_score="5.4" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="4.9" CVSS_base_score="5.4">
    <desc>
      <descript source="cve">components/sessionstore/src/nsSessionStore.js in Mozilla Firefox before 3.0.6 does not block changes of INPUT elements to type="file" during tab restoration, which allows user-assisted remote attackers to read arbitrary files on a client machine via a crafted INPUT element.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/33598" source="BID" patch="1">33598</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-March/msg00771.html" source="FEDORA">FEDORA-2009-2884</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-March/msg00769.html" source="FEDORA">FEDORA-2009-2882</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-February/msg00240.html" source="FEDORA">FEDORA-2009-1399</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=466937" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=466937</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0313" source="VUPEN">ADV-2009-0313</ref>
      <ref url="http://www.ubuntu.com/usn/usn-717-2" source="UBUNTU">USN-717-2</ref>
      <ref url="http://www.ubuntu.com/usn/usn-717-1" source="UBUNTU">USN-717-1</ref>
      <ref url="http://www.securitytracker.com/id?1021665" source="SECTRACK">1021665</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-0258.html" source="REDHAT">RHSA-2009:0258</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-0257.html" source="REDHAT">RHSA-2009:0257</ref>
      <ref url="http://www.mozilla.org/security/announce/2009/mfsa2009-03.html" source="CONFIRM" adv="1">http://www.mozilla.org/security/announce/2009/mfsa2009-03.html</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:044" source="MANDRIVA">MDVSA-2009:044</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2009-040.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2009-040.htm</ref>
      <ref url="http://secunia.com/advisories/34417" source="SECUNIA" adv="1">34417</ref>
      <ref url="http://secunia.com/advisories/34324" source="SECUNIA" adv="1">34324</ref>
      <ref url="http://secunia.com/advisories/33869" source="SECUNIA" adv="1">33869</ref>
      <ref url="http://secunia.com/advisories/33846" source="SECUNIA" adv="1">33846</ref>
      <ref url="http://secunia.com/advisories/33841" source="SECUNIA" adv="1">33841</ref>
      <ref url="http://secunia.com/advisories/33831" source="SECUNIA" adv="1">33831</ref>
      <ref url="http://secunia.com/advisories/33816" source="SECUNIA" adv="1">33816</ref>
      <ref url="http://secunia.com/advisories/33809" source="SECUNIA" adv="1">33809</ref>
      <ref url="http://secunia.com/advisories/33808" source="SECUNIA" adv="1">33808</ref>
      <ref url="http://secunia.com/advisories/33799" source="SECUNIA" adv="1">33799</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2009-0256.html" source="REDHAT">RHSA-2009:0256</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9161" source="OVAL">oval:org.mitre.oval:def:9161</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-02/msg00001.html" source="SUSE">SUSE-SA:2009:009</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="0.1" />
        <vers num="0.10" />
        <vers num="0.10.1" />
        <vers num="0.2" />
        <vers num="0.3" />
        <vers num="0.4" />
        <vers num="0.5" />
        <vers num="0.6" />
        <vers num="0.6.1" />
        <vers num="0.7" />
        <vers num="0.7.1" />
        <vers num="0.8" />
        <vers num="0.9" edition="rc" />
        <vers num="0.9.1" />
        <vers num="0.9.2" />
        <vers num="0.9.3" />
        <vers num="0.9_rc" />
        <vers num="1.0" edition="preview_release" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.5" />
        <vers num="1.0.6" />
        <vers num="1.0.7" />
        <vers num="1.0.8" />
        <vers num="1.5" edition="beta1" />
        <vers num="1.5" edition="beta2" />
        <vers num="1.5.0.1" />
        <vers num="1.5.0.10" />
        <vers num="1.5.0.11" />
        <vers num="1.5.0.12" />
        <vers num="1.5.0.2" />
        <vers num="1.5.0.3" />
        <vers num="1.5.0.4" />
        <vers num="1.5.0.5" />
        <vers num="1.5.0.6" />
        <vers num="1.5.0.7" />
        <vers num="1.5.0.8" />
        <vers num="1.5.0.9" />
        <vers num="1.5.1" />
        <vers num="1.5.2" />
        <vers num="1.5.3" />
        <vers num="1.5.4" />
        <vers num="1.5.5" />
        <vers num="1.5.6" />
        <vers num="1.5.7" />
        <vers num="1.5.8" />
        <vers num="1.8" />
        <vers num="2.0" edition="beta1" />
        <vers num="2.0" edition="beta_1" />
        <vers num="2.0" edition="rc2" />
        <vers num="2.0" edition="rc3" />
        <vers num="2.0.0.1" />
        <vers num="2.0.0.10" />
        <vers num="2.0.0.11" />
        <vers num="2.0.0.12" />
        <vers num="2.0.0.13" />
        <vers num="2.0.0.14" />
        <vers num="2.0.0.15" />
        <vers num="2.0.0.16" />
        <vers num="2.0.0.17" />
        <vers num="2.0.0.18" />
        <vers num="2.0.0.2" />
        <vers num="2.0.0.3" />
        <vers num="2.0.0.4" />
        <vers num="2.0.0.5" />
        <vers num="2.0.0.6" />
        <vers num="2.0.0.7" />
        <vers num="2.0.0.8" />
        <vers num="2.0.0.9" />
        <vers num="2.0_.1" />
        <vers num="2.0_.10" />
        <vers num="2.0_.4" />
        <vers num="2.0_.5" />
        <vers num="2.0_.6" />
        <vers num="2.0_.7" />
        <vers num="2.0_.9" />
        <vers num="2.0_8" />
        <vers num="3.0" edition="alpha" />
        <vers num="3.0" edition="beta2" />
        <vers num="3.0" edition="beta5" />
        <vers num="3.0.1" />
        <vers num="3.0.2" />
        <vers num="3.0.3" />
        <vers num="3.0.4" />
        <vers prev="1" num="3.0.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0356" published="2009-02-04" name="CVE-2009-0356" modified="2011-09-12" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">Mozilla Firefox before 3.0.6 and SeaMonkey do not block links to the (1) about:plugins and (2) about:config URIs from .desktop files, which allows user-assisted remote attackers to bypass the Same Origin Policy and execute arbitrary code with chrome privileges via vectors involving the URL field in a Desktop Entry section of a .desktop file, related to representation of about: URIs as jar:file:// URIs.  NOTE: this issue exists because of an incomplete fix for CVE-2008-4582.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-February/msg00240.html" source="FEDORA">FEDORA-2009-1399</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=460425" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=460425</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0313" source="VUPEN">ADV-2009-0313</ref>
      <ref url="http://www.securitytracker.com/id?1021666" source="SECTRACK">1021666</ref>
      <ref url="http://www.securityfocus.com/bid/33598" source="BID">33598</ref>
      <ref url="http://www.mozilla.org/security/announce/2009/mfsa2009-04.html" source="CONFIRM" adv="1">http://www.mozilla.org/security/announce/2009/mfsa2009-04.html</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:044" source="MANDRIVA">MDVSA-2009:044</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2009-040.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2009-040.htm</ref>
      <ref url="http://secunia.com/advisories/33846" source="SECUNIA">33846</ref>
      <ref url="http://secunia.com/advisories/33841" source="SECUNIA">33841</ref>
      <ref url="http://secunia.com/advisories/33831" source="SECUNIA">33831</ref>
      <ref url="http://secunia.com/advisories/33809" source="SECUNIA">33809</ref>
      <ref url="http://secunia.com/advisories/33799" source="SECUNIA">33799</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2009-0256.html" source="REDHAT">RHSA-2009:0256</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9922" source="OVAL">oval:org.mitre.oval:def:9922</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-02/msg00001.html" source="SUSE">SUSE-SA:2009:009</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="0.1" />
        <vers num="0.10" />
        <vers num="0.10.1" />
        <vers num="0.2" />
        <vers num="0.3" />
        <vers num="0.4" />
        <vers num="0.5" />
        <vers num="0.6" />
        <vers num="0.6.1" />
        <vers num="0.7" />
        <vers num="0.7.1" />
        <vers num="0.8" />
        <vers num="0.9" edition="rc" />
        <vers num="0.9.1" />
        <vers num="0.9.2" />
        <vers num="0.9.3" />
        <vers num="0.9_rc" />
        <vers num="1.0" edition="preview_release" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.5" />
        <vers num="1.0.6" />
        <vers num="1.0.7" />
        <vers num="1.0.8" />
        <vers num="1.5" edition="beta1" />
        <vers num="1.5" edition="beta2" />
        <vers num="1.5.0.1" />
        <vers num="1.5.0.10" />
        <vers num="1.5.0.11" />
        <vers num="1.5.0.12" />
        <vers num="1.5.0.2" />
        <vers num="1.5.0.3" />
        <vers num="1.5.0.4" />
        <vers num="1.5.0.5" />
        <vers num="1.5.0.6" />
        <vers num="1.5.0.7" />
        <vers num="1.5.0.8" />
        <vers num="1.5.0.9" />
        <vers num="1.5.1" />
        <vers num="1.5.2" />
        <vers num="1.5.3" />
        <vers num="1.5.4" />
        <vers num="1.5.5" />
        <vers num="1.5.6" />
        <vers num="1.5.7" />
        <vers num="1.5.8" />
        <vers num="1.8" />
        <vers num="2.0" edition="beta1" />
        <vers num="2.0" edition="beta_1" />
        <vers num="2.0" edition="rc2" />
        <vers num="2.0" edition="rc3" />
        <vers num="2.0.0.1" />
        <vers num="2.0.0.10" />
        <vers num="2.0.0.11" />
        <vers num="2.0.0.12" />
        <vers num="2.0.0.13" />
        <vers num="2.0.0.14" />
        <vers num="2.0.0.15" />
        <vers num="2.0.0.16" />
        <vers num="2.0.0.17" />
        <vers num="2.0.0.18" />
        <vers num="2.0.0.2" />
        <vers num="2.0.0.3" />
        <vers num="2.0.0.4" />
        <vers num="2.0.0.5" />
        <vers num="2.0.0.6" />
        <vers num="2.0.0.7" />
        <vers num="2.0.0.8" />
        <vers num="2.0.0.9" />
        <vers num="2.0_.1" />
        <vers num="2.0_.10" />
        <vers num="2.0_.4" />
        <vers num="2.0_.5" />
        <vers num="2.0_.6" />
        <vers num="2.0_.7" />
        <vers num="2.0_.9" />
        <vers num="2.0_8" />
        <vers num="3.0" edition="alpha" />
        <vers num="3.0" edition="beta2" />
        <vers num="3.0" edition="beta5" />
        <vers num="3.0.1" />
        <vers num="3.0.2" />
        <vers num="3.0.3" />
        <vers num="3.0.4" />
        <vers prev="1" num="3.0.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0357" published="2009-02-04" name="CVE-2009-0357" modified="2011-09-12" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Mozilla Firefox before 3.0.6 and SeaMonkey before 1.1.15 do not properly restrict access from web pages to the (1) Set-Cookie and (2) Set-Cookie2 HTTP response headers, which allows remote attackers to obtain sensitive information from cookies via XMLHttpRequest calls, related to the HTTPOnly protection mechanism.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-March/msg01077.html" source="FEDORA">FEDORA-2009-3101</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-February/msg00240.html" source="FEDORA">FEDORA-2009-1399</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=380418" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=380418</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0313" source="VUPEN">ADV-2009-0313</ref>
      <ref url="http://www.ubuntu.com/usn/usn-717-2" source="UBUNTU">USN-717-2</ref>
      <ref url="http://www.ubuntu.com/usn/usn-717-1" source="UBUNTU">USN-717-1</ref>
      <ref url="http://www.securitytracker.com/id?1021668" source="SECTRACK">1021668</ref>
      <ref url="http://www.securityfocus.com/bid/33598" source="BID">33598</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-0257.html" source="REDHAT">RHSA-2009:0257</ref>
      <ref url="http://www.mozilla.org/security/announce/2009/mfsa2009-05.html" source="CONFIRM" adv="1">http://www.mozilla.org/security/announce/2009/mfsa2009-05.html</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:044" source="MANDRIVA">MDVSA-2009:044</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2009-040.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2009-040.htm</ref>
      <ref url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2009&amp;m=slackware-security.405420" source="SLACKWARE">SSA:2009-083-02</ref>
      <ref url="http://secunia.com/advisories/34527" source="SECUNIA">34527</ref>
      <ref url="http://secunia.com/advisories/34462" source="SECUNIA">34462</ref>
      <ref url="http://secunia.com/advisories/33869" source="SECUNIA">33869</ref>
      <ref url="http://secunia.com/advisories/33846" source="SECUNIA">33846</ref>
      <ref url="http://secunia.com/advisories/33841" source="SECUNIA">33841</ref>
      <ref url="http://secunia.com/advisories/33831" source="SECUNIA">33831</ref>
      <ref url="http://secunia.com/advisories/33816" source="SECUNIA">33816</ref>
      <ref url="http://secunia.com/advisories/33809" source="SECUNIA">33809</ref>
      <ref url="http://secunia.com/advisories/33808" source="SECUNIA">33808</ref>
      <ref url="http://secunia.com/advisories/33799" source="SECUNIA">33799</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2009-0256.html" source="REDHAT">RHSA-2009:0256</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9459" source="OVAL">oval:org.mitre.oval:def:9459</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-02/msg00001.html" source="SUSE">SUSE-SA:2009:009</ref>
      <ref url="http://ha.ckers.org/blog/20070511/bluehat-errata/" source="MISC">http://ha.ckers.org/blog/20070511/bluehat-errata/</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="0.1" />
        <vers num="0.2" />
        <vers num="0.3" />
        <vers num="0.4" />
        <vers num="0.5" />
        <vers num="0.6" />
        <vers num="0.6.1" />
        <vers num="0.7" />
        <vers num="0.7.1" />
        <vers num="0.8" />
        <vers num="0.9" />
        <vers num="0.9.1" />
        <vers num="0.9.2" />
        <vers num="0.9.3" />
        <vers num="1.0" edition="preview_release" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.5" />
        <vers num="1.0.6" />
        <vers num="1.0.7" />
        <vers num="1.0.8" />
        <vers num="1.5" />
        <vers num="1.5.0.1" />
        <vers num="1.5.0.10" />
        <vers num="1.5.0.11" />
        <vers num="1.5.0.12" />
        <vers num="1.5.0.2" />
        <vers num="1.5.0.3" />
        <vers num="1.5.0.4" />
        <vers num="1.5.0.5" />
        <vers num="1.5.0.6" />
        <vers num="1.5.0.7" />
        <vers num="1.5.0.8" />
        <vers num="1.5.0.9" />
        <vers num="2.0" edition="beta1" />
        <vers num="2.0" edition="rc2" />
        <vers num="2.0" edition="rc3" />
        <vers num="2.0.0.1" />
        <vers num="2.0.0.10" />
        <vers num="2.0.0.11" />
        <vers num="2.0.0.12" />
        <vers num="2.0.0.13" />
        <vers num="2.0.0.14" />
        <vers num="2.0.0.15" />
        <vers num="2.0.0.16" />
        <vers num="2.0.0.17" />
        <vers num="2.0.0.18" />
        <vers num="2.0.0.19" />
        <vers num="2.0.0.2" />
        <vers num="2.0.0.20" />
        <vers num="2.0.0.3" />
        <vers num="2.0.0.4" />
        <vers num="2.0.0.5" />
        <vers num="2.0.0.6" />
        <vers num="2.0.0.7" />
        <vers num="2.0.0.8" />
        <vers num="2.0.0.9" />
        <vers num="3.0" edition="alpha" />
        <vers num="3.0" edition="beta2" />
        <vers num="3.0" edition="beta5" />
        <vers num="3.0.1" />
        <vers num="3.0.2" />
        <vers num="3.0.3" />
        <vers num="3.0.4" />
        <vers prev="1" num="3.0.5" />
      </prod>
      <prod vendor="mozilla" name="seamonkey">
        <vers num="1.0" edition="alpha" />
        <vers num="1.0" edition="beta" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.5" />
        <vers num="1.0.6" />
        <vers num="1.0.7" />
        <vers num="1.0.8" />
        <vers num="1.0.9" />
        <vers num="1.1" edition="alpha" />
        <vers num="1.1" edition="beta" />
        <vers num="1.1.1" />
        <vers num="1.1.10" />
        <vers num="1.1.11" />
        <vers num="1.1.12" />
        <vers prev="1" num="1.1.13" />
        <vers num="1.1.2" />
        <vers num="1.1.3" />
        <vers num="1.1.4" />
        <vers num="1.1.5" />
        <vers num="1.1.6" />
        <vers num="1.1.7" />
        <vers num="1.1.8" />
        <vers num="1.1.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2009-0358" published="2009-02-04" name="CVE-2009-0358" modified="2011-09-12" CVSS_version="2.0" CVSS_vector="(AV:A/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="3.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="6.5" CVSS_base_score="3.3">
    <desc>
      <descript source="cve">Mozilla Firefox 3.x before 3.0.6 does not properly implement the (1) no-store and (2) no-cache Cache-Control directives, which allows local users to obtain sensitive information by using the (a) back button or (b) history list of the victim's browser, as demonstrated by reading the response page of an https POST request.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <local_network />
    </range>
    <refs>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-February/msg00240.html" source="FEDORA">FEDORA-2009-1399</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=441751" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=441751</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0313" source="VUPEN">ADV-2009-0313</ref>
      <ref url="http://www.ubuntu.com/usn/usn-717-1" source="UBUNTU">USN-717-1</ref>
      <ref url="http://www.securitytracker.com/id?1021667" source="SECTRACK">1021667</ref>
      <ref url="http://www.securityfocus.com/bid/33598" source="BID">33598</ref>
      <ref url="http://www.mozilla.org/security/announce/2009/mfsa2009-06.html" source="CONFIRM" adv="1">http://www.mozilla.org/security/announce/2009/mfsa2009-06.html</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:044" source="MANDRIVA">MDVSA-2009:044</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2009-040.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2009-040.htm</ref>
      <ref url="http://secunia.com/advisories/33869" source="SECUNIA">33869</ref>
      <ref url="http://secunia.com/advisories/33846" source="SECUNIA">33846</ref>
      <ref url="http://secunia.com/advisories/33841" source="SECUNIA">33841</ref>
      <ref url="http://secunia.com/advisories/33831" source="SECUNIA">33831</ref>
      <ref url="http://secunia.com/advisories/33809" source="SECUNIA">33809</ref>
      <ref url="http://secunia.com/advisories/33799" source="SECUNIA">33799</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2009-0256.html" source="REDHAT">RHSA-2009:0256</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10610" source="OVAL">oval:org.mitre.oval:def:10610</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-02/msg00001.html" source="SUSE">SUSE-SA:2009:009</ref>
      <ref url="http://blogs.imeta.co.uk/JDeabill/archive/2008/07/14/303.aspx" source="MISC">http://blogs.imeta.co.uk/JDeabill/archive/2008/07/14/303.aspx</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="3.0" edition="alpha" />
        <vers num="3.0" edition="beta2" />
        <vers num="3.0" edition="beta5" />
        <vers num="3.0.1" />
        <vers num="3.0.2" />
        <vers num="3.0.3" />
        <vers num="3.0.4" />
        <vers num="3.0.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2009-0359" published="2009-02-17" name="CVE-2009-0359" modified="2009-03-04" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:S/C:N/I:P/A:N)" CVSS_score="3.5" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="6.8" CVSS_base_score="3.5">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Samizdat before 0.6.2 allow remote authenticated users to inject arbitrary web script or HTML via the (1) message title or (2) user full name.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/33768" source="BID" patch="1">33768</ref>
      <ref url="http://www.nongnu.org/samizdat/release-notes/samizdat-0.6.2.html" source="CONFIRM" patch="1" adv="1">http://www.nongnu.org/samizdat/release-notes/samizdat-0.6.2.html</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/500961/100/0/threaded" source="BUGTRAQ">20090213 Cross-site scripting in Samizdat 0.6.1</ref>
      <ref url="http://www.mail-archive.com/debian-testing-security-announce@lists.debian.org/msg00171.html" source="MLIST">[debian-testing-security-announce] 20090211 Security update for Debian Testing - 2009-02-12</ref>
      <ref url="http://samizdat.nongnu.org/release-notes/samizdat-0.6.1-xss-escape-title.patch" source="CONFIRM" adv="1">http://samizdat.nongnu.org/release-notes/samizdat-0.6.1-xss-escape-title.patch</ref>
      <ref url="http://osvdb.org/52022" source="OSVDB">52022</ref>
    </refs>
    <vuln_soft>
      <prod vendor="nongnu" name="samizdat">
        <vers prev="1" num="0.6.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0360" published="2009-02-13" name="CVE-2009-0360" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:H/Au:N/C:C/I:C/A:C)" CVSS_score="6.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="1.9" CVSS_base_score="6.2">
    <desc>
      <descript source="cve">Russ Allbery pam-krb5 before 3.13, when linked against MIT Kerberos, does not properly initialize the Kerberos libraries for setuid use, which allows local users to gain privileges by pointing an environment variable to a modified Kerberos configuration file, and then launching a PAM-based setuid application.</descript>
      <descript source="nvd">Per vendor advisory:
 http://www.eyrie.org/~eagle/software/pam-krb5/security/2009-02-11.html

"This advisory is only for my pam-krb5 module, as distributed from my web site and packaged by Debian, Ubuntu, and Gentoo."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2009/0979" source="VUPEN">ADV-2009-0979</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0426" source="VUPEN">ADV-2009-0426</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0410" source="VUPEN">ADV-2009-0410</ref>
      <ref url="http://www.ubuntu.com/usn/USN-719-1" source="UBUNTU">USN-719-1</ref>
      <ref url="http://www.securityfocus.com/bid/33740" source="BID">33740</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/500892/100/0/threaded" source="BUGTRAQ">20090211 pam-krb5 security advisory (3.12 and earlier)</ref>
      <ref url="http://www.eyrie.org/~eagle/software/pam-krb5/security/2009-02-11.html" source="MISC" adv="1">http://www.eyrie.org/~eagle/software/pam-krb5/security/2009-02-11.html</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1721" source="DEBIAN">DSA-1721</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2009-070.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2009-070.htm</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-252767-1" source="SUNALERT">252767</ref>
      <ref url="http://securitytracker.com/id?1021711" source="SECTRACK">1021711</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200903-39.xml" source="GENTOO">GLSA-200903-39</ref>
      <ref url="http://secunia.com/advisories/34449" source="SECUNIA">34449</ref>
      <ref url="http://secunia.com/advisories/34260" source="SECUNIA">34260</ref>
      <ref url="http://secunia.com/advisories/33917" source="SECUNIA" adv="1">33917</ref>
      <ref url="http://secunia.com/advisories/33914" source="SECUNIA" adv="1">33914</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5732" source="OVAL">oval:org.mitre.oval:def:5732</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5669" source="OVAL">oval:org.mitre.oval:def:5669</ref>
    </refs>
    <vuln_soft>
      <prod vendor="eyrie" name="pam-krb5">
        <vers num="2.0" />
        <vers num="2.1" />
        <vers num="2.2" />
        <vers num="2.3" />
        <vers num="2.4" />
        <vers num="2.5" />
        <vers num="2.6" />
        <vers num="3.0" />
        <vers num="3.1" />
        <vers num="3.10" />
        <vers num="3.11" />
        <vers prev="1" num="3.12" />
        <vers num="3.2" />
        <vers num="3.3" />
        <vers num="3.4" />
        <vers num="3.5" />
        <vers num="3.6" />
        <vers num="3.7" />
        <vers num="3.8" />
        <vers num="3.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0361" published="2009-02-13" name="CVE-2009-0361" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Russ Allbery pam-krb5 before 3.13, as used by libpam-heimdal, su in Solaris 10, and other software, does not properly handle calls to pam_setcred when running setuid, which allows local users to overwrite and change the ownership of arbitrary files by setting the KRB5CCNAME environment variable, and then launching a setuid application that performs certain pam_setcred operations.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2009/0979" source="VUPEN">ADV-2009-0979</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0426" source="VUPEN">ADV-2009-0426</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0410" source="VUPEN">ADV-2009-0410</ref>
      <ref url="http://www.ubuntu.com/usn/USN-719-1" source="UBUNTU">USN-719-1</ref>
      <ref url="http://www.securityfocus.com/bid/33741" source="BID">33741</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/500892/100/0/threaded" source="BUGTRAQ">20090211 pam-krb5 security advisory (3.12 and earlier)</ref>
      <ref url="http://www.eyrie.org/~eagle/software/pam-krb5/security/2009-02-11.html" source="MISC">http://www.eyrie.org/~eagle/software/pam-krb5/security/2009-02-11.html</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1722" source="DEBIAN">DSA-1722</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1721" source="DEBIAN">DSA-1721</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2009-070.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2009-070.htm</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-252767-1" source="SUNALERT">252767</ref>
      <ref url="http://securitytracker.com/id?1021711" source="SECTRACK">1021711</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200903-39.xml" source="GENTOO">GLSA-200903-39</ref>
      <ref url="http://secunia.com/advisories/34449" source="SECUNIA">34449</ref>
      <ref url="http://secunia.com/advisories/34260" source="SECUNIA">34260</ref>
      <ref url="http://secunia.com/advisories/33918" source="SECUNIA" adv="1">33918</ref>
      <ref url="http://secunia.com/advisories/33917" source="SECUNIA" adv="1">33917</ref>
      <ref url="http://secunia.com/advisories/33914" source="SECUNIA" adv="1">33914</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5521" source="OVAL">oval:org.mitre.oval:def:5521</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5403" source="OVAL">oval:org.mitre.oval:def:5403</ref>
    </refs>
    <vuln_soft>
      <prod vendor="eyrie" name="pam-krb5">
        <vers num="3.0" />
        <vers num="3.1" />
        <vers num="3.10" />
        <vers num="3.11" />
        <vers prev="1" num="3.12" />
        <vers num="3.2" />
        <vers num="3.3" />
        <vers num="3.4" />
        <vers num="3.5" />
        <vers num="3.6" />
        <vers num="3.7" />
        <vers num="3.8" />
        <vers num="3.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0362" published="2009-02-12" name="CVE-2009-0362" modified="2009-02-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:N/I:N/A:P)" CVSS_score="4.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.0" CVSS_base_score="4.0">
    <desc>
      <descript source="cve">filter.d/wuftpd.conf in Fail2ban 0.8.3 uses an incorrect regular expression that allows remote attackers to cause a denial of service (forced authentication failures) via a crafted reverse-resolved DNS name (rhost) entry that contains a substring that is interpreted as an IP address, a different vulnerability than CVE-2007-4321.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/33734" source="BID">33734</ref>
      <ref url="http://secunia.com/advisories/33890" source="SECUNIA" adv="1">33890</ref>
      <ref url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=514163" source="CONFIRM">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=514163</ref>
    </refs>
    <vuln_soft>
      <prod vendor="fail2ban" name="fail2ban">
        <vers num="0.8.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0363" published="2009-02-17" name="CVE-2009-0363" modified="2010-03-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple buffer overflows in (a) BarnOwl before 1.0.5 and (b) owl 2.1.11 allow remote attackers to execute arbitrary code via vectors involving (1) a crafted zcrypt message, related to zcrypt.c; (2) a reply command on a message with a Zephyr Cc: list, related to zwrite.c; and unspecified other use of the products.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="https://bugs.launchpad.net/ubuntu/+source/owl/+bug/329165" source="CONFIRM">https://bugs.launchpad.net/ubuntu/+source/owl/+bug/329165</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/48824" source="XF">barnowl-owl-zcrypt-bo(48824)</ref>
      <ref url="http://www.mail-archive.com/debian-testing-security-announce@lists.debian.org/msg00173.html" source="MLIST">[debian-testing-security-announce] 20090213 Security update for Debian Testing - 2009-02-14</ref>
      <ref url="http://bugs.debian.org/515118" source="CONFIRM">http://bugs.debian.org/515118</ref>
      <ref url="http://barnowl.mit.edu/wiki/barnowl-1.0.5-announce" source="CONFIRM" adv="1">http://barnowl.mit.edu/wiki/barnowl-1.0.5-announce</ref>
      <ref url="http://barnowl.mit.edu/browser/ChangeLog" source="CONFIRM" adv="1">http://barnowl.mit.edu/browser/ChangeLog</ref>
    </refs>
    <vuln_soft>
      <prod vendor="barnowl" name="barnowl">
        <vers num="1.0.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.2.1" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers prev="1" num="1.0.4.1" />
      </prod>
      <prod vendor="ktools" name="owl">
        <vers num="2.1.11" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0364" published="2009-03-26" name="CVE-2009-0364" modified="2009-04-02" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Format string vulnerability in the mini_calendar component in Citadel.org WebCit 7.22, and other versions before 7.39, allows remote attackers to execute arbitrary code via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/34206" source="BID" patch="1">34206</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1752" source="DEBIAN">DSA-1752</ref>
      <ref url="http://www.citadel.org/doku.php/news:webcit.security.advisory.-.2009-march-23" source="CONFIRM" adv="1">http://www.citadel.org/doku.php/news:webcit.security.advisory.-.2009-march-23</ref>
      <ref url="http://secunia.com/advisories/34457" source="SECUNIA">34457</ref>
      <ref url="http://osvdb.org/52915" source="OSVDB">52915</ref>
    </refs>
    <vuln_soft>
      <prod vendor="citadel" name="webcit">
        <vers num="7.02" />
        <vers num="7.10" />
        <vers num="7.11" />
        <vers num="7.12" />
        <vers num="7.22" />
        <vers num="7.37" />
        <vers prev="1" num="7.38" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0365" published="2009-03-04" name="CVE-2009-0365" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:S/C:C/I:N/A:N)" CVSS_score="4.6" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="3.1" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">nm-applet.conf in GNOME NetworkManager before 0.7.0.99 contains an incorrect deny setting, which allows local users to discover (1) network connection passwords and (2) pre-shared keys via calls to the GetSecrets method in the dbus request handler.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/33966" source="BID" patch="1">33966</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=487752" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=487752</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=487722" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=487722</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/49062" source="XF">networkmanager-dbus-info-disclosure(49062)</ref>
      <ref url="http://www.ubuntu.com/usn/USN-727-2" source="UBUNTU" adv="1">USN-727-2</ref>
      <ref url="http://www.ubuntu.com/usn/USN-727-1" source="UBUNTU" adv="1">USN-727-1</ref>
      <ref url="http://www.securitytracker.com/id?1021908" source="SECTRACK">1021908</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-0362.html" source="REDHAT">RHSA-2009:0362</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-0361.html" source="REDHAT">RHSA-2009:0361</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1955" source="DEBIAN">DSA-1955</ref>
      <ref url="http://svn.gnome.org/viewvc/network-manager-applet?view=revision&amp;revision=1207" source="CONFIRM">http://svn.gnome.org/viewvc/network-manager-applet?view=revision&amp;revision=1207</ref>
      <ref url="http://svn.gnome.org/viewvc/network-manager-applet/trunk/nm-applet.conf?r1=1133&amp;r2=1207&amp;pathrev=1207" source="CONFIRM">http://svn.gnome.org/viewvc/network-manager-applet/trunk/nm-applet.conf?r1=1133&amp;r2=1207&amp;pathrev=1207</ref>
      <ref url="http://securitytracker.com/id?1021911" source="SECTRACK">1021911</ref>
      <ref url="http://securitytracker.com/id?1021910" source="SECTRACK">1021910</ref>
      <ref url="http://secunia.com/advisories/34473" source="SECUNIA">34473</ref>
      <ref url="http://secunia.com/advisories/34177" source="SECUNIA">34177</ref>
      <ref url="http://secunia.com/advisories/34067" source="SECUNIA">34067</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10828" source="OVAL">oval:org.mitre.oval:def:10828</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-04/msg00010.html" source="SUSE">SUSE-SR:2009:009</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-03/msg00003.html" source="SUSE">SUSE-SA:2009:013</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ubuntu" name="ubuntu_linux">
        <vers num="6.06" edition="-" />
        <vers num="6.06" edition="-:lts" />
        <vers num="7.10" />
        <vers num="8.04" edition="-" />
        <vers num="8.04" edition="-:lts" />
        <vers num="8.10" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0366" published="2009-03-12" name="CVE-2009-0366" modified="2009-03-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">The uncompress_buffer function in src/server/simple_wml.cpp in Wesnoth before r33069 allows remote attackers to cause a denial of service via a large compressed WML document.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="https://gna.org/bugs/index.php?13037" source="CONFIRM">https://gna.org/bugs/index.php?13037</ref>
      <ref url="http://www.securityfocus.com/bid/34085" source="BID">34085</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1737" source="DEBIAN">DSA-1737</ref>
      <ref url="http://svn.gna.org/viewcvs/wesnoth/trunk/src/server/simple_wml.cpp?rev=33069&amp;view=log" source="CONFIRM">http://svn.gna.org/viewcvs/wesnoth/trunk/src/server/simple_wml.cpp?rev=33069&amp;view=log</ref>
      <ref url="http://svn.gna.org/viewcvs/wesnoth/trunk/src/server/simple_wml.cpp?rev=33069&amp;r1=32990&amp;r2=33069" source="CONFIRM">http://svn.gna.org/viewcvs/wesnoth/trunk/src/server/simple_wml.cpp?rev=33069&amp;r1=32990&amp;r2=33069</ref>
      <ref url="http://secunia.com/advisories/34253" source="SECUNIA">34253</ref>
      <ref url="http://secunia.com/advisories/34236" source="SECUNIA">34236</ref>
      <ref url="http://packages.debian.org/changelogs/pool/main/w/wesnoth/wesnoth_1.5.12-1/changelog" source="CONFIRM">http://packages.debian.org/changelogs/pool/main/w/wesnoth/wesnoth_1.5.12-1/changelog</ref>
      <ref url="http://packages.debian.org/changelogs/pool/main/w/wesnoth/wesnoth_1.4.7-4/changelog" source="CONFIRM">http://packages.debian.org/changelogs/pool/main/w/wesnoth/wesnoth_1.4.7-4/changelog</ref>
      <ref url="http://osvdb.org/52672" source="OSVDB">52672</ref>
      <ref url="http://launchpad.net/bugs/cve/2009-0366" source="CONFIRM">http://launchpad.net/bugs/cve/2009-0366</ref>
      <ref url="http://launchpad.net/bugs/336396" source="CONFIRM">http://launchpad.net/bugs/336396</ref>
      <ref url="http://launchpad.net/bugs/335089" source="CONFIRM">http://launchpad.net/bugs/335089</ref>
    </refs>
    <vuln_soft>
      <prod vendor="wesnoth" name="wesnoth">
        <vers num="1.0" edition="rc" />
        <vers num="1.1" />
        <vers num="1.1.1" />
        <vers num="1.1.10" />
        <vers num="1.1.11" />
        <vers num="1.1.12" />
        <vers num="1.1.13" />
        <vers num="1.1.14" />
        <vers num="1.1.2" />
        <vers num="1.1.3" />
        <vers num="1.1.4" />
        <vers num="1.1.5" />
        <vers num="1.1.6" />
        <vers num="1.1.7" />
        <vers num="1.1.8" />
        <vers num="1.1.9" />
        <vers num="1.2" />
        <vers num="1.2.1" />
        <vers num="1.2.2" />
        <vers num="1.2.3" />
        <vers num="1.2.4" />
        <vers num="1.2.5" />
        <vers num="1.2.6" />
        <vers num="1.2.7" />
        <vers num="1.2.8" />
        <vers num="1.3.10" />
        <vers num="1.3.11" />
        <vers num="1.3.12" />
        <vers num="1.3.13" />
        <vers num="1.3.14" />
        <vers num="1.3.15" />
        <vers num="1.3.16" />
        <vers num="1.3.17" />
        <vers num="1.3.18" />
        <vers num="1.3.19" />
        <vers num="1.3.8" />
        <vers num="1.3.9" />
        <vers num="1.4" />
        <vers num="1.4.1" />
        <vers num="1.4.2" />
        <vers num="1.4.3" />
        <vers num="1.4.4" />
        <vers num="1.4.5" />
        <vers num="1.4.6" />
        <vers num="1.4.7" />
        <vers num="1.5.0" />
        <vers num="1.5.1" />
        <vers num="1.5.10" />
        <vers prev="1" num="1.5.11" />
        <vers num="1.5.2" />
        <vers num="1.5.3" />
        <vers num="1.5.4" />
        <vers num="1.5.5" />
        <vers num="1.5.6" />
        <vers num="1.5.7" />
        <vers num="1.5.8" />
        <vers num="1.5.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0367" published="2009-03-04" name="CVE-2009-0367" modified="2010-04-27" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">The Python AI module in Wesnoth 1.4.x and 1.5 before 1.5.11 allows remote attackers to escape the sandbox and execute arbitrary code by using a whitelisted module that imports an unsafe module, then using a hierarchical module name to access the unsafe module through the whitelisted module.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.wesnoth.org/forum/viewtopic.php?t=24340" source="CONFIRM" patch="1" adv="1">http://www.wesnoth.org/forum/viewtopic.php?t=24340</ref>
      <ref url="http://www.wesnoth.org/forum/viewtopic.php?t=24247" source="CONFIRM" patch="1" adv="1">http://www.wesnoth.org/forum/viewtopic.php?t=24247</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0595" source="VUPEN" patch="1" adv="1">ADV-2009-0595</ref>
      <ref url="https://gna.org/bugs/index.php?13048" source="CONFIRM">https://gna.org/bugs/index.php?13048</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/49058" source="XF">wesnoth-pythonai-code-execution(49058)</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1737" source="DEBIAN">DSA-1737</ref>
      <ref url="http://secunia.com/advisories/34236" source="SECUNIA">34236</ref>
      <ref url="http://secunia.com/advisories/34058" source="SECUNIA" adv="1">34058</ref>
      <ref url="http://packages.debian.org/changelogs/pool/main/w/wesnoth/wesnoth_1.5.12-1/changelog" source="CONFIRM">http://packages.debian.org/changelogs/pool/main/w/wesnoth/wesnoth_1.5.12-1/changelog</ref>
      <ref url="http://packages.debian.org/changelogs/pool/main/w/wesnoth/wesnoth_1.4.7-4/changelog" source="CONFIRM">http://packages.debian.org/changelogs/pool/main/w/wesnoth/wesnoth_1.4.7-4/changelog</ref>
      <ref url="http://launchpad.net/bugs/cve/2009-0367" source="CONFIRM">http://launchpad.net/bugs/cve/2009-0367</ref>
      <ref url="http://launchpad.net/bugs/336396" source="CONFIRM">http://launchpad.net/bugs/336396</ref>
      <ref url="http://launchpad.net/bugs/335089" source="CONFIRM">http://launchpad.net/bugs/335089</ref>
    </refs>
    <vuln_soft>
      <prod vendor="wesnoth" name="wesnoth">
        <vers num="1.4" />
        <vers num="1.4.1" />
        <vers num="1.4.2" />
        <vers num="1.4.3" />
        <vers num="1.4.4" />
        <vers num="1.4.5" />
        <vers num="1.4.6" />
        <vers num="1.4.7" />
        <vers num="1.5.0" />
        <vers num="1.5.1" />
        <vers num="1.5.10" />
        <vers num="1.5.2" />
        <vers num="1.5.3" />
        <vers num="1.5.4" />
        <vers num="1.5.5" />
        <vers num="1.5.6" />
        <vers num="1.5.7" />
        <vers num="1.5.8" />
        <vers num="1.5.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2009-0368" published="2009-03-02" name="CVE-2009-0368" modified="2010-04-27" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">OpenSC before 0.11.7 allows physically proximate attackers to bypass intended PIN requirements and read private data objects via a (1) low level APDU command or (2) debugging tool, as demonstrated by reading the 4601 or 4701 file with the opensc-explorer or opensc-tool program.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/33922" source="BID" patch="1">33922</ref>
      <ref url="http://openwall.com/lists/oss-security/2009/02/26/1" source="MLIST" patch="1">[oss-security] 20090226 OpenSC Security Advisory</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-March/msg00686.html" source="FEDORA">FEDORA-2009-2267</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-March/msg00673.html" source="FEDORA">FEDORA-2009-2266</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/48958" source="XF">opensc-pkcs-unauth-access(48958)</ref>
      <ref url="http://www.opensc-project.org/pipermail/opensc-announce/2009-February/000023.html" source="MLIST" adv="1">[opensc-announce] 20090226 OpenSC Security Advisory</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1734" source="DEBIAN">DSA-1734</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200908-01.xml" source="GENTOO">GLSA-200908-01</ref>
      <ref url="http://secunia.com/advisories/36074" source="SECUNIA">36074</ref>
      <ref url="http://secunia.com/advisories/35065" source="SECUNIA">35065</ref>
      <ref url="http://secunia.com/advisories/34377" source="SECUNIA">34377</ref>
      <ref url="http://secunia.com/advisories/34362" source="SECUNIA">34362</ref>
      <ref url="http://secunia.com/advisories/34120" source="SECUNIA">34120</ref>
      <ref url="http://secunia.com/advisories/34052" source="SECUNIA" adv="1">34052</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-05/msg00000.html" source="SUSE">SUSE-SR:2009:010</ref>
    </refs>
    <vuln_soft>
      <prod vendor="opensc-project" name="opensc">
        <vers num="0.10.0" />
        <vers num="0.10.1" />
        <vers num="0.11.0" />
        <vers num="0.11.1" />
        <vers num="0.11.2" />
        <vers num="0.11.3" edition="pre3" />
        <vers num="0.11.4" />
        <vers num="0.11.5" />
        <vers prev="1" num="0.11.6" />
        <vers num="0.3.2" />
        <vers num="0.3.5" />
        <vers num="0.4.0" />
        <vers num="0.5.0" />
        <vers num="0.6.0" />
        <vers num="0.6.1" />
        <vers num="0.7.0" />
        <vers num="0.8" />
        <vers num="0.8.0" />
        <vers num="0.8.0.0" />
        <vers num="0.8.1" />
        <vers num="0.9" />
        <vers num="0.9.2" />
        <vers num="0.9.3" />
        <vers num="0.9.4" />
        <vers num="0.9.5" />
        <vers num="0.9.6" />
        <vers num="0.9.7" edition="b" />
        <vers num="0.9.7" edition="d" />
        <vers num="0.9.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0369" published="2009-01-30" name="CVE-2009-0369" modified="2009-02-12" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Microsoft Internet Explorer 7 allows remote attackers to trick a user into visiting an arbitrary URL via an onclick action that moves a crafted element to the current mouse position, related to a "Clickjacking" vulnerability.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/48542" source="XF">ie-onclickaction-click-hijacking(48542)</ref>
      <ref url="http://www.milw0rm.com/exploits/7912" source="MILW0RM">7912</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="internet_explorer">
        <vers num="7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0370" published="2009-01-30" name="CVE-2009-0370" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Multiple unspecified vulnerabilities in IBM AIX 5.2.0 through 6.1.2 allow local users to append data to arbitrary files, related to (1) rmsock and (2) rmsock64 not creating "secure log files."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/33522" source="BID" patch="1">33522</ref>
      <ref url="http://www.ibm.com/support/docview.wss?uid=isg1IZ42788" source="AIXAPAR" patch="1">IZ42788</ref>
      <ref url="http://www.ibm.com/support/docview.wss?uid=isg1IZ42787" source="AIXAPAR" patch="1">IZ42787</ref>
      <ref url="http://www.ibm.com/support/docview.wss?uid=isg1IZ42786" source="AIXAPAR" patch="1">IZ42786</ref>
      <ref url="http://www.ibm.com/support/docview.wss?uid=isg1IZ42785" source="AIXAPAR" patch="1">IZ42785</ref>
      <ref url="http://www.ibm.com/support/docview.wss?uid=isg1IZ41599" source="AIXAPAR" patch="1">IZ41599</ref>
      <ref url="http://www.ibm.com/support/docview.wss?uid=isg1IZ41510" source="AIXAPAR" patch="1">IZ41510</ref>
      <ref url="http://www.ibm.com/support/docview.wss?uid=isg1IZ40386" source="AIXAPAR" patch="1">IZ40386</ref>
      <ref url="http://www.ibm.com/support/docview.wss?uid=isg1IZ41593" source="AIXAPAR">IZ41593</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6028" source="OVAL">oval:org.mitre.oval:def:6028</ref>
      <ref url="http://aix.software.ibm.com/aix/efixes/security/rmsock_advisory.asc" source="CONFIRM">http://aix.software.ibm.com/aix/efixes/security/rmsock_advisory.asc</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="aix">
        <vers num="5.2" />
        <vers num="5.2.2" />
        <vers num="5.2_l" />
        <vers num="5.3" />
        <vers num="5.3.7" />
        <vers num="5.3.8" />
        <vers num="5.3.9" />
        <vers num="5.3_l" />
        <vers num="6.1" />
        <vers num="6.1.1" />
        <vers num="6.1.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0371" published="2009-01-30" name="CVE-2009-0371" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Directory traversal vulnerability in post.php in SiteXS CMS 0.1.1 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the type parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/48236" source="XF">sitexs-type-file-include(48236)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0247" source="VUPEN">ADV-2009-0247</ref>
      <ref url="http://www.securityfocus.com/bid/33457" source="BID">33457</ref>
      <ref url="http://www.milw0rm.com/exploits/7879" source="MILW0RM">7879</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sitexs_cms" name="sitexs_cms">
        <vers num="0.1" edition="pre-alpha" />
        <vers prev="1" num="0.1.1" edition="pre-alpha" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0372" published="2009-01-30" name="CVE-2009-0372" modified="2009-02-02" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)" CVSS_score="6.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.0" CVSS_base_score="6.5">
    <desc>
      <descript source="cve">Unrestricted file upload vulnerability in index.php in Miltenovik Manojlo MemHT Portal 4.0.1 and earlier allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension and an image content type via a users editProfile action, then accessing this file via a direct request to the file in images/avatar/uploaded/.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/33424" source="BID" patch="1">33424</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/48199" source="XF">memht-avatar-file-upload(48199)</ref>
      <ref url="http://www.milw0rm.com/exploits/7859" source="MILW0RM">7859</ref>
      <ref url="http://secunia.com/advisories/33626" source="SECUNIA" adv="1">33626</ref>
    </refs>
    <vuln_soft>
      <prod vendor="memht" name="memht_portal">
        <vers num="1.0" edition="final" />
        <vers num="1.5" edition="full" />
        <vers num="1.5" edition="update" />
        <vers num="2.0" edition="full" />
        <vers num="2.0" edition="update" />
        <vers num="2.5" edition="full" />
        <vers num="2.5" edition="update" />
        <vers num="2.9" edition="full" />
        <vers num="2.9" edition="update" />
        <vers num="3.0" edition="full" />
        <vers num="3.0" edition="update" />
        <vers num="3.1" edition="full" />
        <vers num="3.1" edition="update" />
        <vers num="3.2" edition="update" />
        <vers num="3.3" edition="full" />
        <vers num="3.3" edition="update" />
        <vers num="3.4" edition="full" />
        <vers num="3.4" edition="update" />
        <vers num="3.4.5" edition="full" />
        <vers num="3.4.5" edition="update" />
        <vers num="3.5.0" edition="full" />
        <vers num="3.6.0" />
        <vers num="3.6.5" />
        <vers num="3.7.0" />
        <vers num="3.7.5" />
        <vers num="3.8.0" />
        <vers num="3.8.1" />
        <vers num="3.8.5" />
        <vers num="3.9.0" />
        <vers prev="1" num="4.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0373" published="2009-01-30" name="CVE-2009-0373" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in the ElearningForce Flash Magazine Deluxe (com_flashmagazinedeluxe) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the mag_id parameter in a magazine action to index.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/48226" source="XF">flashmagazine-index-sql-injection(48226)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0249" source="VUPEN">ADV-2009-0249</ref>
      <ref url="http://www.securityfocus.com/bid/33455" source="BID">33455</ref>
      <ref url="http://www.milw0rm.com/exploits/7881" source="MILW0RM">7881</ref>
      <ref url="http://secunia.com/advisories/33646" source="SECUNIA" adv="1">33646</ref>
    </refs>
    <vuln_soft>
      <prod vendor="elearningforce" name="flash_magazine_deluxe">
        <vers num="_nil_" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0374" published="2009-01-30" name="CVE-2009-0374" modified="2009-02-02" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">** DISPUTED **  Google Chrome 1.0.154.43 allows remote attackers to trick a user into visiting an arbitrary URL via an onclick action that moves a crafted element to the current mouse position, related to a "Clickjacking" vulnerability.  NOTE: a third party disputes the relevance of this issue, stating that "every sufficiently featured browser is and likely will remain susceptible to the behavior known as clickjacking," and adding that the exploit code "is not a valid demonstration of the issue."</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/500533/100/0/threaded" source="BUGTRAQ">20090128 Re: Advisory: Google Chrome 1.0.154.43 ClickJacking Vulnerability.</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/500499/100/0/threaded" source="BUGTRAQ">20090128 Advisory: Google Chrome 1.0.154.43 ClickJacking Vulnerability.</ref>
      <ref url="http://www.secniche.org/gcr_clkj/" source="MISC">http://www.secniche.org/gcr_clkj/</ref>
      <ref url="http://www.milw0rm.com/exploits/7903" source="MILW0RM">7903</ref>
    </refs>
    <vuln_soft>
      <prod vendor="google" name="chrome">
        <vers num="1.0.154.43" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0375" published="2009-02-08" name="CVE-2009-0375" modified="2010-01-28" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Buffer overflow in a DLL file in RealNetworks RealPlayer 10, RealPlayer 10.5 6.0.12.1040 through 6.0.12.1741, RealPlayer 11 11.0.0 through 11.0.4, RealPlayer Enterprise, Mac RealPlayer 10 and 10.1, Linux RealPlayer 10, and Helix Player 10.x allows remote attackers to execute arbitrary code via a crafted Internet Video Recording (IVR) file with a filename length field containing a large integer, which triggers overwrite of an arbitrary memory location with a 0x00 byte value, related to use of RealPlayer through a Windows Explorer plugin.</descript>
      <descript source="nvd">Per http://www.fortiguardcenter.com/advisory/FGA-2009-04.html:

"It should be noted that the victim does not necessarily have to open the malicious file for exploitation to occur: the vulnerabilities lie in a DLL that is also used as a plugin for the Windows Explorer shell. A successful attack could take place by merely previewing the IVR file through Windows Explorer. "</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/48567" source="XF">realplayer-ivr-bo(48567)</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0178" source="VUPEN">ADV-2010-0178</ref>
      <ref url="http://www.securityfocus.com/bid/33652" source="BID">33652</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/500722/100/0/threaded" source="BUGTRAQ">20090206 RealNetworks RealPlayer IVR File Processing Multiple Code Execute Vulnerabilities</ref>
      <ref url="http://www.fortiguardcenter.com/advisory/FGA-2009-04.html" source="MISC">http://www.fortiguardcenter.com/advisory/FGA-2009-04.html</ref>
      <ref url="http://service.real.com/realplayer/security/01192010_player/en/" source="CONFIRM">http://service.real.com/realplayer/security/01192010_player/en/</ref>
      <ref url="http://secunia.com/advisories/38218" source="SECUNIA">38218</ref>
      <ref url="http://secunia.com/advisories/33810" source="SECUNIA">33810</ref>
    </refs>
    <vuln_soft>
      <prod vendor="realnetworks" name="realplayer">
        <vers num="11" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0376" published="2009-02-08" name="CVE-2009-0376" modified="2010-01-28" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Heap-based buffer overflow in a DLL file in RealNetworks RealPlayer 10, RealPlayer 10.5 6.0.12.1040 through 6.0.12.1741, RealPlayer 11 11.0.0 through 11.0.4, RealPlayer Enterprise, Mac RealPlayer 10 and 10.1, Linux RealPlayer 10, and Helix Player 10.x allows remote attackers to execute arbitrary code via a crafted Internet Video Recording (IVR) file with a modified field that controls an unspecified structure length and triggers heap corruption, related to use of RealPlayer through a Windows Explorer plugin.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/48568" source="XF">realplayer-ivr-code-execution(48568)</ref>
      <ref url="http://www.zerodayinitiative.com/advisories/ZDI-10-009/" source="MISC">http://www.zerodayinitiative.com/advisories/ZDI-10-009/</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0178" source="VUPEN">ADV-2010-0178</ref>
      <ref url="http://www.securityfocus.com/bid/33652" source="BID">33652</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/509097/100/0/threaded" source="BUGTRAQ">20100121 ZDI-10-009: RealNetworks RealPlayer IVR Format Remote Code Execution Vulnerability</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/500722/100/0/threaded" source="BUGTRAQ">20090206 RealNetworks RealPlayer IVR File Processing Multiple Code Execute Vulnerabilities</ref>
      <ref url="http://www.fortiguardcenter.com/advisory/FGA-2009-04.html" source="MISC">http://www.fortiguardcenter.com/advisory/FGA-2009-04.html</ref>
      <ref url="http://service.real.com/realplayer/security/01192010_player/en/" source="CONFIRM">http://service.real.com/realplayer/security/01192010_player/en/</ref>
      <ref url="http://secunia.com/advisories/38218" source="SECUNIA">38218</ref>
      <ref url="http://secunia.com/advisories/33810" source="SECUNIA">33810</ref>
    </refs>
    <vuln_soft>
      <prod vendor="realnetworks" name="realplayer">
        <vers num="11" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0377" published="2009-02-02" name="CVE-2009-0377" modified="2009-02-02" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in the beamospetition (com_beamospetition) 1.0.12 component for Joomla! allows remote attackers to execute arbitrary SQL commands via the mpid parameter in a sign action to index.php, a different vector than CVE-2008-3132.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/33391" source="BID">33391</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/500250/100/0/threaded" source="BUGTRAQ">20090121 Joomla component beamospetition 1.0.12 Sql Injection</ref>
      <ref url="http://www.milw0rm.com/exploits/7847" source="MILW0RM">7847</ref>
    </refs>
    <vuln_soft>
      <prod vendor="joomla" name="com_beamospetition">
        <vers num="1.0.12" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0378" published="2009-02-02" name="CVE-2009-0378" modified="2009-02-02" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in index.php in the beamospetition (com_beamospetition) 1.0.12 component for Joomla! allows remote attackers to inject arbitrary web script or HTML via the pet parameter in a sign action.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/33391" source="BID">33391</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/500250/100/0/threaded" source="BUGTRAQ">20090121 Joomla component beamospetition 1.0.12 Sql Injection</ref>
      <ref url="http://www.milw0rm.com/exploits/7847" source="MILW0RM">7847</ref>
    </refs>
    <vuln_soft>
      <prod vendor="joomla" name="com_beamospetition">
        <vers num="1.0.12" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0379" published="2009-02-02" name="CVE-2009-0379" modified="2009-02-02" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in the Prince Clan Chess Club (com_pcchess) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the game_id parameter in a showgame action to index.php, a different vector than CVE-2008-0761.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/48144" source="XF">joomla-pcchess-gameid-sql-injection(48144)</ref>
      <ref url="http://www.securityfocus.com/bid/33394" source="BID">33394</ref>
      <ref url="http://www.milw0rm.com/exploits/7846" source="MILW0RM">7846</ref>
    </refs>
    <vuln_soft>
      <prod vendor="joomla" name="com_pcchess">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0380" published="2009-02-02" name="CVE-2009-0380" modified="2009-02-02" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">** DISPUTED **  SQL injection vulnerability in the Sigsiu Online Business Index 2 (SOBI2, com_sobi2) RC 2.8.2 component for Joomla! and Mambo allows remote attackers to execute arbitrary SQL commands via the bid parameter in a showbiz action to index.php, a different vector than CVE-2008-0607.  NOTE: CVE disputes this issue, since neither "showbiz" nor "bid" appears in the source code for SOBI2.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/48131" source="XF">sobi2-bid-sql-injection(48131)</ref>
      <ref url="http://www.securityfocus.com/bid/33378" source="BID">33378</ref>
      <ref url="http://www.milw0rm.com/exploits/7841" source="MILW0RM">7841</ref>
      <ref url="http://www.attrition.org/pipermail/vim/2009-January/002136.html" source="VIM">20090130 SOBI2 showbiz SQL injection - false, or site-specific</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sigsiu.net" name="sobi2">
        <vers num="2.8.2" edition="rc" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0381" published="2009-02-02" name="CVE-2009-0381" modified="2009-02-02" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in the BazaarBuilder Ecommerce Shopping Cart (com_prod) 5.0 component for Joomla! allows remote attackers to execute arbitrary SQL commands via the cid parameter in a products action to index.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/48141" source="XF">bazaarbuilder-index-sql-injection(48141)</ref>
      <ref url="http://www.securityfocus.com/bid/33380" source="BID">33380</ref>
      <ref url="http://www.milw0rm.com/exploits/7840" source="MILW0RM">7840</ref>
      <ref url="http://secunia.com/advisories/33612" source="SECUNIA" adv="1">33612</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bazaarbuilder" name="ecommerce_shopping_cart">
        <vers num="5.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0382" published="2009-02-02" name="CVE-2009-0382" modified="2009-02-02" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Unspecified vulnerability in Internationalization (i18n) Translation 5.x before 5.x-2.5, a module for Drupal, allows remote attackers with "translate node" permissions to bypass intended access restrictions and read unpublished nodes via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://drupal.org/node/358958" source="CONFIRM" patch="1" adv="1">http://drupal.org/node/358958</ref>
      <ref url="http://www.securityfocus.com/bid/33283" source="BID">33283</ref>
      <ref url="http://secunia.com/advisories/33549" source="SECUNIA" adv="1">33549</ref>
    </refs>
    <vuln_soft>
      <prod vendor="drupal" name="internationalization">
        <vers num="5.x-1.1" />
        <vers prev="1" num="5.x-2.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0383" published="2009-02-02" name="CVE-2009-0383" modified="2009-02-02" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:P)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">delete.php in Max.Blog 1.0.6 does not properly restrict access, which allows remote attackers to delete arbitrary blog posts via a direct request.</descript>
    </desc>
    <loss_types>
      <avail />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.mzbservices.com/show_post.php?id=72" source="CONFIRM" patch="1" adv="1">http://www.mzbservices.com/show_post.php?id=72</ref>
      <ref url="http://secunia.com/advisories/33590" source="SECUNIA" patch="1" adv="1">33590</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/48125" source="XF">maxblog-delete-security-bypass(48125)</ref>
      <ref url="http://www.securityfocus.com/bid/33368" source="BID">33368</ref>
      <ref url="http://www.milw0rm.com/exploits/7835" source="MILW0RM">7835</ref>
      <ref url="http://osvdb.org/51482" source="OSVDB">51482</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mzbservices" name="max.blog">
        <vers num="1.0.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0384" published="2009-02-02" name="CVE-2009-0384" modified="2009-02-02" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">SQL injection vulnerability in autor.php in OwnRS CMS 1.2 allows remote attackers to execute arbitrary SQL commands via the id parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.milw0rm.com/exploits/7849" source="MILW0RM">7849</ref>
    </refs>
    <vuln_soft>
      <prod vendor="adam_tomecek" name="ownrs">
        <vers num="1.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0385" published="2009-02-02" name="CVE-2009-0385" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Integer signedness error in the fourxm_read_header function in libavformat/4xm.c in FFmpeg before revision 16846 allows remote attackers to execute arbitrary code via a malformed 4X movie file with a large current_track value, which triggers a NULL pointer dereference.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-April/msg00215.html" source="FEDORA">FEDORA-2009-3433</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-April/msg00210.html" source="FEDORA">FEDORA-2009-3428</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/48330" source="XF">ffmpeg-fourxmreadheader-code-execution(48330)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0277" source="VUPEN">ADV-2009-0277</ref>
      <ref url="http://www.ubuntu.com/usn/USN-734-1" source="UBUNTU">USN-734-1</ref>
      <ref url="http://www.trapkit.de/advisories/TKADV2009-004.txt" source="MISC">http://www.trapkit.de/advisories/TKADV2009-004.txt</ref>
      <ref url="http://www.securityfocus.com/bid/33502" source="BID">33502</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/500514/100/0/threaded" source="BUGTRAQ">20090128 [TKADV2009-004] FFmpeg Type Conversion Vulnerability</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:297" source="MANDRIVA">MDVSA-2009:297</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1782" source="DEBIAN">DSA-1782</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1781" source="DEBIAN">DSA-1781</ref>
      <ref url="http://svn.mplayerhq.hu/ffmpeg?view=rev&amp;revision=16846" source="CONFIRM">http://svn.mplayerhq.hu/ffmpeg?view=rev&amp;revision=16846</ref>
      <ref url="http://svn.mplayerhq.hu/ffmpeg/trunk/libavformat/4xm.c?r1=16838&amp;r2=16846&amp;pathrev=16846" source="CONFIRM">http://svn.mplayerhq.hu/ffmpeg/trunk/libavformat/4xm.c?r1=16838&amp;r2=16846&amp;pathrev=16846</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200903-33.xml" source="GENTOO">GLSA-200903-33</ref>
      <ref url="http://secunia.com/advisories/34905" source="SECUNIA">34905</ref>
      <ref url="http://secunia.com/advisories/34845" source="SECUNIA">34845</ref>
      <ref url="http://secunia.com/advisories/34712" source="SECUNIA">34712</ref>
      <ref url="http://secunia.com/advisories/34385" source="SECUNIA">34385</ref>
      <ref url="http://secunia.com/advisories/34296" source="SECUNIA">34296</ref>
      <ref url="http://secunia.com/advisories/33711" source="SECUNIA" adv="1">33711</ref>
      <ref url="http://osvdb.org/51643" source="OSVDB">51643</ref>
      <ref url="http://git.ffmpeg.org/?p=ffmpeg;a=commitdiff;h=72e715fb798f2cb79fd24a6d2eaeafb7c6eeda17" source="CONFIRM">http://git.ffmpeg.org/?p=ffmpeg;a=commitdiff;h=72e715fb798f2cb79fd24a6d2eaeafb7c6eeda17</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ffmpeg" name="ffmpeg">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0386" published="2009-02-02" name="CVE-2009-0386" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Heap-based buffer overflow in the qtdemux_parse_samples function in gst/qtdemux/qtdemux.c in GStreamer Good Plug-ins (aka gst-plugins-good) 0.10.9 through 0.10.11 might allow remote attackers to execute arbitrary code via crafted Composition Time To Sample (ctts) atom data in a malformed QuickTime media .mov file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/33405" source="BID" patch="1">33405</ref>
      <ref url="http://gstreamer.freedesktop.org/releases/gst-plugins-good/0.10.12.html" source="CONFIRM" patch="1" adv="1">http://gstreamer.freedesktop.org/releases/gst-plugins-good/0.10.12.html</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=481267" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=481267</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0225" source="VUPEN">ADV-2009-0225</ref>
      <ref url="http://www.ubuntu.com/usn/USN-736-1" source="UBUNTU">USN-736-1</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/500317/100/0/threaded" source="BUGTRAQ">20090122 [TKADV2009-003] GStreamer Heap Overflow and Array Index out of Bounds Vulnerabilities</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-0271.html" source="REDHAT">RHSA-2009:0271</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2009/01/29/3" source="MLIST">[oss-security] 20090129 CVE Request -- (sort of urgent) gstreamer-plugins-good (repost) (more details about affected versions -- final version)</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:035" source="MANDRIVA">MDVSA-2009:035</ref>
      <ref url="http://trapkit.de/advisories/TKADV2009-003.txt" source="MISC">http://trapkit.de/advisories/TKADV2009-003.txt</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200907-11.xml" source="GENTOO">GLSA-200907-11</ref>
      <ref url="http://secunia.com/advisories/35777" source="SECUNIA">35777</ref>
      <ref url="http://secunia.com/advisories/34336" source="SECUNIA">34336</ref>
      <ref url="http://secunia.com/advisories/33815" source="SECUNIA">33815</ref>
      <ref url="http://secunia.com/advisories/33650" source="SECUNIA" adv="1">33650</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10306" source="OVAL">oval:org.mitre.oval:def:10306</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-03/msg00000.html" source="SUSE">SUSE-SR:2009:005</ref>
      <ref url="http://cgit.freedesktop.org/gstreamer/gst-plugins-good/commit/?id=bdc20b9baf13564d9a061343416395f8f9a92b53" source="CONFIRM">http://cgit.freedesktop.org/gstreamer/gst-plugins-good/commit/?id=bdc20b9baf13564d9a061343416395f8f9a92b53</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gstreamer" name="good_plug-ins">
        <vers num="0.10.10" />
        <vers num="0.10.11" />
        <vers num="0.10.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0387" published="2009-02-02" name="CVE-2009-0387" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Array index error in the qtdemux_parse_samples function in gst/qtdemux/qtdemux.c in GStreamer Good Plug-ins (aka gst-plugins-good) 0.10.9 through 0.10.11 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via crafted Sync Sample (aka stss) atom data in a malformed QuickTime media .mov file, related to "mark keyframes."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://gstreamer.freedesktop.org/releases/gst-plugins-good/0.10.12.html" source="CONFIRM" patch="1" adv="1">http://gstreamer.freedesktop.org/releases/gst-plugins-good/0.10.12.html</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=481267" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=481267</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0225" source="VUPEN">ADV-2009-0225</ref>
      <ref url="http://www.ubuntu.com/usn/USN-736-1" source="UBUNTU">USN-736-1</ref>
      <ref url="http://www.securityfocus.com/bid/33405" source="BID">33405</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/500317/100/0/threaded" source="BUGTRAQ">20090122 [TKADV2009-003] GStreamer Heap Overflow and Array Index out of Bounds Vulnerabilities</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-0271.html" source="REDHAT">RHSA-2009:0271</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2009/01/29/3" source="MLIST">[oss-security] 20090129 CVE Request -- (sort of urgent) gstreamer-plugins-good (repost) (more details about affected versions -- final version)</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:035" source="MANDRIVA">MDVSA-2009:035</ref>
      <ref url="http://trapkit.de/advisories/TKADV2009-003.txt" source="MISC">http://trapkit.de/advisories/TKADV2009-003.txt</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200907-11.xml" source="GENTOO">GLSA-200907-11</ref>
      <ref url="http://secunia.com/advisories/35777" source="SECUNIA">35777</ref>
      <ref url="http://secunia.com/advisories/34336" source="SECUNIA">34336</ref>
      <ref url="http://secunia.com/advisories/33815" source="SECUNIA">33815</ref>
      <ref url="http://secunia.com/advisories/33650" source="SECUNIA" adv="1">33650</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10611" source="OVAL">oval:org.mitre.oval:def:10611</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-03/msg00000.html" source="SUSE">SUSE-SR:2009:005</ref>
      <ref url="http://cgit.freedesktop.org/gstreamer/gst-plugins-good/commit/?id=bdc20b9baf13564d9a061343416395f8f9a92b53" source="CONFIRM">http://cgit.freedesktop.org/gstreamer/gst-plugins-good/commit/?id=bdc20b9baf13564d9a061343416395f8f9a92b53</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gstreamer" name="good_plug-ins">
        <vers num="0.10.10" />
        <vers num="0.10.11" />
        <vers num="0.10.9" />
      </prod>
      <prod vendor="gstreamer" name="plug-ins">
        <vers num="0.8.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0388" published="2009-02-04" name="CVE-2009-0388" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Multiple integer signedness errors in (1) UltraVNC 1.0.2 and 1.0.5 and (2) TightVnc 1.3.9 allow remote VNC servers to cause a denial of service (heap corruption and application crash) or possibly execute arbitrary code via a large length value in a message, related to the (a) ClientConnection::CheckBufferSize and (b) ClientConnection::CheckFileZipBufferSize functions in ClientConnection.cpp.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/33568" source="BID" patch="1">33568</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0322" source="VUPEN">ADV-2009-0322</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0321" source="VUPEN">ADV-2009-0321</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/500632/100/0/threaded" source="BUGTRAQ">20090203 CORE-2008-1009 - VNC Multiple Integer Overflows</ref>
      <ref url="http://www.milw0rm.com/exploits/8024" source="MILW0RM">8024</ref>
      <ref url="http://www.milw0rm.com/exploits/7990" source="MILW0RM">7990</ref>
      <ref url="http://www.coresecurity.com/content/vnc-integer-overflows" source="MISC">http://www.coresecurity.com/content/vnc-integer-overflows</ref>
      <ref url="http://vnc-tight.svn.sourceforge.net/viewvc/vnc-tight?view=rev&amp;revision=3564" source="CONFIRM">http://vnc-tight.svn.sourceforge.net/viewvc/vnc-tight?view=rev&amp;revision=3564</ref>
      <ref url="http://secunia.com/advisories/33807" source="SECUNIA">33807</ref>
      <ref url="http://forum.ultravnc.info/viewtopic.php?t=14654" source="CONFIRM">http://forum.ultravnc.info/viewtopic.php?t=14654</ref>
    </refs>
    <vuln_soft>
      <prod vendor="tightvnc" name="tightvnc">
        <vers num="1.3.9" />
      </prod>
      <prod vendor="ultravnc" name="ultravnc">
        <vers num="1.0.2" />
        <vers num="1.0.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0389" published="2009-02-02" name="CVE-2009-0389" modified="2009-02-03" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Multiple insecure method vulnerabilities in the Web On Windows (WOW) ActiveX control in WOW ActiveX 2 allow remote attackers to (1) create and overwrite arbitrary files via the WriteIniFileString method, (2) execute arbitrary programs via the ShellExecute method, (3) read from the registry via unspecified vectors, and (4) write to the registry via unspecified vectors.  NOTE: vectors 1 and 2 can be used together to execute arbitrary code.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/48337" source="XF">wow-writeinifilestring-code-execution(48337)</ref>
      <ref url="http://www.securityfocus.com/bid/33515" source="BID">33515</ref>
      <ref url="http://www.milw0rm.com/exploits/7910" source="MILW0RM">7910</ref>
    </refs>
    <vuln_soft>
      <prod vendor="eztools-software" name="web_on_windows_activex">
        <vers num="2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0390" published="2009-02-02" name="CVE-2009-0390" modified="2009-02-03" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Argument injection vulnerability in Enomaly Elastic Computing Platform (ECP), formerly Enomalism, before 2.1.1 allows local users to send signals to arbitrary processes by populating the /tmp/enomalism2.pid file with command-line arguments for the kill program.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/500573/100/0/threaded" source="BUGTRAQ">20090130 CVE-2008-4990 Enomaly ECP/Enomalism: Insecure temporary file creation vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="enomaly" name="elastic_computing_platform">
        <vers prev="1" num="2.1" edition="beta_2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0391" published="2009-02-02" name="CVE-2009-0391" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:N/A:N)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Unspecified vulnerability in IBM WebSphere Application Server (WAS) 6.0.1 on z/OS allows attackers to read arbitrary files via unknown vectors.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2009/0423" source="VUPEN">ADV-2009-0423</ref>
      <ref url="http://www.securitytracker.com/id?1021658" source="SECTRACK">1021658</ref>
      <ref url="http://www.securityfocus.com/bid/33533" source="BID">33533</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg1PK79232" source="AIXAPAR" adv="1">PK79232</ref>
      <ref url="http://secunia.com/advisories/33729" source="SECUNIA" adv="1">33729</ref>
      <ref url="http://osvdb.org/51663" source="OSVDB">51663</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="websphere_application_server">
        <vers num="6.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0392" published="2009-02-02" name="CVE-2009-0392" modified="2009-02-03" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:C/I:N/A:N)" CVSS_score="6.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="8.0" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Directory traversal vulnerability in sysconf.cgi in Motorola Wimax modem CPEi300 allows remote authenticated users to read arbitrary files via a .. (dot dot) in the page parameter.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/33519" source="BID">33519</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/500545/100/0/threaded" source="BUGTRAQ">20090129 Motorola Wimax Modem CPEi300 Multiple Vulnerabilities</ref>
      <ref url="http://www.milw0rm.com/exploits/7915" source="MILW0RM">7915</ref>
    </refs>
    <vuln_soft>
      <prod vendor="motorola" name="cpei300">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2009-0393" published="2009-02-02" name="CVE-2009-0393" modified="2009-04-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:S/C:N/I:P/A:N)" CVSS_score="3.5" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="6.8" CVSS_base_score="3.5">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in sysconf.cgi in Motorola Wimax modem CPEi300 allows remote authenticated users to inject arbitrary web script or HTML via the page parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/33519" source="BID">33519</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/500545/100/0/threaded" source="BUGTRAQ">20090129 Motorola Wimax Modem CPEi300 Multiple Vulnerabilities</ref>
      <ref url="http://www.milw0rm.com/exploits/7915" source="MILW0RM">7915</ref>
    </refs>
    <vuln_soft>
      <prod vendor="motorola" name="cpei300">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0394" published="2009-02-02" name="CVE-2009-0394" modified="2009-02-03" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in login.php in Pre Lecture Exercises (PLEs) CMS 1.0 beta 4.2 allows remote attackers to execute arbitrary SQL commands via the school parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/33524" source="BID">33524</ref>
      <ref url="http://www.milw0rm.com/exploits/7917" source="MILW0RM">7917</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ple_cms" name="ple_cms">
        <vers num="1.0" edition="beta_4.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0395" published="2009-02-02" name="CVE-2009-0395" modified="2009-02-03" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in the login feature in NetArt Media Car Portal 1.0 allows remote attackers to execute arbitrary SQL commands via the (1) username and (2) password parameters.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/33521" source="BID">33521</ref>
      <ref url="http://www.milw0rm.com/exploits/7916" source="MILW0RM">7916</ref>
    </refs>
    <vuln_soft>
      <prod vendor="netartmedia" name="car_portal">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0396" published="2009-02-02" name="CVE-2009-0396" modified="2009-02-03" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">The Sony Ericsson W910i, W660i, K618i, K610i, Z610i, K810i, K660i, W880i, and K530i phones allow remote attackers to cause a denial of service (device reboot or hang-up) via a malformed WAP Push packet to (1) SMS or (2) UDP port 2948.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securitytracker.com/id?1021634" source="SECTRACK">1021634</ref>
      <ref url="http://www.securityfocus.com/bid/33433" source="BID">33433</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/500382/100/0/threaded" source="BUGTRAQ">20090126 SonyEricsson WAP Push Denial of Service</ref>
      <ref url="http://www.mseclab.com/index.php?page_id=123" source="MISC">http://www.mseclab.com/index.php?page_id=123</ref>
      <ref url="http://secunia.com/advisories/33616" source="SECUNIA" adv="1">33616</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sony_ericsson" name="k530i">
        <vers num="" />
      </prod>
      <prod vendor="sony_ericsson" name="k610i">
        <vers num="" />
      </prod>
      <prod vendor="sony_ericsson" name="k618i">
        <vers num="" />
      </prod>
      <prod vendor="sony_ericsson" name="k660i">
        <vers num="" />
      </prod>
      <prod vendor="sony_ericsson" name="k810i">
        <vers num="" />
      </prod>
      <prod vendor="sony_ericsson" name="w660i">
        <vers num="" />
      </prod>
      <prod vendor="sony_ericsson" name="w880i">
        <vers num="" />
      </prod>
      <prod vendor="sony_ericsson" name="w910i">
        <vers num="" />
      </prod>
      <prod vendor="sony_ericsson" name="z610i">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0397" published="2009-02-03" name="CVE-2009-0397" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Heap-based buffer overflow in the qtdemux_parse_samples function in gst/qtdemux/qtdemux.c in GStreamer Good Plug-ins (aka gst-plugins-good) 0.10.9 through 0.10.11, and GStreamer Plug-ins (aka gstreamer-plugins) 0.8.5, might allow remote attackers to execute arbitrary code via crafted Time-to-sample (aka stts) atom data in a malformed QuickTime media .mov file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/33405" source="BID" patch="1">33405</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=481267" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=481267</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/48555" source="XF">gstreamer-qtdemuxparse-bo(48555)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0225" source="VUPEN">ADV-2009-0225</ref>
      <ref url="http://www.ubuntu.com/usn/USN-736-1" source="UBUNTU">USN-736-1</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/500317/100/0/threaded" source="BUGTRAQ">20090122 [TKADV2009-003] GStreamer Heap Overflow and Array Index out of Bounds Vulnerabilities</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-0271.html" source="REDHAT">RHSA-2009:0271</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-0270.html" source="REDHAT">RHSA-2009:0270</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2009/01/29/3" source="MLIST">[oss-security] 20090129 CVE Request -- (sort of urgent) gstreamer-plugins-good (repost) (more details about affected versions -- final version)</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:035" source="MANDRIVA">MDVSA-2009:035</ref>
      <ref url="http://trapkit.de/advisories/TKADV2009-003.txt" source="MISC">http://trapkit.de/advisories/TKADV2009-003.txt</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2009-052.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2009-052.htm</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200907-11.xml" source="GENTOO">GLSA-200907-11</ref>
      <ref url="http://secunia.com/advisories/35777" source="SECUNIA">35777</ref>
      <ref url="http://secunia.com/advisories/34336" source="SECUNIA">34336</ref>
      <ref url="http://secunia.com/advisories/33830" source="SECUNIA">33830</ref>
      <ref url="http://secunia.com/advisories/33815" source="SECUNIA">33815</ref>
      <ref url="http://secunia.com/advisories/33650" source="SECUNIA" adv="1">33650</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9942" source="OVAL">oval:org.mitre.oval:def:9942</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-03/msg00000.html" source="SUSE">SUSE-SR:2009:005</ref>
      <ref url="http://gstreamer.freedesktop.org/releases/gst-plugins-good/0.10.12.html" source="CONFIRM">http://gstreamer.freedesktop.org/releases/gst-plugins-good/0.10.12.html</ref>
      <ref url="http://cgit.freedesktop.org/gstreamer/gst-plugins-good/commit/?id=bdc20b9baf13564d9a061343416395f8f9a92b53" source="CONFIRM">http://cgit.freedesktop.org/gstreamer/gst-plugins-good/commit/?id=bdc20b9baf13564d9a061343416395f8f9a92b53</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gstreamer" name="good_plug-ins">
        <vers num="0.10.10" />
        <vers num="0.10.11" />
        <vers num="0.10.9" />
      </prod>
      <prod vendor="gstreamer" name="plug-ins">
        <vers num="0.8.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0398" published="2009-02-03" name="CVE-2009-0398" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Array index error in the gst_qtp_trak_handler function in gst/qtdemux/qtdemux.c in GStreamer Plug-ins (aka gstreamer-plugins) 0.6.0 allows remote attackers to have an unknown impact via a crafted QuickTime media file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-0269.html" source="REDHAT">RHSA-2009:0269</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2009/01/29/3" source="MLIST">[oss-security] 20090129 CVE Request -- (sort of urgent) gstreamer-plugins-good (repost) (more details about affected versions -- final version)</ref>
      <ref url="http://secunia.com/advisories/33830" source="SECUNIA">33830</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9886" source="OVAL">oval:org.mitre.oval:def:9886</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gstreamer" name="plug-ins">
        <vers num="0.6.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0399" published="2009-02-03" name="CVE-2009-0399" modified="2009-02-04" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Chipmunk Blogger Script allows remote attackers to gain administrator privileges via a direct request to admin/reguser.php.  NOTE: this is only a vulnerability when the administrator does not properly follow installation directions.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.milw0rm.com/exploits/7894" source="MILW0RM">7894</ref>
    </refs>
    <vuln_soft>
      <prod vendor="chipmunk_scripts" name="chipmunk_blogger">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0400" published="2009-02-03" name="CVE-2009-0400" modified="2009-02-10" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">SQL injection vulnerability in blog.php in SocialEngine 3.06 trial allows remote attackers to execute arbitrary SQL commands via the category_id parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/48316" source="XF">socialengine-blog-sql-injection(48316)</ref>
      <ref url="http://www.securityfocus.com/bid/33495" source="BID">33495</ref>
      <ref url="http://www.milw0rm.com/exploits/7900" source="MILW0RM">7900</ref>
      <ref url="http://secunia.com/advisories/33701" source="SECUNIA" adv="1">33701</ref>
      <ref url="http://osvdb.org/51644" source="OSVDB">51644</ref>
    </refs>
    <vuln_soft>
      <prod vendor="socialengine" name="socialengine">
        <vers num="3.06" edition="" />
        <vers num="3.06" edition=":trial" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0401" published="2009-02-03" name="CVE-2009-0401" modified="2009-08-19" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in browsecats.php in E-Php CMS allows remote attackers to execute arbitrary SQL commands via the cid parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/48297" source="XF">ephpcms-browsecats-sql-injection(48297)</ref>
      <ref url="http://www.securityfocus.com/bid/33470" source="BID">33470</ref>
      <ref url="http://secunia.com/advisories/31923" source="SECUNIA">31923</ref>
      <ref url="http://packetstormsecurity.org/0901-exploits/ephpcmscid-sql.txt" source="MISC">http://packetstormsecurity.org/0901-exploits/ephpcmscid-sql.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ephpscripts" name="e-php_cms">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0402" published="2009-02-03" name="CVE-2009-0402" modified="2009-02-10" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in client/new_account.php in Domain Technologie Control (DTC) before 0.29.16 allows remote attackers to execute arbitrary SQL commands via the (1) familyname, (2) christname, (3) company_name, (4) is_company, (5) email, (6) phone, (7) fax, (8) addr1, (9) addr2, (10) addr3, (11) zipcode, (12) city, (13) state, (14) country, and (15) vat_num parameters.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/48292" source="XF">domaintechnologie-newaccount-sql-injection(48292)</ref>
      <ref url="http://www.securityfocus.com/bid/33496" source="BID">33496</ref>
      <ref url="http://secunia.com/advisories/33698" source="SECUNIA" adv="1">33698</ref>
      <ref url="http://osvdb.org/51631" source="OSVDB">51631</ref>
      <ref url="http://git.gplhost.com/gitweb/?p=dtc.git;a=commitdiff;h=056e1d1849ff3aa183a410e2aab1c1c3e969247d" source="CONFIRM">http://git.gplhost.com/gitweb/?p=dtc.git;a=commitdiff;h=056e1d1849ff3aa183a410e2aab1c1c3e969247d</ref>
      <ref url="http://freshmeat.net/projects/dtc/?branch_id=22759&amp;release_id=292973" source="CONFIRM">http://freshmeat.net/projects/dtc/?branch_id=22759&amp;release_id=292973</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gplhost" name="domain_technologie_control">
        <vers num="0.26.7" />
        <vers num="0.26.8" />
        <vers num="0.26.9" />
        <vers num="0.27.3" />
        <vers num="0.28.10" />
        <vers num="0.28.2" />
        <vers num="0.28.3" />
        <vers num="0.29.1" />
        <vers prev="1" num="0.29.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0403" published="2009-02-03" name="CVE-2009-0403" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in admin/authenticate.php in Chipmunk Blogger Script allows remote attackers to execute arbitrary SQL commands via the (1) username and (2) password parameters.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/48313" source="XF">chipmunkblog-authenticate-sql-injection(48313)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0267" source="VUPEN">ADV-2009-0267</ref>
      <ref url="http://www.milw0rm.com/exploits/7894" source="MILW0RM">7894</ref>
    </refs>
    <vuln_soft>
      <prod vendor="chipmunk_scripts" name="chipmunk_blogger">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0404" published="2009-02-03" name="CVE-2009-0404" modified="2009-02-10" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Bioinformatics htmLawed 1.1.3 and 1.1.4 allow remote attackers to inject arbitrary web script or HTML via invalid Cascading Style Sheets (CSS) expressions in the style attribute, which is processed by Internet Explorer 7.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/48333" source="XF">htmlawed-unspecified-xss(48333)</ref>
      <ref url="http://www.securityfocus.com/bid/33507" source="BID">33507</ref>
      <ref url="http://www.bioinformatics.org/phplabware/internal_utilities/htmLawed/htmLawed_README.htm#s4.3" source="CONFIRM">http://www.bioinformatics.org/phplabware/internal_utilities/htmLawed/htmLawed_README.htm#s4.3</ref>
      <ref url="http://www.bioinformatics.org/phplabware/forum/viewtopic.php?id=85" source="CONFIRM" adv="1">http://www.bioinformatics.org/phplabware/forum/viewtopic.php?id=85</ref>
      <ref url="http://secunia.com/advisories/33655" source="SECUNIA" adv="1">33655</ref>
      <ref url="http://osvdb.org/51650" source="OSVDB">51650</ref>
      <ref url="http://freshmeat.net/projects/htmlawed/?branch_id=74760&amp;release_id=293090" source="CONFIRM">http://freshmeat.net/projects/htmlawed/?branch_id=74760&amp;release_id=293090</ref>
      <ref url="http://freshmeat.net/projects/htmlawed/?branch_id=74760&amp;release_id=293026" source="CONFIRM">http://freshmeat.net/projects/htmlawed/?branch_id=74760&amp;release_id=293026</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bioinformatics" name="htmlawed">
        <vers num="1.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.5" />
        <vers num="1.0.6" />
        <vers num="1.0.7" />
        <vers num="1.0.8" />
        <vers num="1.0.9" />
        <vers num="1.1" />
        <vers num="1.1.1" />
        <vers num="1.1.2" />
        <vers prev="1" num="1.1.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0405" published="2009-02-03" name="CVE-2009-0405" modified="2009-02-04" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in articles.php in smartSite CMS 1.0 allows remote attackers to execute arbitrary SQL commands via the var parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/48321" source="XF">smartsitecms-articles-sql-injection(48321)</ref>
      <ref url="http://www.securityfocus.com/bid/33497" source="BID">33497</ref>
      <ref url="http://www.milw0rm.com/exploits/7901" source="MILW0RM">7901</ref>
    </refs>
    <vuln_soft>
      <prod vendor="smartsitecms" name="smartsitecms">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0406" published="2009-02-03" name="CVE-2009-0406" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in index.php in Community CMS 0.4 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/48304" source="XF">communitycms-index-sql-injection(48304)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0265" source="VUPEN">ADV-2009-0265</ref>
      <ref url="http://www.securityfocus.com/bid/33484" source="BID">33484</ref>
      <ref url="http://www.milw0rm.com/exploits/7892" source="MILW0RM">7892</ref>
    </refs>
    <vuln_soft>
      <prod vendor="community_cms" name="community_cms">
        <vers num="0.1" />
        <vers num="0.1.1" />
        <vers num="0.2" />
        <vers num="0.3" />
        <vers prev="1" num="0.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0407" published="2009-02-03" name="CVE-2009-0407" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in admin/login.php in PHP-CMS Project 1 allows remote attackers to execute arbitrary SQL commands via the username parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/48267" source="XF">phpcms-login-sql-injection(48267)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0244" source="VUPEN">ADV-2009-0244</ref>
      <ref url="http://www.securityfocus.com/bid/33473" source="BID">33473</ref>
      <ref url="http://www.milw0rm.com/exploits/7876" source="MILW0RM">7876</ref>
    </refs>
    <vuln_soft>
      <prod vendor="humayun_shabbir" name="php-cms_project">
        <vers num="1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0408" published="2009-02-03" name="CVE-2009-0408" modified="2009-04-02" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:S/C:P/I:P/A:P)" CVSS_score="6.0" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="6.8" CVSS_base_score="6.0">
    <desc>
      <descript source="cve">Cross-site request forgery (CSRF) vulnerability in osCommerce 2.2 RC 2a allows remote attackers to hijack the authentication of administrators.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/48289" source="XF">oscommerce-unspecified-csrf(48289)</ref>
      <ref url="http://secunia.com/advisories/33446" source="SECUNIA">33446</ref>
      <ref url="http://osvdb.org/51605" source="OSVDB">51605</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oscommerce" name="oscommerce">
        <vers num="2.2" edition="rc_2a" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0409" published="2009-02-03" name="CVE-2009-0409" modified="2009-02-10" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">SQL injection vulnerability in offline_auth.php in Max.Blog 1.0.6 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the username parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/33493" source="BID">33493</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/500470/100/0/threaded" source="BUGTRAQ">20090127 Max.Blog &lt;= 1.0.6 (offline_auth.php) Offline Authentication Bypass</ref>
      <ref url="http://www.milw0rm.com/exploits/7899" source="MILW0RM">7899</ref>
      <ref url="http://secunia.com/advisories/33658" source="SECUNIA" adv="1">33658</ref>
      <ref url="http://osvdb.org/51645" source="OSVDB">51645</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mzbservices" name="max.blog">
        <vers num="1.0.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0410" published="2009-02-03" name="CVE-2009-0410" modified="2009-02-04" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Off-by-one error in the SMTP daemon in GroupWise Internet Agent (GWIA) in Novell GroupWise 6.5x, 7.0, 7.01, 7.02, 7.03, 7.03HP1a, and 8.0 allows remote attackers to execute arbitrary code via a long e-mail address in a malformed RCPT command, leading to a buffer overflow.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.zerodayinitiative.com/advisories/ZDI-09-010/" source="MISC" patch="1">http://www.zerodayinitiative.com/advisories/ZDI-09-010/</ref>
      <ref url="http://download.novell.com/Download?buildid=GjZRRdqCFW0" source="CONFIRM" patch="1">http://download.novell.com/Download?buildid=GjZRRdqCFW0</ref>
      <ref url="http://www.securityfocus.com/bid/33560" source="BID">33560</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/500609/100/0/threaded" source="BUGTRAQ">20090202 ZDI-09-010: Novell Netware Groupwise GWIA RCPT Command Buffer Overflow Vulnerability</ref>
      <ref url="http://www.novell.com/support/viewContent.do?externalId=7002502" source="CONFIRM" adv="1">http://www.novell.com/support/viewContent.do?externalId=7002502</ref>
      <ref url="http://secunia.com/advisories/33744" source="SECUNIA" adv="1">33744</ref>
    </refs>
    <vuln_soft>
      <prod vendor="novell" name="groupwise">
        <vers num="6.5" />
        <vers num="7.0" />
        <vers num="7.01" />
        <vers num="7.02x" />
        <vers num="7.03" edition="hp1a" />
        <vers num="8.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0411" published="2009-02-03" name="CVE-2009-0411" modified="2009-02-12" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Google Chrome before 1.0.154.46 does not properly restrict access from web pages to the (1) Set-Cookie and (2) Set-Cookie2 HTTP response headers, which allows remote attackers to obtain sensitive information from cookies via XMLHttpRequest calls and other web script.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/48554" source="XF">googlechrome-xmlhttprequest-info-disclosure(48554)</ref>
      <ref url="http://src.chromium.org/viewvc/chrome?view=rev&amp;revision=8529" source="CONFIRM">http://src.chromium.org/viewvc/chrome?view=rev&amp;revision=8529</ref>
      <ref url="http://sites.google.com/a/chromium.org/dev/getting-involved/dev-channel/release-notes" source="CONFIRM">http://sites.google.com/a/chromium.org/dev/getting-involved/dev-channel/release-notes</ref>
      <ref url="http://codereview.chromium.org/18533" source="CONFIRM">http://codereview.chromium.org/18533</ref>
      <ref url="http://codereview.chromium.org/11264" source="CONFIRM">http://codereview.chromium.org/11264</ref>
    </refs>
    <vuln_soft>
      <prod vendor="google" name="chrome">
        <vers num="0.2.152.1" />
        <vers num="0.2.153.1" />
        <vers num="0.3.154.0" />
        <vers num="0.3.154.3" />
        <vers num="0.4.154.18" />
        <vers num="0.4.154.22" />
        <vers num="0.4.154.31" />
        <vers num="0.4.154.33" />
        <vers num="1.0.154.36" />
        <vers num="1.0.154.39" />
        <vers num="1.0.154.42" />
        <vers prev="1" num="1.0.154.43" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0412" published="2009-02-03" name="CVE-2009-0412" modified="2009-02-04" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The ProcessLogin function in class.auth.php in Interspire Shopping Cart (ISC) 4.0.1 Ultimate edition allows remote attackers to bypass authentication and obtain administrative access by reusing the RememberToken cookie after a failed admin login attempt.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/47899" source="XF">interspire-classauth-security-bypass(47899)</ref>
      <ref url="http://www.securitytracker.com/id?1021557" source="SECTRACK">1021557</ref>
      <ref url="http://www.securityfocus.com/bid/33212" source="BID">33212</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/499967/100/0/threaded" source="BUGTRAQ">20090112 [BMSA-2009-01] Authentication bypass in Interspire Shopping Cart v4.0.1 and below</ref>
    </refs>
    <vuln_soft>
      <prod vendor="interspire" name="shopping_cart">
        <vers num="4.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0413" published="2009-02-03" name="CVE-2009-0413" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in RoundCube Webmail (roundcubemail) 0.2 stable allows remote attackers to inject arbitrary web script or HTML via the background attribute embedded in an HTML e-mail message.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-February/msg00082.html" source="FEDORA">FEDORA-2009-1256</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/48129" source="XF">roundcube-html-xss(48129)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0192" source="VUPEN">ADV-2009-0192</ref>
      <ref url="http://www.securityfocus.com/bid/33372" source="BID">33372</ref>
      <ref url="http://trac.roundcube.net/changeset/2245" source="CONFIRM">http://trac.roundcube.net/changeset/2245</ref>
      <ref url="http://secunia.com/advisories/33827" source="SECUNIA">33827</ref>
      <ref url="http://secunia.com/advisories/33622" source="SECUNIA" adv="1">33622</ref>
    </refs>
    <vuln_soft>
      <prod vendor="roundcube" name="roundcube_webmail">
        <vers num="0.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0414" published="2009-02-03" name="CVE-2009-0414" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in Tor before 0.2.0.33 has unspecified impact and remote attack vectors that trigger heap corruption.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/33399" source="BID" patch="1">33399</ref>
      <ref url="http://blog.torproject.org/blog/tor-0.2.0.33-stable-released" source="CONFIRM" patch="1" adv="1">http://blog.torproject.org/blog/tor-0.2.0.33-stable-released</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-January/msg00902.html" source="FEDORA">FEDORA-2009-0897</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0210" source="VUPEN">ADV-2009-0210</ref>
      <ref url="http://www.securitytracker.com/id?1021633" source="SECTRACK">1021633</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200904-11.xml" source="GENTOO">GLSA-200904-11</ref>
      <ref url="http://secunia.com/advisories/34583" source="SECUNIA">34583</ref>
      <ref url="http://secunia.com/advisories/33677" source="SECUNIA">33677</ref>
      <ref url="http://secunia.com/advisories/33635" source="SECUNIA" adv="1">33635</ref>
      <ref url="http://archives.seul.org/or/announce/Jan-2009/msg00000.html" source="MLIST">[or-announce] 20090122 Tor 0.2.0.33 is released</ref>
    </refs>
    <vuln_soft>
      <prod vendor="tor" name="tor">
        <vers num="0.0.2" />
        <vers num="0.0.2_pre13" />
        <vers num="0.0.2_pre14" />
        <vers num="0.0.2_pre15" />
        <vers num="0.0.2_pre16" />
        <vers num="0.0.2_pre17" />
        <vers num="0.0.2_pre18" />
        <vers num="0.0.2_pre19" />
        <vers num="0.0.2_pre20" />
        <vers num="0.0.2_pre21" />
        <vers num="0.0.2_pre22" />
        <vers num="0.0.2_pre23" />
        <vers num="0.0.2_pre24" />
        <vers num="0.0.2_pre25" />
        <vers num="0.0.2_pre26" />
        <vers num="0.0.2_pre27" />
        <vers num="0.0.3" />
        <vers num="0.0.4" />
        <vers num="0.0.5" />
        <vers num="0.0.6" />
        <vers num="0.0.6.1" />
        <vers num="0.0.6.2" />
        <vers num="0.0.7" />
        <vers num="0.0.7.1" />
        <vers num="0.0.7.2" />
        <vers num="0.0.7.3" />
        <vers num="0.0.8" />
        <vers num="0.0.8.1" />
        <vers num="0.0.9" />
        <vers num="0.0.9.1" />
        <vers num="0.0.9.10" />
        <vers num="0.0.9.2" />
        <vers num="0.0.9.3" />
        <vers num="0.0.9.4" />
        <vers num="0.0.9.5" />
        <vers num="0.0.9.6" />
        <vers num="0.0.9.7" />
        <vers num="0.0.9.8" />
        <vers num="0.0.9.9" />
        <vers num="0.1.0.1" />
        <vers num="0.1.0.10" />
        <vers num="0.1.0.11" />
        <vers num="0.1.0.12" />
        <vers num="0.1.0.13" />
        <vers num="0.1.0.14" />
        <vers num="0.1.0.15" />
        <vers num="0.1.0.16" />
        <vers num="0.1.0.17" />
        <vers num="0.1.0.18" />
        <vers num="0.1.0.19" />
        <vers num="0.1.0.2" />
        <vers num="0.1.0.3" />
        <vers num="0.1.0.4" />
        <vers num="0.1.0.5" />
        <vers num="0.1.0.6" />
        <vers num="0.1.0.7" />
        <vers num="0.1.0.8" />
        <vers num="0.1.0.9" />
        <vers num="0.1.1" />
        <vers num="0.1.1.1" />
        <vers num="0.1.1.10" />
        <vers num="0.1.1.10_alpha" />
        <vers num="0.1.1.11" />
        <vers num="0.1.1.12" />
        <vers num="0.1.1.13" />
        <vers num="0.1.1.14" />
        <vers num="0.1.1.15" />
        <vers num="0.1.1.16" />
        <vers num="0.1.1.17" />
        <vers num="0.1.1.18" />
        <vers num="0.1.1.19" />
        <vers num="0.1.1.1_alpha" />
        <vers num="0.1.1.2" />
        <vers num="0.1.1.20" />
        <vers num="0.1.1.21" />
        <vers num="0.1.1.22" />
        <vers num="0.1.1.23" />
        <vers num="0.1.1.25" />
        <vers num="0.1.1.26" />
        <vers num="0.1.1.2_alpha" />
        <vers num="0.1.1.3" />
        <vers num="0.1.1.3_alpha" />
        <vers num="0.1.1.4" />
        <vers num="0.1.1.4_alpha" />
        <vers num="0.1.1.5" />
        <vers num="0.1.1.5_alpha" />
        <vers num="0.1.1.6" />
        <vers num="0.1.1.6_alpha" />
        <vers num="0.1.1.7" />
        <vers num="0.1.1.7_alpha" />
        <vers num="0.1.1.8" />
        <vers num="0.1.1.8_alpha" />
        <vers num="0.1.1.9" />
        <vers num="0.1.1.9_alpha" />
        <vers num="0.1.2.10" />
        <vers num="0.1.2.11" />
        <vers num="0.1.2.12" />
        <vers num="0.1.2.13" />
        <vers num="0.1.2.14" />
        <vers num="0.1.2.15" />
        <vers num="0.1.2.16" />
        <vers num="0.1.2.17" />
        <vers num="0.1.2.18" />
        <vers num="0.1.2.19" />
        <vers num="0.1.2.1_alpha-cvs" />
        <vers num="0.1.2.3" edition="alpha" />
        <vers num="0.1.2.30" />
        <vers num="0.1.2.31" />
        <vers num="0.1.2.4" />
        <vers num="0.1.2.5" edition="alpha" />
        <vers num="0.1.2.6" edition="alpha" />
        <vers num="0.1.2.7" edition="alpha" />
        <vers num="0.1.2.8" edition="beta" />
        <vers num="0.1.2.9" />
        <vers num="0.2.0.1" edition="alpha" />
        <vers num="0.2.0.10" edition="alpha" />
        <vers num="0.2.0.11" edition="alpha" />
        <vers num="0.2.0.12" edition="alpha" />
        <vers num="0.2.0.13" edition="alpha" />
        <vers num="0.2.0.14" edition="alpha" />
        <vers num="0.2.0.15" edition="alpha" />
        <vers num="0.2.0.16" edition="alpha" />
        <vers num="0.2.0.17" edition="alpha" />
        <vers num="0.2.0.18" edition="alpha" />
        <vers num="0.2.0.19" edition="alpha" />
        <vers num="0.2.0.2" edition="alpha" />
        <vers num="0.2.0.20" edition="alpha" />
        <vers num="0.2.0.21" edition="alpha" />
        <vers num="0.2.0.22" edition="alpha" />
        <vers num="0.2.0.23" edition="alpha" />
        <vers num="0.2.0.24" edition="alpha" />
        <vers num="0.2.0.25" edition="alpha" />
        <vers num="0.2.0.26" edition="alpha" />
        <vers num="0.2.0.27" edition="alpha" />
        <vers num="0.2.0.28" edition="alpha" />
        <vers num="0.2.0.29" edition="alpha" />
        <vers num="0.2.0.3" edition="alpha" />
        <vers num="0.2.0.30" edition="alpha" />
        <vers num="0.2.0.31" edition="alpha" />
        <vers prev="1" num="0.2.0.32" edition="alpha" />
        <vers num="0.2.0.4" edition="alpha" />
        <vers num="0.2.0.5" edition="alpha" />
        <vers num="0.2.0.6" edition="alpha" />
        <vers num="0.2.0.7" edition="alpha" />
        <vers num="0.2.0.8" edition="alpha" />
        <vers num="0.2.0.9" edition="alpha" />
        <vers num="0.2.1.1.1" edition="alpha" />
        <vers num="0.2.1.1.10" edition="alpha" />
        <vers num="0.2.1.1.11" edition="alpha" />
        <vers num="0.2.1.1.12" edition="alpha" />
        <vers num="0.2.1.1.2" edition="alpha" />
        <vers num="0.2.1.1.3" edition="alpha" />
        <vers num="0.2.1.1.4" edition="alpha" />
        <vers num="0.2.1.1.5" edition="alpha" />
        <vers num="0.2.1.1.6" edition="alpha" />
        <vers num="0.2.1.1.7" edition="alpha" />
        <vers num="0.2.1.1.8" edition="alpha" />
        <vers num="0.2.1.1.9" edition="alpha" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2009-0415" published="2009-02-03" name="CVE-2009-0415" modified="2009-02-04" CVSS_version="2.0" CVSS_vector="(AV:L/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="3.7" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="1.9" CVSS_base_score="3.7">
    <desc>
      <descript source="cve">Untrusted search path vulnerability in trickle 1.07 allows local users to execute arbitrary code via a Trojan horse trickle-overload.so in the current working directory, which is referenced in the LD_PRELOAD path.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <local />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/33516" source="BID">33516</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2009/01/29/5" source="MLIST">[oss-security] 20090129 CVE Request (trickle)</ref>
      <ref url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=513456" source="MISC">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=513456</ref>
    </refs>
    <vuln_soft>
      <prod vendor="monkey" name="trickle">
        <vers num="1.07" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0416" published="2009-02-03" name="CVE-2009-0416" modified="2009-02-20" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="6.9" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.4" CVSS_base_score="6.9">
    <desc>
      <descript source="cve">The SSL certificate setup program (genSslCert.sh) in Standards Based Linux Instrumentation for Manageability (SBLIM) sblim-sfcb 1.3.2 allows local users to overwrite arbitrary files via a symlink attack on the (1) /var/tmp/key.pem, (2) /var/tmp/cert.pem, and (3) /var/tmp/ssl.cnf temporary files.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/33583" source="BID">33583</ref>
      <ref url="http://sourceforge.net/tracker/index.php?func=detail&amp;aid=2561165&amp;group_id=128809&amp;atid=712784" source="MISC">http://sourceforge.net/tracker/index.php?func=detail&amp;aid=2561165&amp;group_id=128809&amp;atid=712784</ref>
      <ref url="http://sourceforge.net/forum/forum.php?forum_id=874261" source="MLIST">[oss-security] 20090203 CVE Request: sblim-sfcb genSslCert.sh temp race</ref>
      <ref url="http://secunia.com/advisories/33795" source="SECUNIA">33795</ref>
      <ref url="http://osvdb.org/51783" source="OSVDB">51783</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-02/msg00002.html" source="SUSE">SUSE-SR:2009:004</ref>
    </refs>
    <vuln_soft>
      <prod vendor="standards_based_linux_instrumentation" name="sblim-sfcb">
        <vers num="1.3.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0417" published="2009-02-10" name="CVE-2009-0417" modified="2009-03-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the AgaviWebRouting::gen(null) method in Agavi 0.11 before 0.11.6 and 1.0 before 1.0.0 beta 8 allows remote attackers to inject arbitrary web script or HTML via a crafted URL with certain characters that are not properly handled by web browsers that do not strictly follow RFC 3986, such as Internet Explorer 6 and 7.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://blog.agavi.org/post/75830918/agavi-1-0-0-beta-8-released-fixes-vulnerability" source="CONFIRM" patch="1" adv="1">http://blog.agavi.org/post/75830918/agavi-1-0-0-beta-8-released-fixes-vulnerability</ref>
      <ref url="http://blog.agavi.org/post/75829956/agavi-0-11-6-released-fixes-vulnerability" source="CONFIRM" patch="1" adv="1">http://blog.agavi.org/post/75829956/agavi-0-11-6-released-fixes-vulnerability</ref>
      <ref url="http://www.securityfocus.com/bid/33826" source="BID">33826</ref>
      <ref url="http://trac.agavi.org/ticket/1019" source="CONFIRM" adv="1">http://trac.agavi.org/ticket/1019</ref>
    </refs>
    <vuln_soft>
      <prod vendor="agavi" name="agavi">
        <vers num="0.11.0" edition="rc1" />
        <vers num="0.11.0" edition="rc2" />
        <vers num="0.11.0" edition="rc3" />
        <vers num="0.11.0" edition="rc4" />
        <vers num="0.11.0" edition="rc5" />
        <vers num="0.11.0" edition="rc6" />
        <vers num="0.11.0" edition="rc7" />
        <vers num="0.11.1" edition="rc1" />
        <vers num="0.11.1" edition="rc2" />
        <vers num="0.11.1" edition="rc3" />
        <vers num="0.11.2" edition="rc1" />
        <vers num="0.11.2" edition="rc2" />
        <vers num="0.11.3" edition="rc1" />
        <vers num="0.11.3" edition="rc2" />
        <vers num="0.11.4" edition="rc1" />
        <vers num="0.11.5" edition="rc1" />
        <vers num="0.11.6" edition="rc1" />
        <vers num="0.11.6" edition="rc2" />
        <vers num="1.0.0" edition="beta1" />
        <vers num="1.0.0" edition="beta2" />
        <vers num="1.0.0" edition="beta3" />
        <vers num="1.0.0" edition="beta4" />
        <vers num="1.0.0" edition="beta5" />
        <vers num="1.0.0" edition="beta6" />
        <vers num="1.0.0" edition="beta7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0418" published="2009-02-04" name="CVE-2009-0418" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">The IPv6 Neighbor Discovery Protocol (NDP) implementation in HP HP-UX B.11.11, B.11.23, and B.11.31 does not validate the origin of Neighbor Discovery messages, which allows remote attackers to cause a denial of service (loss of connectivity), read private network traffic, and possibly execute arbitrary code via a spoofed message that modifies the Forward Information Base (FIB), a related issue to CVE-2008-2476.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2009/0312" source="VUPEN">ADV-2009-0312</ref>
      <ref url="http://www.securitytracker.com/id?1021660" source="SECTRACK">1021660</ref>
      <ref url="http://secunia.com/advisories/33787" source="SECUNIA">33787</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5943" source="OVAL">oval:org.mitre.oval:def:5943</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=123368621330334&amp;w=2" source="HP">SSRT080107</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="hp-ux">
        <vers num="b.11.11" />
        <vers num="b.11.23" />
        <vers num="b.11.31" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0419" published="2009-02-04" name="CVE-2009-0419" modified="2009-03-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Microsoft XML Core Services, as used in Microsoft Expression Web, Office, Internet Explorer 6 and 7, and other products, does not properly restrict access from web pages to Set-Cookie2 HTTP response headers, which allows remote attackers to obtain sensitive information from cookies via XMLHttpRequest calls, related to the HTTPOnly protection mechanism.  NOTE: this issue reportedly exists because of an incomplete fix for CVE-2008-4033.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=380418" source="MISC">https://bugzilla.mozilla.org/show_bug.cgi?id=380418</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/48815" source="XF">msxml-httponly-cookie-information-disclosure(48815)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="xml_core_services">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0420" published="2009-02-04" name="CVE-2009-0420" modified="2009-02-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in the RD-Autos (com_rdautos) 1.5.5 Stable component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter to index.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/33297" source="BID">33297</ref>
      <ref url="http://www.milw0rm.com/exploits/7795" source="MILW0RM">7795</ref>
      <ref url="http://secunia.com/advisories/33562" source="SECUNIA" adv="1">33562</ref>
    </refs>
    <vuln_soft>
      <prod vendor="rd-media" name="rd-autos">
        <vers num="1.5.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0421" published="2009-02-04" name="CVE-2009-0421" modified="2009-02-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in the Eventing (com_eventing) 1.6.x component for Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter to index.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/48016" source="XF">eventing-index-sql-injection(48016)</ref>
      <ref url="http://www.securityfocus.com/bid/33296" source="BID">33296</ref>
      <ref url="http://www.milw0rm.com/exploits/7793" source="MILW0RM">7793</ref>
      <ref url="http://secunia.com/advisories/33563" source="SECUNIA" adv="1">33563</ref>
    </refs>
    <vuln_soft>
      <prod vendor="joomla" name="com_eventing">
        <vers num="1.6" />
        <vers num="1.6.1" />
        <vers num="1.6.2" />
        <vers num="1.6.3" />
        <vers num="1.6.4" />
        <vers num="1.6.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0422" published="2009-02-04" name="CVE-2009-0422" modified="2011-05-03" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Dynamic variable evaluation vulnerability in lists/admin.php in phpList 2.10.8 and earlier, when register_globals is disabled, allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the _SERVER[ConfigFile] parameter to admin/index.php.</descript>
      <descript source="nvd">Register Globals are disabled by default, so this will not increase access complexity.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/47945" source="XF">phplist-indexphp-file-include(47945)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/500057/100/0/threaded" source="BUGTRAQ">20090114 phpList &lt;= 2.10.8 Local File inclusion</ref>
      <ref url="http://www.milw0rm.com/exploits/7778" source="MILW0RM">7778</ref>
      <ref url="http://www.bugreport.ir/index_60.htm" source="MISC">http://www.bugreport.ir/index_60.htm</ref>
      <ref url="http://secunia.com/advisories/33533" source="SECUNIA" adv="1">33533</ref>
    </refs>
    <vuln_soft>
      <prod vendor="tincan" name="phplist">
        <vers num="1.0" />
        <vers num="1.0.1" />
        <vers num="1.1.2b" />
        <vers num="1.1.3b" />
        <vers num="1.1.4b" />
        <vers num="1.1.5" />
        <vers num="1.1.5b" />
        <vers num="1.1.6" />
        <vers num="1.1.7" />
        <vers num="1.3.5" />
        <vers num="1.3.7" />
        <vers num="1.4.1" />
        <vers num="1.5.0" />
        <vers num="1.5.1" />
        <vers num="1.6.0" />
        <vers num="1.6.1" />
        <vers num="1.6.3" />
        <vers num="1.6.4" />
        <vers num="1.7.0" />
        <vers num="1.7.1" />
        <vers num="1.8.0" />
        <vers num="1.9.0" />
        <vers num="1.9.1" />
        <vers num="1.9.2" />
        <vers num="1.9.3" />
        <vers num="2.1.0" />
        <vers num="2.1.1" />
        <vers num="2.1.3" />
        <vers num="2.1.4" />
        <vers num="2.10.1" />
        <vers num="2.10.2" />
        <vers num="2.10.3" />
        <vers num="2.10.4" />
        <vers num="2.10.5" />
        <vers num="2.10.6" />
        <vers num="2.10.7" />
        <vers prev="1" num="2.10.8" />
        <vers num="2.2.0" />
        <vers num="2.2.1" />
        <vers num="2.3.0" />
        <vers num="2.3.1" />
        <vers num="2.3.2" />
        <vers num="2.3.3" />
        <vers num="2.3.4" />
        <vers num="2.4.0" />
        <vers num="2.4.7" />
        <vers num="2.5.0" />
        <vers num="2.5.1" />
        <vers num="2.5.2" />
        <vers num="2.5.3" />
        <vers num="2.5.4" />
        <vers num="2.5.5" />
        <vers num="2.5.6" />
        <vers num="2.5.7" />
        <vers num="2.5.8" />
        <vers num="2.6" />
        <vers num="2.6.0" />
        <vers num="2.6.1" />
        <vers num="2.6.2" />
        <vers num="2.6.3" />
        <vers num="2.6.4" />
        <vers num="2.6.5" />
        <vers num="2.7.1" />
        <vers num="2.7.2" />
        <vers num="2.8.12" />
        <vers num="2.8.2" />
        <vers num="2.8.7" />
        <vers num="2.9.3" />
        <vers num="2.9.4" />
        <vers num="2.9.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0423" published="2009-02-04" name="CVE-2009-0423" modified="2009-02-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Directory traversal vulnerability in index.php in Php Photo Album (PHPPA) 0.8 BETA allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the preview parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/48017" source="XF">phpphotoalbum-index-file-include(48017)</ref>
      <ref url="http://www.securityfocus.com/bid/33277" source="BID">33277</ref>
      <ref url="http://www.milw0rm.com/exploits/7786" source="MILW0RM">7786</ref>
    </refs>
    <vuln_soft>
      <prod vendor="kevin_walker" name="php_photo_album">
        <vers num="0.8" edition="beta" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0424" published="2009-02-04" name="CVE-2009-0424" modified="2009-02-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in sign1.php in AN Guestbook (ANG) before 0.7.7 allows remote attackers to inject arbitrary web script or HTML via the country parameter, which is not properly handled in (1) administrator/manage.php or (2) administrator/trash.php.  NOTE: some of these details are obtained from third party information.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/33292" source="BID" patch="1">33292</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/48018" source="XF">anguestbook-sign1-xss(48018)</ref>
      <ref url="http://sourceforge.net/project/shownotes.php?release_id=653720" source="CONFIRM">http://sourceforge.net/project/shownotes.php?release_id=653720</ref>
      <ref url="http://sourceforge.net/forum/forum.php?forum_id=907703" source="CONFIRM" adv="1">http://sourceforge.net/forum/forum.php?forum_id=907703</ref>
      <ref url="http://secunia.com/advisories/33490" source="SECUNIA" adv="1">33490</ref>
    </refs>
    <vuln_soft>
      <prod vendor="an_guestbook" name="an_guestbook">
        <vers num="0.3.1" />
        <vers num="0.3.2" />
        <vers num="0.3.3" />
        <vers num="0.3.4" />
        <vers num="0.3.5" />
        <vers num="0.4" />
        <vers num="0.4.1" />
        <vers num="0.4.5" />
        <vers num="0.5" />
        <vers num="0.6" />
        <vers num="0.7" />
        <vers num="0.7.1" />
        <vers num="0.7.5" />
        <vers prev="1" num="0.7.6" />
        <vers num="1.0" />
        <vers num="1.1" />
        <vers num="1.2" />
        <vers num="1.5" />
        <vers num="2.0" />
        <vers num="2.1" />
        <vers num="2.2" />
        <vers num="2.2a" />
        <vers num="3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0425" published="2009-02-04" name="CVE-2009-0425" modified="2009-02-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in index.php in Blue Eye CMS 1.0.0 and earlier allows remote attackers to execute arbitrary SQL commands via the clanek parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/33303" source="BID">33303</ref>
      <ref url="http://www.milw0rm.com/exploits/7797" source="MILW0RM">7797</ref>
    </refs>
    <vuln_soft>
      <prod vendor="blue_eye_cms" name="blue_eye_cms">
        <vers prev="1" num="1.0.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0426" published="2009-02-04" name="CVE-2009-0426" modified="2009-02-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in CategoryManager/upload_image_category.asp in DMXReady Classified Listings Manager 1.1 and earlier allows remote attackers to execute arbitrary SQL commands via the cid parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/47959" source="XF">classifieds-uploadimage-sql-injection(47959)</ref>
      <ref url="http://www.securityfocus.com/bid/33253" source="BID">33253</ref>
      <ref url="http://secunia.com/advisories/33482" source="SECUNIA" adv="1">33482</ref>
      <ref url="http://milw0rm.com/exploits/7767" source="MILW0RM">7767</ref>
    </refs>
    <vuln_soft>
      <prod vendor="dmxready" name="classified_listings_manager">
        <vers num="1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0427" published="2009-02-04" name="CVE-2009-0427" modified="2009-02-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in CategoryManager/upload_image_category.asp in DMXReady Member Directory Manager 1.1 and earlier allows remote attackers to execute arbitrary SQL commands via the cid parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/47960" source="XF">memberdirectory-uploadimage-sql-injection(47960)</ref>
      <ref url="http://www.securityfocus.com/bid/33253" source="BID">33253</ref>
      <ref url="http://secunia.com/advisories/33482" source="SECUNIA" adv="1">33482</ref>
      <ref url="http://milw0rm.com/exploits/7773" source="MILW0RM">7773</ref>
      <ref url="http://dmxready.helpserve.com/index.php?_m=news&amp;_a=viewnews&amp;newsid=12" source="CONFIRM" adv="1">http://dmxready.helpserve.com/index.php?_m=news&amp;_a=viewnews&amp;newsid=12</ref>
      <ref url="http://dmxready.helpserve.com/index.php?_m=knowledgebase&amp;_a=viewarticle&amp;kbarticleid=93" source="CONFIRM">http://dmxready.helpserve.com/index.php?_m=knowledgebase&amp;_a=viewarticle&amp;kbarticleid=93</ref>
    </refs>
    <vuln_soft>
      <prod vendor="dmxready" name="member_directory_manager">
        <vers num="1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0428" published="2009-02-04" name="CVE-2009-0428" modified="2009-02-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in CategoryManager/upload_image_category.asp in DMXReady Secure Document Library 1.1 and earlier allows remote attackers to execute arbitrary SQL commands via the cid parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/48013" source="XF">securedocumentlibrary-uploadimage-sql-inj(48013)</ref>
      <ref url="http://www.securityfocus.com/bid/33253" source="BID">33253</ref>
      <ref url="http://secunia.com/advisories/33482" source="SECUNIA" adv="1">33482</ref>
      <ref url="http://milw0rm.com/exploits/7787" source="MILW0RM">7787</ref>
      <ref url="http://dmxready.helpserve.com/index.php?_m=news&amp;_a=viewnews&amp;newsid=12" source="CONFIRM" adv="1">http://dmxready.helpserve.com/index.php?_m=news&amp;_a=viewnews&amp;newsid=12</ref>
      <ref url="http://dmxready.helpserve.com/index.php?_m=knowledgebase&amp;_a=viewarticle&amp;kbarticleid=93" source="CONFIRM">http://dmxready.helpserve.com/index.php?_m=knowledgebase&amp;_a=viewarticle&amp;kbarticleid=93</ref>
    </refs>
    <vuln_soft>
      <prod vendor="dmxready" name="secure_document_library">
        <vers num="1.0" />
        <vers prev="1" num="1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0429" published="2009-02-04" name="CVE-2009-0429" modified="2009-02-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in Active Bids allow remote attackers to execute arbitrary SQL commands via the (1) search parameter to search.asp, (2) SortDir parameter to auctionsended.asp, and the (3) catid parameter to wishlist.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/33306" source="BID">33306</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/500144/100/0/threaded" source="BUGTRAQ">20090116 Active Bids</ref>
    </refs>
    <vuln_soft>
      <prod vendor="activewebsoftwares" name="active_bids">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0430" published="2009-02-04" name="CVE-2009-0430" modified="2009-02-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Active Bids allow remote attackers to inject arbitrary web script or HTML via the (1) search parameter to search.asp and the (2) URL parameter to tellafriend.asp.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/33306" source="BID">33306</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/500144/100/0/threaded" source="BUGTRAQ">20090116 Active Bids</ref>
    </refs>
    <vuln_soft>
      <prod vendor="activewebsoftwares" name="active_bids">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0431" published="2009-02-04" name="CVE-2009-0431" modified="2009-02-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in Default.asp in LinksPro Standard Edition allows remote attackers to execute arbitrary SQL commands via the OrderDirection parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/33305" source="BID">33305</ref>
      <ref url="http://packetstormsecurity.org/0901-exploits/linkspro-sql.txt" source="MISC">http://packetstormsecurity.org/0901-exploits/linkspro-sql.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="codefixer" name="linkspro">
        <vers num="_nil_" edition="_nil_" />
        <vers num="_nil_" edition="_nil_:standard" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0432" published="2009-02-10" name="CVE-2009-0432" modified="2009-02-12" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The installation process for the File Transfer servlet in the System Management/Repository component in IBM WebSphere Application Server (WAS) 6.1.x before 6.1.0.19 does not enable the secure version, which allows remote attackers to obtain sensitive information via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg27007951" source="CONFIRM" patch="1" adv="1">http://www-01.ibm.com/support/docview.wss?uid=swg27007951</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/48522" source="XF">websphere-file-transfer-info-disclosure(48522)</ref>
      <ref url="http://www.securityfocus.com/bid/33700" source="BID">33700</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="websphere_application_server">
        <vers num="6.1.0.1" />
        <vers num="6.1.0.11" />
        <vers num="6.1.0.13" />
        <vers num="6.1.0.15" />
        <vers num="6.1.0.17" />
        <vers num="6.1.0.2" />
        <vers num="6.1.0.3" />
        <vers num="6.1.0.5" />
        <vers num="6.1.0.7" />
        <vers num="6.1.0.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2009-0433" published="2009-02-10" name="CVE-2009-0433" modified="2009-02-11" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:N/A:P)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Unspecified vulnerability in IBM WebSphere Application Server (WAS) 5.1.x before 5.1.1.19, 6.0.x before 6.0.2.29, and 6.1.x before 6.1.0.19, when Web Server plug-in content buffering is enabled, allows attackers to cause a denial of service (daemon crash) via unknown vectors, related to a mishandling of client read failures in which clients receive many 500 HTTP error responses and backend servers are incorrectly labeled as down.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/33700" source="BID" patch="1">33700</ref>
      <ref url="http://www-1.ibm.com/support/docview.wss?uid=swg1PK63499" source="AIXAPAR" patch="1">PK63499</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg27007951" source="CONFIRM" patch="1">http://www-01.ibm.com/support/docview.wss?uid=swg27007951</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg27007033" source="CONFIRM" patch="1">http://www-01.ibm.com/support/docview.wss?uid=swg27007033</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg27006879" source="CONFIRM" patch="1">http://www-01.ibm.com/support/docview.wss?uid=swg27006879</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/48523" source="XF">websphere-server-plugin-dos(48523)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="websphere_application_server">
        <vers num="5.1.0" />
        <vers num="5.1.0.2" />
        <vers num="5.1.0.3" />
        <vers num="5.1.0.4" />
        <vers num="5.1.0.5" />
        <vers num="5.1.1" />
        <vers num="5.1.1.1" />
        <vers num="5.1.1.10" />
        <vers num="5.1.1.11" />
        <vers num="5.1.1.12" />
        <vers num="5.1.1.13" />
        <vers num="5.1.1.14" />
        <vers num="5.1.1.15" />
        <vers num="5.1.1.16" />
        <vers num="5.1.1.17" />
        <vers num="5.1.1.18" />
        <vers num="5.1.1.19" />
        <vers num="6.0" />
        <vers num="6.0.0.1" />
        <vers num="6.0.0.2" />
        <vers num="6.0.0.3" />
        <vers num="6.0.1" />
        <vers num="6.0.1.1" />
        <vers num="6.0.1.11" />
        <vers num="6.0.1.13" />
        <vers num="6.0.1.15" />
        <vers num="6.0.1.17" />
        <vers num="6.0.1.2" />
        <vers num="6.0.1.3" />
        <vers num="6.0.1.5" />
        <vers num="6.0.1.7" />
        <vers num="6.0.1.9" />
        <vers num="6.0.2" />
        <vers num="6.0.2.1" />
        <vers num="6.0.2.11" />
        <vers num="6.0.2.13" />
        <vers num="6.0.2.15" />
        <vers num="6.0.2.17" />
        <vers num="6.0.2.19" />
        <vers num="6.0.2.2" />
        <vers num="6.0.2.22" />
        <vers num="6.0.2.23" />
        <vers num="6.0.2.24" />
        <vers num="6.0.2.25" />
        <vers num="6.0.2.27" />
        <vers num="6.0.2.28" />
        <vers num="6.0.2.3" />
        <vers num="6.0.2.4" />
        <vers num="6.0.2.5" />
        <vers num="6.0.2.6" />
        <vers num="6.0.2.7" />
        <vers num="6.0.2.9" />
        <vers num="6.1" />
        <vers num="6.1.0" />
        <vers num="6.1.0.0" />
        <vers num="6.1.0.1" />
        <vers num="6.1.0.10" />
        <vers num="6.1.0.11" />
        <vers num="6.1.0.12" />
        <vers num="6.1.0.13" />
        <vers num="6.1.0.14" />
        <vers num="6.1.0.15" />
        <vers num="6.1.0.16" />
        <vers num="6.1.0.17" />
        <vers num="6.1.0.18" />
        <vers num="6.1.0.2" />
        <vers num="6.1.0.3" />
        <vers num="6.1.0.4" />
        <vers num="6.1.0.5" />
        <vers num="6.1.0.6" />
        <vers num="6.1.0.7" />
        <vers num="6.1.0.8" />
        <vers num="6.1.0.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2009-0434" published="2009-02-10" name="CVE-2009-0434" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:P/I:N/A:N)" CVSS_score="1.9" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.4" CVSS_base_score="1.9">
    <desc>
      <descript source="cve">PerfServlet in the PMI/Performance Tools component in IBM WebSphere Application Server (WAS) 6.0.x before 6.0.2.31, 6.1.x before 6.1.0.21, and 7.0.x before 7.0.0.1, when Performance Monitoring Infrastructure (PMI) is enabled, allows local users to obtain sensitive information by reading the (1) systemout.log and (2) ffdc files.  NOTE: this is probably a duplicate of CVE-2008-5413.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/48524" source="XF">websphere-pmi-information-disclosure(48524)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0423" source="VUPEN">ADV-2009-0423</ref>
      <ref url="http://www.securityfocus.com/bid/33700" source="BID">33700</ref>
      <ref url="http://www-1.ibm.com/support/docview.wss?uid=swg1PK79230" source="AIXAPAR">PK79230</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg27014463" source="CONFIRM">http://www-01.ibm.com/support/docview.wss?uid=swg27014463</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg27007951" source="CONFIRM">http://www-01.ibm.com/support/docview.wss?uid=swg27007951</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg27006876" source="MISC">http://www-01.ibm.com/support/docview.wss?uid=swg27006876</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="websphere_application_server">
        <vers num="6.0" />
        <vers num="6.0.0.1" />
        <vers num="6.0.0.2" />
        <vers num="6.0.0.3" />
        <vers num="6.0.1" />
        <vers num="6.0.1.1" />
        <vers num="6.0.1.11" />
        <vers num="6.0.1.13" />
        <vers num="6.0.1.15" />
        <vers num="6.0.1.17" />
        <vers num="6.0.1.2" />
        <vers num="6.0.1.3" />
        <vers num="6.0.1.5" />
        <vers num="6.0.1.7" />
        <vers num="6.0.1.9" />
        <vers num="6.0.2" />
        <vers num="6.0.2.1" />
        <vers num="6.0.2.11" />
        <vers num="6.0.2.13" />
        <vers num="6.0.2.15" />
        <vers num="6.0.2.17" />
        <vers num="6.0.2.19" />
        <vers num="6.0.2.2" />
        <vers num="6.0.2.22" />
        <vers num="6.0.2.23" />
        <vers num="6.0.2.24" />
        <vers num="6.0.2.25" />
        <vers num="6.0.2.27" />
        <vers num="6.0.2.28" />
        <vers num="6.0.2.29" />
        <vers num="6.0.2.3" />
        <vers num="6.0.2.30" />
        <vers num="6.0.2.31" />
        <vers num="6.0.2.4" />
        <vers num="6.0.2.5" />
        <vers num="6.0.2.6" />
        <vers num="6.0.2.7" />
        <vers num="6.0.2.9" />
        <vers num="6.1" />
        <vers num="6.1.0" />
        <vers num="6.1.0.0" />
        <vers num="6.1.0.1" />
        <vers num="6.1.0.10" />
        <vers num="6.1.0.11" />
        <vers num="6.1.0.12" />
        <vers num="6.1.0.13" />
        <vers num="6.1.0.14" />
        <vers num="6.1.0.15" />
        <vers num="6.1.0.16" />
        <vers num="6.1.0.17" />
        <vers num="6.1.0.18" />
        <vers num="6.1.0.19" />
        <vers num="6.1.0.2" />
        <vers num="6.1.0.20" />
        <vers num="6.1.0.21" />
        <vers num="7.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0435" published="2009-02-10" name="CVE-2009-0435" modified="2009-02-12" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the IBM Asynchronous I/O (aka AIO or libibmaio) library in the Java Message Service (JMS) component in IBM WebSphere Application Server (WAS) 6.1.x before 6.1.0.17 on AIX 5.3 allows attackers to cause a denial of service (daemon crash) via vectors related to the aio_getioev2 and getEvent methods.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg27007951" source="CONFIRM" patch="1" adv="1">http://www-01.ibm.com/support/docview.wss?uid=swg27007951</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?rs=0&amp;uid=swg24019205" source="AIXAPAR" patch="1" adv="1">PK64529</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/48525" source="XF">websphere-libibmaio-dos(48525)</ref>
      <ref url="http://www.securityfocus.com/bid/33700" source="BID">33700</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="websphere_application_server">
        <vers num="6.1.0" />
        <vers num="6.1.0.0" />
        <vers num="6.1.0.1" />
        <vers num="6.1.0.10" />
        <vers num="6.1.0.11" />
        <vers num="6.1.0.12" />
        <vers num="6.1.0.13" />
        <vers num="6.1.0.14" />
        <vers num="6.1.0.15" />
        <vers num="6.1.0.16" />
        <vers num="6.1.0.2" />
        <vers num="6.1.0.3" />
        <vers num="6.1.0.4" />
        <vers num="6.1.0.5" />
        <vers num="6.1.0.6" />
        <vers num="6.1.0.7" />
        <vers num="6.1.0.8" />
        <vers num="6.1.0.9" />
        <vers num="6.1.1" />
        <vers num="6.1.13" />
        <vers num="6.1.14" />
        <vers num="6.1.3" />
        <vers num="6.1.5" />
        <vers num="6.1.6" />
        <vers num="6.1.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0436" published="2009-02-10" name="CVE-2009-0436" modified="2009-06-17" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">The (1) mod_ibm_ssl and (2) mod_cgid modules in IBM HTTP Server 6.0.x before 6.0.2.31 and 6.1.x before 6.1.0.19, as used in WebSphere Application Server (WAS), set incorrect permissions for AF_UNIX sockets, which has unknown impact and local attack vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg27008517" source="CONFIRM" patch="1">http://www-01.ibm.com/support/docview.wss?uid=swg27008517</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg27007951" source="MISC" patch="1" adv="1">http://www-01.ibm.com/support/docview.wss?uid=swg27007951</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg27007033" source="CONFIRM" patch="1">http://www-01.ibm.com/support/docview.wss?uid=swg27007033</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg27006876" source="MISC" patch="1">http://www-01.ibm.com/support/docview.wss?uid=swg27006876</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/48526" source="XF">websphere-http-afunix-incorrect-permissions(48526)</ref>
      <ref url="http://www.securityfocus.com/bid/33700" source="BID">33700</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="websphere_application_server">
        <vers num="6.0" />
        <vers num="6.0.0.1" />
        <vers num="6.0.0.2" />
        <vers num="6.0.0.3" />
        <vers num="6.0.1" />
        <vers num="6.0.1.1" />
        <vers num="6.0.1.11" />
        <vers num="6.0.1.13" />
        <vers num="6.0.1.15" />
        <vers num="6.0.1.17" />
        <vers num="6.0.1.2" />
        <vers num="6.0.1.3" />
        <vers num="6.0.1.5" />
        <vers num="6.0.1.7" />
        <vers num="6.0.1.9" />
        <vers num="6.0.2" />
        <vers num="6.0.2.1" />
        <vers num="6.0.2.11" />
        <vers num="6.0.2.13" />
        <vers num="6.0.2.15" />
        <vers num="6.0.2.17" />
        <vers num="6.0.2.19" />
        <vers num="6.0.2.2" />
        <vers num="6.0.2.22" />
        <vers num="6.0.2.23" />
        <vers num="6.0.2.24" />
        <vers num="6.0.2.25" />
        <vers num="6.0.2.27" />
        <vers num="6.0.2.28" />
        <vers num="6.0.2.29" />
        <vers num="6.0.2.3" />
        <vers num="6.0.2.30" />
        <vers num="6.0.2.4" />
        <vers num="6.0.2.5" />
        <vers num="6.0.2.6" />
        <vers num="6.0.2.7" />
        <vers num="6.0.2.9" />
        <vers num="6.1" />
        <vers num="6.1.0" />
        <vers num="6.1.0.0" />
        <vers num="6.1.0.1" />
        <vers num="6.1.0.10" />
        <vers num="6.1.0.11" />
        <vers num="6.1.0.12" />
        <vers num="6.1.0.13" />
        <vers num="6.1.0.14" />
        <vers num="6.1.0.15" />
        <vers num="6.1.0.16" />
        <vers num="6.1.0.17" />
        <vers num="6.1.0.18" />
        <vers num="6.1.0.2" />
        <vers num="6.1.0.3" />
        <vers num="6.1.0.4" />
        <vers num="6.1.0.5" />
        <vers num="6.1.0.6" />
        <vers num="6.1.0.7" />
        <vers num="6.1.0.8" />
        <vers num="6.1.0.9" />
        <vers num="6.1.13" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2009-0437" published="2009-02-10" name="CVE-2009-0437" modified="2009-02-26" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:P/I:N/A:N)" CVSS_score="1.9" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.4" CVSS_base_score="1.9">
    <desc>
      <descript source="cve">The Installation Factory installation process for IBM WebSphere Application Server (WAS) 6.0.2 on Windows, when WAS is registered as a Windows service, allows local users to obtain sensitive information by reading the logs/instconfigifwas6.log log file.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/48527" source="XF">websphere-install-log-info-disclosure(48527)</ref>
      <ref url="http://www.securityfocus.com/bid/33849" source="BID">33849</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="websphere_application_server">
        <vers num="6.0.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0438" published="2009-02-10" name="CVE-2009-0438" modified="2009-02-11" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">IBM WebSphere Application Server (WAS) 7 before 7.0.0.1 on Windows allows remote attackers to bypass "Authorization checking" and obtain sensitive information from JSP pages via a crafted request.  NOTE: this is probably a duplicate of CVE-2008-5412.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg27014463" source="CONFIRM" patch="1" adv="1">http://www-01.ibm.com/support/docview.wss?uid=swg27014463</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/48528" source="XF">websphere-jsp-win-information-disclosure(48528)</ref>
      <ref url="http://www.securityfocus.com/bid/33700" source="BID">33700</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="websphere_application_server">
        <vers num="7.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0439" published="2009-02-24" name="CVE-2009-0439" modified="2009-03-06" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Unspecified vulnerability in the queue manager in IBM WebSphere MQ (WMQ) 5.3, 6.0 before 6.0.2.6, and 7.0 before 7.0.0.2 allows local users to gain privileges via vectors related to the (1) setmqaut, (2) dmpmqaut, and (3) dspmqaut authorization commands.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/48529" source="XF" patch="1">websphere-mq-privilege-escalation(48529)</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?rs=171&amp;uid=swg27006037" source="MISC" patch="1">http://www-01.ibm.com/support/docview.wss?rs=171&amp;uid=swg27006037</ref>
      <ref url="http://www.securityfocus.com/bid/33857" source="BID">33857</ref>
      <ref url="http://secunia.com/advisories/34034" source="SECUNIA">34034</ref>
      <ref url="http://osvdb.org/52297" source="OSVDB">52297</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="websphere_mq">
        <vers num="5.3" edition="-" />
        <vers num="5.3" edition="-:express" />
        <vers num="5.3.1" />
        <vers num="6.0.0.0" />
        <vers num="6.0.1.0" />
        <vers num="6.0.1.1" />
        <vers num="6.0.2.0" />
        <vers num="6.0.2.1" />
        <vers num="6.0.2.2" />
        <vers num="6.0.2.3" />
        <vers num="6.0.2.4" />
        <vers num="7.0" />
        <vers num="7.0.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0440" published="2009-02-22" name="CVE-2009-0440" modified="2009-02-23" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)" CVSS_score="6.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.0" CVSS_base_score="6.5">
    <desc>
      <descript source="cve">IBM WebSphere Partner Gateway (WPG) 6.0.0 through 6.0.0.7 does not properly handle failures of signature verification, which might allow remote authenticated users to submit a crafted RosettaNet (aka RNIF) document to a backend application, related to (1) "altered service content" and (2) "digital signature foot-print."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg21330341" source="CONFIRM" patch="1" adv="1">http://www-01.ibm.com/support/docview.wss?uid=swg21330341</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/48530" source="XF">websphere-pgateway-rnif-signatures(48530)</ref>
      <ref url="http://www.securityfocus.com/bid/33839" source="BID">33839</ref>
      <ref url="http://www-1.ibm.com/support/docview.wss?uid=swg1JR31231" source="AIXAPAR" adv="1">JR31231</ref>
      <ref url="http://secunia.com/advisories/33994" source="SECUNIA" adv="1">33994</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="websphere_partner_gateway">
        <vers num="6.0.0" />
        <vers num="6.0.0.1" />
        <vers num="6.0.0.2" />
        <vers num="6.0.0.3" />
        <vers num="6.0.0.4" />
        <vers num="6.0.0.5" />
        <vers num="6.0.0.6" />
        <vers num="6.0.0.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0441" published="2009-02-10" name="CVE-2009-0441" modified="2009-03-06" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in skin_shop/standard/2_view_body/body_default.php in Technote 7.2, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the shop_this_skin_path parameter, a different vector than CVE-2008-4138.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/33592" source="BID">33592</ref>
      <ref url="http://www.milw0rm.com/exploits/7965" source="MILW0RM">7965</ref>
      <ref url="http://secunia.com/advisories/33732" source="SECUNIA" adv="1">33732</ref>
      <ref url="http://osvdb.org/51740" source="OSVDB">51740</ref>
    </refs>
    <vuln_soft>
      <prod vendor="technote" name="technote">
        <vers num="7.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0442" published="2009-02-10" name="CVE-2009-0442" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Directory traversal vulnerability in bbcode.php in PHPbbBook 1.3 and 1.3h allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the l parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2009/0317" source="VUPEN">ADV-2009-0317</ref>
      <ref url="http://www.securityfocus.com/bid/33603" source="BID">33603</ref>
      <ref url="http://www.milw0rm.com/exploits/7980" source="MILW0RM">7980</ref>
      <ref url="http://secunia.com/advisories/33811" source="SECUNIA" adv="1">33811</ref>
      <ref url="http://osvdb.org/51737" source="OSVDB">51737</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpbbbook" name="phpbbbook">
        <vers num="1.3" />
        <vers num="1.3h" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0443" published="2009-02-10" name="CVE-2009-0443" modified="2009-02-10" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Stack-based buffer overflow in Elecard AVC HD PLAYER 5.5.90116 allows remote attackers to execute arbitrary code via an M3U file containing a long string in a URL.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/33089" source="BID">33089</ref>
      <ref url="http://www.milw0rm.com/exploits/7942" source="MILW0RM">7942</ref>
      <ref url="http://secunia.com/advisories/33742" source="SECUNIA" adv="1">33742</ref>
      <ref url="http://osvdb.org/51717" source="OSVDB">51717</ref>
    </refs>
    <vuln_soft>
      <prod vendor="elecard" name="elecard_avc_hd_player">
        <vers num="5.5.90116" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0444" published="2009-02-10" name="CVE-2009-0444" modified="2009-03-06" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple PHP remote file inclusion vulnerabilities in GRBoard 1.8, when register_globals is enabled and magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary PHP code via a URL in the (1) theme parameter to (a) 179_squarebox_pds_list/view.php, (b) 179_squarebox_minishop_expand/view.php, (c) 179_squarebox_gallery_list_pds/view.php, (d) 179_squarebox_gallery_list/view.php, (e) 179_squarebox_gallery/view.php, (f) 179_squarebox_board_swfupload/view.php, (g) 179_squarebox_board_expand/view.php, (h) 179_squarebox_board_basic_with_grcode/view.php, (i) 179_squarebox_board_basic/view.php, (j) 179_simplebar_pds_list/view.php, (k) 179_simplebar_notice/view.php, (l) 179_simplebar_gallery_list_pds/view.php, (m) 179_simplebar_gallery/view.php, and (n) 179_simplebar_basic/view.php in theme/; the (2) path parameter to (o) latest/sirini_gallery_latest/list.php; and the (3) grboard parameter to (p) include.php and (q) form_mail.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/33602" source="BID">33602</ref>
      <ref url="http://www.milw0rm.com/exploits/7979" source="MILW0RM">7979</ref>
      <ref url="http://secunia.com/advisories/33812" source="SECUNIA" adv="1">33812</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sirini" name="grboard">
        <vers num="1.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0445" published="2009-02-10" name="CVE-2009-0445" modified="2009-08-24" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in index.php in Dreampics Gallery Builder allows remote attackers to execute arbitrary SQL commands via the exhibition_id parameter in a gallery.viewPhotos action.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/48468" source="XF">dreampics-exhibitionid-sql-injection(48468)</ref>
      <ref url="http://www.securityfocus.com/bid/33596" source="BID">33596</ref>
      <ref url="http://www.milw0rm.com/exploits/9451" source="MILW0RM">9451</ref>
      <ref url="http://www.milw0rm.com/exploits/7968" source="MILW0RM">7968</ref>
      <ref url="http://secunia.com/advisories/33730" source="SECUNIA" adv="1">33730</ref>
      <ref url="http://osvdb.org/51741" source="OSVDB">51741</ref>
    </refs>
    <vuln_soft>
      <prod vendor="dreampics" name="gallery_builder">
        <vers num="-" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0446" published="2009-02-10" name="CVE-2009-0446" modified="2009-02-10" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in photo.php in WEBalbum 2.4b allows remote attackers to execute arbitrary SQL commands via the id parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/33590" source="BID">33590</ref>
      <ref url="http://www.milw0rm.com/exploits/7961" source="MILW0RM">7961</ref>
    </refs>
    <vuln_soft>
      <prod vendor="web-album" name="webalbum">
        <vers num="2.4b" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0447" published="2009-02-10" name="CVE-2009-0447" modified="2009-03-06" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in default.asp in MyDesign Sayac 2.0 allow remote attackers to execute arbitrary SQL commands via (1) the user parameter (aka UserName field) or (2) the pass parameter (aka Pass field) to (a) admin/admin.asp or (b) the default URI under admin/.  NOTE: some of these details are obtained from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/33593" source="BID">33593</ref>
      <ref url="http://www.milw0rm.com/exploits/7963" source="MILW0RM">7963</ref>
      <ref url="http://secunia.com/advisories/33771" source="SECUNIA" adv="1">33771</ref>
      <ref url="http://osvdb.org/51754" source="OSVDB">51754</ref>
    </refs>
    <vuln_soft>
      <prod vendor="aspindir" name="mydesign_sayac">
        <vers num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0448" published="2009-02-10" name="CVE-2009-0448" modified="2009-03-06" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Directory traversal vulnerability in admin/modules/aa/preview.php in Syntax Desktop 2.7 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the synTarget parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/48496" source="XF">syntax-desktop-preview-file-include(48496)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0319" source="VUPEN">ADV-2009-0319</ref>
      <ref url="http://www.securityfocus.com/bid/33601" source="BID">33601</ref>
      <ref url="http://www.milw0rm.com/exploits/7977" source="MILW0RM">7977</ref>
    </refs>
    <vuln_soft>
      <prod vendor="syntax_desktop" name="syntax_desktop">
        <vers num="2.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0449" published="2009-02-10" name="CVE-2009-0449" modified="2009-02-10" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in klim5.sys in Kaspersky Anti-Virus for Workstations 6.0 and Anti-Virus 2008 allows local users to gain privileges via an IOCTL 0x80052110 call.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.wintercore.com/advisories/advisory_W020209.html" source="MISC">http://www.wintercore.com/advisories/advisory_W020209.html</ref>
      <ref url="http://www.securitytracker.com/id?1021661" source="SECTRACK">1021661</ref>
      <ref url="http://www.securityfocus.com/bid/33561" source="BID">33561</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/500606/100/0/threaded" source="BUGTRAQ">20090202 [Wintercore Research WS02-0209] Kaspersky Products Klim5.sys local privilege escalation</ref>
      <ref url="http://www.reversemode.com/index.php?option=com_content&amp;task=view&amp;id=60&amp;Itemid=1" source="MISC">http://www.reversemode.com/index.php?option=com_content&amp;task=view&amp;id=60&amp;Itemid=1</ref>
      <ref url="http://secunia.com/advisories/33788" source="SECUNIA" adv="1">33788</ref>
      <ref url="http://kartoffel.reversemode.com/downloads/kaspersky_klim5_plugin.zip" source="MISC">http://kartoffel.reversemode.com/downloads/kaspersky_klim5_plugin.zip</ref>
    </refs>
    <vuln_soft>
      <prod vendor="kaspersky_lab" name="kaspersky_anti-virus">
        <vers num="2008" />
        <vers num="6.0" edition="" />
        <vers num="6.0" edition=":workstations" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0450" published="2009-02-10" name="CVE-2009-0450" modified="2009-02-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Stack-based buffer overflow in BlazeVideo HDTV Player 3.5 and earlier allows remote attackers to execute arbitrary code via a long string in a playlist (aka .plf) file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/48498" source="XF">blazevideo-hdtv-plf-bo(48498)</ref>
      <ref url="http://www.securityfocus.com/bid/33588" source="BID">33588</ref>
      <ref url="http://www.milw0rm.com/exploits/7975" source="MILW0RM">7975</ref>
    </refs>
    <vuln_soft>
      <prod vendor="blazevideo" name="hdtv_player">
        <vers num="2.1" />
        <vers prev="1" num="3.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0451" published="2009-02-10" name="CVE-2009-0451" modified="2009-02-10" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in Skalfa SkaLinks 1.5 allows remote attackers to execute arbitrary SQL commands via the Admin name field to the default URI under admin/.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/33546" source="BID">33546</ref>
      <ref url="http://www.milw0rm.com/exploits/7932" source="MILW0RM">7932</ref>
    </refs>
    <vuln_soft>
      <prod vendor="skalinks" name="skalinks">
        <vers num="1.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0452" published="2009-02-10" name="CVE-2009-0452" modified="2009-02-10" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in parents/login.php in Online Grades 3.2.4, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) uname or (2) pass parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/33576" source="BID">33576</ref>
      <ref url="http://www.milw0rm.com/exploits/7956" source="MILW0RM">7956</ref>
      <ref url="http://secunia.com/advisories/33767" source="SECUNIA" adv="1">33767</ref>
      <ref url="http://osvdb.org/51712" source="OSVDB">51712</ref>
    </refs>
    <vuln_soft>
      <prod vendor="onlinegrades" name="online_grades">
        <vers num="3.2.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0453" published="2009-02-10" name="CVE-2009-0453" modified="2009-02-10" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Online Grades 3.2.4 allows remote attackers to obtain configuration information via a direct request to phpinfo.php, which calls the phpinfo function.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.milw0rm.com/exploits/7956" source="MILW0RM">7956</ref>
      <ref url="http://secunia.com/advisories/33767" source="SECUNIA" adv="1">33767</ref>
      <ref url="http://osvdb.org/51713" source="OSVDB">51713</ref>
    </refs>
    <vuln_soft>
      <prod vendor="onlinegrades" name="online_grades">
        <vers num="3.2.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0454" published="2009-02-10" name="CVE-2009-0454" modified="2009-02-20" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in DMXReady Online Notebook Manager 1.1 allow remote attackers to execute arbitrary SQL commands via the (1) username or (2) password field.  NOTE: some third parties report inability to verify this issue.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/48503" source="XF">onm-login-sql-injection(48503)</ref>
      <ref url="http://www.securityfocus.com/bid/33600" source="BID">33600</ref>
      <ref url="http://www.milw0rm.com/exploits/7970" source="MILW0RM">7970</ref>
    </refs>
    <vuln_soft>
      <prod vendor="dmxready" name="online_notebook_manager">
        <vers num="1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2009-0455" published="2009-02-10" name="CVE-2009-0455" modified="2009-02-11" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the anonymous comments feature in lib-comment.php in glFusion 1.1.0, 1.1.1, and earlier versions allows remote attackers to inject arbitrary web script or HTML via the username parameter to comment.php.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/33683" source="BID" patch="1">33683</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/48603" source="XF">glfusion-libcomment-xss(48603)</ref>
      <ref url="http://www.glfusion.org/article.php/xsscomments" source="CONFIRM" adv="1">http://www.glfusion.org/article.php/xsscomments</ref>
      <ref url="http://www.fortconsult.net/images/pdf/advisories/glFusion-xss-advisory.pdf" source="MISC">http://www.fortconsult.net/images/pdf/advisories/glFusion-xss-advisory.pdf</ref>
      <ref url="http://secunia.com/advisories/33878" source="SECUNIA" adv="1">33878</ref>
    </refs>
    <vuln_soft>
      <prod vendor="glfusion" name="glfusion">
        <vers num="1.1.0" />
        <vers prev="1" num="1.1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0456" published="2009-02-10" name="CVE-2009-0456" modified="2009-02-10" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in examples/example_clientside_javascript.php in patForms, as used in Sourdough 0.3.5, allows remote attackers to execute arbitrary PHP code via a URL in the neededFiles[patForms] parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/33569" source="BID">33569</ref>
      <ref url="http://www.milw0rm.com/exploits/7946" source="MILW0RM">7946</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sourdough" name="sourdough">
        <vers num="0.3.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0457" published="2009-02-10" name="CVE-2009-0457" modified="2009-02-12" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple directory traversal vulnerabilities in AJA Portal 1.2 allow remote attackers to include and execute arbitrary local files via directory traversal sequences in the currentlang parameter to admin/case.php in the (1) Contact_Plus and (2) Reviews modules, and (3) the module_name parameter to admin/includes/FANCYNLOptions.php in the Fancy_NewsLetter module.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/33565" source="BID">33565</ref>
      <ref url="http://www.milw0rm.com/exploits/7939" source="MILW0RM">7939</ref>
      <ref url="http://secunia.com/advisories/33735" source="SECUNIA" adv="1">33735</ref>
      <ref url="http://osvdb.org/51709" source="OSVDB">51709</ref>
      <ref url="http://osvdb.org/51708" source="OSVDB">51708</ref>
    </refs>
    <vuln_soft>
      <prod vendor="magtrb" name="aja_portal">
        <vers num="1.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0458" published="2009-02-10" name="CVE-2009-0458" modified="2009-03-06" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in admin/login_submit.php in Whole Hog Ware Support 1.x allow remote attackers to execute arbitrary SQL commands via (1) the uid parameter (aka Username field) or (2) the pwd parameter (aka Password field).  NOTE: some of these details are obtained from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/33564" source="BID">33564</ref>
      <ref url="http://secunia.com/advisories/33777" source="SECUNIA" adv="1">33777</ref>
      <ref url="http://osvdb.org/51733" source="OSVDB">51733</ref>
      <ref url="http://milw0rm.com/exploits/7940" source="MILW0RM">7940</ref>
    </refs>
    <vuln_soft>
      <prod vendor="wholehogsoftware" name="ware_support">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0459" published="2009-02-10" name="CVE-2009-0459" modified="2009-03-06" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in admin/login_submit.php in Whole Hog Password Protect: Enhanced 1.x allow remote attackers to execute arbitrary SQL commands via (1) the uid parameter (aka Username field) or (2) the pwd parameter (aka Password field).  NOTE: some of these details are obtained from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/33564" source="BID">33564</ref>
      <ref url="http://secunia.com/advisories/33777" source="SECUNIA" adv="1">33777</ref>
      <ref url="http://osvdb.org/51733" source="OSVDB">51733</ref>
      <ref url="http://milw0rm.com/exploits/7941" source="MILW0RM">7941</ref>
    </refs>
    <vuln_soft>
      <prod vendor="wholehogsoftware" name="password_protect">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0460" published="2009-02-10" name="CVE-2009-0460" modified="2009-03-06" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Whole Hog Ware Support 1.x allows remote attackers to bypass authentication and obtain administrative access via an integer value in the adminid cookie.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/33577" source="BID">33577</ref>
      <ref url="http://secunia.com/advisories/33777" source="SECUNIA" adv="1">33777</ref>
      <ref url="http://osvdb.org/51734" source="OSVDB">51734</ref>
      <ref url="http://milw0rm.com/exploits/7951" source="MILW0RM">7951</ref>
    </refs>
    <vuln_soft>
      <prod vendor="wholehogsoftware" name="ware_support">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0461" published="2009-02-10" name="CVE-2009-0461" modified="2009-03-06" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Whole Hog Password Protect: Enhanced 1.x allows remote attackers to bypass authentication and obtain administrative access via an integer value in the adminid cookie.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/33577" source="BID">33577</ref>
      <ref url="http://secunia.com/advisories/33777" source="SECUNIA" adv="1">33777</ref>
      <ref url="http://osvdb.org/51734" source="OSVDB">51734</ref>
      <ref url="http://milw0rm.com/exploits/7952" source="MILW0RM">7952</ref>
    </refs>
    <vuln_soft>
      <prod vendor="wholehogsoftware" name="password_protect">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0462" published="2009-02-10" name="CVE-2009-0462" modified="2009-03-06" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in customer_login_check.asp in ClickTech ClickCart 6.0 allow remote attackers to execute arbitrary SQL commands via (1) the txtEmail parameter (aka E-MAIL field) or (2) the txtPassword parameter (aka password field) to customer_login.asp. NOTE: some of these details are obtained from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/33575" source="BID">33575</ref>
      <ref url="http://www.milw0rm.com/exploits/7953" source="MILW0RM">7953</ref>
      <ref url="http://secunia.com/advisories/33774" source="SECUNIA" adv="1">33774</ref>
      <ref url="http://osvdb.org/51718" source="OSVDB">51718</ref>
    </refs>
    <vuln_soft>
      <prod vendor="clicktech" name="clickcart">
        <vers num="6.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0463" published="2009-02-10" name="CVE-2009-0463" modified="2009-03-16" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in includes/header.php in Groone GLinks 2.1 allows remote attackers to execute arbitrary PHP code via a URL in the abspath parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/33578" source="BID">33578</ref>
      <ref url="http://www.milw0rm.com/exploits/7954" source="MILW0RM">7954</ref>
      <ref url="http://secunia.com/advisories/33649" source="SECUNIA" adv="1">33649</ref>
    </refs>
    <vuln_soft>
      <prod vendor="groonesworld" name="glinks">
        <vers num="2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0464" published="2009-02-10" name="CVE-2009-0464" modified="2009-03-06" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in includes/header.php in Groone GBook 2.0 allows remote attackers to execute arbitrary PHP code via a URL in the abspath parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/33578" source="BID">33578</ref>
      <ref url="http://www.milw0rm.com/exploits/7955" source="MILW0RM">7955</ref>
      <ref url="http://secunia.com/advisories/33768" source="SECUNIA" adv="1">33768</ref>
      <ref url="http://osvdb.org/51716" source="OSVDB">51716</ref>
    </refs>
    <vuln_soft>
      <prod vendor="groonesworld" name="gbook">
        <vers num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0465" published="2009-02-10" name="CVE-2009-0465" modified="2009-03-06" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">The SaveDoc method in the All_In_The_Box.AllBox ActiveX control in ALL_IN_THE_BOX.OCX in Synactis ALL In-The-Box ActiveX 3 allows remote attackers to create and overwrite arbitrary files via an argument ending in a '\0' character, which bypasses the intended .box filename extension, as demonstrated by a C:\boot.ini\0 argument.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2009/0298" source="VUPEN">ADV-2009-0298</ref>
      <ref url="http://www.securityfocus.com/bid/33535" source="BID">33535</ref>
      <ref url="http://www.milw0rm.com/exploits/7928" source="MILW0RM">7928</ref>
      <ref url="http://www.dsecrg.com/pages/vul/show.php?id=62" source="MISC">http://www.dsecrg.com/pages/vul/show.php?id=62</ref>
      <ref url="http://secunia.com/advisories/33728" source="SECUNIA" adv="1">33728</ref>
      <ref url="http://osvdb.org/51693" source="OSVDB">51693</ref>
    </refs>
    <vuln_soft>
      <prod vendor="synactis" name="all_in_the_box.ocx">
        <vers num="3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0466" published="2009-02-10" name="CVE-2009-0466" modified="2009-03-06" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Vivvo CMS before 4.1.1 allows remote attackers to inject arbitrary web script or HTML via a URI that triggers a 404 Page Not Found response.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vivvo.net/changelog.php" source="CONFIRM">http://www.vivvo.net/changelog.php</ref>
      <ref url="http://www.securityfocus.com/bid/33582" source="BID">33582</ref>
      <ref url="http://secunia.com/advisories/33368" source="SECUNIA" adv="1">33368</ref>
    </refs>
    <vuln_soft>
      <prod vendor="vivvo" name="vivvo">
        <vers num="4.0.1" />
        <vers num="4.0.2" />
        <vers num="4.0.3" />
        <vers num="4.0.4" />
        <vers prev="1" num="4.1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0467" published="2009-02-10" name="CVE-2009-0467" modified="2009-02-12" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in proxy.html in Profense Web Application Firewall 2.6.2 and 2.6.3 allows remote attackers to inject arbitrary web script or HTML via the proxy parameter in a deny_log manage action.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/33523" source="BID">33523</ref>
      <ref url="http://www.milw0rm.com/exploits/7919" source="MILW0RM">7919</ref>
      <ref url="http://secunia.com/advisories/33739" source="SECUNIA" adv="1">33739</ref>
      <ref url="http://osvdb.org/51659" source="OSVDB">51659</ref>
    </refs>
    <vuln_soft>
      <prod vendor="armorlogic" name="profense_web_application_firewall">
        <vers num="2.6.2" />
        <vers num="2.6.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0468" published="2009-02-10" name="CVE-2009-0468" modified="2009-04-02" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple cross-site request forgery (CSRF) vulnerabilities in ajax.html in Profense Web Application Firewall 2.6.2 and 2.6.3 allow remote attackers to hijack the authentication of administrators for requests that (1) shutdown the server, (2) send ping packets, (3) enable network services, (4) configure a proxy server, and (5) modify other settings via parameters in the query string.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/33523" source="BID">33523</ref>
      <ref url="http://www.milw0rm.com/exploits/7919" source="MILW0RM">7919</ref>
      <ref url="http://secunia.com/advisories/33739" source="SECUNIA" adv="1">33739</ref>
      <ref url="http://osvdb.org/51660" source="OSVDB">51660</ref>
    </refs>
    <vuln_soft>
      <prod vendor="armorlogic" name="profense_web_application_firewall">
        <vers num="2.6.2" />
        <vers num="2.6.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0469" published="2009-02-10" name="CVE-2009-0469" modified="2009-03-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Unspecified vulnerability in futomi's CGI Cafe Fulltext search CGI 1.1.2 allows remote attackers to gain administrative privileges via unknown vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/33409" source="BID">33409</ref>
      <ref url="http://www.futomi.com/library/info/2009/20090123.html" source="CONFIRM">http://www.futomi.com/library/info/2009/20090123.html</ref>
      <ref url="http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-000008.html" source="JVNDB">JVNDB-2009-000008</ref>
      <ref url="http://jvn.jp/en/jp/JVN80771386/index.html" source="JVN">JVN#80771386</ref>
    </refs>
    <vuln_soft>
      <prod vendor="futomis_cgi_cafe" name="fulltext_search_cgi">
        <vers num="1.1.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0470" published="2009-02-06" name="CVE-2009-0470" modified="2009-02-12" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in the HTTP server in Cisco IOS 12.4(23) allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to the default URI under (1) level/15/exec/-/ or (2) exec/, a different vulnerability than CVE-2008-3821.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/33625" source="BID">33625</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/500674/100/0/threaded" source="BUGTRAQ">20090204 Cisco IOS XSS/CSRF Vulnerability</ref>
      <ref url="http://secunia.com/advisories/33844" source="SECUNIA">33844</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="ios">
        <vers num="12.4(23)" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0471" published="2009-02-06" name="CVE-2009-0471" modified="2009-02-12" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site request forgery (CSRF) vulnerability in the HTTP server in Cisco IOS 12.4(23) allows remote attackers to execute arbitrary commands, as demonstrated by executing the hostname command with a level/15/configure/-/hostname request.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/500674/100/0/threaded" source="BUGTRAQ">20090204 Cisco IOS XSS/CSRF Vulnerability</ref>
      <ref url="http://secunia.com/advisories/33844" source="SECUNIA">33844</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="ios">
        <vers num="12.4(23)" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0472" published="2009-02-06" name="CVE-2009-0472" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in the web interface in the Rockwell Automation ControlLogix 1756-ENBT/A EtherNet/IP Bridge Module allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/882619" source="CERT-VN">VU#882619</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0347" source="VUPEN">ADV-2009-0347</ref>
      <ref url="http://www.securityfocus.com/bid/33638" source="BID">33638</ref>
      <ref url="http://secunia.com/advisories/33783" source="SECUNIA">33783</ref>
      <ref url="http://rockwellautomation.custhelp.com/cgi-bin/rockwellautomation.cfg/php/enduser/std_adp.php?p_faqid=57729" source="CONFIRM" adv="1">http://rockwellautomation.custhelp.com/cgi-bin/rockwellautomation.cfg/php/enduser/std_adp.php?p_faqid=57729</ref>
    </refs>
    <vuln_soft>
      <prod vendor="rockwellautomation" name="controllogix_1756-enbt/a_ethernet/_ip_bridge">
        <vers num="-" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0473" published="2009-02-06" name="CVE-2009-0473" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Open redirect vulnerability in the web interface in the Rockwell Automation ControlLogix 1756-ENBT/A EtherNet/IP Bridge Module allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/619499" source="CERT-VN">VU#619499</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0347" source="VUPEN">ADV-2009-0347</ref>
      <ref url="http://www.securityfocus.com/bid/33636" source="BID">33636</ref>
      <ref url="http://secunia.com/advisories/33783" source="SECUNIA">33783</ref>
      <ref url="http://rockwellautomation.custhelp.com/cgi-bin/rockwellautomation.cfg/php/enduser/std_adp.php?p_faqid=57729" source="CONFIRM" adv="1">http://rockwellautomation.custhelp.com/cgi-bin/rockwellautomation.cfg/php/enduser/std_adp.php?p_faqid=57729</ref>
    </refs>
    <vuln_soft>
      <prod vendor="rockwellautomation" name="controllogix_1756-enbt/a_ethernet/_ip_bridge">
        <vers num="-" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0474" published="2009-02-06" name="CVE-2009-0474" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The web interface in the Rockwell Automation ControlLogix 1756-ENBT/A EtherNet/IP Bridge Module allows remote attackers to obtain "internal web page information" and "internal information about the module" via unspecified vectors.  NOTE: this may overlap CVE-2002-1603.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/124059" source="CERT-VN">VU#124059</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0347" source="VUPEN">ADV-2009-0347</ref>
      <ref url="http://www.kb.cert.org/vuls/id/RGII-7MWKZ3" source="CONFIRM">http://www.kb.cert.org/vuls/id/RGII-7MWKZ3</ref>
      <ref url="http://secunia.com/advisories/33783" source="SECUNIA">33783</ref>
      <ref url="http://rockwellautomation.custhelp.com/cgi-bin/rockwellautomation.cfg/php/enduser/std_adp.php?p_faqid=57729" source="CONFIRM" adv="1">http://rockwellautomation.custhelp.com/cgi-bin/rockwellautomation.cfg/php/enduser/std_adp.php?p_faqid=57729</ref>
    </refs>
    <vuln_soft>
      <prod vendor="rockwellautomation" name="controllogix_1756-enbt/a_ethernet/_ip_bridge">
        <vers num="-" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0475" published="2009-02-10" name="CVE-2009-0475" modified="2009-03-11" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Integer underflow in the Huffman decoding functionality (pvmp3_huffman_parsing.cpp) in OpenCORE 2.0 and earlier allows remote attackers to cause a denial of service (process crash) and possibly execute arbitrary code via a crafted MP3 file that triggers heap corruption.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/33673" source="BID">33673</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/500750/100/0/threaded" source="BUGTRAQ">20090207 [oCERT-2009-002] OpenCORE insufficient bounds checking during MP3 decoding</ref>
      <ref url="http://www.ocert.org/advisories/ocert-2009-002.html" source="MISC">http://www.ocert.org/advisories/ocert-2009-002.html</ref>
      <ref url="http://review.source.android.com/Gerrit#change,8815" source="CONFIRM">http://review.source.android.com/Gerrit#change,8815</ref>
      <ref url="http://android.git.kernel.org/?p=platform/external/opencore.git;a=commit;h=7b466cd0ecfdba72c4cbd0f3a8c2001141376b0f" source="CONFIRM" adv="1">http://android.git.kernel.org/?p=platform/external/opencore.git;a=commit;h=7b466cd0ecfdba72c4cbd0f3a8c2001141376b0f</ref>
    </refs>
    <vuln_soft>
      <prod vendor="android" name="opencore">
        <vers num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0476" published="2009-02-08" name="CVE-2009-0476" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Stack-based buffer overflow in MultiMedia Soft AdjMmsEng.dll 7.11.1.0 and 7.11.2.7, as distributed in multiple MultiMedia Soft audio components for .NET, allows remote attackers to execute arbitrary code via a long string in a playlist (.pls) file, as originally reported for Euphonics Audio Player 1.0.  NOTE: some of these details are obtained from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2009/0316" source="VUPEN">ADV-2009-0316</ref>
      <ref url="http://www.securityfocus.com/bid/33589" source="BID">33589</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/500652/100/0/threaded" source="BUGTRAQ">20090203 Euphonics Audio Player v1.0 (.pls) Local BOF POC</ref>
      <ref url="http://www.milw0rm.com/exploits/7974" source="MILW0RM">7974</ref>
      <ref url="http://www.milw0rm.com/exploits/7973" source="MILW0RM">7973</ref>
      <ref url="http://www.milw0rm.com/exploits/7958" source="MILW0RM">7958</ref>
      <ref url="http://secunia.com/advisories/33817" source="SECUNIA" adv="1">33817</ref>
      <ref url="http://secunia.com/advisories/33791" source="SECUNIA" adv="1">33791</ref>
    </refs>
    <vuln_soft>
      <prod vendor="multimediasoft" name="audio_dj_studio_for_.net">
        <vers num="-" />
      </prod>
      <prod vendor="multimediasoft" name="audio_sound_editer_for_.net">
        <vers num="-" />
      </prod>
      <prod vendor="multimediasoft" name="audio_sound_recorder_for_.net">
        <vers num="-" />
      </prod>
      <prod vendor="multimediasoft" name="audio_sound_studio_for_.net">
        <vers num="-" />
      </prod>
      <prod vendor="multimediasoft" name="audio_sound_suite_for_.net">
        <vers num="-" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0477" published="2009-02-08" name="CVE-2009-0477" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Unspecified vulnerability in the process (aka proc) filesystem in Sun OpenSolaris snv_85 through snv_100 allows local users to gain privileges via vectors related to the contract filesystem.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2009/0352" source="VUPEN">ADV-2009-0352</ref>
      <ref url="http://www.securityfocus.com/bid/33654" source="BID">33654</ref>
      <ref url="http://www.ioactive.com/pdfs/OpenSolarisUPtrDeref.pdf" source="MISC">http://www.ioactive.com/pdfs/OpenSolarisUPtrDeref.pdf</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-244026-1" source="SUNALERT" adv="1">244026</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="opensolaris">
        <vers num="snv_100" edition="" />
        <vers num="snv_100" edition=":x86" />
        <vers num="snv_100" edition=":sparc" />
        <vers num="snv_85" edition="" />
        <vers num="snv_85" edition=":sparc" />
        <vers num="snv_85" edition=":x86" />
        <vers num="snv_86" edition="" />
        <vers num="snv_86" edition=":sparc" />
        <vers num="snv_86" edition=":x86" />
        <vers num="snv_87" edition="" />
        <vers num="snv_87" edition=":sparc" />
        <vers num="snv_87" edition=":x86" />
        <vers num="snv_88" edition="" />
        <vers num="snv_88" edition=":x86" />
        <vers num="snv_88" edition=":sparc" />
        <vers num="snv_89" edition="" />
        <vers num="snv_89" edition=":x86" />
        <vers num="snv_89" edition=":sparc" />
        <vers num="snv_90" edition="" />
        <vers num="snv_90" edition=":x86" />
        <vers num="snv_90" edition=":sparc" />
        <vers num="snv_91" edition="" />
        <vers num="snv_91" edition=":x86" />
        <vers num="snv_91" edition=":sparc" />
        <vers num="snv_92" edition="" />
        <vers num="snv_92" edition=":sparc" />
        <vers num="snv_92" edition=":x86" />
        <vers num="snv_93" edition="" />
        <vers num="snv_93" edition=":x86" />
        <vers num="snv_93" edition=":sparc" />
        <vers num="snv_94" edition="" />
        <vers num="snv_94" edition=":x86" />
        <vers num="snv_94" edition=":sparc" />
        <vers num="snv_95" edition="" />
        <vers num="snv_95" edition=":x86" />
        <vers num="snv_95" edition=":sparc" />
        <vers num="snv_96" edition="" />
        <vers num="snv_96" edition=":sparc" />
        <vers num="snv_96" edition=":x86" />
        <vers num="snv_97" edition="" />
        <vers num="snv_97" edition=":x86" />
        <vers num="snv_97" edition=":sparc" />
        <vers num="snv_98" edition="" />
        <vers num="snv_98" edition=":x86" />
        <vers num="snv_98" edition=":sparc" />
        <vers num="snv_99" edition="" />
        <vers num="snv_99" edition=":sparc" />
        <vers num="snv_99" edition=":x86" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0478" published="2009-02-08" name="CVE-2009-0478" modified="2009-08-18" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Squid 2.7 to 2.7.STABLE5, 3.0 to 3.0.STABLE12, and 3.1 to 3.1.0.4 allows remote attackers to cause a denial of service via an HTTP request with an invalid version number, which triggers a reachable assertion in (1) HttpMsg.c and (2) HttpStatusLine.c.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/33604" source="BID" patch="1">33604</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=484246" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=484246</ref>
      <ref url="http://www.squid-cache.org/Versions/v2/2.7/changesets/12432.patch" source="CONFIRM" adv="1">http://www.squid-cache.org/Versions/v2/2.7/changesets/12432.patch</ref>
      <ref url="http://www.squid-cache.org/Advisories/SQUID-2009_1.txt" source="CONFIRM" adv="1">http://www.squid-cache.org/Advisories/SQUID-2009_1.txt</ref>
      <ref url="http://www.securitytracker.com/id?1021684" source="SECTRACK">1021684</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/500653/100/0/threaded" source="BUGTRAQ">20090204 Squid Proxy Cache Denial of Service in request handling</ref>
      <ref url="http://www.milw0rm.com/exploits/8021" source="MILW0RM">8021</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:034" source="MANDRIVA">MDVSA-2009:034</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200903-38.xml" source="GENTOO">GLSA-200903-38</ref>
      <ref url="http://secunia.com/advisories/34467" source="SECUNIA" adv="1">34467</ref>
      <ref url="http://secunia.com/advisories/33731" source="SECUNIA" adv="1">33731</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-03/msg00000.html" source="SUSE">SUSE-SR:2009:005</ref>
    </refs>
    <vuln_soft>
      <prod vendor="squid" name="squid">
        <vers num="2.7.stable1" />
        <vers num="2.7.stable2" />
        <vers num="2.7.stable3" />
        <vers num="2.7.stable4" />
        <vers num="2.7.stable5" />
        <vers num="3.0.stable1" />
        <vers num="3.0.stable10" />
        <vers num="3.0.stable11" />
        <vers num="3.0.stable12" />
        <vers num="3.0.stable2" />
        <vers num="3.0.stable3" />
        <vers num="3.0.stable4" />
        <vers num="3.0.stable5" />
        <vers num="3.0.stable6" />
        <vers num="3.0.stable7" />
        <vers num="3.0.stable8" />
        <vers num="3.0.stable9" />
        <vers num="3.1" />
        <vers num="3.1.0.1" />
        <vers num="3.1.0.2" />
        <vers num="3.1.0.3" />
        <vers num="3.1.0.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0479" published="2009-02-08" name="CVE-2009-0479" modified="2009-02-09" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in admin/admin_login.php in Online Grades 3.2.4 allow remote attackers to execute arbitrary SQL commands via the (1) uname or (2) pword parameter.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/33767" source="SECUNIA" adv="1">33767</ref>
      <ref url="http://osvdb.org/51711" source="OSVDB">51711</ref>
    </refs>
    <vuln_soft>
      <prod vendor="onlinegrades" name="online_grades">
        <vers num="3.2.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0480" published="2009-02-09" name="CVE-2009-0480" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="4.9" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="3.9" CVSS_base_score="4.9">
    <desc>
      <descript source="cve">The IP implementation in Sun Solaris 8 through 10, and OpenSolaris before snv_82, uses an improper arena when allocating minor numbers for sockets, which allows local users to cause a denial of service (32-bit application failure and login outage) by opening a large number of sockets.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-248026-1" source="SUNALERT" patch="1" adv="1">248026</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-21-116965-34-1" source="CONFIRM" patch="1">http://sunsolve.sun.com/search/document.do?assetkey=1-21-116965-34-1</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0364" source="VUPEN">ADV-2009-0364</ref>
      <ref url="http://www.securityfocus.com/bid/33550" source="BID">33550</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2009-042.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2009-042.htm</ref>
      <ref url="http://securitytracker.com/id?1021653" source="SECTRACK">1021653</ref>
      <ref url="http://secunia.com/advisories/33751" source="SECUNIA" adv="1">33751</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6038" source="OVAL">oval:org.mitre.oval:def:6038</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="opensolaris">
        <vers num="snv_01" edition="" />
        <vers num="snv_01" edition=":sparc" />
        <vers num="snv_01" edition=":x86" />
        <vers num="snv_02" edition="" />
        <vers num="snv_02" edition=":sparc" />
        <vers num="snv_02" edition=":x86" />
        <vers num="snv_03" edition="" />
        <vers num="snv_03" edition=":x86" />
        <vers num="snv_03" edition=":sparc" />
        <vers num="snv_04" edition="" />
        <vers num="snv_04" edition=":x86" />
        <vers num="snv_04" edition=":sparc" />
        <vers num="snv_05" edition="" />
        <vers num="snv_05" edition=":sparc" />
        <vers num="snv_05" edition=":x86" />
        <vers num="snv_06" edition="" />
        <vers num="snv_06" edition=":sparc" />
        <vers num="snv_06" edition=":x86" />
        <vers num="snv_07" edition="" />
        <vers num="snv_07" edition=":sparc" />
        <vers num="snv_07" edition=":x86" />
        <vers num="snv_08" edition="" />
        <vers num="snv_08" edition=":x86" />
        <vers num="snv_08" edition=":sparc" />
        <vers num="snv_09" edition="" />
        <vers num="snv_09" edition=":sparc" />
        <vers num="snv_09" edition=":x86" />
        <vers num="snv_10" edition="" />
        <vers num="snv_10" edition=":x86" />
        <vers num="snv_10" edition=":sparc" />
        <vers num="snv_11" edition="" />
        <vers num="snv_11" edition=":x86" />
        <vers num="snv_11" edition=":sparc" />
        <vers num="snv_12" edition="" />
        <vers num="snv_12" edition=":x86" />
        <vers num="snv_12" edition=":sparc" />
        <vers num="snv_13" edition="" />
        <vers num="snv_13" edition=":x86" />
        <vers num="snv_13" edition=":sparc" />
        <vers num="snv_14" edition="" />
        <vers num="snv_14" edition=":x86" />
        <vers num="snv_14" edition=":sparc" />
        <vers num="snv_15" edition="" />
        <vers num="snv_15" edition=":x86" />
        <vers num="snv_15" edition=":sparc" />
        <vers num="snv_16" edition="" />
        <vers num="snv_16" edition=":sparc" />
        <vers num="snv_16" edition=":x86" />
        <vers num="snv_17" edition="" />
        <vers num="snv_17" edition=":x86" />
        <vers num="snv_17" edition=":sparc" />
        <vers num="snv_18" edition="" />
        <vers num="snv_18" edition=":x86" />
        <vers num="snv_18" edition=":sparc" />
        <vers num="snv_19" edition="" />
        <vers num="snv_19" edition=":sparc" />
        <vers num="snv_19" edition=":x86" />
        <vers num="snv_20" edition="" />
        <vers num="snv_20" edition=":x86" />
        <vers num="snv_20" edition=":sparc" />
        <vers num="snv_21" edition="" />
        <vers num="snv_21" edition=":x86" />
        <vers num="snv_21" edition=":sparc" />
        <vers num="snv_22" edition="" />
        <vers num="snv_22" edition=":sparc" />
        <vers num="snv_22" edition=":x86" />
        <vers num="snv_23" edition="" />
        <vers num="snv_23" edition=":sparc" />
        <vers num="snv_23" edition=":x86" />
        <vers num="snv_24" edition="" />
        <vers num="snv_24" edition=":sparc" />
        <vers num="snv_24" edition=":x86" />
        <vers num="snv_25" edition="" />
        <vers num="snv_25" edition=":sparc" />
        <vers num="snv_25" edition=":x86" />
        <vers num="snv_26" edition="" />
        <vers num="snv_26" edition=":sparc" />
        <vers num="snv_26" edition=":x86" />
        <vers num="snv_27" edition="" />
        <vers num="snv_27" edition=":sparc" />
        <vers num="snv_27" edition=":x86" />
        <vers num="snv_28" edition="" />
        <vers num="snv_28" edition=":sparc" />
        <vers num="snv_28" edition=":x86" />
        <vers num="snv_29" edition="" />
        <vers num="snv_29" edition=":x86" />
        <vers num="snv_29" edition=":sparc" />
        <vers num="snv_30" edition="" />
        <vers num="snv_30" edition=":sparc" />
        <vers num="snv_30" edition=":x86" />
        <vers num="snv_31" edition="" />
        <vers num="snv_31" edition=":sparc" />
        <vers num="snv_31" edition=":x86" />
        <vers num="snv_32" edition="" />
        <vers num="snv_32" edition=":x86" />
        <vers num="snv_32" edition=":sparc" />
        <vers num="snv_33" edition="" />
        <vers num="snv_33" edition=":x86" />
        <vers num="snv_33" edition=":sparc" />
        <vers num="snv_34" edition="" />
        <vers num="snv_34" edition=":sparc" />
        <vers num="snv_34" edition=":x86" />
        <vers num="snv_35" edition="" />
        <vers num="snv_35" edition=":sparc" />
        <vers num="snv_35" edition=":x86" />
        <vers num="snv_36" edition="" />
        <vers num="snv_36" edition=":sparc" />
        <vers num="snv_36" edition=":x86" />
        <vers num="snv_37" edition="" />
        <vers num="snv_37" edition=":sparc" />
        <vers num="snv_37" edition=":x86" />
        <vers num="snv_38" edition="" />
        <vers num="snv_38" edition=":sparc" />
        <vers num="snv_38" edition=":x86" />
        <vers num="snv_39" edition="" />
        <vers num="snv_39" edition=":sparc" />
        <vers num="snv_39" edition=":x86" />
        <vers num="snv_40" edition="" />
        <vers num="snv_40" edition=":x86" />
        <vers num="snv_40" edition=":sparc" />
        <vers num="snv_41" edition="" />
        <vers num="snv_41" edition=":sparc" />
        <vers num="snv_41" edition=":x86" />
        <vers num="snv_42" edition="" />
        <vers num="snv_42" edition=":x86" />
        <vers num="snv_42" edition=":sparc" />
        <vers num="snv_43" edition="" />
        <vers num="snv_43" edition=":sparc" />
        <vers num="snv_43" edition=":x86" />
        <vers num="snv_44" edition="" />
        <vers num="snv_44" edition=":x86" />
        <vers num="snv_44" edition=":sparc" />
        <vers num="snv_45" edition="" />
        <vers num="snv_45" edition=":x86" />
        <vers num="snv_45" edition=":sparc" />
        <vers num="snv_46" edition="" />
        <vers num="snv_46" edition=":sparc" />
        <vers num="snv_46" edition=":x86" />
        <vers num="snv_47" edition="" />
        <vers num="snv_47" edition=":x86" />
        <vers num="snv_47" edition=":sparc" />
        <vers num="snv_48" edition="" />
        <vers num="snv_48" edition=":sparc" />
        <vers num="snv_48" edition=":x86" />
        <vers num="snv_49" edition="" />
        <vers num="snv_49" edition=":sparc" />
        <vers num="snv_49" edition=":x86" />
        <vers num="snv_50" edition="" />
        <vers num="snv_50" edition=":sparc" />
        <vers num="snv_50" edition=":x86" />
        <vers num="snv_51" edition="" />
        <vers num="snv_51" edition=":x86" />
        <vers num="snv_51" edition=":sparc" />
        <vers num="snv_52" edition="" />
        <vers num="snv_52" edition=":x86" />
        <vers num="snv_52" edition=":sparc" />
        <vers num="snv_53" edition="" />
        <vers num="snv_53" edition=":sparc" />
        <vers num="snv_53" edition=":x86" />
        <vers num="snv_54" edition="" />
        <vers num="snv_54" edition=":sparc" />
        <vers num="snv_54" edition=":x86" />
        <vers num="snv_55" edition="" />
        <vers num="snv_55" edition=":sparc" />
        <vers num="snv_55" edition=":x86" />
        <vers num="snv_56" edition="" />
        <vers num="snv_56" edition=":x86" />
        <vers num="snv_56" edition=":sparc" />
        <vers num="snv_57" edition="" />
        <vers num="snv_57" edition=":x86" />
        <vers num="snv_57" edition=":sparc" />
        <vers num="snv_58" edition="" />
        <vers num="snv_58" edition=":sparc" />
        <vers num="snv_58" edition=":x86" />
        <vers num="snv_59" edition="" />
        <vers num="snv_59" edition=":sparc" />
        <vers num="snv_59" edition=":x86" />
        <vers num="snv_60" edition="" />
        <vers num="snv_60" edition=":x86" />
        <vers num="snv_60" edition=":sparc" />
        <vers num="snv_61" edition="" />
        <vers num="snv_61" edition=":sparc" />
        <vers num="snv_61" edition=":x86" />
        <vers num="snv_62" edition="" />
        <vers num="snv_62" edition=":x86" />
        <vers num="snv_62" edition=":sparc" />
        <vers num="snv_63" edition="" />
        <vers num="snv_63" edition=":x86" />
        <vers num="snv_63" edition=":sparc" />
        <vers num="snv_64" edition="" />
        <vers num="snv_64" edition=":x86" />
        <vers num="snv_64" edition=":sparc" />
        <vers num="snv_65" edition="" />
        <vers num="snv_65" edition=":sparc" />
        <vers num="snv_65" edition=":x86" />
        <vers num="snv_66" edition="" />
        <vers num="snv_66" edition=":x86" />
        <vers num="snv_66" edition=":sparc" />
        <vers num="snv_67" edition="" />
        <vers num="snv_67" edition=":sparc" />
        <vers num="snv_67" edition=":x86" />
        <vers num="snv_68" edition="" />
        <vers num="snv_68" edition=":x86" />
        <vers num="snv_68" edition=":sparc" />
        <vers num="snv_69" edition="" />
        <vers num="snv_69" edition=":sparc" />
        <vers num="snv_69" edition=":x86" />
        <vers num="snv_70" edition="" />
        <vers num="snv_70" edition=":sparc" />
        <vers num="snv_70" edition=":x86" />
        <vers num="snv_71" edition="" />
        <vers num="snv_71" edition=":sparc" />
        <vers num="snv_71" edition=":x86" />
        <vers num="snv_72" edition="" />
        <vers num="snv_72" edition=":x86" />
        <vers num="snv_72" edition=":sparc" />
        <vers num="snv_73" edition="" />
        <vers num="snv_73" edition=":x86" />
        <vers num="snv_73" edition=":sparc" />
        <vers num="snv_74" edition="" />
        <vers num="snv_74" edition=":x86" />
        <vers num="snv_74" edition=":sparc" />
        <vers num="snv_75" edition="" />
        <vers num="snv_75" edition=":x86" />
        <vers num="snv_75" edition=":sparc" />
        <vers num="snv_76" edition="" />
        <vers num="snv_76" edition=":sparc" />
        <vers num="snv_76" edition=":x86" />
        <vers num="snv_77" edition="" />
        <vers num="snv_77" edition=":sparc" />
        <vers num="snv_77" edition=":x86" />
        <vers num="snv_78" edition="" />
        <vers num="snv_78" edition=":sparc" />
        <vers num="snv_78" edition=":x86" />
        <vers num="snv_79" edition="" />
        <vers num="snv_79" edition=":x86" />
        <vers num="snv_79" edition=":sparc" />
        <vers num="snv_80" edition="" />
        <vers num="snv_80" edition=":x86" />
        <vers num="snv_80" edition=":sparc" />
        <vers prev="1" num="snv_81" edition="" />
        <vers prev="1" num="snv_81" edition=":x86" />
        <vers prev="1" num="snv_81" edition=":sparc" />
      </prod>
      <prod vendor="sun" name="solaris">
        <vers num="10" edition="" />
        <vers num="10" edition=":sparc" />
        <vers num="10" edition=":x86" />
        <vers num="8" edition="" />
        <vers num="8" edition=":sparc" />
        <vers num="8" edition=":x86" />
        <vers num="9" edition="" />
        <vers num="9" edition=":sparc" />
        <vers num="9" edition=":x86" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2009-0481" published="2009-02-09" name="CVE-2009-0481" modified="2009-03-25" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:S/C:N/I:P/A:N)" CVSS_score="3.5" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="6.8" CVSS_base_score="3.5">
    <desc>
      <descript source="cve">Bugzilla 2.x before 2.22.7, 3.0 before 3.0.7, 3.2 before 3.2.1, and 3.3 before 3.3.2 allows remote authenticated users to conduct cross-site scripting (XSS) and related attacks by uploading HTML and JavaScript attachments that are rendered by web browsers.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-March/msg00687.html" source="FEDORA">FEDORA-2009-2417</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-March/msg00664.html" source="FEDORA">FEDORA-2009-2418</ref>
      <ref url="http://www.securityfocus.com/bid/33580" source="BID">33580</ref>
      <ref url="http://www.bugzilla.org/security/2.22.6/" source="CONFIRM">http://www.bugzilla.org/security/2.22.6/</ref>
      <ref url="http://secunia.com/advisories/34361" source="SECUNIA">34361</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="bugzilla">
        <vers num="2.10" />
        <vers num="2.12" />
        <vers num="2.14" />
        <vers num="2.14.1" />
        <vers num="2.14.2" />
        <vers num="2.14.3" />
        <vers num="2.14.4" />
        <vers num="2.14.5" />
        <vers num="2.16" edition="rc1" />
        <vers num="2.16.1" />
        <vers num="2.16.10" />
        <vers num="2.16.11" />
        <vers num="2.16.2" />
        <vers num="2.16.3" />
        <vers num="2.16.4" />
        <vers num="2.16.5" />
        <vers num="2.16.6" />
        <vers num="2.16.7" />
        <vers num="2.16.8" />
        <vers num="2.16.9" />
        <vers num="2.16_rc2" />
        <vers num="2.17" />
        <vers num="2.17.1" />
        <vers num="2.17.2" />
        <vers num="2.17.3" />
        <vers num="2.17.4" />
        <vers num="2.17.5" />
        <vers num="2.17.6" />
        <vers num="2.17.7" />
        <vers num="2.18" edition="rc1" />
        <vers num="2.18" edition="rc2" />
        <vers num="2.18" edition="rc3" />
        <vers num="2.18.1" />
        <vers num="2.18.2" />
        <vers num="2.18.3" />
        <vers num="2.18.4" />
        <vers num="2.18.5" />
        <vers num="2.18.6" />
        <vers num="2.18.7" />
        <vers num="2.18.8" />
        <vers num="2.18.9" />
        <vers num="2.19" />
        <vers num="2.19.1" />
        <vers num="2.19.2" />
        <vers num="2.19.3" />
        <vers num="2.20" edition="rc1" />
        <vers num="2.20" edition="rc2" />
        <vers num="2.20.1" />
        <vers num="2.20.2" />
        <vers num="2.20.3" />
        <vers num="2.20.4" />
        <vers num="2.20.5" />
        <vers num="2.20.6" />
        <vers num="2.21" />
        <vers num="2.21.1" />
        <vers num="2.21.2" />
        <vers num="2.22" edition="rc1" />
        <vers num="2.22.1" />
        <vers num="2.22.2" />
        <vers num="2.22.3" />
        <vers num="2.22.4" />
        <vers num="2.22.5" />
        <vers num="2.22.6" />
        <vers num="3.0.0" />
        <vers num="3.0.1" />
        <vers num="3.0.2" />
        <vers num="3.0.3" />
        <vers num="3.0.4" />
        <vers num="3.0.5" />
        <vers num="3.0.6" />
        <vers num="3.2" />
        <vers num="3.3.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0482" published="2009-02-09" name="CVE-2009-0482" modified="2009-03-25" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:P)" CVSS_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_base_score="5.8">
    <desc>
      <descript source="cve">Cross-site request forgery (CSRF) vulnerability in Bugzilla before 3.2 before 3.2.1, 3.3 before 3.3.2, and other versions before 3.2 allows remote attackers to perform bug updating activities as other users via a link or IMG tag to process_bug.cgi.</descript>
    </desc>
    <loss_types>
      <avail />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-March/msg00687.html" source="FEDORA">FEDORA-2009-2417</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-March/msg00664.html" source="FEDORA">FEDORA-2009-2418</ref>
      <ref url="http://www.securityfocus.com/bid/33580" source="BID">33580</ref>
      <ref url="http://www.bugzilla.org/security/2.22.6/" source="CONFIRM" adv="1">http://www.bugzilla.org/security/2.22.6/</ref>
      <ref url="http://secunia.com/advisories/34361" source="SECUNIA">34361</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="bugzilla">
        <vers num="2.10" />
        <vers num="2.12" />
        <vers num="2.14" />
        <vers num="2.14.1" />
        <vers num="2.14.2" />
        <vers num="2.14.3" />
        <vers num="2.14.4" />
        <vers num="2.14.5" />
        <vers num="2.16" edition="rc1" />
        <vers num="2.16.1" />
        <vers num="2.16.10" />
        <vers num="2.16.11" />
        <vers num="2.16.2" />
        <vers num="2.16.3" />
        <vers num="2.16.4" />
        <vers num="2.16.5" />
        <vers num="2.16.6" />
        <vers num="2.16.7" />
        <vers num="2.16.8" />
        <vers num="2.16.9" />
        <vers num="2.16_rc2" />
        <vers num="2.17" />
        <vers num="2.17.1" />
        <vers num="2.17.2" />
        <vers num="2.17.3" />
        <vers num="2.17.4" />
        <vers num="2.17.5" />
        <vers num="2.17.6" />
        <vers num="2.17.7" />
        <vers num="2.18" edition="rc1" />
        <vers num="2.18" edition="rc2" />
        <vers num="2.18" edition="rc3" />
        <vers num="2.18.1" />
        <vers num="2.18.2" />
        <vers num="2.18.3" />
        <vers num="2.18.4" />
        <vers num="2.18.5" />
        <vers num="2.18.6" />
        <vers num="2.18.7" />
        <vers num="2.18.8" />
        <vers num="2.18.9" />
        <vers num="2.19" />
        <vers num="2.19.1" />
        <vers num="2.19.2" />
        <vers num="2.19.3" />
        <vers num="2.20" edition="rc1" />
        <vers num="2.20" edition="rc2" />
        <vers num="2.20.1" />
        <vers num="2.20.2" />
        <vers num="2.20.3" />
        <vers num="2.20.4" />
        <vers num="2.20.5" />
        <vers num="2.20.6" />
        <vers num="2.21" />
        <vers num="2.21.1" />
        <vers num="2.21.2" />
        <vers num="2.22" edition="rc1" />
        <vers num="2.22.1" />
        <vers num="2.22.2" />
        <vers num="2.22.3" />
        <vers num="2.22.4" />
        <vers num="2.22.5" />
        <vers num="2.22.6" />
        <vers num="3.0.0" />
        <vers num="3.0.1" />
        <vers num="3.0.2" />
        <vers num="3.0.3" />
        <vers num="3.0.4" />
        <vers num="3.0.5" />
        <vers num="3.0.6" />
        <vers num="3.2" />
        <vers num="3.3.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0483" published="2009-02-09" name="CVE-2009-0483" modified="2009-03-25" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:P)" CVSS_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_base_score="5.8">
    <desc>
      <descript source="cve">Cross-site request forgery (CSRF) vulnerability in Bugzilla 2.22 before 2.22.7, 3.0 before 3.0.7, 3.2 before 3.2.1, and 3.3 before 3.3.2 allows remote attackers to delete keywords and user preferences via a link or IMG tag to (1) editkeywords.cgi or (2) userprefs.cgi.</descript>
    </desc>
    <loss_types>
      <avail />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-March/msg00687.html" source="FEDORA">FEDORA-2009-2417</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-March/msg00664.html" source="FEDORA">FEDORA-2009-2418</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=472362" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=472362</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=466692" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=466692</ref>
      <ref url="http://www.securityfocus.com/bid/33580" source="BID">33580</ref>
      <ref url="http://www.bugzilla.org/security/2.22.6/" source="CONFIRM">http://www.bugzilla.org/security/2.22.6/</ref>
      <ref url="http://secunia.com/advisories/34361" source="SECUNIA">34361</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="bugzilla">
        <vers num="2.10" />
        <vers num="2.12" />
        <vers num="2.14" />
        <vers num="2.14.1" />
        <vers num="2.14.2" />
        <vers num="2.14.3" />
        <vers num="2.14.4" />
        <vers num="2.14.5" />
        <vers num="2.16" edition="rc1" />
        <vers num="2.16.1" />
        <vers num="2.16.10" />
        <vers num="2.16.11" />
        <vers num="2.16.2" />
        <vers num="2.16.3" />
        <vers num="2.16.4" />
        <vers num="2.16.5" />
        <vers num="2.16.6" />
        <vers num="2.16.7" />
        <vers num="2.16.8" />
        <vers num="2.16.9" />
        <vers num="2.16_rc2" />
        <vers num="2.17" />
        <vers num="2.17.1" />
        <vers num="2.17.2" />
        <vers num="2.17.3" />
        <vers num="2.17.4" />
        <vers num="2.17.5" />
        <vers num="2.17.6" />
        <vers num="2.17.7" />
        <vers num="2.18" edition="rc1" />
        <vers num="2.18" edition="rc2" />
        <vers num="2.18" edition="rc3" />
        <vers num="2.18.1" />
        <vers num="2.18.2" />
        <vers num="2.18.3" />
        <vers num="2.18.4" />
        <vers num="2.18.5" />
        <vers num="2.18.6" />
        <vers num="2.18.7" />
        <vers num="2.18.8" />
        <vers num="2.18.9" />
        <vers num="2.19" />
        <vers num="2.19.1" />
        <vers num="2.19.2" />
        <vers num="2.19.3" />
        <vers num="2.20" edition="rc1" />
        <vers num="2.20" edition="rc2" />
        <vers num="2.20.1" />
        <vers num="2.20.2" />
        <vers num="2.20.3" />
        <vers num="2.20.4" />
        <vers num="2.20.5" />
        <vers num="2.20.6" />
        <vers num="2.21" />
        <vers num="2.21.1" />
        <vers num="2.21.2" />
        <vers num="2.22" edition="rc1" />
        <vers num="2.22.1" />
        <vers num="2.22.2" />
        <vers num="2.22.3" />
        <vers num="2.22.4" />
        <vers num="2.22.5" />
        <vers num="2.22.6" />
        <vers num="3.0.0" />
        <vers num="3.0.1" />
        <vers num="3.0.2" />
        <vers num="3.0.3" />
        <vers num="3.0.4" />
        <vers num="3.0.5" />
        <vers num="3.0.6" />
        <vers num="3.2" />
        <vers num="3.3.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0484" published="2009-02-09" name="CVE-2009-0484" modified="2009-03-25" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:P)" CVSS_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_base_score="5.8">
    <desc>
      <descript source="cve">Cross-site request forgery (CSRF) vulnerability in Bugzilla 3.0 before 3.0.7, 3.2 before 3.2.1, and 3.3 before 3.3.2 allows remote attackers to delete shared or saved searches via a link or IMG tag to buglist.cgi.</descript>
    </desc>
    <loss_types>
      <avail />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-March/msg00687.html" source="FEDORA">FEDORA-2009-2417</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-March/msg00664.html" source="FEDORA">FEDORA-2009-2418</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=466748" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=466748</ref>
      <ref url="http://www.securityfocus.com/bid/33580" source="BID">33580</ref>
      <ref url="http://www.bugzilla.org/security/2.22.6/" source="CONFIRM" adv="1">http://www.bugzilla.org/security/2.22.6/</ref>
      <ref url="http://secunia.com/advisories/34361" source="SECUNIA">34361</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="bugzilla">
        <vers num="3.0.0" />
        <vers num="3.0.1" />
        <vers num="3.0.2" />
        <vers num="3.0.3" />
        <vers num="3.0.4" />
        <vers num="3.0.5" />
        <vers num="3.0.6" />
        <vers num="3.2" />
        <vers num="3.3.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0485" published="2009-02-09" name="CVE-2009-0485" modified="2009-03-25" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:P)" CVSS_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_base_score="5.8">
    <desc>
      <descript source="cve">Cross-site request forgery (CSRF) vulnerability in Bugzilla 2.17 to 2.22.7, 3.0 before 3.0.7, 3.2 before 3.2.1, and 3.3 before 3.3.2 allows remote attackers to delete unused flag types via a link or IMG tag to editflagtypes.cgi.</descript>
    </desc>
    <loss_types>
      <avail />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-March/msg00687.html" source="FEDORA">FEDORA-2009-2417</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-March/msg00664.html" source="FEDORA">FEDORA-2009-2418</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=466692" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=466692</ref>
      <ref url="http://www.securityfocus.com/bid/33580" source="BID">33580</ref>
      <ref url="http://www.bugzilla.org/security/2.22.6/" source="CONFIRM" adv="1">http://www.bugzilla.org/security/2.22.6/</ref>
      <ref url="http://secunia.com/advisories/34361" source="SECUNIA">34361</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="bugzilla">
        <vers num="2.17" />
        <vers num="2.17.1" />
        <vers num="2.17.3" />
        <vers num="2.17.4" />
        <vers num="2.17.5" />
        <vers num="2.17.6" />
        <vers num="2.17.7" />
        <vers num="2.18" edition="rc1" />
        <vers num="2.18" edition="rc2" />
        <vers num="2.18" edition="rc3" />
        <vers num="2.18.1" />
        <vers num="2.18.2" />
        <vers num="2.18.3" />
        <vers num="2.18.4" />
        <vers num="2.18.5" />
        <vers num="2.18.6" />
        <vers num="2.18.6+" />
        <vers num="2.19" />
        <vers num="2.19.1" />
        <vers num="2.19.2" />
        <vers num="2.19.3" />
        <vers num="2.20" edition="rc1" />
        <vers num="2.20" edition="rc2" />
        <vers num="2.20.1" />
        <vers num="2.20.2" />
        <vers num="2.20.3" />
        <vers num="2.20.4" />
        <vers num="2.20.5" />
        <vers num="2.20.6" />
        <vers num="2.20.7" />
        <vers num="2.21" />
        <vers num="2.21.1" />
        <vers num="2.22" edition="rc1" />
        <vers num="2.22.1" />
        <vers num="2.22.2" />
        <vers num="2.22.3" />
        <vers num="2.22.4" />
        <vers num="2.22.5" />
        <vers num="2.22.6" />
        <vers num="3.0" edition="rc1" />
        <vers num="3.0.1" />
        <vers num="3.0.2" />
        <vers num="3.0.3" />
        <vers num="3.0.4" />
        <vers num="3.0.5" />
        <vers num="3.0.6" />
        <vers num="3.2" edition="rc1" />
        <vers num="3.2" edition="rc2" />
        <vers num="3.3.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0486" published="2009-02-09" name="CVE-2009-0486" modified="2009-03-25" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Bugzilla 3.2.1, 3.0.7, and 3.3.2, when running under mod_perl, calls the srand function at startup time, which causes Apache children to have the same seed and produce insufficiently random numbers for random tokens, which allows remote attackers to bypass cross-site request forgery (CSRF) protection mechanisms and conduct unauthorized activities as other users.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-March/msg00687.html" source="FEDORA">FEDORA-2009-2417</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-March/msg00664.html" source="FEDORA">FEDORA-2009-2418</ref>
      <ref url="http://www.securityfocus.com/bid/33581" source="BID">33581</ref>
      <ref url="http://www.bugzilla.org/security/3.0.7/" source="CONFIRM" adv="1">http://www.bugzilla.org/security/3.0.7/</ref>
      <ref url="http://secunia.com/advisories/34361" source="SECUNIA">34361</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="bugzilla">
        <vers num="3.0.7" />
        <vers num="3.2.1" />
        <vers num="3.3.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0487" published="2009-02-09" name="CVE-2009-0487" modified="2009-02-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Mahara before 1.0.9 allows remote attackers to inject arbitrary web script or HTML via a crafted forum post.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/48518" source="XF">mahara-unspecified-xss(48518)</ref>
      <ref url="http://www.securityfocus.com/bid/33619" source="BID">33619</ref>
      <ref url="http://secunia.com/advisories/33813" source="SECUNIA">33813</ref>
      <ref url="http://mahara.org/interaction/forum/topic.php?id=198" source="CONFIRM" adv="1">http://mahara.org/interaction/forum/topic.php?id=198</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mahara" name="mahara">
        <vers num="0.9.0" />
        <vers num="0.9.1" />
        <vers num="0.9.2" />
        <vers num="1.0.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.5" />
        <vers num="1.0.6" />
        <vers num="1.0.7" />
        <vers prev="1" num="1.0.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0488" published="2009-02-09" name="CVE-2009-0488" modified="2009-02-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Phorum before 5.2.10 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/33657" source="BID">33657</ref>
      <ref url="http://www.phorum.org/phorum5/read.php?64,136129" source="CONFIRM" adv="1">http://www.phorum.org/phorum5/read.php?64,136129</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phorum" name="phorum">
        <vers num="3.0.7" />
        <vers num="3.1" />
        <vers num="3.1.1" />
        <vers num="3.1.1_pre" />
        <vers num="3.1.1_rc2" />
        <vers num="3.1.1a" />
        <vers num="3.1.2" />
        <vers num="3.2" />
        <vers num="3.2.2" />
        <vers num="3.2.3" />
        <vers num="3.2.3a" />
        <vers num="3.2.3b" />
        <vers num="3.2.4" />
        <vers num="3.2.5" />
        <vers num="3.2.6" />
        <vers num="3.2.7" />
        <vers num="3.2.8" />
        <vers num="3.3.1" />
        <vers num="3.3.1a" />
        <vers num="3.3.2" />
        <vers num="3.3.2a" />
        <vers num="3.3.2b3" />
        <vers num="3.4" />
        <vers num="3.4.1" />
        <vers num="3.4.2" />
        <vers num="3.4.3" />
        <vers num="3.4.4" />
        <vers num="3.4.5" />
        <vers num="3.4.6" />
        <vers num="3.4.7" />
        <vers num="3.4.8" />
        <vers num="3.4.8a" />
        <vers num="4.3.7" />
        <vers num="5.0.0_alpha" />
        <vers num="5.0.10" />
        <vers num="5.0.11" />
        <vers num="5.0.12" />
        <vers num="5.0.13" />
        <vers num="5.0.13a" />
        <vers num="5.0.14" />
        <vers num="5.0.14a" />
        <vers num="5.0.15" />
        <vers num="5.0.15a" />
        <vers num="5.0.16" />
        <vers num="5.0.17" />
        <vers num="5.0.17a" />
        <vers num="5.0.18" />
        <vers num="5.0.19" />
        <vers num="5.0.1_alpha" />
        <vers num="5.0.20" />
        <vers num="5.0.2_alpha" />
        <vers num="5.0.3_beta" />
        <vers num="5.0.4_beta" />
        <vers num="5.0.4a_beta" />
        <vers num="5.0.5_beta" />
        <vers num="5.0.6_beta" />
        <vers num="5.0.7_beta" />
        <vers num="5.0.7a_beta" />
        <vers num="5.0.8_rc" />
        <vers num="5.0.9" />
        <vers num="5.1.13" />
        <vers num="5.1.14" />
        <vers num="5.1.17" />
        <vers num="5.1.18" />
        <vers num="5.1.20" />
        <vers num="5.1.21" />
        <vers num="5.1.25" />
        <vers num="5.2" />
        <vers num="5.2.1" />
        <vers prev="1" num="5.2.10" edition="rc1" />
        <vers num="5.2.2" edition="beta" />
        <vers num="5.2.3" edition="rc1" />
        <vers num="5.2.4" edition="rc2" />
        <vers num="5.2.5" />
        <vers num="5.2.8" />
        <vers num="5.2.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2009-0489" published="2009-02-09" name="CVE-2009-0489" modified="2009-04-16" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">The DBus configuration file for Wicd before 1.5.9 allows arbitrary users to own org.wicd.daemon, which allows local users to receive messages that were intended for the Wicd daemon, possibly including credentials.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.openwall.com/lists/oss-security/2009/02/06/4" source="MLIST">[oss-security] 20090206 CVE Request - Wicd &lt;= 1.5.8</ref>
      <ref url="http://sourceforge.net/project/shownotes.php?group_id=194573&amp;release_id=659059" source="CONFIRM">http://sourceforge.net/project/shownotes.php?group_id=194573&amp;release_id=659059</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200904-12.xml" source="GENTOO">GLSA-200904-12</ref>
      <ref url="http://secunia.com/advisories/34685" source="SECUNIA">34685</ref>
      <ref url="http://secunia.com/advisories/33870" source="SECUNIA">33870</ref>
      <ref url="http://bazaar.launchpad.net/~wicd-devel/wicd/trunk/revision/222" source="CONFIRM">http://bazaar.launchpad.net/~wicd-devel/wicd/trunk/revision/222</ref>
    </refs>
    <vuln_soft>
      <prod vendor="wicd" name="wicd">
        <vers num="1.2.7" />
        <vers num="1.3.1" />
        <vers num="1.4.0" />
        <vers num="1.4.1" />
        <vers num="1.4.2" />
        <vers num="1.5.0" />
        <vers num="1.5.1" />
        <vers num="1.5.2" />
        <vers num="1.5.3" />
        <vers num="1.5.4" />
        <vers num="1.5.5" />
        <vers num="1.5.6" />
        <vers num="1.5.7" />
        <vers num="1.5.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0490" published="2009-02-09" name="CVE-2009-0490" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Stack-based buffer overflow in the String_parse::get_nonspace_quoted function in lib-src/allegro/strparse.cpp in Audacity 1.2.6 and other versions before 1.3.6 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a .gro file containing a long string.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2009/0008" source="VUPEN">ADV-2009-0008</ref>
      <ref url="http://www.securityfocus.com/bid/33090" source="BID">33090</ref>
      <ref url="http://www.milw0rm.com/exploits/7634" source="MILW0RM">7634</ref>
      <ref url="http://secunia.com/advisories/33356" source="SECUNIA" adv="1">33356</ref>
      <ref url="http://osvdb.org/51070" source="OSVDB">51070</ref>
      <ref url="http://n2.nabble.com/Audacity-%22String_parse::get_nonspace_quoted%28%29%22-Buffer-Overflow-td2139537.html" source="MLIST">[audacity-devel] 20090110 Audacity "String_parse::get_nonspace_quoted()" Buffer Overflow</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-02/msg00002.html" source="SUSE">SUSE-SR:2009:004</ref>
      <ref url="http://bugs.gentoo.org/show_bug.cgi?id=253493" source="CONFIRM">http://bugs.gentoo.org/show_bug.cgi?id=253493</ref>
    </refs>
    <vuln_soft>
      <prod vendor="audacity" name="audacity">
        <vers num="1.2.6" />
        <vers num="1.3.0" />
        <vers num="1.3.1" />
        <vers num="1.3.3" />
        <vers num="1.3.4" />
        <vers num="1.3.5" />
        <vers num="1.3.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0491" published="2009-02-09" name="CVE-2009-0491" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Stack-based buffer overflow in Elecard MPEG Player 5.5 build 15884.081218 allows remote attackers to execute arbitrary code via a M3U file containing a long URL.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2009/0007" source="VUPEN">ADV-2009-0007</ref>
      <ref url="http://www.milw0rm.com/exploits/7637" source="MILW0RM">7637</ref>
      <ref url="http://secunia.com/advisories/33355" source="SECUNIA" adv="1">33355</ref>
      <ref url="http://osvdb.org/51075" source="OSVDB">51075</ref>
    </refs>
    <vuln_soft>
      <prod vendor="elecard" name="elecard_mpeg_player">
        <vers prev="1" num="5.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0492" published="2009-02-09" name="CVE-2009-0492" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in SimpleIrcBot before 1.0 Stable has unknown impact and attack vectors related to an "auth vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/33127" source="BID" patch="1">33127</ref>
      <ref url="http://sourceforge.net/project/shownotes.php?group_id=249202&amp;release_id=650796" source="CONFIRM" patch="1">http://sourceforge.net/project/shownotes.php?group_id=249202&amp;release_id=650796</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0020" source="VUPEN">ADV-2009-0020</ref>
    </refs>
    <vuln_soft>
      <prod vendor="simpleircbot" name="simpleircbot">
        <vers num="1.0" edition="alpha" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0493" published="2009-02-09" name="CVE-2009-0493" modified="2009-04-20" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in login.php in IT!CMS 2.1a and earlier allows remote attackers to execute arbitrary SQL commands via the Username.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/47791" source="XF">itcms-login-sql-injection(47791)</ref>
      <ref url="http://www.securityfocus.com/bid/33139" source="BID">33139</ref>
      <ref url="http://www.milw0rm.com/exploits/7686" source="MILW0RM">7686</ref>
    </refs>
    <vuln_soft>
      <prod vendor="martin_unzner" name="it!cms">
        <vers prev="1" num="0.21-alpha" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0494" published="2009-02-09" name="CVE-2009-0494" modified="2009-02-10" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in the Portfol (com_portfol) 1.2 component for Joomla! allows remote attackers to execute arbitrary SQL commands via the vcatid parameter in a viewcategory action to index.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/33218" source="BID">33218</ref>
      <ref url="http://www.milw0rm.com/exploits/7734" source="MILW0RM">7734</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mivaco" name="com_portfol">
        <vers num="1.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0495" published="2009-02-09" name="CVE-2009-0495" modified="2009-02-10" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in include/define.php in REALTOR 747 4.11 allows remote attackers to execute arbitrary PHP code via a URL in the INC_DIR parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/33227" source="BID">33227</ref>
      <ref url="http://www.milw0rm.com/exploits/7743" source="MILW0RM">7743</ref>
    </refs>
    <vuln_soft>
      <prod vendor="it747" name="realtor_747">
        <vers num="4.11" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0496" published="2009-02-09" name="CVE-2009-0496" modified="2009-02-10" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Ignite Realtime Openfire 3.6.2 allow remote attackers to inject arbitrary web script or HTML via the (1) log parameter to (a) logviewer.jsp and (b) log.jsp; (2) search parameter to (c) group-summary.jsp; (3) username parameter to (d) user-properties.jsp; (4) logDir, (5) maxTotalSize, (6) maxFileSize, (7) maxDays, and (8) logTimeout parameters to (e) audit-policy.jsp; (9) propName parameter to (f) server-properties.jsp; and the (10) roomconfig_roomname and (11) roomconfig_roomdesc parameters to (g) muc-room-edit-form.jsp.  NOTE: this can be leveraged for arbitrary code execution by using XSS to upload a malicious plugin.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="https://bugs.gentoo.org/show_bug.cgi?id=254309" source="CONFIRM">https://bugs.gentoo.org/show_bug.cgi?id=254309</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/47845" source="XF">openfire-mucroomeditform-xss(47845)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/47835" source="XF">openfire-serverproperties-xss(47835)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/47834" source="XF">openfire-multiple-scripts-xss(47834)</ref>
      <ref url="http://www.securityfocus.com/bid/32944" source="BID">32944</ref>
      <ref url="http://www.securityfocus.com/bid/32943" source="BID">32943</ref>
      <ref url="http://www.securityfocus.com/bid/32940" source="BID">32940</ref>
      <ref url="http://www.securityfocus.com/bid/32939" source="BID">32939</ref>
      <ref url="http://www.securityfocus.com/bid/32938" source="BID">32938</ref>
      <ref url="http://www.securityfocus.com/bid/32937" source="BID">32937</ref>
      <ref url="http://www.securityfocus.com/bid/32935" source="BID">32935</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/499880/100/0/threaded" source="BUGTRAQ">20090108 CORE-2008-1128: Openfire multiple vulnerabilities</ref>
      <ref url="http://www.igniterealtime.org/issues/browse/JM-1506" source="CONFIRM">http://www.igniterealtime.org/issues/browse/JM-1506</ref>
      <ref url="http://www.coresecurity.com/content/openfire-multiple-vulnerabilities" source="MISC">http://www.coresecurity.com/content/openfire-multiple-vulnerabilities</ref>
      <ref url="http://secunia.com/advisories/33452" source="SECUNIA" adv="1">33452</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ignite_realtime" name="openfire">
        <vers num="3.6.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0497" published="2009-02-09" name="CVE-2009-0497" modified="2009-02-10" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in log.jsp in Ignite Realtime Openfire 3.6.2 allows remote attackers to read arbitrary files via a ..\ (dot dot backslash) in the log parameter.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="https://bugs.gentoo.org/show_bug.cgi?id=257585" source="MISC">https://bugs.gentoo.org/show_bug.cgi?id=257585</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/47806" source="XF">openfire-log-directory-traversal(47806)</ref>
      <ref url="http://www.securityfocus.com/bid/32945" source="BID">32945</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/499880/100/0/threaded" source="BUGTRAQ">20090108 CORE-2008-1128: Openfire multiple vulnerabilities</ref>
      <ref url="http://www.coresecurity.com/content/openfire-multiple-vulnerabilities" source="MISC">http://www.coresecurity.com/content/openfire-multiple-vulnerabilities</ref>
      <ref url="http://svn.igniterealtime.org/svn/repos/openfire/trunk/src/web/log.jsp" source="MISC">http://svn.igniterealtime.org/svn/repos/openfire/trunk/src/web/log.jsp</ref>
      <ref url="http://secunia.com/advisories/33452" source="SECUNIA" adv="1">33452</ref>
    </refs>
    <vuln_soft>
      <prod vendor="igniterealtime" name="openfire">
        <vers num="3.6.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0498" published="2009-02-09" name="CVE-2009-0498" modified="2009-02-12" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Virtual GuestBook (vgbook) 2.1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file via a direct request to guestbook.mdb.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.milw0rm.com/exploits/7744" source="MILW0RM">7744</ref>
    </refs>
    <vuln_soft>
      <prod vendor="minitdesign" name="virtual_guestbook">
        <vers num="2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0499" published="2009-02-09" name="CVE-2009-0499" modified="2009-04-01" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:P)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">Cross-site request forgery (CSRF) vulnerability in the forum code in Moodle 1.7 before 1.7.7, 1.8 before 1.8.8, and 1.9 before 1.9.4 allows remote attackers to delete unauthorized forum posts via a link or IMG tag to post.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.openwall.com/lists/oss-security/2009/02/04/1" source="MLIST">[oss-security] 20090204 CVS request - Moodle</ref>
      <ref url="http://secunia.com/advisories/34418" source="SECUNIA">34418</ref>
      <ref url="http://moodle.org/security/" source="CONFIRM">http://moodle.org/security/</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-03/msg00004.html" source="SUSE">SUSE-SR:2009:007</ref>
      <ref url="http://cvs.moodle.org/moodle/mod/forum/post.php?r1=1.154.2.14&amp;r2=1.154.2.15" source="CONFIRM">http://cvs.moodle.org/moodle/mod/forum/post.php?r1=1.154.2.14&amp;r2=1.154.2.15</ref>
    </refs>
    <vuln_soft>
      <prod vendor="moodle" name="moodle">
        <vers num="1.7" />
        <vers num="1.7.1" />
        <vers num="1.7.2" />
        <vers num="1.7.3" />
        <vers num="1.7.4" />
        <vers num="1.7.5" />
        <vers num="1.7.6" />
        <vers num="1.8" />
        <vers num="1.8.1" />
        <vers num="1.8.2" />
        <vers num="1.8.3" />
        <vers num="1.8.4" />
        <vers num="1.8.5" />
        <vers num="1.8.6" />
        <vers num="1.8.7" />
        <vers num="1.9" />
        <vers num="1.9.1" />
        <vers num="1.9.2" />
        <vers num="1.9.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0500" published="2009-02-09" name="CVE-2009-0500" modified="2011-09-12" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in course/lib.php in Moodle 1.6 before 1.6.9, 1.7 before 1.7.7, 1.8 before 1.8.8, and 1.9 before 1.9.4 allows remote attackers to inject arbitrary web script or HTML via crafted log table information that is not properly handled when it is displayed in a log report.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.openwall.com/lists/oss-security/2009/02/04/1" source="MLIST">[oss-security] 20090204 CVS request - Moodle</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1724" source="DEBIAN">DSA-1724</ref>
      <ref url="http://secunia.com/advisories/34418" source="SECUNIA">34418</ref>
      <ref url="http://secunia.com/advisories/33955" source="SECUNIA">33955</ref>
      <ref url="http://moodle.org/security/" source="CONFIRM" adv="1">http://moodle.org/security/</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-03/msg00004.html" source="SUSE">SUSE-SR:2009:007</ref>
    </refs>
    <vuln_soft>
      <prod vendor="moodle" name="moodle">
        <vers num="1.6" />
        <vers num="1.6.1" />
        <vers num="1.6.2" />
        <vers num="1.6.3" />
        <vers num="1.6.4" />
        <vers num="1.6.5" />
        <vers num="1.6.6" />
        <vers num="1.6.7" />
        <vers num="1.6.8" />
        <vers num="1.7" />
        <vers num="1.7.1" />
        <vers num="1.7.2" />
        <vers num="1.7.3" />
        <vers num="1.7.4" />
        <vers num="1.7.5" />
        <vers num="1.7.6" />
        <vers num="1.8" />
        <vers num="1.8.1" />
        <vers num="1.8.2" />
        <vers num="1.8.3" />
        <vers num="1.8.4" />
        <vers num="1.8.5" />
        <vers num="1.8.6" />
        <vers num="1.8.7" />
        <vers num="1.9" />
        <vers num="1.9.1" />
        <vers num="1.9.2" />
        <vers num="1.9.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0501" published="2009-02-09" name="CVE-2009-0501" modified="2009-04-01" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Calendar export feature in Moodle 1.8 before 1.8.8 and 1.9 before 1.9.4 allows attackers to obtain sensitive information and conduct "brute force attacks on user accounts" via unknown vectors.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.openwall.com/lists/oss-security/2009/02/04/1" source="MLIST">[oss-security] 20090204 CVS request - Moodle</ref>
      <ref url="http://secunia.com/advisories/34418" source="SECUNIA">34418</ref>
      <ref url="http://moodle.org/security/" source="CONFIRM" adv="1">http://moodle.org/security/</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-03/msg00004.html" source="SUSE">SUSE-SR:2009:007</ref>
    </refs>
    <vuln_soft>
      <prod vendor="moodle" name="moodle">
        <vers num="1.8" />
        <vers num="1.8.1" />
        <vers num="1.8.2" />
        <vers num="1.8.3" />
        <vers num="1.8.4" />
        <vers num="1.8.5" />
        <vers num="1.8.6" />
        <vers num="1.8.7" />
        <vers num="1.9" />
        <vers num="1.9.1" />
        <vers num="1.9.2" />
        <vers num="1.9.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0502" published="2009-02-09" name="CVE-2009-0502" modified="2011-09-12" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in blocks/html/block_html.php in Snoopy 1.2.3, as used in Moodle 1.6 before 1.6.9, 1.7 before 1.7.7, 1.8 before 1.8.8, and 1.9 before 1.9.4, allows remote attackers to inject arbitrary web script or HTML via an HTML block, which is not properly handled when the "Login as" feature is used to visit a MyMoodle or Blog page.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.openwall.com/lists/oss-security/2009/02/04/1" source="MLIST">[oss-security] 20090204 CVS request - Moodle</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1724" source="DEBIAN">DSA-1724</ref>
      <ref url="http://secunia.com/advisories/34418" source="SECUNIA">34418</ref>
      <ref url="http://secunia.com/advisories/33955" source="SECUNIA">33955</ref>
      <ref url="http://moodle.org/security/" source="CONFIRM" adv="1">http://moodle.org/security/</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-03/msg00004.html" source="SUSE">SUSE-SR:2009:007</ref>
    </refs>
    <vuln_soft>
      <prod vendor="moodle" name="moodle">
        <vers num="1.7" />
        <vers num="1.7.1" />
        <vers num="1.7.2" />
        <vers num="1.7.3" />
        <vers num="1.7.4" />
        <vers num="1.7.5" />
        <vers num="1.7.6" />
        <vers num="1.8" />
        <vers num="1.8.1" />
        <vers num="1.8.2" />
        <vers num="1.8.3" />
        <vers num="1.8.4" />
        <vers num="1.8.5" />
        <vers num="1.8.6" />
        <vers num="1.8.7" />
        <vers num="1.9" />
        <vers num="1.9.1" />
        <vers num="1.9.2" />
        <vers num="1.9.3" />
      </prod>
      <prod vendor="snoopy" name="snoopy">
        <vers num="1.2.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2009-0503" published="2009-02-13" name="CVE-2009-0503" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">IBM WebSphere Message Broker 6.1.x before 6.1.0.2 writes a database connection password to the Event Log and System Log during exception handling for a JDBC error, which allows local users to obtain sensitive information by reading these logs.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www-01.ibm.com/support/docview.wss?rs=849&amp;uid=swg27011431" source="CONFIRM" patch="1" adv="1">http://www-01.ibm.com/support/docview.wss?rs=849&amp;uid=swg27011431</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/48642" source="XF">websphere-msgbroker-info-disclosure(48642)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0460" source="VUPEN">ADV-2009-0460</ref>
      <ref url="http://www.securitytracker.com/id?1021735" source="SECTRACK">1021735</ref>
      <ref url="http://www.securityfocus.com/bid/33819" source="BID">33819</ref>
      <ref url="http://www-1.ibm.com/support/docview.wss?uid=swg1IC55298" source="AIXAPAR" adv="1">IC55298</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="websphere_message_broker">
        <vers num="6.1" />
        <vers prev="1" num="6.1.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2009-0504" published="2009-02-17" name="CVE-2009-0504" modified="2009-02-18" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">WSPolicy in the Web Services component in IBM WebSphere Application Server (WAS) 7.0.x before 7.0.0.1 does not properly recognize the IDAssertion.isUsed binding property, which allows local users to discover a password by reading a SOAP message.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg27014463" source="CONFIRM" patch="1" adv="1">http://www-01.ibm.com/support/docview.wss?uid=swg27014463</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/48700" source="XF">websphere-wspolicy-information-disclosure(48700)</ref>
      <ref url="http://www-1.ibm.com/support/docview.wss?uid=swg1PK73573" source="AIXAPAR" adv="1">PK73573</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="websphere_application_server">
        <vers prev="1" num="7.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0505" published="2009-02-25" name="CVE-2009-0505" modified="2009-04-08" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:C/I:C/A:C)" CVSS_score="9.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.0" CVSS_base_score="9.0">
    <desc>
      <descript source="cve">The CICS listener in IBM TXSeries for Multiplatforms 6.2 GA waits for a forcepurge acknowledgement from the CICS Application Server (CICSAS) after an eci response timeout, which might allow remote authenticated users to cause a denial of service (forcepurge handling delay), or have unspecified other impact, via vectors involving slow or nonexistent acknowledgement.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg24019725" source="CONFIRM" patch="1" adv="1">http://www-01.ibm.com/support/docview.wss?uid=swg24019725</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/48885" source="XF">txseries-forcepurge-wait-unspecified(48885)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0911" source="VUPEN">ADV-2009-0911</ref>
      <ref url="http://www.securityfocus.com/bid/33883" source="BID">33883</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="txseries">
        <vers num="6.2" edition="-" />
        <vers num="6.2" edition="-:windows" />
        <vers num="6.2" edition="-:ga" />
        <vers num="6.2" edition="-:aix" />
        <vers num="6.2" edition="-:hp-ux" />
        <vers num="6.2" edition="-:solaris" />
        <vers num="6.2" edition="-:hp-ia" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0506" published="2009-02-25" name="CVE-2009-0506" modified="2009-07-22" CVSS_version="2.0" CVSS_vector="(AV:L/AC:H/Au:N/C:C/I:C/A:C)" CVSS_score="6.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="1.9" CVSS_base_score="6.2">
    <desc>
      <descript source="cve">Unspecified vulnerability in IBM WebSphere Application Server (WAS) 5.1 and 6.0.2 before 6.0.2.33 on z/OS, when CSIv2 Identity Assertion is enabled and Enterprise JavaBeans (EJB) interaction occurs between a WAS 6.1 instance and a WAS pre-6.1 instance, allows local users to have an unknown impact via vectors related to (1) use of the wrong subject and (2) multiple CBIND checks.</descript>
    </desc>
    <sols>
      <sol source="nvd">Per http://www-01.ibm.com/support/docview.wss?uid=swg27006876#60223:

"Note: WebSphere Application Server V6.0.2 Fix Pack 2 (6.0.2.2), Fix Pack 4 (6.0.2.4), Fix Pack 6 (6.0.2.6), Fix Pack 8 (6.0.2.8), Fix Pack 10 (6.0.2.10), Fix Pack 12 (6.0.2.12), Fix Pack 14 (6.0.2.14), Fix Pack 16 (6.0.2.16), Fix Pack 18 (6.0.2.18), Fix Pack 20 (6.0.2.20), Fix Pack 22 (6.0.2.22) and Fix Pack 24 (6.0.2.24) were only published for the z/OS® platform."</sol>
    </sols>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/48886" source="XF" patch="1">websphere-zos-csiv2-unspecified(48886)</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg27006876" source="CONFIRM" patch="1">http://www-01.ibm.com/support/docview.wss?uid=swg27006876</ref>
      <ref url="http://www.securityfocus.com/bid/33884" source="BID">33884</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="websphere_application_server">
        <vers num="5.1.0" />
        <vers num="6.0.2" />
        <vers num="6.0.2.10" />
        <vers num="6.0.2.12" />
        <vers num="6.0.2.14" />
        <vers num="6.0.2.16" />
        <vers num="6.0.2.18" />
        <vers num="6.0.2.20" />
        <vers num="6.0.2.22" />
        <vers num="6.0.2.24" />
        <vers num="6.0.2.4" />
        <vers num="6.0.2.6" />
        <vers num="6.0.2.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0507" published="2009-02-26" name="CVE-2009-0507" modified="2009-05-16" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:N/A:N)" CVSS_score="4.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.0" CVSS_base_score="4.0">
    <desc>
      <descript source="cve">IBM WebSphere Process Server (WPS) 6.1.2 before 6.1.2.3 and 6.2 before 6.2.0.1 does not properly restrict configuration data during an export of the cluster configuration file from the administrative console, which allows remote authenticated users to obtain the (1) JMSAPI, (2) ESCALATION, and (3) MAILSESSION (aka mail session) cleartext passwords via vectors involving access to a cluster member.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/48892" source="XF">websphere-process-server-info-disclosure(48892)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0670" source="VUPEN">ADV-2009-0670</ref>
      <ref url="http://www-1.ibm.com/support/docview.wss?uid=swg1JR30088" source="AIXAPAR" adv="1">JR30088</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg27015580" source="CONFIRM">http://www-01.ibm.com/support/docview.wss?uid=swg27015580</ref>
      <ref url="http://secunia.com/advisories/34249" source="SECUNIA">34249</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="websphere_process_server">
        <vers num="6.1.2" />
        <vers num="6.1.2.1" />
        <vers prev="1" num="6.1.2.2" />
        <vers prev="1" num="6.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0508" published="2009-03-16" name="CVE-2009-0508" modified="2009-06-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The Servlet Engine/Web Container and JSP components in IBM WebSphere Application Server (WAS) 5.1.0, 5.1.1.19, 6.0.2 before 6.0.2.35, 6.1 before 6.1.0.23, and 7.0 before 7.0.0.3 allow remote attackers to read arbitrary files contained in war files in (1) web-inf, (2) meta-inf, and unspecified other directories via unknown vectors, related to (a) web-based applications and (b) the administrative console.</descript>
    </desc>
    <impacts>
      <impact source="nvd">Per: http://xforce.iss.net/xforce/xfdb/49085

CVSS score based on information provided by ISS.</impact>
    </impacts>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2009/1464" source="VUPEN" patch="1" adv="1">ADV-2009-1464</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1188" source="VUPEN" patch="1" adv="1">ADV-2009-1188</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0704" source="VUPEN" patch="1" adv="1">ADV-2009-0704</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg27006876" source="CONFIRM" patch="1">http://www-01.ibm.com/support/docview.wss?uid=swg27006876</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg21380376" source="CONFIRM" patch="1" adv="1">http://www-01.ibm.com/support/docview.wss?uid=swg21380376</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?rs=180&amp;uid=swg24022456" source="CONFIRM" patch="1" adv="1">http://www-01.ibm.com/support/docview.wss?rs=180&amp;uid=swg24022456</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/49085" source="XF">websphere-web-app-information-disclosure(49085)</ref>
      <ref url="http://www.securityfocus.com/bid/34104" source="BID">34104</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg21380233" source="CONFIRM" adv="1">http://www-01.ibm.com/support/docview.wss?uid=swg21380233</ref>
      <ref url="http://secunia.com/advisories/34876" source="SECUNIA" adv="1">34876</ref>
      <ref url="http://secunia.com/advisories/34283" source="SECUNIA" adv="1">34283</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="websphere_application_server">
        <vers num="5.1.0" />
        <vers num="5.1.1.19" />
        <vers num="6.0.2" />
        <vers num="6.0.2.1" />
        <vers num="6.0.2.11" />
        <vers num="6.0.2.15" />
        <vers num="6.0.2.17" />
        <vers num="6.0.2.19" />
        <vers num="6.0.2.21" />
        <vers num="6.0.2.23" />
        <vers num="6.0.2.25" />
        <vers num="6.0.2.27" />
        <vers num="6.0.2.29" />
        <vers num="6.0.2.3" />
        <vers num="6.0.2.31" />
        <vers num="6.0.2.33" />
        <vers num="6.0.2.5" />
        <vers num="6.0.2.7" />
        <vers num="6.0.2.9" />
        <vers num="6.1" />
        <vers num="6.1.0.1" />
        <vers num="6.1.0.11" />
        <vers num="6.1.0.13" />
        <vers num="6.1.0.15" />
        <vers num="6.1.0.17" />
        <vers num="6.1.0.19" />
        <vers num="6.1.0.2" />
        <vers num="6.1.0.21" />
        <vers num="6.1.0.3" />
        <vers num="6.1.0.5" />
        <vers num="6.1.0.7" />
        <vers num="6.1.0.9" />
        <vers num="7.0" />
        <vers num="7.0.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0509" published="2009-06-11" name="CVE-2009-0509" modified="2010-05-04" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Heap-based buffer overflow in the JBIG2 filter in Adobe Reader 7 and Acrobat 7 before 7.1.3, Adobe Reader 8 and Acrobat 8 before 8.1.6, and Adobe Reader 9 and Acrobat 9 before 9.1.2 allows remote attackers to execute arbitrary code via a crafted file that triggers memory corruption.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-161A.html" source="CERT">TA09-161A</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1547" source="VUPEN" patch="1" adv="1">ADV-2009-1547</ref>
      <ref url="http://www.adobe.com/support/security/bulletins/apsb09-07.html" source="CONFIRM" patch="1" adv="1">http://www.adobe.com/support/security/bulletins/apsb09-07.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/49239" source="XF">reader-text-bo(49239)</ref>
      <ref url="http://www.securityfocus.com/bid/35274" source="BID">35274</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-1109.html" source="REDHAT">RHSA-2009:1109</ref>
      <ref url="http://securitytracker.com/id?1022361" source="SECTRACK">1022361</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200907-06.xml" source="GENTOO">GLSA-200907-06</ref>
      <ref url="http://secunia.com/advisories/35734" source="SECUNIA">35734</ref>
      <ref url="http://secunia.com/advisories/35685" source="SECUNIA">35685</ref>
      <ref url="http://secunia.com/advisories/35655" source="SECUNIA">35655</ref>
      <ref url="http://secunia.com/advisories/35496" source="SECUNIA">35496</ref>
      <ref url="http://secunia.com/advisories/34580" source="SECUNIA" adv="1">34580</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-07/msg00002.html" source="SUSE">SUSE-SR:2009:012</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-07/msg00000.html" source="SUSE">SUSE-SA:2009:035</ref>
    </refs>
    <vuln_soft>
      <prod vendor="adobe" name="acrobat">
        <vers num="7.0" edition="" />
        <vers num="7.0" edition=":standard" />
        <vers num="7.0" edition=":professional" />
        <vers num="7.0.1" edition="" />
        <vers num="7.0.1" edition=":professional" />
        <vers num="7.0.1" edition=":standard" />
        <vers num="7.0.2" edition="" />
        <vers num="7.0.2" edition=":professional" />
        <vers num="7.0.2" edition=":standard" />
        <vers num="7.0.3" edition="" />
        <vers num="7.0.3" edition=":professional" />
        <vers num="7.0.3" edition=":standard" />
        <vers num="7.0.4" edition="" />
        <vers num="7.0.4" edition=":professional" />
        <vers num="7.0.4" edition=":standard" />
        <vers num="7.0.5" edition="" />
        <vers num="7.0.5" edition=":professional" />
        <vers num="7.0.5" edition=":standard" />
        <vers num="7.0.6" edition="" />
        <vers num="7.0.6" edition=":professional" />
        <vers num="7.0.6" edition=":standard" />
        <vers num="7.0.7" edition="" />
        <vers num="7.0.7" edition=":professional" />
        <vers num="7.0.7" edition=":standard" />
        <vers num="7.0.8" edition="" />
        <vers num="7.0.8" edition=":elements" />
        <vers num="7.0.8" edition=":standard" />
        <vers num="7.0.8" edition=":professional" />
        <vers num="7.0.9" edition="" />
        <vers num="7.0.9" edition=":professional" />
        <vers num="7.1" edition="" />
        <vers num="7.1" edition=":standard" />
        <vers num="7.1" edition=":professional" />
        <vers num="7.1.0" />
        <vers num="7.1.1" edition="" />
        <vers num="7.1.1" edition=":standard" />
        <vers num="8.0" edition="" />
        <vers num="8.0" edition=":professional" />
        <vers num="8.0" edition=":standard" />
        <vers num="8.1" edition="" />
        <vers num="8.1" edition=":standard" />
        <vers num="8.1.1" edition="" />
        <vers num="8.1.1" edition=":standard" />
        <vers num="8.1.1" edition=":professional" />
        <vers num="8.1.2" edition="" />
        <vers num="8.1.2" edition=":standard" />
        <vers num="8.1.2" edition=":professional" />
        <vers num="8.1.2" edition="security_update" />
        <vers num="8.1.2" edition="security_update:professional" />
        <vers num="8.1.3" edition="" />
        <vers num="8.1.3" edition=":standard" />
        <vers num="8.1.3" edition=":professional" />
        <vers num="8.1.4" edition="" />
        <vers num="8.1.4" edition=":standard" />
        <vers num="8.1.4" edition=":professional" />
        <vers num="9" />
        <vers num="9.0" edition="" />
        <vers num="9.0" edition=":standard" />
        <vers num="9.0.0" />
        <vers num="9.1" edition="" />
        <vers num="9.1" edition=":standard" />
      </prod>
      <prod vendor="adobe" name="acrobat_reader">
        <vers num="7.0" />
        <vers num="7.0.1" />
        <vers num="7.0.2" />
        <vers num="7.0.3" />
        <vers num="7.0.4" />
        <vers num="7.0.5" />
        <vers num="7.0.6" />
        <vers num="7.0.7" />
        <vers num="7.0.8" />
        <vers num="7.0.9" />
        <vers num="7.1" />
        <vers num="7.1.1" />
        <vers num="8.0" />
        <vers num="8.1" />
        <vers num="8.1.1" />
        <vers num="8.1.2" edition="security_update" />
        <vers num="8.1.3" />
        <vers num="8.1.4" />
        <vers num="8.1.5" />
        <vers num="9" />
        <vers num="9.1" />
        <vers num="9.1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0510" published="2009-06-11" name="CVE-2009-0510" modified="2010-05-04" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Heap-based buffer overflow in the JBIG2 filter in Adobe Reader 7 and Acrobat 7 before 7.1.3, Adobe Reader 8 and Acrobat 8 before 8.1.6, and Adobe Reader 9 and Acrobat 9 before 9.1.2 might allow remote attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2009-0511, CVE-2009-0512, CVE-2009-0888, and CVE-2009-0889.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-161A.html" source="CERT">TA09-161A</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1547" source="VUPEN" patch="1" adv="1">ADV-2009-1547</ref>
      <ref url="http://www.adobe.com/support/security/bulletins/apsb09-07.html" source="CONFIRM" patch="1" adv="1">http://www.adobe.com/support/security/bulletins/apsb09-07.html</ref>
      <ref url="http://www.securityfocus.com/bid/35274" source="BID">35274</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-1109.html" source="REDHAT">RHSA-2009:1109</ref>
      <ref url="http://securitytracker.com/id?1022361" source="SECTRACK">1022361</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200907-06.xml" source="GENTOO">GLSA-200907-06</ref>
      <ref url="http://secunia.com/advisories/35734" source="SECUNIA">35734</ref>
      <ref url="http://secunia.com/advisories/35685" source="SECUNIA">35685</ref>
      <ref url="http://secunia.com/advisories/35655" source="SECUNIA">35655</ref>
      <ref url="http://secunia.com/advisories/35496" source="SECUNIA">35496</ref>
      <ref url="http://secunia.com/advisories/34580" source="SECUNIA" adv="1">34580</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-07/msg00002.html" source="SUSE">SUSE-SR:2009:012</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-07/msg00000.html" source="SUSE">SUSE-SA:2009:035</ref>
    </refs>
    <vuln_soft>
      <prod vendor="adobe" name="acrobat">
        <vers num="7.0" edition="" />
        <vers num="7.0" edition=":standard" />
        <vers num="7.0" edition=":professional" />
        <vers num="7.0.1" edition="" />
        <vers num="7.0.1" edition=":professional" />
        <vers num="7.0.1" edition=":standard" />
        <vers num="7.0.2" edition="" />
        <vers num="7.0.2" edition=":professional" />
        <vers num="7.0.2" edition=":standard" />
        <vers num="7.0.3" edition="" />
        <vers num="7.0.3" edition=":professional" />
        <vers num="7.0.3" edition=":standard" />
        <vers num="7.0.4" edition="" />
        <vers num="7.0.4" edition=":professional" />
        <vers num="7.0.4" edition=":standard" />
        <vers num="7.0.5" edition="" />
        <vers num="7.0.5" edition=":professional" />
        <vers num="7.0.5" edition=":standard" />
        <vers num="7.0.6" edition="" />
        <vers num="7.0.6" edition=":professional" />
        <vers num="7.0.6" edition=":standard" />
        <vers num="7.0.7" edition="" />
        <vers num="7.0.7" edition=":professional" />
        <vers num="7.0.7" edition=":standard" />
        <vers num="7.0.8" edition="" />
        <vers num="7.0.8" edition=":elements" />
        <vers num="7.0.8" edition=":standard" />
        <vers num="7.0.8" edition=":professional" />
        <vers num="7.0.9" edition="" />
        <vers num="7.0.9" edition=":professional" />
        <vers num="7.1" edition="" />
        <vers num="7.1" edition=":standard" />
        <vers num="7.1" edition=":professional" />
        <vers num="7.1.0" />
        <vers num="7.1.1" edition="" />
        <vers num="7.1.1" edition=":standard" />
        <vers num="8.0" edition="" />
        <vers num="8.0" edition=":professional" />
        <vers num="8.0" edition=":standard" />
        <vers num="8.1" edition="" />
        <vers num="8.1" edition=":standard" />
        <vers num="8.1.1" edition="" />
        <vers num="8.1.1" edition=":standard" />
        <vers num="8.1.1" edition=":professional" />
        <vers num="8.1.2" edition="" />
        <vers num="8.1.2" edition=":standard" />
        <vers num="8.1.2" edition=":professional" />
        <vers num="8.1.2" edition="security_update" />
        <vers num="8.1.2" edition="security_update:professional" />
        <vers num="8.1.3" edition="" />
        <vers num="8.1.3" edition=":standard" />
        <vers num="8.1.3" edition=":professional" />
        <vers num="8.1.4" edition="" />
        <vers num="8.1.4" edition=":standard" />
        <vers num="8.1.4" edition=":professional" />
        <vers num="9" />
        <vers num="9.0" edition="" />
        <vers num="9.0" edition=":standard" />
        <vers num="9.0.0" />
        <vers num="9.1" edition="" />
        <vers num="9.1" edition=":standard" />
      </prod>
      <prod vendor="adobe" name="acrobat_reader">
        <vers num="7.0" />
        <vers num="7.0.1" />
        <vers num="7.0.2" />
        <vers num="7.0.3" />
        <vers num="7.0.4" />
        <vers num="7.0.5" />
        <vers num="7.0.6" />
        <vers num="7.0.7" />
        <vers num="7.0.8" />
        <vers num="7.0.9" />
        <vers num="7.1" />
        <vers num="7.1.1" />
        <vers num="8.0" />
        <vers num="8.1" />
        <vers num="8.1.1" />
        <vers num="8.1.2" edition="security_update" />
        <vers num="8.1.3" />
        <vers num="8.1.4" />
        <vers num="8.1.5" />
        <vers num="9" />
        <vers num="9.1" />
        <vers num="9.1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0511" published="2009-06-11" name="CVE-2009-0511" modified="2010-05-04" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Heap-based buffer overflow in the JBIG2 filter in Adobe Reader 7 and Acrobat 7 before 7.1.3, Adobe Reader 8 and Acrobat 8 before 8.1.6, and Adobe Reader 9 and Acrobat 9 before 9.1.2 might allow remote attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2009-0510, CVE-2009-0512, CVE-2009-0888, and CVE-2009-0889.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-161A.html" source="CERT">TA09-161A</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1547" source="VUPEN" patch="1" adv="1">ADV-2009-1547</ref>
      <ref url="http://www.adobe.com/support/security/bulletins/apsb09-07.html" source="CONFIRM" patch="1" adv="1">http://www.adobe.com/support/security/bulletins/apsb09-07.html</ref>
      <ref url="http://www.securityfocus.com/bid/35274" source="BID">35274</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-1109.html" source="REDHAT">RHSA-2009:1109</ref>
      <ref url="http://securitytracker.com/id?1022361" source="SECTRACK">1022361</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200907-06.xml" source="GENTOO">GLSA-200907-06</ref>
      <ref url="http://secunia.com/advisories/35734" source="SECUNIA">35734</ref>
      <ref url="http://secunia.com/advisories/35685" source="SECUNIA">35685</ref>
      <ref url="http://secunia.com/advisories/35655" source="SECUNIA">35655</ref>
      <ref url="http://secunia.com/advisories/35496" source="SECUNIA">35496</ref>
      <ref url="http://secunia.com/advisories/34580" source="SECUNIA" adv="1">34580</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-07/msg00002.html" source="SUSE">SUSE-SR:2009:012</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-07/msg00000.html" source="SUSE">SUSE-SA:2009:035</ref>
    </refs>
    <vuln_soft>
      <prod vendor="adobe" name="acrobat">
        <vers num="7.0" edition="" />
        <vers num="7.0" edition=":standard" />
        <vers num="7.0" edition=":professional" />
        <vers num="7.0.1" edition="" />
        <vers num="7.0.1" edition=":professional" />
        <vers num="7.0.1" edition=":standard" />
        <vers num="7.0.2" edition="" />
        <vers num="7.0.2" edition=":professional" />
        <vers num="7.0.2" edition=":standard" />
        <vers num="7.0.3" edition="" />
        <vers num="7.0.3" edition=":professional" />
        <vers num="7.0.3" edition=":standard" />
        <vers num="7.0.4" edition="" />
        <vers num="7.0.4" edition=":professional" />
        <vers num="7.0.4" edition=":standard" />
        <vers num="7.0.5" edition="" />
        <vers num="7.0.5" edition=":professional" />
        <vers num="7.0.5" edition=":standard" />
        <vers num="7.0.6" edition="" />
        <vers num="7.0.6" edition=":professional" />
        <vers num="7.0.6" edition=":standard" />
        <vers num="7.0.7" edition="" />
        <vers num="7.0.7" edition=":professional" />
        <vers num="7.0.7" edition=":standard" />
        <vers num="7.0.8" edition="" />
        <vers num="7.0.8" edition=":elements" />
        <vers num="7.0.8" edition=":standard" />
        <vers num="7.0.8" edition=":professional" />
        <vers num="7.0.9" edition="" />
        <vers num="7.0.9" edition=":professional" />
        <vers num="7.1" edition="" />
        <vers num="7.1" edition=":standard" />
        <vers num="7.1" edition=":professional" />
        <vers num="7.1.0" />
        <vers num="7.1.1" edition="" />
        <vers num="7.1.1" edition=":standard" />
        <vers num="8.0" edition="" />
        <vers num="8.0" edition=":professional" />
        <vers num="8.0" edition=":standard" />
        <vers num="8.1" edition="" />
        <vers num="8.1" edition=":standard" />
        <vers num="8.1.1" edition="" />
        <vers num="8.1.1" edition=":standard" />
        <vers num="8.1.1" edition=":professional" />
        <vers num="8.1.2" edition="" />
        <vers num="8.1.2" edition=":standard" />
        <vers num="8.1.2" edition=":professional" />
        <vers num="8.1.2" edition="security_update" />
        <vers num="8.1.2" edition="security_update:professional" />
        <vers num="8.1.3" edition="" />
        <vers num="8.1.3" edition=":standard" />
        <vers num="8.1.3" edition=":professional" />
        <vers num="8.1.4" edition="" />
        <vers num="8.1.4" edition=":standard" />
        <vers num="8.1.4" edition=":professional" />
        <vers num="9" />
        <vers num="9.0" edition="" />
        <vers num="9.0" edition=":standard" />
        <vers num="9.0.0" />
        <vers num="9.1" edition="" />
        <vers num="9.1" edition=":standard" />
      </prod>
      <prod vendor="adobe" name="acrobat_reader">
        <vers num="7.0" />
        <vers num="7.0.1" />
        <vers num="7.0.2" />
        <vers num="7.0.3" />
        <vers num="7.0.4" />
        <vers num="7.0.5" />
        <vers num="7.0.6" />
        <vers num="7.0.7" />
        <vers num="7.0.8" />
        <vers num="7.0.9" />
        <vers num="7.1" />
        <vers num="7.1.1" />
        <vers num="8.0" />
        <vers num="8.1" />
        <vers num="8.1.1" />
        <vers num="8.1.2" edition="security_update" />
        <vers num="8.1.3" />
        <vers num="8.1.4" />
        <vers num="8.1.5" />
        <vers num="9" />
        <vers num="9.1" />
        <vers num="9.1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0512" published="2009-06-11" name="CVE-2009-0512" modified="2010-05-04" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Heap-based buffer overflow in the JBIG2 filter in Adobe Reader 7 and Acrobat 7 before 7.1.3, Adobe Reader 8 and Acrobat 8 before 8.1.6, and Adobe Reader 9 and Acrobat 9 before 9.1.2 might allow remote attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2009-0510, CVE-2009-0511, CVE-2009-0888, and CVE-2009-0889.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-161A.html" source="CERT">TA09-161A</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1547" source="VUPEN" patch="1" adv="1">ADV-2009-1547</ref>
      <ref url="http://www.adobe.com/support/security/bulletins/apsb09-07.html" source="CONFIRM" patch="1" adv="1">http://www.adobe.com/support/security/bulletins/apsb09-07.html</ref>
      <ref url="http://www.securityfocus.com/bid/35293" source="BID">35293</ref>
      <ref url="http://www.securityfocus.com/bid/35274" source="BID">35274</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-1109.html" source="REDHAT">RHSA-2009:1109</ref>
      <ref url="http://securitytracker.com/id?1022361" source="SECTRACK">1022361</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200907-06.xml" source="GENTOO">GLSA-200907-06</ref>
      <ref url="http://secunia.com/advisories/35734" source="SECUNIA">35734</ref>
      <ref url="http://secunia.com/advisories/35685" source="SECUNIA">35685</ref>
      <ref url="http://secunia.com/advisories/35655" source="SECUNIA">35655</ref>
      <ref url="http://secunia.com/advisories/35496" source="SECUNIA">35496</ref>
      <ref url="http://secunia.com/advisories/34580" source="SECUNIA" adv="1">34580</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-07/msg00002.html" source="SUSE">SUSE-SR:2009:012</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-07/msg00000.html" source="SUSE">SUSE-SA:2009:035</ref>
    </refs>
    <vuln_soft>
      <prod vendor="adobe" name="acrobat">
        <vers num="7.0" edition="" />
        <vers num="7.0" edition=":standard" />
        <vers num="7.0" edition=":professional" />
        <vers num="7.0.1" edition="" />
        <vers num="7.0.1" edition=":professional" />
        <vers num="7.0.1" edition=":standard" />
        <vers num="7.0.2" edition="" />
        <vers num="7.0.2" edition=":professional" />
        <vers num="7.0.2" edition=":standard" />
        <vers num="7.0.3" edition="" />
        <vers num="7.0.3" edition=":professional" />
        <vers num="7.0.3" edition=":standard" />
        <vers num="7.0.4" edition="" />
        <vers num="7.0.4" edition=":professional" />
        <vers num="7.0.4" edition=":standard" />
        <vers num="7.0.5" edition="" />
        <vers num="7.0.5" edition=":professional" />
        <vers num="7.0.5" edition=":standard" />
        <vers num="7.0.6" edition="" />
        <vers num="7.0.6" edition=":professional" />
        <vers num="7.0.6" edition=":standard" />
        <vers num="7.0.7" edition="" />
        <vers num="7.0.7" edition=":professional" />
        <vers num="7.0.7" edition=":standard" />
        <vers num="7.0.8" edition="" />
        <vers num="7.0.8" edition=":elements" />
        <vers num="7.0.8" edition=":standard" />
        <vers num="7.0.8" edition=":professional" />
        <vers num="7.0.9" edition="" />
        <vers num="7.0.9" edition=":professional" />
        <vers num="7.1" edition="" />
        <vers num="7.1" edition=":standard" />
        <vers num="7.1" edition=":professional" />
        <vers num="7.1.0" />
        <vers num="7.1.1" edition="" />
        <vers num="7.1.1" edition=":standard" />
        <vers num="8.0" edition="" />
        <vers num="8.0" edition=":professional" />
        <vers num="8.0" edition=":standard" />
        <vers num="8.1" edition="" />
        <vers num="8.1" edition=":standard" />
        <vers num="8.1.1" edition="" />
        <vers num="8.1.1" edition=":standard" />
        <vers num="8.1.1" edition=":professional" />
        <vers num="8.1.2" edition="" />
        <vers num="8.1.2" edition=":standard" />
        <vers num="8.1.2" edition=":professional" />
        <vers num="8.1.2" edition="security_update" />
        <vers num="8.1.2" edition="security_update:professional" />
        <vers num="8.1.3" edition="" />
        <vers num="8.1.3" edition=":standard" />
        <vers num="8.1.3" edition=":professional" />
        <vers num="8.1.4" edition="" />
        <vers num="8.1.4" edition=":standard" />
        <vers num="8.1.4" edition=":professional" />
        <vers num="9" />
        <vers num="9.0" edition="" />
        <vers num="9.0" edition=":standard" />
        <vers num="9.0.0" />
        <vers num="9.1" edition="" />
        <vers num="9.1" edition=":standard" />
      </prod>
      <prod vendor="adobe" name="acrobat_reader">
        <vers num="7.0" />
        <vers num="7.0.1" />
        <vers num="7.0.2" />
        <vers num="7.0.3" />
        <vers num="7.0.4" />
        <vers num="7.0.5" />
        <vers num="7.0.6" />
        <vers num="7.0.7" />
        <vers num="7.0.8" />
        <vers num="7.0.9" />
        <vers num="7.1" />
        <vers num="7.1.1" />
        <vers num="8.0" />
        <vers num="8.1" />
        <vers num="8.1.1" />
        <vers num="8.1.2" edition="security_update" />
        <vers num="8.1.3" />
        <vers num="8.1.4" />
        <vers num="8.1.5" />
        <vers num="9" />
        <vers num="9.1" />
        <vers num="9.1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0513" published="2009-02-10" name="CVE-2009-0513" modified="2009-02-11" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple PHP remote file inclusion vulnerabilities in WebFrame 0.76 allow remote attackers to execute arbitrary PHP code via a URL in the classFiles parameter to (1) admin/doc/index.php, (2) index.php, and (3) base/menu.php in mod/.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/33701" source="BID">33701</ref>
      <ref url="http://www.milw0rm.com/exploits/8025" source="MILW0RM">8025</ref>
    </refs>
    <vuln_soft>
      <prod vendor="webframe" name="webframe">
        <vers num="0.76" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0514" published="2009-02-10" name="CVE-2009-0514" modified="2009-02-11" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple directory traversal vulnerabilities in WebFrame 0.76 allow remote attackers to include and execute arbitrary local files via directory traversal sequences in the (1) currentmod and (2) LANG parameters to mod/index.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/33701" source="BID">33701</ref>
      <ref url="http://www.milw0rm.com/exploits/8025" source="MILW0RM">8025</ref>
    </refs>
    <vuln_soft>
      <prod vendor="webframe" name="webframe">
        <vers num="0.76" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0515" published="2009-02-10" name="CVE-2009-0515" modified="2009-02-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Directory traversal vulnerability in check_lang.php in Yet Another NOCC (YANOCC) 0.1.0 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the lang parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/48608" source="XF">yanocc-checklang-file-include(48608)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0383" source="VUPEN">ADV-2009-0383</ref>
      <ref url="http://www.securityfocus.com/bid/33704" source="BID">33704</ref>
      <ref url="http://www.milw0rm.com/exploits/8020" source="MILW0RM">8020</ref>
      <ref url="http://secunia.com/advisories/33862" source="SECUNIA">33862</ref>
    </refs>
    <vuln_soft>
      <prod vendor="yanocc" name="yanocc">
        <vers prev="1" num="0.1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0516" published="2009-02-10" name="CVE-2009-0516" modified="2010-09-01" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in the classified page (classified.php) in BusinessSpace 1.2 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter to index.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/48606" source="XF">businessspace-index-sql-injection(48606)</ref>
      <ref url="http://www.securityfocus.com/bid/33692" source="BID">33692</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/500787/100/0/threaded" source="BUGTRAQ">20090209 [ECHO_ADV_102$2009] BusinessSpace &lt;= 1.2 (id) Remote SQL Injection Vulnerability</ref>
      <ref url="http://www.milw0rm.com/exploits/8011" source="MILW0RM">8011</ref>
      <ref url="http://secunia.com/advisories/33875" source="SECUNIA" adv="1">33875</ref>
    </refs>
    <vuln_soft>
      <prod vendor="businessspace" name="businessspace">
        <vers prev="1" num="1.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0517" published="2009-02-10" name="CVE-2009-0517" modified="2009-02-11" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Eval injection vulnerability in index.php in phpSlash 0.8.1.1 and earlier allows remote attackers to execute arbitrary PHP code via the fields parameter, which is supplied to an eval function call within the generic function in include/class/tz_env.class.  NOTE: some of these details are obtained from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/48441" source="XF">phpslash-generic-code-execution(48441)</ref>
      <ref url="http://www.securityfocus.com/bid/33572" source="BID">33572</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/500664/100/0/threaded" source="BUGTRAQ">20090201 phpslash &lt;= 0.8.1.1 Remote Code Execution Exploit</ref>
      <ref url="http://www.milw0rm.com/exploits/7948" source="MILW0RM">7948</ref>
      <ref url="http://secunia.com/advisories/33717" source="SECUNIA" adv="1">33717</ref>
      <ref url="http://osvdb.org/51727" source="OSVDB">51727</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpslash" name="phpslash">
        <vers num="0.5.3.2" />
        <vers num="0.6" />
        <vers num="0.6.1" />
        <vers num="0.6.2" />
        <vers num="0.61" />
        <vers num="0.7.1" />
        <vers num="0.7.2" />
        <vers num="0.8.0" />
        <vers num="0.8.1" />
        <vers prev="1" num="0.8.1.1" />
        <vers num="065" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2009-0518" published="2009-04-06" name="CVE-2009-0518" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">VI Client in VMware VirtualCenter before 2.5 Update 4, VMware ESXi 3.5 before Update 4, and VMware ESX 3.5 before Update 4 retains the VirtualCenter Server password in process memory, which might allow local users to obtain this password.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://lists.vmware.com/pipermail/security-announce/2009/000054.html" source="MLIST" patch="1" adv="1">[security-announce] 20090403 VMSA-2009-0005 VMware Hosted products, VI Client and patches for ESX and ESXi resolve multiple security issues</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0944" source="VUPEN">ADV-2009-0944</ref>
      <ref url="http://www.vmware.com/security/advisories/VMSA-2009-0005.html" source="CONFIRM">http://www.vmware.com/security/advisories/VMSA-2009-0005.html</ref>
      <ref url="http://www.securityfocus.com/bid/34373" source="BID">34373</ref>
      <ref url="http://secunia.com/advisories/34585" source="SECUNIA">34585</ref>
      <ref url="http://seclists.org/fulldisclosure/2009/Apr/0036.html" source="FULLDISC">20090403 VMSA-2009-0005 VMware Hosted products, VI Client and patches for ESX and ESXi resolve multiple security issues</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6376" source="OVAL">oval:org.mitre.oval:def:6376</ref>
    </refs>
    <vuln_soft>
      <prod vendor="vmware" name="vmware_esx">
        <vers num="3.5" />
      </prod>
      <prod vendor="vmware" name="vmware_esxi">
        <vers num="3.5" />
      </prod>
      <prod vendor="vmware" name="vmware_virtualcenter">
        <vers num="1.1" />
        <vers num="1.2" />
        <vers num="1.3" />
        <vers num="1.3.1" />
        <vers num="1.4" />
        <vers num="1.4.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0519" published="2009-02-26" name="CVE-2009-0519" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Unspecified vulnerability in Adobe Flash Player 9.x before 9.0.159.0 and 10.x before 10.0.22.87 allows remote attackers to cause a denial of service (browser crash) or possibly execute arbitrary code via a crafted Shockwave Flash (aka .swf) file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-133A.html" source="CERT">TA09-133A</ref>
      <ref url="http://www.securityfocus.com/bid/33890" source="BID" patch="1">33890</ref>
      <ref url="http://www.adobe.com/support/security/bulletins/apsb09-01.html" source="CONFIRM" patch="1" adv="1">http://www.adobe.com/support/security/bulletins/apsb09-01.html</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=487141" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=487141</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/48900" source="XF">flash-swf-unspecified-dos(48900)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1297" source="VUPEN">ADV-2009-1297</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0743" source="VUPEN">ADV-2009-0743</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0513" source="VUPEN" adv="1">ADV-2009-0513</ref>
      <ref url="http://support.apple.com/kb/HT3549" source="CONFIRM">http://support.apple.com/kb/HT3549</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-254909-1" source="SUNALERT">254909</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200903-23.xml" source="GENTOO">GLSA-200903-23</ref>
      <ref url="http://secunia.com/advisories/35074" source="SECUNIA">35074</ref>
      <ref url="http://secunia.com/advisories/34293" source="SECUNIA">34293</ref>
      <ref url="http://secunia.com/advisories/34226" source="SECUNIA">34226</ref>
      <ref url="http://secunia.com/advisories/34012" source="SECUNIA" adv="1">34012</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2009-0334.html" source="REDHAT">RHSA-2009:0334</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2009-0332.html" source="REDHAT">RHSA-2009:0332</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6470" source="OVAL">oval:org.mitre.oval:def:6470</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2009/May/msg00002.html" source="APPLE">APPLE-SA-2009-05-12</ref>
      <ref url="http://isc.sans.org/diary.html?storyid=5929" source="MISC">http://isc.sans.org/diary.html?storyid=5929</ref>
    </refs>
    <vuln_soft>
      <prod vendor="adobe" name="air">
        <vers num="1.5" />
      </prod>
      <prod vendor="adobe" name="flash_player">
        <vers num="10.0.0.584" />
        <vers num="10.0.12.10" />
        <vers prev="1" num="10.0.12.36" />
        <vers num="7.0" />
        <vers num="7.0.1" />
        <vers num="7.0.25" />
        <vers num="7.0.63" edition="" />
        <vers num="7.0.63" edition=":linux" />
        <vers num="7.0.69.0" />
        <vers num="7.0.70.0" />
        <vers num="7.1" />
        <vers num="7.1.1" />
        <vers num="7.2" />
        <vers num="8.0" edition="" />
        <vers num="8.0" edition=":pro" />
        <vers num="8.0" edition=":basic" />
        <vers num="8.0.24.0" />
        <vers num="8.0.34.0" />
        <vers num="8.0.35.0" />
        <vers num="8.0.39.0" />
        <vers num="9.0.112.0" />
        <vers num="9.0.114.0" />
        <vers num="9.0.115.0" />
        <vers num="9.0.124.0" />
        <vers num="9.0.16" />
        <vers num="9.0.20" />
        <vers num="9.0.20.0" />
        <vers num="9.0.28" />
        <vers num="9.0.28.0" />
        <vers num="9.0.31.0" />
        <vers num="9.0.45.0" />
        <vers num="9.0.47.0" />
        <vers num="9.0.48.0" />
        <vers num="cs3" edition="" />
        <vers num="cs3" edition=":pro" />
        <vers num="cs4" edition="" />
        <vers num="cs4" edition=":pro" />
      </prod>
      <prod vendor="adobe" name="flash_player_for_linux">
        <vers prev="1" num="10.0.15.3" />
      </prod>
      <prod vendor="adobe" name="flex">
        <vers num="3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0520" published="2009-02-26" name="CVE-2009-0520" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Adobe Flash Player 9.x before 9.0.159.0 and 10.x before 10.0.22.87 does not properly remove references to destroyed objects during Shockwave Flash file processing, which allows remote attackers to execute arbitrary code via a crafted file, related to a "buffer overflow issue."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-133A.html" source="CERT">TA09-133A</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0513" source="VUPEN" patch="1">ADV-2009-0513</ref>
      <ref url="http://www.securityfocus.com/bid/33880" source="BID" patch="1">33880</ref>
      <ref url="http://www.adobe.com/support/security/bulletins/apsb09-01.html" source="CONFIRM" patch="1" adv="1">http://www.adobe.com/support/security/bulletins/apsb09-01.html</ref>
      <ref url="http://isc.sans.org/diary.html?storyid=5929" source="MISC" patch="1">http://isc.sans.org/diary.html?storyid=5929</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=487142" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=487142</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/48887" source="XF">flash-invalid-object-bo(48887)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1297" source="VUPEN">ADV-2009-1297</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0743" source="VUPEN">ADV-2009-0743</ref>
      <ref url="http://support.apple.com/kb/HT3549" source="CONFIRM">http://support.apple.com/kb/HT3549</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-254909-1" source="SUNALERT">254909</ref>
      <ref url="http://securitytracker.com/id?1021750" source="SECTRACK">1021750</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200903-23.xml" source="GENTOO">GLSA-200903-23</ref>
      <ref url="http://secunia.com/advisories/35074" source="SECUNIA">35074</ref>
      <ref url="http://secunia.com/advisories/34293" source="SECUNIA">34293</ref>
      <ref url="http://secunia.com/advisories/34226" source="SECUNIA">34226</ref>
      <ref url="http://secunia.com/advisories/34012" source="SECUNIA">34012</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2009-0334.html" source="REDHAT">RHSA-2009:0334</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2009-0332.html" source="REDHAT">RHSA-2009:0332</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6593" source="OVAL">oval:org.mitre.oval:def:6593</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2009/May/msg00002.html" source="APPLE">APPLE-SA-2009-05-12</ref>
      <ref url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=773" source="IDEFENSE">20090224 Adobe Flash Player Invalid Object Reference Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="adobe" name="air">
        <vers num="1.5" />
      </prod>
      <prod vendor="adobe" name="flash_player">
        <vers num="10.0.0.584" />
        <vers num="10.0.12.10" />
        <vers prev="1" num="10.0.12.36" />
        <vers num="7.0" />
        <vers num="7.0.1" />
        <vers num="7.0.25" />
        <vers num="7.0.63" edition="" />
        <vers num="7.0.63" edition=":linux" />
        <vers num="7.0.69.0" />
        <vers num="7.0.70.0" />
        <vers num="7.1" />
        <vers num="7.1.1" />
        <vers num="7.2" />
        <vers num="8.0" edition="" />
        <vers num="8.0" edition=":pro" />
        <vers num="8.0" edition=":basic" />
        <vers num="8.0.24.0" />
        <vers num="8.0.34.0" />
        <vers num="8.0.35.0" />
        <vers num="8.0.39.0" />
        <vers num="9.0.112.0" />
        <vers num="9.0.114.0" />
        <vers num="9.0.115.0" />
        <vers num="9.0.124.0" />
        <vers num="9.0.16" />
        <vers num="9.0.20" />
        <vers num="9.0.20.0" />
        <vers num="9.0.28" />
        <vers num="9.0.28.0" />
        <vers num="9.0.31.0" />
        <vers num="9.0.45.0" />
        <vers num="9.0.47.0" />
        <vers num="9.0.48.0" />
        <vers num="cs3" edition="" />
        <vers num="cs3" edition=":pro" />
        <vers num="cs4" edition="" />
        <vers num="cs4" edition=":pro" />
      </prod>
      <prod vendor="adobe" name="flash_player_for_linux">
        <vers prev="1" num="10.0.15.3" />
      </prod>
      <prod vendor="adobe" name="flex">
        <vers num="3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0521" published="2009-02-26" name="CVE-2009-0521" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Untrusted search path vulnerability in Adobe Flash Player 9.x before 9.0.159.0 and 10.x before 10.0.22.87 on Linux allows local users to obtain sensitive information or gain privileges via a crafted library in a directory contained in the RPATH.</descript>
    </desc>
    <sols>
      <sol source="nvd">http://www.adobe.com/support/security/bulletins/apsb09-01.html

"This update prevents a potential Linux-only information disclosure issue in the Flash Player binary that could lead to privilege escalation. (CVE-2009-0521)"</sol>
    </sols>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2009/0513" source="VUPEN" patch="1" adv="1">ADV-2009-0513</ref>
      <ref url="http://www.adobe.com/support/security/bulletins/apsb09-01.html" source="CONFIRM" patch="1" adv="1">http://www.adobe.com/support/security/bulletins/apsb09-01.html</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=487144" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=487144</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/48904" source="XF">flash-unspecified-information-disclosure(48904)</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200903-23.xml" source="GENTOO">GLSA-200903-23</ref>
      <ref url="http://secunia.com/advisories/34226" source="SECUNIA">34226</ref>
      <ref url="http://secunia.com/advisories/34012" source="SECUNIA" adv="1">34012</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2009-0332.html" source="REDHAT">RHSA-2009:0332</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6160" source="OVAL">oval:org.mitre.oval:def:6160</ref>
      <ref url="http://isc.sans.org/diary.html?storyid=5929" source="MISC">http://isc.sans.org/diary.html?storyid=5929</ref>
    </refs>
    <vuln_soft>
      <prod vendor="adobe" name="flash_player_for_linux">
        <vers num="10.0.12.36" />
        <vers prev="1" num="10.0.15.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0522" published="2009-02-26" name="CVE-2009-0522" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Adobe Flash Player 9.x before 9.0.159.0 and 10.x before 10.0.22.87 on Windows allows remote attackers to trick a user into visiting an arbitrary URL via an unspecified manipulation of the "mouse pointer display," related to a "Clickjacking attack."</descript>
    </desc>
    <sols>
      <sol source="nvd">Per: http://www.adobe.com/support/security/bulletins/apsb09-01.html

"This update resolves a Windows-only issue with mouse pointer display that could potentially contribute to a Clickjacking attack. (CVE-2009-0522)"</sol>
    </sols>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.adobe.com/support/security/bulletins/apsb09-01.html" source="CONFIRM" patch="1" adv="1">http://www.adobe.com/support/security/bulletins/apsb09-01.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/48903" source="XF">flash-unspecified-click-hijacking(48903)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0513" source="VUPEN" adv="1">ADV-2009-0513</ref>
      <ref url="http://securitytracker.com/id?1021752" source="SECTRACK">1021752</ref>
      <ref url="http://secunia.com/advisories/34012" source="SECUNIA" adv="1">34012</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6674" source="OVAL">oval:org.mitre.oval:def:6674</ref>
      <ref url="http://isc.sans.org/diary.html?storyid=5929" source="MISC">http://isc.sans.org/diary.html?storyid=5929</ref>
    </refs>
    <vuln_soft>
      <prod vendor="adobe" name="air">
        <vers num="1.5" />
      </prod>
      <prod vendor="adobe" name="flash_player">
        <vers num="10.0.0.584" />
        <vers num="10.0.12.10" />
        <vers prev="1" num="10.0.12.36" />
        <vers num="7.0" />
        <vers num="7.0.1" />
        <vers num="7.0.25" />
        <vers num="7.0.63" edition="" />
        <vers num="7.0.63" edition=":linux" />
        <vers num="7.0.69.0" />
        <vers num="7.0.70.0" />
        <vers num="7.1" />
        <vers num="7.1.1" />
        <vers num="7.2" />
        <vers num="8.0" edition="" />
        <vers num="8.0" edition=":pro" />
        <vers num="8.0" edition=":basic" />
        <vers num="8.0.24.0" />
        <vers num="8.0.34.0" />
        <vers num="8.0.35.0" />
        <vers num="8.0.39.0" />
        <vers num="9.0.112.0" />
        <vers num="9.0.114.0" />
        <vers num="9.0.115.0" />
        <vers num="9.0.124.0" />
        <vers num="9.0.16" />
        <vers num="9.0.20" />
        <vers num="9.0.20.0" />
        <vers num="9.0.28" />
        <vers num="9.0.28.0" />
        <vers num="9.0.31.0" />
        <vers num="9.0.45.0" />
        <vers num="9.0.47.0" />
        <vers num="9.0.48.0" />
        <vers num="cs3" edition="" />
        <vers num="cs3" edition=":pro" />
        <vers num="cs4" edition="" />
        <vers num="cs4" edition=":pro" />
      </prod>
      <prod vendor="adobe" name="flash_player_for_linux">
        <vers prev="1" num="10.0.15.3" />
      </prod>
      <prod vendor="adobe" name="flex">
        <vers num="3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0523" published="2009-02-26" name="CVE-2009-0523" modified="2009-02-27" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Adobe RoboHelp Server 6 and 7 allows remote attackers to inject arbitrary web script or HTML via a crafted URL, which is not properly handled when displaying the Help Errors log.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2009/0512" source="VUPEN" patch="1">ADV-2009-0512</ref>
      <ref url="http://www.securityfocus.com/bid/33887" source="BID" patch="1">33887</ref>
      <ref url="http://www.adobe.com/support/security/bulletins/apsb09-02.html" source="CONFIRM" patch="1" adv="1">http://www.adobe.com/support/security/bulletins/apsb09-02.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/48890" source="XF">robohelp-errors-log-xss(48890)</ref>
      <ref url="http://securitytracker.com/id?1021755" source="SECTRACK">1021755</ref>
      <ref url="http://secunia.com/advisories/34048" source="SECUNIA" adv="1">34048</ref>
    </refs>
    <vuln_soft>
      <prod vendor="adobe" name="robohelp">
        <vers num="6" />
        <vers num="7" />
      </prod>
      <prod vendor="adobe" name="robohelp_server">
        <vers num="6" />
        <vers num="7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0524" published="2009-02-26" name="CVE-2009-0524" modified="2009-02-27" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Adobe RoboHelp 6 and 7, and RoboHelp Server 6 and 7, allows remote attackers to inject arbitrary web script or HTML via vectors involving files produced by RoboHelp.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/33888" source="BID" patch="1">33888</ref>
      <ref url="http://www.adobe.com/support/security/bulletins/apsb09-02.html" source="CONFIRM" patch="1" adv="1">http://www.adobe.com/support/security/bulletins/apsb09-02.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/48889" source="XF">robohelp-generated-files-xss(48889)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0512" source="VUPEN" adv="1">ADV-2009-0512</ref>
      <ref url="http://securitytracker.com/id?1021755" source="SECTRACK">1021755</ref>
      <ref url="http://secunia.com/advisories/34048" source="SECUNIA" adv="1">34048</ref>
      <ref url="http://secunia.com/advisories/34032" source="SECUNIA" adv="1">34032</ref>
    </refs>
    <vuln_soft>
      <prod vendor="adobe" name="robohelp">
        <vers num="6" />
        <vers num="7" />
      </prod>
      <prod vendor="adobe" name="robohelp_server">
        <vers num="6" />
        <vers num="7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0525" published="2009-02-11" name="CVE-2009-0525" modified="2009-02-12" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the sajax_get_common_js function in php/Sajax.php in Sajax 0.12 allows remote attackers to inject arbitrary web script or HTML via the URL parameter, which is not properly handled when using browsers that do not URL-encode requests, such as Internet Explorer 6.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/33711" source="BID">33711</ref>
      <ref url="http://secunia.com/advisories/33894" source="SECUNIA" adv="1">33894</ref>
    </refs>
    <vuln_soft>
      <prod vendor="modernmethod" name="sajax">
        <vers num="0.12" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0526" published="2009-02-11" name="CVE-2009-0526" modified="2009-02-12" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in index.php in AdaptCMS Lite 1.4 allow remote attackers to inject arbitrary web script or HTML via the (1) url and (2) acuparam parameters, and (3) the URI.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/48611" source="XF">adaptcms-index-xss(48611)</ref>
      <ref url="http://www.securityfocus.com/bid/33698" source="BID">33698</ref>
      <ref url="http://www.milw0rm.com/exploits/8016" source="MILW0RM">8016</ref>
      <ref url="http://secunia.com/advisories/33866" source="SECUNIA" adv="1">33866</ref>
    </refs>
    <vuln_soft>
      <prod vendor="adaptcms" name="adaptcms">
        <vers num="1.4" edition="unknown" />
        <vers num="1.4" edition="unknown:lite" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0527" published="2009-02-11" name="CVE-2009-0527" modified="2009-02-12" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in plugins/rss_importer_functions.php in AdaptCMS Lite 1.4 allows remote attackers to execute arbitrary PHP code via a URL in the sitepath parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/48610" source="XF">adaptcms-sitepath-file-include(48610)</ref>
      <ref url="http://www.securityfocus.com/bid/33698" source="BID">33698</ref>
      <ref url="http://www.milw0rm.com/exploits/8016" source="MILW0RM">8016</ref>
      <ref url="http://secunia.com/advisories/33866" source="SECUNIA" adv="1">33866</ref>
    </refs>
    <vuln_soft>
      <prod vendor="adaptcms" name="adaptcms">
        <vers num="1.4" edition="unknown" />
        <vers num="1.4" edition="unknown:lite" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0528" published="2009-02-11" name="CVE-2009-0528" modified="2009-02-12" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in frame.php in Rhadrix If-CMS 2.07 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/33697" source="BID">33697</ref>
      <ref url="http://www.milw0rm.com/exploits/8007" source="MILW0RM">8007</ref>
      <ref url="http://secunia.com/advisories/33883" source="SECUNIA" adv="1">33883</ref>
    </refs>
    <vuln_soft>
      <prod vendor="rhadrix" name="if-cms">
        <vers prev="1" num="2.07" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0529" published="2009-02-11" name="CVE-2009-0529" modified="2009-02-12" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in index.php in SnippetMaster Webpage Editor 2.2.2 allows remote attackers to inject arbitrary web script or HTML via the language parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/33705" source="BID">33705</ref>
      <ref url="http://www.milw0rm.com/exploits/8017" source="MILW0RM">8017</ref>
      <ref url="http://secunia.com/advisories/33865" source="SECUNIA" adv="1">33865</ref>
    </refs>
    <vuln_soft>
      <prod vendor="electrictoad" name="snippetmaster_webpage_editor">
        <vers num="2.2.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0530" published="2009-02-11" name="CVE-2009-0530" modified="2009-03-11" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple PHP remote file inclusion vulnerabilities in SnippetMaster 2.2.2, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the (1) _SESSION[SCRIPT_PATH] parameter to includes/vars.inc.php and the (2) g_pcltar_lib_dir parameter to includes/tar_lib/pcltar.lib.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/33705" source="BID">33705</ref>
      <ref url="http://www.milw0rm.com/exploits/8017" source="MILW0RM">8017</ref>
      <ref url="http://secunia.com/advisories/33865" source="SECUNIA" adv="1">33865</ref>
    </refs>
    <vuln_soft>
      <prod vendor="electrictoad" name="snippetmaster_webpage_editor">
        <vers num="2.2.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0531" published="2009-02-11" name="CVE-2009-0531" modified="2009-03-10" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in gallery/view.asp in A Better Member-Based ASP Photo Gallery before 1.2 allows remote attackers to execute arbitrary SQL commands via the entry parameter.</descript>
    </desc>
    <sols>
      <sol source="nvd">Version 1.2 released which fixed the SQL injection bug. It also properly deletes thumbnails for invalid filetypes (invalid files were removed but the thumbnails remained).

http://www.ontarioabandonedplaces.com/ipguardian/</sol>
    </sols>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/48612" source="XF">bettermember-view-sql-injection(48612)</ref>
      <ref url="http://www.securityfocus.com/bid/33693" source="BID">33693</ref>
      <ref url="http://www.ontarioabandonedplaces.com/ipguardian/gallery/readme.txt" source="CONFIRM" adv="1">http://www.ontarioabandonedplaces.com/ipguardian/gallery/readme.txt</ref>
      <ref url="http://www.milw0rm.com/exploits/8012" source="MILW0RM">8012</ref>
      <ref url="http://secunia.com/advisories/33874" source="SECUNIA" adv="1">33874</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ontarioabandonedplaces" name="a_better_member-based_asp_photo_gallery">
        <vers prev="1" num="1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0532" published="2009-02-11" name="CVE-2009-0532" modified="2009-03-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in password.php in Scripts For Sites (SFS) EZ Baby allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, possibly involving the u2 parameter.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/48547" source="XF">ezbaby-password-xss(48547)</ref>
      <ref url="http://www.securityfocus.com/bid/33635" source="BID">33635</ref>
      <ref url="http://secunia.com/advisories/33989" source="SECUNIA">33989</ref>
    </refs>
    <vuln_soft>
      <prod vendor="scripts-for-sites" name="ez_baby">
        <vers num="-" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0533" published="2009-02-11" name="CVE-2009-0533" modified="2009-03-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in password.php in Scripts for Sites EZ Reminder allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, possibly involving the u2 parameter.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/48548" source="XF">ezreminder-password-xss(48548)</ref>
      <ref url="http://www.securityfocus.com/bid/33641" source="BID">33641</ref>
      <ref url="http://secunia.com/advisories/33989" source="SECUNIA">33989</ref>
    </refs>
    <vuln_soft>
      <prod vendor="scripts-for-sites" name="ez_reminder">
        <vers num="-" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0534" published="2009-02-11" name="CVE-2009-0534" modified="2009-02-12" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in FlexCMS allows remote attackers to execute arbitrary SQL commands via the catId parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/48609" source="XF">flexcms-catid-sql-injection(48609)</ref>
      <ref url="http://www.securityfocus.com/bid/33696" source="BID">33696</ref>
      <ref url="http://www.milw0rm.com/exploits/8018" source="MILW0RM">8018</ref>
    </refs>
    <vuln_soft>
      <prod vendor="flexcms" name="flexcms">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0535" published="2009-02-11" name="CVE-2009-0535" modified="2009-02-12" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Directory traversal vulnerability in export.php in Thyme 1.3 and earlier, when register_globals is disabled, allows remote attackers to read arbitrary files via a .. (dot dot) in the export_to parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.milw0rm.com/exploits/8029" source="MILW0RM">8029</ref>
    </refs>
    <vuln_soft>
      <prod vendor="extrosoft" name="thyme">
        <vers num="1.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0536" published="2009-02-11" name="CVE-2009-0536" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:N/A:N)" CVSS_score="4.9" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="3.9" CVSS_base_score="4.9">
    <desc>
      <descript source="cve">at in bos.rte.cron on IBM AIX 5.2.0, 5.3.0 through 5.3.9, and 6.1.0 through 6.1.2 allows local users to read arbitrary files via unspecified vectors, related to failure to drop root privileges.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/33730" source="BID" patch="1">33730</ref>
      <ref url="http://aix.software.ibm.com/aix/efixes/security/at_advisory.asc" source="CONFIRM" patch="1" adv="1">http://aix.software.ibm.com/aix/efixes/security/at_advisory.asc</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/48660" source="XF">ibm-aix-at-information-disclosure(48660)</ref>
      <ref url="http://www14.software.ibm.com/webapp/set2/subscriptions/pqvcmjd?mode=18&amp;ID=4558" source="CONFIRM" adv="1">http://www14.software.ibm.com/webapp/set2/subscriptions/pqvcmjd?mode=18&amp;ID=4558</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0405" source="VUPEN">ADV-2009-0405</ref>
      <ref url="http://www.securitytracker.com/id?1021704" source="SECTRACK">1021704</ref>
      <ref url="http://www.ibm.com/support/docview.wss?uid=isg1IZ43459" source="AIXAPAR" adv="1">IZ43459</ref>
      <ref url="http://www.ibm.com/support/docview.wss?uid=isg1IZ43458" source="AIXAPAR" adv="1">IZ43458</ref>
      <ref url="http://www.ibm.com/support/docview.wss?uid=isg1IZ43457" source="AIXAPAR" adv="1">IZ43457</ref>
      <ref url="http://www.ibm.com/support/docview.wss?uid=isg1IZ43456" source="AIXAPAR" adv="1">IZ43456</ref>
      <ref url="http://www.ibm.com/support/docview.wss?uid=isg1IZ43455" source="AIXAPAR" adv="1">IZ43455</ref>
      <ref url="http://www.ibm.com/support/docview.wss?uid=isg1IZ43454" source="AIXAPAR" adv="1">IZ43454</ref>
      <ref url="http://www.ibm.com/support/docview.wss?uid=isg1IZ43453" source="AIXAPAR" adv="1">IZ43453</ref>
      <ref url="http://www.ibm.com/support/docview.wss?uid=isg1IZ43452" source="AIXAPAR" adv="1">IZ43452</ref>
      <ref url="http://secunia.com/advisories/33915" source="SECUNIA">33915</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6155" source="OVAL">oval:org.mitre.oval:def:6155</ref>
      <ref url="http://osvdb.org/51952" source="OSVDB">51952</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="aix">
        <vers num="5.2.0" />
        <vers num="5.3.0" />
        <vers num="5.3.7" />
        <vers num="5.3.8" />
        <vers num="5.3.9" />
        <vers num="6.1.0" />
        <vers num="6.1.1" />
        <vers num="6.1.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0537" published="2009-03-09" name="CVE-2009-0537" modified="2009-03-21" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="4.9" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="3.9" CVSS_base_score="4.9">
    <desc>
      <descript source="cve">Integer overflow in the fts_build function in fts.c in libc in (1) OpenBSD 4.4 and earlier and (2) Microsoft Interix 6.0 build 10.0.6030.0 allows context-dependent attackers to cause a denial of service (application crash) via a deep directory tree, related to the fts_level structure member, as demonstrated by (a) du, (b) rm, (c) chmod, and (d) chgrp on OpenBSD; and (e) SearchIndexer.exe on Vista Enterprise.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securitytracker.com/id?1021818" source="SECTRACK">1021818</ref>
      <ref url="http://www.securityfocus.com/bid/34008" source="BID">34008</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/501505/100/0/threaded" source="BUGTRAQ">20090305 libc:fts_*():multiple vendors, Denial-of-service</ref>
      <ref url="http://www.openbsd.org/cgi-bin/cvsweb/src/lib/libc/gen/fts.c.diff?r1=1.41;r2=1.42;f=h" source="CONFIRM" adv="1">http://www.openbsd.org/cgi-bin/cvsweb/src/lib/libc/gen/fts.c.diff?r1=1.41;r2=1.42;f=h</ref>
      <ref url="http://www.openbsd.org/cgi-bin/cvsweb/src/lib/libc/gen/fts.c" source="CONFIRM" adv="1">http://www.openbsd.org/cgi-bin/cvsweb/src/lib/libc/gen/fts.c</ref>
      <ref url="http://www.milw0rm.com/exploits/8163" source="MILW0RM">8163</ref>
      <ref url="http://securityreason.com/achievement_securityalert/60" source="SREASONRES">20090304 libc:fts_*():multiple vendors, Denial-of-service</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="interix">
        <vers num="6.0" edition="" />
        <vers num="6.0" edition=":10.0.6030.0" />
      </prod>
      <prod vendor="openbsd" name="openbsd">
        <vers num="2.0" />
        <vers num="2.1" />
        <vers num="2.2" />
        <vers num="2.3" />
        <vers num="2.4" />
        <vers num="2.5" />
        <vers num="2.6" />
        <vers num="2.7" />
        <vers num="2.8" />
        <vers num="2.9" />
        <vers num="3.0" />
        <vers num="3.1" />
        <vers num="3.2" />
        <vers num="3.3" />
        <vers num="3.4" />
        <vers num="3.5" />
        <vers num="3.6" />
        <vers num="3.7" />
        <vers num="3.8" />
        <vers num="3.9" />
        <vers num="4.0" />
        <vers num="4.1" />
        <vers num="4.2" />
        <vers num="4.3" />
        <vers prev="1" num="4.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0538" published="2009-03-18" name="CVE-2009-0538" modified="2009-04-01" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Format string vulnerability in Symantec pcAnywhere before 12.5 SP1 allows local users to read and modify arbitrary memory locations, and cause a denial of service (application crash) or possibly have unspecified other impact, via format string specifiers in the pathname of a remote control file (aka .CHF file).</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://securityresponse.symantec.com/avcenter/security/Content/2009.03.17.html" source="CONFIRM" patch="1" adv="1">http://securityresponse.symantec.com/avcenter/security/Content/2009.03.17.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/49291" source="XF">symantec-pcanywhere-unspecified-dos(49291)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0755" source="VUPEN">ADV-2009-0755</ref>
      <ref url="http://www.securityfocus.com/bid/33845" source="BID">33845</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/501930/100/0/threaded" source="BUGTRAQ">20090318 Layered Defense Research Advisory: Format String Vulnerablity in Symantec PcAnywhere v10-12.5</ref>
      <ref url="http://www.layereddefense.com/pcanywhere17mar.html" source="MISC" adv="1">http://www.layereddefense.com/pcanywhere17mar.html</ref>
      <ref url="http://securitytracker.com/id?1021855" source="SECTRACK">1021855</ref>
      <ref url="http://secunia.com/advisories/34305" source="SECUNIA">34305</ref>
      <ref url="http://osvdb.org/52797" source="OSVDB">52797</ref>
    </refs>
    <vuln_soft>
      <prod vendor="symantec" name="pcanywhere">
        <vers num="10.0" />
        <vers num="10.5" />
        <vers num="11.0" />
        <vers num="11.0.1" />
        <vers num="11.5" />
        <vers num="11.5.1" />
        <vers num="12.0" />
        <vers num="12.1" />
        <vers prev="1" num="12.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0540" published="2009-02-25" name="CVE-2009-0540" modified="2009-06-09" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Libero 5.3 SP5, and possibly other versions before 5.5 SP1, allows remote attackers to inject arbitrary web script or HTML via the search term field.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/48870" source="XF">libero-searchterm-xss(48870)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0493" source="VUPEN" adv="1">ADV-2009-0493</ref>
      <ref url="http://www.securityfocus.com/bid/33856" source="BID">33856</ref>
      <ref url="http://osvdb.org/52263" source="OSVDB">52263</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2009-02/0243.html" source="FULLDISC">20090222 Libero Cross-Site Scripting Vulnerability - Security Advisory - SOS-09-001</ref>
    </refs>
    <vuln_soft>
      <prod vendor="insightinformatics" name="libero">
        <vers num="5.3" edition="sp5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0541" published="2009-02-25" name="CVE-2009-0541" modified="2009-02-25" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Magento 1.2.0 and 1.2.1.1 allow remote attackers to inject arbitrary web script or HTML via (1) the username field in an admin/ request to index.php, possibly related to the login[username] parameter and the app/code/core/Mage/Admin/Model/Session.php login function; (2) the email address field in an admin/index/forgotpassword/ request to index.php, possibly related to the email parameter and the app/code/core/Mage/Adminhtml/controllers/IndexController.php forgotpasswordAction function; or (3) the return parameter to the default URI under downloader/.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/48878" source="XF">magneto-downloader-xss(48878)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/48877" source="XF">magento-forgotpasswordaction-xss(48877)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/48876" source="XF">magento-login-xss(48876)</ref>
      <ref url="http://www.securityfocus.com/bid/33872" source="BID">33872</ref>
      <ref url="http://securitytracker.com/id?1021746" source="SECTRACK">1021746</ref>
      <ref url="http://secunia.com/advisories/34000" source="SECUNIA" adv="1">34000</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2009-02/0257.html" source="FULLDISC">20090223 Magento Multiple Cross-Site Scripting Vulnerabilities - Security Advisory - SOS-09-002</ref>
    </refs>
    <vuln_soft>
      <prod vendor="magentocommerc" name="magento">
        <vers num="1.2.0" />
        <vers num="1.2.1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0542" published="2009-02-12" name="CVE-2009-0542" modified="2009-06-09" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in ProFTPD Server 1.3.1 through 1.3.2rc2 allows remote attackers to execute arbitrary SQL commands via a "%" (percent) character in the username, which introduces a "'" (single quote) character during variable substitution by mod_sql.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/500852/100/0/threaded" source="BUGTRAQ">20090211 Re: Re: Another SQL injection in ProFTPd with mod_mysql (probably postgres as well)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/500851/100/0/threaded" source="BUGTRAQ">20090210 ProFTPd with mod_mysql Authentication Bypass Exploit</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/500833/100/0/threaded" source="BUGTRAQ">20090210 Re: Another SQL injection in ProFTPd with mod_mysql (probably postgres as well)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/500823/100/0/threaded" source="BUGTRAQ">20090210 Another SQL injection in ProFTPd with mod_mysql (probably postgres as well)</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2009/02/11/5" source="MLIST">[oss-security] 20090211 Re: CVE request for proftpd</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2009/02/11/3" source="MLIST">[oss-security] 20090211 Re: CVE request for proftpd</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2009/02/11/1" source="MLIST">[oss-security] 20090211 CVE request for proftpd</ref>
      <ref url="http://www.milw0rm.com/exploits/8037" source="MILW0RM">8037</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:061" source="MANDRIVA">MDVSA-2009:061</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1730" source="DEBIAN">DSA-1730</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200903-27.xml" source="GENTOO">GLSA-200903-27</ref>
      <ref url="http://secunia.com/advisories/34268" source="SECUNIA">34268</ref>
      <ref url="http://bugs.proftpd.org/show_bug.cgi?id=3180" source="CONFIRM">http://bugs.proftpd.org/show_bug.cgi?id=3180</ref>
    </refs>
    <vuln_soft>
      <prod vendor="proftpd_project" name="proftpd">
        <vers num="1.3.1" />
        <vers num="1.3.2" />
        <vers num="1.3.2_rc2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0543" published="2009-02-12" name="CVE-2009-0543" modified="2009-06-09" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">ProFTPD Server 1.3.1, with NLS support enabled, allows remote attackers to bypass SQL injection protection mechanisms via invalid, encoded multibyte characters, which are not properly handled in (1) mod_sql_mysql and (2) mod_sql_postgres.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.openwall.com/lists/oss-security/2009/02/11/5" source="MLIST">[oss-security] 20090211 Re: CVE request for proftpd</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2009/02/11/4" source="MLIST">[oss-security] 20090211 CVE request for proftpd</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:061" source="MANDRIVA">MDVSA-2009:061</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1730" source="DEBIAN">DSA-1730</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200903-27.xml" source="GENTOO">GLSA-200903-27</ref>
      <ref url="http://secunia.com/advisories/34268" source="SECUNIA">34268</ref>
      <ref url="http://bugs.proftpd.org/show_bug.cgi?id=3173" source="CONFIRM">http://bugs.proftpd.org/show_bug.cgi?id=3173</ref>
    </refs>
    <vuln_soft>
      <prod vendor="proftpd" name="proftpd">
        <vers num="1.3.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0544" published="2009-02-12" name="CVE-2009-0544" modified="2009-05-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in the PyCrypto ARC2 module 2.0.1 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a large ARC2 key length.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/48617" source="XF">pycrypto-arc2module-bo(48617)</ref>
      <ref url="http://www.securityfocus.com/bid/33674" source="BID">33674</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2009/02/12/5" source="MLIST">[oss-security] 20090212 Re: CVE Request: pycrypto</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2009/02/07/1" source="MLIST">[oss-security] 20090207 CVE Request: pycrypto</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:050" source="MANDRIVA">MDVSA-2009:050</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:049" source="MANDRIVA">MDVSA-2009:049</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200903-11.xml" source="GENTOO">GLSA-200903-11</ref>
      <ref url="http://secunia.com/advisories/35065" source="SECUNIA">35065</ref>
      <ref url="http://secunia.com/advisories/34199" source="SECUNIA">34199</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-05/msg00000.html" source="SUSE">SUSE-SR:2009:010</ref>
      <ref url="http://gitweb2.dlitz.net/?p=crypto/pycrypto-2.x.git;a=commitdiff;h=fd73731dfad451a81056fbb01e09aa78ab82eb5d" source="CONFIRM">http://gitweb2.dlitz.net/?p=crypto/pycrypto-2.x.git;a=commitdiff;h=fd73731dfad451a81056fbb01e09aa78ab82eb5d</ref>
      <ref url="http://gitweb2.dlitz.net/?p=crypto/pycrypto-2.x.git;a=commitdiff;h=d1c4875e1f220652fe7ff8358f56dee3b2aba31b" source="CONFIRM">http://gitweb2.dlitz.net/?p=crypto/pycrypto-2.x.git;a=commitdiff;h=d1c4875e1f220652fe7ff8358f56dee3b2aba31b</ref>
    </refs>
    <vuln_soft>
      <prod vendor="pycrypto" name="arc2">
        <vers num="2.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0545" published="2009-02-12" name="CVE-2009-0545" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">cgi-bin/kerbynet in ZeroShell 1.0beta11 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the type parameter in a NoAuthREQ x509List action.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.zeroshell.net/eng/patch-details/#C100" source="MISC" patch="1">http://www.zeroshell.net/eng/patch-details/#C100</ref>
      <ref url="http://www.zeroshell.net/eng/announcements/" source="MISC" patch="1" adv="1">http://www.zeroshell.net/eng/announcements/</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0385" source="VUPEN">ADV-2009-0385</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/500763/100/0/threaded" source="BUGTRAQ">20090209 ZeroShell &lt;= 1.0beta11 Remote Code Execution</ref>
      <ref url="http://www.milw0rm.com/exploits/8023" source="MILW0RM">8023</ref>
      <ref url="http://www.ikkisoft.com/stuff/LC-2009-01.txt" source="MISC">http://www.ikkisoft.com/stuff/LC-2009-01.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="zeroshell" name="zeroshell">
        <vers num="1.0" edition="beta1" />
        <vers num="1.0" edition="beta10" />
        <vers num="1.0" edition="beta11" />
        <vers num="1.0" edition="beta2" />
        <vers num="1.0" edition="beta3" />
        <vers num="1.0" edition="beta4" />
        <vers num="1.0" edition="beta5" />
        <vers num="1.0" edition="beta6" />
        <vers num="1.0" edition="beta7" />
        <vers num="1.0" edition="beta8" />
        <vers num="1.0" edition="beta9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0546" published="2009-02-12" name="CVE-2009-0546" modified="2009-02-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Stack-based buffer overflow in NewsGator FeedDemon 2.7 and earlier allows user-assisted remote attackers to execute arbitrary code via a long text attribute in an outline element in a .opml file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/33630" source="BID">33630</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/500686/100/0/threaded" source="BUGTRAQ">20090205 [SVRT-02-09] FeedDemon (ver&lt;=2.7) Buffer Overflow Vulnerability</ref>
      <ref url="http://www.milw0rm.com/exploits/8010" source="MILW0RM">8010</ref>
      <ref url="http://www.milw0rm.com/exploits/7995" source="MILW0RM">7995</ref>
      <ref url="http://security.bkis.vn/?p=329" source="MISC">http://security.bkis.vn/?p=329</ref>
      <ref url="http://secunia.com/advisories/33718" source="SECUNIA" adv="1">33718</ref>
      <ref url="http://osvdb.org/51753" source="OSVDB">51753</ref>
    </refs>
    <vuln_soft>
      <prod vendor="newsgator" name="feeddemon">
        <vers num="2.0.0.24" />
        <vers num="2.6" />
        <vers num="2.6.1.4" />
        <vers num="2.6.1.5" />
        <vers prev="1" num="2.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0547" published="2009-02-12" name="CVE-2009-0547" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Evolution 2.22.3.1 checks S/MIME signatures against a copy of the e-mail text within a signed-data blob, not the copy of the e-mail text displayed to the user, which allows remote attackers to spoof a signature by modifying the latter copy, a different vulnerability than CVE-2008-5077.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-March/msg00672.html" source="FEDORA">FEDORA-2009-2792</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-March/msg00666.html" source="FEDORA">FEDORA-2009-2784</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=484925" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=484925</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1107" source="VUPEN">ADV-2010-1107</ref>
      <ref url="http://www.securityfocus.com/bid/33720" source="BID">33720</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-0355.html" source="REDHAT">RHSA-2009:0355</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-0354.html" source="REDHAT">RHSA-2009:0354</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:078" source="MANDRIVA">MDVSA-2009:078</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1813" source="DEBIAN">DSA-1813</ref>
      <ref url="http://secunia.com/advisories/38915" source="SECUNIA">38915</ref>
      <ref url="http://secunia.com/advisories/35357" source="SECUNIA">35357</ref>
      <ref url="http://secunia.com/advisories/34363" source="SECUNIA">34363</ref>
      <ref url="http://secunia.com/advisories/34339" source="SECUNIA">34339</ref>
      <ref url="http://secunia.com/advisories/34338" source="SECUNIA">34338</ref>
      <ref url="http://secunia.com/advisories/33848" source="SECUNIA" adv="1">33848</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9619" source="OVAL">oval:org.mitre.oval:def:9619</ref>
      <ref url="http://openwall.com/lists/oss-security/2009/02/10/7" source="MLIST">[oss-security] 20090210 CVE Request -- evolution</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-05/msg00002.html" source="SUSE">SUSE-SR:2010:012</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-05/msg00001.html" source="SUSE">SUSE-SR:2010:011</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-03/msg00004.html" source="SUSE">SUSE-SR:2010:006</ref>
      <ref url="http://bugzilla.gnome.org/show_bug.cgi?id=564465" source="CONFIRM">http://bugzilla.gnome.org/show_bug.cgi?id=564465</ref>
      <ref url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=508479" source="MISC">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=508479</ref>
    </refs>
    <vuln_soft>
      <prod vendor="evolution" name="evolution">
        <vers num="2.22.3.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0548" published="2009-02-12" name="CVE-2009-0548" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the Additional Report Settings interface in ESET Remote Administrator before 3.0.105 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.  NOTE: some of these details are obtained from third party information.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2009/0339" source="VUPEN">ADV-2009-0339</ref>
      <ref url="http://www.eset.eu/support/changelog-eset-remote-administrator-3" source="CONFIRM" adv="1">http://www.eset.eu/support/changelog-eset-remote-administrator-3</ref>
      <ref url="http://secunia.com/advisories/33805" source="SECUNIA" adv="1">33805</ref>
      <ref url="http://osvdb.org/51804" source="OSVDB">51804</ref>
    </refs>
    <vuln_soft>
      <prod vendor="eset" name="remote_administrator">
        <vers prev="1" num="3.0.35" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0549" published="2009-06-10" name="CVE-2009-0549" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Excel in Microsoft Office 2000 SP3, Office XP SP3, Office 2003 SP3, and Office 2004 and 2008 for Mac; Open XML File Format Converter for Mac; and Microsoft Office Excel Viewer 2003 SP3 allow remote attackers to execute arbitrary code via a crafted Excel file with a malformed record object, aka "Record Pointer Corruption Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-160A.html" source="CERT">TA09-160A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS09-021.mspx" source="MS" patch="1" adv="1">MS09-021</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1540" source="VUPEN">ADV-2009-1540</ref>
      <ref url="http://www.securitytracker.com/id?1022351" source="SECTRACK">1022351</ref>
      <ref url="http://www.securityfocus.com/bid/35215" source="BID">35215</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5830" source="OVAL">oval:org.mitre.oval:def:5830</ref>
      <ref url="http://osvdb.org/54952" source="OSVDB">54952</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="office">
        <vers num="2004" edition="" />
        <vers num="2004" edition=":mac" />
        <vers num="2008" edition="" />
        <vers num="2008" edition=":mac" />
        <vers num="xp" edition="sp3" />
      </prod>
      <prod vendor="microsoft" name="office_compatibility_pack_for_word_excel_ppt_2007">
        <vers num="" edition="sp1" />
        <vers num="" edition="sp2" />
      </prod>
      <prod vendor="microsoft" name="office_excel">
        <vers num="2000" edition="sp3" />
        <vers num="2003" edition="sp3" />
        <vers num="2007" edition="sp1" />
        <vers num="2007" edition="sp2" />
      </prod>
      <prod vendor="microsoft" name="office_excel_viewer">
        <vers num="2003" edition="sp3" />
      </prod>
      <prod vendor="microsoft" name="office_sharepoint_server">
        <vers num="2007" edition="sp1" />
        <vers num="2007" edition="sp1:x64" />
        <vers num="2007" edition="sp1:x32" />
        <vers num="2007" edition="sp2" />
        <vers num="2007" edition="sp2:x64" />
        <vers num="2007" edition="sp2:x32" />
      </prod>
      <prod vendor="microsoft" name="open_xml_file_format_converter">
        <vers num="" edition=":mac" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0550" published="2009-04-15" name="CVE-2009-0550" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Windows HTTP Services (aka WinHTTP) in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008; and WinINet in Microsoft Internet Explorer 5.01 SP4, 6 SP1, 6 and 7 on Windows XP SP2 and SP3, 6 and 7 on Windows Server 2003 SP1 and SP2, 7 on Windows Vista Gold and SP1, and 7 on Windows Server 2008; allows remote web servers to capture and replay NTLM credentials, and execute arbitrary code, via vectors related to absence of a "credential-reflection protections" opt-in step, aka "Windows HTTP Services Credential Reflection Vulnerability" and "WinINet Credential Reflection Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-104A.html" source="CERT">TA09-104A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS09-014.mspx" source="MS" patch="1" adv="1">MS09-014</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS09-013.mspx" source="MS" patch="1" adv="1">MS09-013</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1028" source="VUPEN">ADV-2009-1028</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1027" source="VUPEN">ADV-2009-1027</ref>
      <ref url="http://www.securitytracker.com/id?1022041" source="SECTRACK">1022041</ref>
      <ref url="http://www.securityfocus.com/bid/34439" source="BID">34439</ref>
      <ref url="http://support.nortel.com/go/main.jsp?cscat=BLTNDETAIL&amp;id=871138" source="CONFIRM">http://support.nortel.com/go/main.jsp?cscat=BLTNDETAIL&amp;id=871138</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2009-133.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2009-133.htm</ref>
      <ref url="http://secunia.com/advisories/34678" source="SECUNIA">34678</ref>
      <ref url="http://secunia.com/advisories/34677" source="SECUNIA">34677</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7569" source="OVAL">oval:org.mitre.oval:def:7569</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6233" source="OVAL">oval:org.mitre.oval:def:6233</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5320" source="OVAL">oval:org.mitre.oval:def:5320</ref>
      <ref url="http://osvdb.org/53619" source="OSVDB">53619</ref>
      <ref url="http://blogs.technet.com/srd/archive/2009/04/14/ntlm-credential-reflection-updates-for-http-clients.aspx" source="MISC">http://blogs.technet.com/srd/archive/2009/04/14/ntlm-credential-reflection-updates-for-http-clients.aspx</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="5.01" edition="sp4" />
        <vers num="6.0" edition="sp1" />
      </prod>
      <prod vendor="microsoft" name="internet_explorer">
        <vers num="6" />
        <vers num="7" />
      </prod>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition="sp4" />
      </prod>
      <prod vendor="microsoft" name="windows_server_2003">
        <vers num="" edition=":x64" />
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:itanium" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:itanium" />
        <vers num="" edition="sp2:x64" />
      </prod>
      <prod vendor="microsoft" name="windows_server_2008">
        <vers num="" edition=":32_bit" />
        <vers num="" edition=":x32" />
        <vers num="" edition=":itanium" />
        <vers num="" edition=":x64" />
      </prod>
      <prod vendor="microsoft" name="windows_vista">
        <vers num="" edition=":x64" />
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:x64" />
        <vers num="gold" />
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition=":x64" />
        <vers num="" edition=":pro_x64" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:pro_x64" />
        <vers num="" edition="sp2:x64" />
        <vers num="" edition="sp3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0551" published="2009-04-15" name="CVE-2009-0551" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Microsoft Internet Explorer 6 SP1, 6 and 7 on Windows XP SP2 and SP3, 6 and 7 on Windows Server 2003 SP1 and SP2, 7 on Windows Vista Gold and SP1, and 7 on Windows Server 2008 does not properly handle transition errors in a request for one HTTP document followed by a request for a second HTTP document, which allows remote attackers to execute arbitrary code via vectors involving (1) multiple crafted pages on a web site or (2) a web page with crafted inline content such as banner advertisements, aka "Page Transition Memory Corruption Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-104A.html" source="CERT">TA09-104A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS09-014.mspx" source="MS" patch="1" adv="1">MS09-014</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1028" source="VUPEN">ADV-2009-1028</ref>
      <ref url="http://www.securitytracker.com/id?1022042" source="SECTRACK">1022042</ref>
      <ref url="http://support.nortel.com/go/main.jsp?cscat=BLTNDETAIL&amp;id=871138" source="CONFIRM">http://support.nortel.com/go/main.jsp?cscat=BLTNDETAIL&amp;id=871138</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2009-133.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2009-133.htm</ref>
      <ref url="http://secunia.com/advisories/34678" source="SECUNIA">34678</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6164" source="OVAL">oval:org.mitre.oval:def:6164</ref>
      <ref url="http://osvdb.org/53624" source="OSVDB">53624</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="internet_explorer">
        <vers num="6" edition="sp1" />
        <vers num="7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0552" published="2009-04-15" name="CVE-2009-0552" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Unspecified vulnerability in Microsoft Internet Explorer 5.01 SP4, 6 SP1, 6 on Windows XP SP2 and SP3, and 6 on Windows Server 2003 SP1 and SP2 allows remote attackers to execute arbitrary code via a web page that triggers presence of an object in memory that was (1) not properly initialized or (2) deleted, aka "Uninitialized Memory Corruption Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-104A.html" source="CERT">TA09-104A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS09-014.mspx" source="MS" patch="1" adv="1">MS09-014</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1028" source="VUPEN">ADV-2009-1028</ref>
      <ref url="http://www.securitytracker.com/id?1022042" source="SECTRACK">1022042</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2009-133.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2009-133.htm</ref>
      <ref url="http://secunia.com/advisories/34678" source="SECUNIA">34678</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5551" source="OVAL">oval:org.mitre.oval:def:5551</ref>
      <ref url="http://osvdb.org/53625" source="OSVDB">53625</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="5.0.1" edition="sp4" />
        <vers num="6" />
        <vers num="6.0" edition="sp1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0553" published="2009-04-15" name="CVE-2009-0553" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Microsoft Internet Explorer 6 SP1, 6 and 7 on Windows XP SP2 and SP3, 6 and 7 on Windows Server 2003 SP1 and SP2, 7 on Windows Vista Gold and SP1, and 7 on Windows Server 2008 allows remote attackers to execute arbitrary code via a web page that triggers presence of an object in memory that was (1) not properly initialized or (2) deleted, aka "Uninitialized Memory Corruption Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-104A.html" source="CERT">TA09-104A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS09-014.mspx" source="MS" patch="1" adv="1">MS09-014</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1028" source="VUPEN">ADV-2009-1028</ref>
      <ref url="http://www.securitytracker.com/id?1022042" source="SECTRACK">1022042</ref>
      <ref url="http://www.securityfocus.com/bid/34424" source="BID">34424</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2009-133.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2009-133.htm</ref>
      <ref url="http://skypher.com/index.php/2009/04/19/ms09-014-embed-element-memory-corruption/" source="MISC">http://skypher.com/index.php/2009/04/19/ms09-014-embed-element-memory-corruption/</ref>
      <ref url="http://secunia.com/advisories/34678" source="SECUNIA">34678</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6069" source="OVAL">oval:org.mitre.oval:def:6069</ref>
      <ref url="http://osvdb.org/53626" source="OSVDB">53626</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0554" published="2009-04-15" name="CVE-2009-0554" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Microsoft Internet Explorer 5.01 SP4, 6 SP1, 6 and 7 on Windows XP SP2 and SP3, 6 and 7 on Windows Server 2003 SP1 and SP2, 7 on Windows Vista Gold and SP1, and 7 on Windows Server 2008 allows remote attackers to execute arbitrary code via a web page that triggers presence of an object in memory that was (1) not properly initialized or (2) deleted, aka "Uninitialized Memory Corruption Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-104A.html" source="CERT">TA09-104A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS09-014.mspx" source="MS" patch="1" adv="1">MS09-014</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1028" source="VUPEN">ADV-2009-1028</ref>
      <ref url="http://www.securitytracker.com/id?1022042" source="SECTRACK">1022042</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2009-133.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2009-133.htm</ref>
      <ref url="http://secunia.com/advisories/34678" source="SECUNIA">34678</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5723" source="OVAL">oval:org.mitre.oval:def:5723</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="internet_explorer">
        <vers num="5.01" edition="sp4" />
        <vers num="6" edition="sp1" />
        <vers num="7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0555" published="2009-10-14" name="CVE-2009-0555" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Microsoft Windows Media Runtime, as used in DirectShow WMA Voice Codec, Windows Media Audio Voice Decoder, and Audio Compression Manager (ACM), does not properly process Advanced Systems Format (ASF) files, which allows remote attackers to execute arbitrary code via a crafted audio file that uses the Windows Media Speech codec, aka "Windows Media Runtime Voice Sample Rate Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-286A.html" source="CERT">TA09-286A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS09-051.mspx" source="MS" patch="1" adv="1">MS09-051</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6407" source="OVAL">oval:org.mitre.oval:def:6407</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_media_format_runtime">
        <vers num="11" />
        <vers num="9.0" />
        <vers num="9.5" />
      </prod>
      <prod vendor="microsoft" name="windows_media_player">
        <vers num="9" />
      </prod>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition="sp4" />
      </prod>
      <prod vendor="microsoft" name="windows_server_2003">
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:x64" />
      </prod>
      <prod vendor="microsoft" name="windows_server_2008">
        <vers num="" edition=":x64" />
        <vers num="" edition=":x32" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:x64" />
        <vers num="" edition="sp2:x32" />
      </prod>
      <prod vendor="microsoft" name="windows_vista">
        <vers num="" edition=":x64" />
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:x64" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:x64" />
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:x64" />
        <vers num="" edition="sp3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0556" published="2009-04-03" name="CVE-2009-0556" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Microsoft Office PowerPoint 2000 SP3, 2002 SP3, and 2003 SP3, and PowerPoint in Microsoft Office 2004 for Mac, allows remote attackers to execute arbitrary code via a PowerPoint file with an OutlineTextRefAtom containing an an invalid index value that triggers memory corruption, as exploited in the wild in April 2009 by Exploit:Win32/Apptom.gen, aka "Memory Corruption Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-132A.html" source="CERT">TA09-132A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/627331" source="CERT-VN">VU#627331</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS09-017.mspx" source="MS" patch="1" adv="1">MS09-017</ref>
      <ref url="http://www.microsoft.com/technet/security/advisory/969136.mspx" source="CONFIRM" patch="1" adv="1">http://www.microsoft.com/technet/security/advisory/969136.mspx</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/49632" source="XF">powerpoint-unspecified-code-execution(49632)</ref>
      <ref url="http://www.zerodayinitiative.com/advisories/ZDI-09-019" source="MISC">http://www.zerodayinitiative.com/advisories/ZDI-09-019</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1290" source="VUPEN">ADV-2009-1290</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0915" source="VUPEN" adv="1">ADV-2009-0915</ref>
      <ref url="http://www.securitytracker.com/id?1021967" source="SECTRACK">1021967</ref>
      <ref url="http://www.securityfocus.com/bid/34351" source="BID">34351</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/503453/100/0/threaded" source="BUGTRAQ">20090512 ZDI-09-019: Microsoft Office PowerPoint OutlineTextRefAtom Parsing Memory Corruption Vulnerability</ref>
      <ref url="http://secunia.com/advisories/34572" source="SECUNIA" adv="1">34572</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6279" source="OVAL">oval:org.mitre.oval:def:6279</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6204" source="OVAL">oval:org.mitre.oval:def:6204</ref>
      <ref url="http://osvdb.org/53182" source="OSVDB">53182</ref>
      <ref url="http://blogs.technet.com/srd/archive/2009/04/02/investigating-the-new-powerpoint-issue.aspx" source="CONFIRM" adv="1">http://blogs.technet.com/srd/archive/2009/04/02/investigating-the-new-powerpoint-issue.aspx</ref>
      <ref url="http://blogs.technet.com/msrc/archive/2009/04/02/microsoft-security-advisory-969136.aspx" source="CONFIRM" adv="1">http://blogs.technet.com/msrc/archive/2009/04/02/microsoft-security-advisory-969136.aspx</ref>
      <ref url="http://blogs.technet.com/mmpc/archive/2009/04/02/new-0-day-exploits-using-powerpoint-files.aspx" source="CONFIRM" adv="1">http://blogs.technet.com/mmpc/archive/2009/04/02/new-0-day-exploits-using-powerpoint-files.aspx</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="office_powerpoint">
        <vers num="2004" />
      </prod>
      <prod vendor="microsoft" name="powerpoint">
        <vers num="2000" edition="sp3" />
        <vers num="2002" edition="sp3" />
        <vers num="2003" edition="sp3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0557" published="2009-06-10" name="CVE-2009-0557" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Excel in Microsoft Office 2000 SP3, Office XP SP3, Office 2003 SP3, and Office 2004 and 2008 for Mac; Excel in 2007 Microsoft Office System SP1 and SP2; Open XML File Format Converter for Mac; Microsoft Office Excel Viewer 2003 SP3; Microsoft Office Excel Viewer; and Microsoft Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2 allow remote attackers to execute arbitrary code via a crafted Excel file with a malformed record object, aka "Object Record Corruption Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-160A.html" source="CERT">TA09-160A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS09-021.mspx" source="MS" patch="1" adv="1">MS09-021</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1540" source="VUPEN">ADV-2009-1540</ref>
      <ref url="http://www.securitytracker.com/id?1022351" source="SECTRACK">1022351</ref>
      <ref url="http://www.securityfocus.com/bid/35241" source="BID">35241</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5564" source="OVAL">oval:org.mitre.oval:def:5564</ref>
      <ref url="http://osvdb.org/54953" source="OSVDB">54953</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="office">
        <vers num="2004" edition="" />
        <vers num="2004" edition=":mac" />
        <vers num="2008" edition="" />
        <vers num="2008" edition=":mac" />
        <vers num="xp" edition="sp3" />
      </prod>
      <prod vendor="microsoft" name="office_compatibility_pack_for_word_excel_ppt_2007">
        <vers num="" edition="sp1" />
        <vers num="" edition="sp2" />
      </prod>
      <prod vendor="microsoft" name="office_excel">
        <vers num="2000" edition="sp3" />
        <vers num="2003" edition="sp3" />
        <vers num="2007" edition="sp1" />
        <vers num="2007" edition="sp2" />
      </prod>
      <prod vendor="microsoft" name="office_excel_viewer">
        <vers num="2003" edition="sp3" />
      </prod>
      <prod vendor="microsoft" name="office_sharepoint_server">
        <vers num="2007" edition="sp1" />
        <vers num="2007" edition="sp1:x64" />
        <vers num="2007" edition="sp1:x32" />
        <vers num="2007" edition="sp2" />
        <vers num="2007" edition="sp2:x64" />
        <vers num="2007" edition="sp2:x32" />
      </prod>
      <prod vendor="microsoft" name="open_xml_file_format_converter">
        <vers num="" edition=":mac" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0558" published="2009-06-10" name="CVE-2009-0558" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Array index error in Excel in Microsoft Office 2000 SP3 and Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac, allows remote attackers to execute arbitrary code via a crafted Excel file with a malformed record object, aka "Array Indexing Memory Corruption Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-160A.html" source="CERT">TA09-160A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS09-021.mspx" source="MS" patch="1" adv="1">MS09-021</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1540" source="VUPEN">ADV-2009-1540</ref>
      <ref url="http://www.securitytracker.com/id?1022351" source="SECTRACK">1022351</ref>
      <ref url="http://www.securityfocus.com/bid/35242" source="BID">35242</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/504188/100/0/threaded" source="BUGTRAQ">20090609 Secunia Research: Microsoft Excel Record Parsing Array Indexing Vulnerability</ref>
      <ref url="http://secunia.com/secunia_research/2009-1/" source="MISC" adv="1">http://secunia.com/secunia_research/2009-1/</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11525" source="OVAL">oval:org.mitre.oval:def:11525</ref>
      <ref url="http://osvdb.org/54954" source="OSVDB">54954</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="office">
        <vers num="2004" edition="" />
        <vers num="2004" edition=":mac" />
        <vers num="2008" edition="" />
        <vers num="2008" edition=":mac" />
        <vers num="xp" edition="sp3" />
      </prod>
      <prod vendor="microsoft" name="office_compatibility_pack_for_word_excel_ppt_2007">
        <vers num="" edition="sp1" />
        <vers num="" edition="sp2" />
      </prod>
      <prod vendor="microsoft" name="office_excel">
        <vers num="2000" edition="sp3" />
        <vers num="2003" edition="sp3" />
        <vers num="2007" edition="sp1" />
        <vers num="2007" edition="sp2" />
      </prod>
      <prod vendor="microsoft" name="office_excel_viewer">
        <vers num="2003" edition="sp3" />
      </prod>
      <prod vendor="microsoft" name="office_sharepoint_server">
        <vers num="2007" edition="sp1" />
        <vers num="2007" edition="sp1:x64" />
        <vers num="2007" edition="sp1:x32" />
        <vers num="2007" edition="sp2" />
        <vers num="2007" edition="sp2:x64" />
        <vers num="2007" edition="sp2:x32" />
      </prod>
      <prod vendor="microsoft" name="open_xml_file_format_converter">
        <vers num="" edition=":mac" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0559" published="2009-06-10" name="CVE-2009-0559" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Stack-based buffer overflow in Excel in Microsoft Office 2000 SP3 and Office XP SP3 allows remote attackers to execute arbitrary code via a crafted Excel file with a malformed record object, aka "String Copy Stack-Based Overrun Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-160A.html" source="CERT">TA09-160A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS09-021.mspx" source="MS" patch="1" adv="1">MS09-021</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1540" source="VUPEN">ADV-2009-1540</ref>
      <ref url="http://www.securitytracker.com/id?1022351" source="SECTRACK">1022351</ref>
      <ref url="http://www.securityfocus.com/bid/35243" source="BID">35243</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6273" source="OVAL">oval:org.mitre.oval:def:6273</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="office">
        <vers num="2004" edition="" />
        <vers num="2004" edition=":mac" />
        <vers num="2008" edition="" />
        <vers num="2008" edition=":mac" />
        <vers num="xp" edition="sp3" />
      </prod>
      <prod vendor="microsoft" name="office_compatibility_pack_for_word_excel_ppt_2007">
        <vers num="" edition="sp1" />
        <vers num="" edition="sp2" />
      </prod>
      <prod vendor="microsoft" name="office_excel">
        <vers num="2000" edition="sp3" />
        <vers num="2003" edition="sp3" />
        <vers num="2007" edition="sp1" />
        <vers num="2007" edition="sp2" />
      </prod>
      <prod vendor="microsoft" name="office_excel_viewer">
        <vers num="2003" edition="sp3" />
      </prod>
      <prod vendor="microsoft" name="office_sharepoint_server">
        <vers num="2007" edition="sp1" />
        <vers num="2007" edition="sp1:x64" />
        <vers num="2007" edition="sp1:x32" />
        <vers num="2007" edition="sp2" />
        <vers num="2007" edition="sp2:x64" />
        <vers num="2007" edition="sp2:x32" />
      </prod>
      <prod vendor="microsoft" name="open_xml_file_format_converter">
        <vers num="" edition=":mac" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0560" published="2009-06-10" name="CVE-2009-0560" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Excel in Microsoft Office 2000 SP3, Office XP SP3, Office 2003 SP3, and Office 2004 and 2008 for Mac; Excel in 2007 Microsoft Office System SP1 and SP2; Open XML File Format Converter for Mac; Microsoft Office Excel Viewer 2003 SP3; Microsoft Office Excel Viewer; and Microsoft Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2 allow remote attackers to execute arbitrary code via a crafted Excel file with a malformed record object, aka "Field Sanitization Memory Corruption Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-160A.html" source="CERT">TA09-160A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS09-021.mspx" source="MS" patch="1" adv="1">MS09-021</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1540" source="VUPEN">ADV-2009-1540</ref>
      <ref url="http://www.securitytracker.com/id?1022351" source="SECTRACK">1022351</ref>
      <ref url="http://www.securityfocus.com/bid/35244" source="BID">35244</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6178" source="OVAL">oval:org.mitre.oval:def:6178</ref>
      <ref url="http://osvdb.org/54956" source="OSVDB">54956</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="office">
        <vers num="2004" edition="" />
        <vers num="2004" edition=":mac" />
        <vers num="2008" edition="" />
        <vers num="2008" edition=":mac" />
        <vers num="xp" edition="sp3" />
      </prod>
      <prod vendor="microsoft" name="office_compatibility_pack_for_word_excel_ppt_2007">
        <vers num="" edition="sp1" />
        <vers num="" edition="sp2" />
      </prod>
      <prod vendor="microsoft" name="office_excel">
        <vers num="2000" edition="sp3" />
        <vers num="2003" edition="sp3" />
        <vers num="2007" edition="sp1" />
        <vers num="2007" edition="sp2" />
      </prod>
      <prod vendor="microsoft" name="office_excel_viewer">
        <vers num="2003" edition="sp3" />
      </prod>
      <prod vendor="microsoft" name="office_sharepoint_server">
        <vers num="2007" edition="sp1" />
        <vers num="2007" edition="sp1:x64" />
        <vers num="2007" edition="sp1:x32" />
        <vers num="2007" edition="sp2" />
        <vers num="2007" edition="sp2:x64" />
        <vers num="2007" edition="sp2:x32" />
      </prod>
      <prod vendor="microsoft" name="open_xml_file_format_converter">
        <vers num="" edition=":mac" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0561" published="2009-06-10" name="CVE-2009-0561" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Integer overflow in Excel in Microsoft Office 2000 SP3, Office XP SP3, Office 2003 SP3, and Office 2004 and 2008 for Mac; Excel in 2007 Microsoft Office System SP1 and SP2; Open XML File Format Converter for Mac; Microsoft Office Excel Viewer 2003 SP3; Microsoft Office Excel Viewer; Microsoft Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2; and Microsoft Office SharePoint Server 2007 SP1 and SP2 allows remote attackers to execute arbitrary code via an Excel file with a Shared String Table (SST) record with a numeric field that specifies an invalid number of unique strings, which triggers a heap-based buffer overflow, aka "Record Integer Overflow Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-160A.html" source="CERT">TA09-160A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS09-021.mspx" source="MS" patch="1" adv="1">MS09-021</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1540" source="VUPEN" adv="1">ADV-2009-1540</ref>
      <ref url="http://www.securitytracker.com/id?1022351" source="SECTRACK">1022351</ref>
      <ref url="http://www.securityfocus.com/bid/35245" source="BID">35245</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/504190/100/0/threaded" source="BUGTRAQ">20090609 Secunia Research: Microsoft Excel String Parsing Integer Overflow Vulnerability</ref>
      <ref url="http://secunia.com/secunia_research/2009-12/" source="MISC" adv="1">http://secunia.com/secunia_research/2009-12/</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5925" source="OVAL">oval:org.mitre.oval:def:5925</ref>
      <ref url="http://osvdb.org/54957" source="OSVDB">54957</ref>
      <ref url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=805" source="IDEFENSE">20090609 Microsoft Excel SST Record Integer Overflow Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="office">
        <vers num="2004" edition="" />
        <vers num="2004" edition=":mac" />
        <vers num="2008" edition="" />
        <vers num="2008" edition=":mac" />
        <vers num="xp" edition="sp3" />
      </prod>
      <prod vendor="microsoft" name="office_compatibility_pack_for_word_excel_ppt_2007">
        <vers num="" edition="sp1" />
        <vers num="" edition="sp2" />
      </prod>
      <prod vendor="microsoft" name="office_excel">
        <vers num="2000" edition="sp3" />
        <vers num="2003" edition="sp3" />
        <vers num="2007" edition="sp1" />
        <vers num="2007" edition="sp2" />
      </prod>
      <prod vendor="microsoft" name="office_excel_viewer">
        <vers num="2003" edition="sp3" />
      </prod>
      <prod vendor="microsoft" name="office_sharepoint_server">
        <vers num="2007" edition="sp1" />
        <vers num="2007" edition="sp1:x64" />
        <vers num="2007" edition="sp1:x32" />
        <vers num="2007" edition="sp2" />
        <vers num="2007" edition="sp2:x64" />
        <vers num="2007" edition="sp2:x32" />
      </prod>
      <prod vendor="microsoft" name="open_xml_file_format_converter">
        <vers num="" edition=":mac" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0562" published="2009-08-12" name="CVE-2009-0562" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">The Office Web Components ActiveX Control in Microsoft Office XP SP3, Office 2003 SP3, Office XP Web Components SP3, Office 2003 Web Components SP3, Office 2003 Web Components SP1 for the 2007 Microsoft Office System, Internet Security and Acceleration (ISA) Server 2004 SP3 and 2006 SP1, and Office Small Business Accounting 2006 does not properly allocate memory, which allows remote attackers to execute arbitrary code via unspecified vectors that trigger "system state" corruption, aka "Office Web Components Memory Allocation Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-223A.html" source="CERT">TA09-223A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS09-043.mspx" source="MS" patch="1" adv="1">MS09-043</ref>
      <ref url="http://www.securitytracker.com/id?1022708" source="SECTRACK">1022708</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6337" source="OVAL">oval:org.mitre.oval:def:6337</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="isa_server">
        <vers num="2004" edition="sp3" />
        <vers num="2004" edition="sp3:standard" />
        <vers num="2004" edition="sp3:enterprise" />
        <vers num="2006" edition="sp1" />
        <vers num="2006" edition="sp1:standard" />
        <vers num="2006" edition="sp1:enterprise" />
      </prod>
      <prod vendor="microsoft" name="office">
        <vers num="-" edition="" />
        <vers num="-" edition=":small_business_accounting_2006" />
        <vers num="2003" edition="sp3" />
        <vers num="xp" edition="sp3" />
      </prod>
      <prod vendor="microsoft" name="office_web_components">
        <vers num="2000" edition="sp3" />
        <vers num="2003" edition="sp1" />
        <vers num="2003" edition="sp1:2007_microsoft_office" />
        <vers num="2003" edition="sp3" />
        <vers num="xp" edition="sp3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0563" published="2009-06-10" name="CVE-2009-0563" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Stack-based buffer overflow in Microsoft Office Word 2002 SP3, 2003 SP3, and 2007 SP1 and SP2; Microsoft Office for Mac 2004 and 2008; Open XML File Format Converter for Mac; Microsoft Office Word Viewer 2003 SP3; Microsoft Office Word Viewer; and Microsoft Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2 allows remote attackers to execute arbitrary code via a Word document with a crafted tag containing an invalid length field, aka "Word Buffer Overflow Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-160A.html" source="CERT">TA09-160A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS09-027.mspx" source="MS" patch="1" adv="1">MS09-027</ref>
      <ref url="http://www.zerodayinitiative.com/advisories/ZDI-09-035" source="MISC">http://www.zerodayinitiative.com/advisories/ZDI-09-035</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1546" source="VUPEN">ADV-2009-1546</ref>
      <ref url="http://www.securitytracker.com/id?1022356" source="SECTRACK">1022356</ref>
      <ref url="http://www.securityfocus.com/bid/35188" source="BID">35188</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/504204/100/0/threaded" source="BUGTRAQ">20090610 ZDI-09-035: Microsoft Word Document Stack Based Buffer Overflow Vulnerability</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6133" source="OVAL">oval:org.mitre.oval:def:6133</ref>
      <ref url="http://osvdb.org/54959" source="OSVDB">54959</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="office">
        <vers num="2004" edition="" />
        <vers num="2004" edition=":mac" />
        <vers num="2008" edition="" />
        <vers num="2008" edition=":mac" />
      </prod>
      <prod vendor="microsoft" name="office_compatibility_pack_for_word_excel_ppt_2007">
        <vers num="" edition="sp1" />
        <vers num="" edition="sp2" />
      </prod>
      <prod vendor="microsoft" name="office_word">
        <vers num="2000" edition="sp3" />
        <vers num="2002" edition="sp3" />
        <vers num="2003" edition="sp3" />
        <vers num="2007" edition="sp1" />
        <vers num="2007" edition="sp2" />
      </prod>
      <prod vendor="microsoft" name="office_word_viewer">
        <vers num="2003" edition="sp3" />
      </prod>
      <prod vendor="microsoft" name="open_xml_file_format_converter">
        <vers num="" edition=":mac" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0565" published="2009-06-10" name="CVE-2009-0565" modified="2011-09-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Buffer overflow in Microsoft Office Word 2000 SP3, 2002 SP3, and 2007 SP1 and SP2; Microsoft Office for Mac 2004 and 2008; Open XML File Format Converter for Mac; and Microsoft Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2 allows remote attackers to execute arbitrary code via a Word document with a malformed record that triggers memory corruption, aka "Word Buffer Overflow Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-160A.html" source="CERT">TA09-160A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS09-027.mspx" source="MS" patch="1" adv="1">MS09-027</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1546" source="VUPEN">ADV-2009-1546</ref>
      <ref url="http://www.securitytracker.com/id?1022356" source="SECTRACK">1022356</ref>
      <ref url="http://www.securityfocus.com/bid/35190" source="BID">35190</ref>
      <ref url="http://securityreason.com/securityalert/8206" source="SREASON">8206</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6334" source="OVAL">oval:org.mitre.oval:def:6334</ref>
      <ref url="http://osvdb.org/54960" source="OSVDB">54960</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="office">
        <vers num="2004" edition="" />
        <vers num="2004" edition=":mac" />
        <vers num="2008" edition="" />
        <vers num="2008" edition=":mac" />
      </prod>
      <prod vendor="microsoft" name="office_compatibility_pack_for_word_excel_ppt_2007">
        <vers num="" edition="sp1" />
        <vers num="" edition="sp2" />
      </prod>
      <prod vendor="microsoft" name="office_word">
        <vers num="2000" edition="sp3" />
        <vers num="2002" edition="sp3" />
        <vers num="2003" edition="sp3" />
        <vers num="2007" edition="sp1" />
        <vers num="2007" edition="sp2" />
      </prod>
      <prod vendor="microsoft" name="office_word_viewer">
        <vers num="2003" edition="sp3" />
      </prod>
      <prod vendor="microsoft" name="open_xml_file_format_converter">
        <vers num="" edition=":mac" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0566" published="2009-07-15" name="CVE-2009-0566" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Microsoft Office Publisher 2007 SP1 does not properly calculate object handler data for Publisher files, which allows remote attackers to execute arbitrary code via a crafted file in a legacy format that triggers memory corruption, aka "Pointer Dereference Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-195A.html" source="CERT">TA09-195A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS09-030.mspx" source="MS" patch="1" adv="1">MS09-030</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1888" source="VUPEN">ADV-2009-1888</ref>
      <ref url="http://www.securitytracker.com/id?1022546" source="SECTRACK">1022546</ref>
      <ref url="http://www.securityfocus.com/bid/35599" source="BID">35599</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6285" source="OVAL">oval:org.mitre.oval:def:6285</ref>
      <ref url="http://osvdb.org/55838" source="OSVDB">55838</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="office_publisher">
        <vers num="2007" edition="sp1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0568" published="2009-06-10" name="CVE-2009-0568" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">The RPC Marshalling Engine (aka NDR) in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 SP2 does not properly maintain its internal state, which allows remote attackers to overwrite arbitrary memory locations via a crafted RPC message that triggers incorrect pointer reading, related to "IDL interfaces containing a non-conformant varying array" and FC_SMVARRAY, FC_LGVARRAY, FC_VARIABLE_REPEAT, and FC_VARIABLE_OFFSET, aka "RPC Marshalling Engine Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-160A.html" source="CERT">TA09-160A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS09-026.mspx" source="MS" patch="1" adv="1">MS09-026</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1545" source="VUPEN">ADV-2009-1545</ref>
      <ref url="http://www.securitytracker.com/id?1022357" source="SECTRACK">1022357</ref>
      <ref url="http://www.securityfocus.com/bid/35219" source="BID">35219</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6227" source="OVAL">oval:org.mitre.oval:def:6227</ref>
      <ref url="http://osvdb.org/54936" source="OSVDB">54936</ref>
      <ref url="http://blogs.technet.com/srd/archive/2009/06/09/ms09-026-how-a-developer-can-know-if-their-rpc-interface-is-affected.aspx" source="CONFIRM">http://blogs.technet.com/srd/archive/2009/06/09/ms09-026-how-a-developer-can-know-if-their-rpc-interface-is-affected.aspx</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition="sp4" />
      </prod>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:itanium" />
        <vers num="" edition="sp2:x64" />
      </prod>
      <prod vendor="microsoft" name="windows_server">
        <vers num="2008" edition="" />
        <vers num="2008" edition=":" />
        <vers num="2008" edition="::itanium" />
        <vers num="2008" edition=":sp2" />
        <vers num="2008" edition=":sp2:itanium" />
      </prod>
      <prod vendor="microsoft" name="windows_server_2008">
        <vers num="" edition=":x64" />
        <vers num="" edition=":x32" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:x64" />
        <vers num="" edition="sp2:x32" />
      </prod>
      <prod vendor="microsoft" name="windows_vista">
        <vers num="" edition=":x64" />
        <vers num="" edition="sp1" />
        <vers num="" edition="sp2" />
        <vers num="gold" />
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:x64" />
        <vers num="" edition="sp3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0569" published="2009-02-12" name="CVE-2009-0569" modified="2009-02-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Buffer overflow in Becky! Internet Mail 2.48.02 and earlier allows remote attackers to execute arbitrary code via a mail message with a crafted return receipt request.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/48684" source="XF">becky-readreceipt-bo(48684)</ref>
      <ref url="http://www.securityfocus.com/bid/33756" source="BID">33756</ref>
      <ref url="http://www.rimarts.jp/downloads/B2/Readme-e.txt" source="CONFIRM">http://www.rimarts.jp/downloads/B2/Readme-e.txt</ref>
      <ref url="http://secunia.com/advisories/33892" source="SECUNIA" adv="1">33892</ref>
      <ref url="http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-000011.html" source="JVNDB">JVNDB-2009-000011</ref>
      <ref url="http://jvn.jp/en/jp/JVN29641290/index.html" source="JVN">JVN#29641290</ref>
    </refs>
    <vuln_soft>
      <prod vendor="rimarts." name="becky!_internet_mail">
        <vers num="1.26.3" />
        <vers num="1.26.4" />
        <vers num="1.26.5" />
        <vers num="2.0.3" />
        <vers num="2.0.5" />
        <vers num="2.00.0" />
        <vers num="2.00.01" />
        <vers num="2.00.02" />
        <vers num="2.00.03" />
        <vers num="2.00.04" />
        <vers num="2.00.05" />
        <vers num="2.00.06" />
        <vers num="2.00.07" />
        <vers num="2.00.08" />
        <vers num="2.00.09" />
        <vers num="2.00.10" />
        <vers num="2.00.11" />
        <vers num="2.05.00" />
        <vers num="2.05.01" />
        <vers num="2.05.02" />
        <vers num="2.05.03" />
        <vers num="2.05.04" />
        <vers num="2.05.05" />
        <vers num="2.05.06" />
        <vers num="2.05.07" />
        <vers num="2.05.08" />
        <vers num="2.05.09" />
        <vers num="2.05.10" />
        <vers num="2.05.11" />
        <vers num="2.06" />
        <vers num="2.06.02" />
        <vers num="2.07" />
        <vers num="2.07.01" />
        <vers num="2.07.02" />
        <vers num="2.07.03" />
        <vers num="2.07.04" />
        <vers num="2.08" />
        <vers num="2.08.01" />
        <vers num="2.09" />
        <vers num="2.09.01" />
        <vers num="2.10" />
        <vers num="2.10.01" />
        <vers num="2.10.02" />
        <vers num="2.10.03" />
        <vers num="2.10.04" />
        <vers num="2.11" />
        <vers num="2.11.01" />
        <vers num="2.11.02" />
        <vers num="2.12" />
        <vers num="2.12.01" />
        <vers num="2.20" />
        <vers num="2.20.01" />
        <vers num="2.20.02" />
        <vers num="2.20.03" />
        <vers num="2.20.04" />
        <vers num="2.20.05" />
        <vers num="2.20.06" />
        <vers num="2.20.07" />
        <vers num="2.21" />
        <vers num="2.21.01" />
        <vers num="2.21.02" />
        <vers num="2.21.03" />
        <vers num="2.21.04" />
        <vers num="2.22" />
        <vers num="2.22.01" />
        <vers num="2.22.02" />
        <vers num="2.23" />
        <vers num="2.24" />
        <vers num="2.24.01" />
        <vers num="2.24.02" />
        <vers num="2.25" />
        <vers num="2.25.01" />
        <vers num="2.25.02" />
        <vers num="2.26" />
        <vers num="2.27" />
        <vers num="2.28" />
        <vers num="2.28.01" />
        <vers num="2.29" />
        <vers num="2.30" />
        <vers num="2.30.01" />
        <vers num="2.30.02" />
        <vers num="2.30.03" />
        <vers num="2.30.04" />
        <vers num="2.31.00" />
        <vers num="2.40.00" />
        <vers num="2.40.01" />
        <vers num="2.40.02" />
        <vers num="2.40.03" />
        <vers num="2.40.04" />
        <vers num="2.41.00" />
        <vers num="2.42.00" />
        <vers num="2.43.00" />
        <vers num="2.44.00" />
        <vers num="2.45.00" />
        <vers num="2.45.01" />
        <vers num="2.45.02" />
        <vers num="2.46" />
        <vers num="2.47" />
        <vers num="2.47.01" />
        <vers num="2.48" />
        <vers num="2.48.01" />
        <vers prev="1" num="2.48.02" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0570" published="2009-02-13" name="CVE-2009-0570" modified="2009-02-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">Directory traversal vulnerability in send.php in Ninja Designs Mailist 3.0, when register_globals is enabled and magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the load parameter.  NOTE: some of these details are obtained from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/33648" source="BID">33648</ref>
      <ref url="http://www.milw0rm.com/exploits/8001" source="MILW0RM">8001</ref>
      <ref url="http://secunia.com/advisories/33682" source="SECUNIA" adv="1">33682</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ninjadesigns" name="mailist">
        <vers num="3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0571" published="2009-02-13" name="CVE-2009-0571" modified="2009-02-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">admin.php in Ninja Designs Mailist 3.0 stores backup copies of maillist.php under the web root with insufficient access control, which allows remote attackers to obtain sensitive information via a direct request to the backup directory.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.milw0rm.com/exploits/8001" source="MILW0RM">8001</ref>
      <ref url="http://secunia.com/advisories/33682" source="SECUNIA" adv="1">33682</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ninjadesigns" name="mailist">
        <vers num="3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0572" published="2009-02-13" name="CVE-2009-0572" modified="2009-02-16" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in include/flatnux.php in FlatnuX CMS (aka Flatnuke3) 2009-01-27 and 2009-02-04, when register_globals is enabled and magic_quotes_gpc disabled, allows remote attackers to execute arbitrary PHP code via a URL in the _FNROOTPATH parameter to (1) index.php and (2) filemanager.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/48491" source="XF">flatnuxcms-fnrootpath-file-include(48491)</ref>
      <ref url="http://www.securityfocus.com/bid/33599" source="BID">33599</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/500663/100/0/threaded" source="BUGTRAQ">20090202 flatnux Flatnux-2009-01-27 Remote File Include</ref>
      <ref url="http://www.milw0rm.com/exploits/7969" source="MILW0RM">7969</ref>
      <ref url="http://secunia.com/advisories/33721" source="SECUNIA" adv="1">33721</ref>
      <ref url="http://osvdb.org/51729" source="OSVDB">51729</ref>
      <ref url="http://osvdb.org/51728" source="OSVDB">51728</ref>
    </refs>
    <vuln_soft>
      <prod vendor="flatnux" name="flatnux">
        <vers num="2009-01-27" />
        <vers num="2009-02-04" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0573" published="2009-02-13" name="CVE-2009-0573" modified="2009-02-16" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in FotoWeb 6.0 (Build 273) allow remote attackers to inject arbitrary web script or HTML via the (1) s parameter to cmdrequest/Login.fwx and the (2) search parameter to Grid.fwx.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/33677" source="BID">33677</ref>
      <ref url="http://www.fortconsult.net/images/pdf/advisories/FotoWebXSS_final.pdf" source="MISC" adv="1">http://www.fortconsult.net/images/pdf/advisories/FotoWebXSS_final.pdf</ref>
      <ref url="http://secunia.com/advisories/33879" source="SECUNIA" adv="1">33879</ref>
    </refs>
    <vuln_soft>
      <prod vendor="fotoware" name="fotoweb">
        <vers num="6.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0574" published="2009-02-13" name="CVE-2009-0574" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in index.php in Easy CafeEngine allows remote attackers to execute arbitrary SQL commands via the catid parameter, a different vector than CVE-2008-4604.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2009/0359" source="VUPEN">ADV-2009-0359</ref>
      <ref url="http://www.securityfocus.com/bid/33655" source="BID">33655</ref>
      <ref url="http://www.milw0rm.com/exploits/8002" source="MILW0RM">8002</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cafeengine" name="easycafeengine">
        <vers num="-" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0575" published="2009-02-13" name="CVE-2009-0575" modified="2009-02-16" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the theme_views_bulk_operations_confirmation function in views_bulk_operations.module in Views Bulk Operations 5.x before 5.x-1.3 and 6.x before 6.x-1.4, a module for Drupal, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors related to node titles.  NOTE: some of these details are obtained from third party information.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/33622" source="BID" patch="1">33622</ref>
      <ref url="http://drupal.org/node/369223" source="CONFIRM" patch="1" adv="1">http://drupal.org/node/369223</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/48516" source="XF">viewsbulk-themeviewsbulk-xss(48516)</ref>
      <ref url="http://secunia.com/advisories/33836" source="SECUNIA" adv="1">33836</ref>
      <ref url="http://osvdb.org/51751" source="OSVDB">51751</ref>
    </refs>
    <vuln_soft>
      <prod vendor="drupal" name="views_bulk_operations">
        <vers num="5.x-1.0" />
        <vers num="5.x-1.0beta1" />
        <vers num="5.x-1.0beta3" />
        <vers num="5.x-1.0beta4" />
        <vers num="5.x-1.0beta5" />
        <vers num="5.x-1.1" />
        <vers prev="1" num="5.x-1.2" />
        <vers num="6.x-1.0" />
        <vers num="6.x-1.1" />
        <vers num="6.x-1.2" />
        <vers prev="1" num="6.x-1.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0576" published="2009-02-13" name="CVE-2009-0576" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Unspecified vulnerability in Sun Java System Directory Server 5.2 p6 and earlier, and Enterprise Edition 5, allows remote attackers to cause a denial of service (daemon crash) via crafted LDAP requests.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-250086-1" source="SUNALERT" patch="1" adv="1">250086</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-21-116837-04-1" source="CONFIRM" patch="1" adv="1">http://sunsolve.sun.com/search/document.do?assetkey=1-21-116837-04-1</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/48662" source="XF">sun-java-sds-ldap-dos(48662)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0409" source="VUPEN">ADV-2009-0409</ref>
      <ref url="http://www.securityfocus.com/bid/33732" source="BID">33732</ref>
      <ref url="http://secunia.com/advisories/33850" source="SECUNIA" adv="1">33850</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="java_system_directory_server">
        <vers num="5.0" edition="-" />
        <vers num="5.0" edition="-:enterprise" />
        <vers prev="1" num="5.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0577" published="2009-02-20" name="CVE-2009-0577" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Integer overflow in the WriteProlog function in texttops in CUPS 1.1.17 on Red Hat Enterprise Linux (RHEL) 3 allows remote attackers to execute arbitrary code via a crafted PostScript file that triggers a heap-based buffer overflow.  NOTE: this issue exists because of an incorrect fix for CVE-2008-3640.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-0308.html" source="REDHAT" patch="1" adv="1">RHSA-2009:0308</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=486052" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=486052</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/48977" source="XF">cups-texttops-writeprolog-bo(48977)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/48977" source="XF">cups-texttops-writeprolog-bo(48977)</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2009-064.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2009-064.htm</ref>
      <ref url="http://secunia.com/advisories/33995" source="SECUNIA">33995</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9968" source="OVAL">oval:org.mitre.oval:def:9968</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="cups">
        <vers num="1.1.17" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0578" published="2009-03-04" name="CVE-2009-0578" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:S/C:N/I:C/A:C)" CVSS_score="6.2" CVSS_impact_subscore="9.2" CVSS_exploit_subscore="3.1" CVSS_base_score="6.2">
    <desc>
      <descript source="cve">GNOME NetworkManager before 0.7.0.99 does not properly verify privileges for dbus (1) modify and (2) delete requests, which allows local users to change or remove the network connections of arbitrary users via unspecified vectors related to org.freedesktop.NetworkManagerUserSettings and at_console.</descript>
    </desc>
    <loss_types>
      <avail />
      <int />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=487752" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=487752</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/49063" source="XF">networkmanager-dbus-security-bypass(49063)</ref>
      <ref url="http://www.ubuntu.com/usn/USN-727-1" source="UBUNTU" adv="1">USN-727-1</ref>
      <ref url="http://www.securitytracker.com/id?1021909" source="SECTRACK">1021909</ref>
      <ref url="http://www.securityfocus.com/bid/33966" source="BID">33966</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-0361.html" source="REDHAT">RHSA-2009:0361</ref>
      <ref url="http://secunia.com/advisories/34473" source="SECUNIA">34473</ref>
      <ref url="http://secunia.com/advisories/34067" source="SECUNIA">34067</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:8931" source="OVAL">oval:org.mitre.oval:def:8931</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-04/msg00010.html" source="SUSE">SUSE-SR:2009:009</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-03/msg00003.html" source="SUSE">SUSE-SA:2009:013</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ubuntu" name="ubuntu_linux">
        <vers num="8.10" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0579" published="2009-04-16" name="CVE-2009-0579" modified="2009-04-16" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Linux-PAM before 1.0.4 does not enforce the minimum password age (MINDAYS) as specified in /etc/shadow, which allows local users to bypass intended security policy and change their passwords sooner than specified.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-April/msg00420.html" source="FEDORA" patch="1" adv="1">FEDORA-2009-3231</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=487216" source="CONFIRM" patch="1">https://bugzilla.redhat.com/show_bug.cgi?id=487216</ref>
      <ref url="https://www.redhat.com/archives/pam-list/2009-March/msg00006.html" source="MLIST" adv="1">[pam-list] 20090309 Linux-PAM 1.0.4 released</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-April/msg00398.html" source="FEDORA">FEDORA-2009-3204</ref>
      <ref url="http://secunia.com/advisories/34733" source="SECUNIA" adv="1">34733</ref>
      <ref url="http://secunia.com/advisories/34728" source="SECUNIA" adv="1">34728</ref>
      <ref url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=514437" source="CONFIRM">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=514437</ref>
    </refs>
    <vuln_soft>
      <prod vendor="kernel" name="linux-pam">
        <vers num="0.99.1.0" />
        <vers num="0.99.10.0" />
        <vers num="0.99.2.0" />
        <vers num="0.99.2.1" />
        <vers num="0.99.3.0" />
        <vers num="0.99.4.0" />
        <vers num="0.99.5.0" />
        <vers num="0.99.6.0" />
        <vers num="0.99.6.1" />
        <vers num="0.99.6.2" />
        <vers num="0.99.6.3" />
        <vers num="0.99.7.0" />
        <vers num="0.99.7.1" />
        <vers num="0.99.8.0" />
        <vers num="0.99.8.1" />
        <vers num="0.99.9.0" />
        <vers num="1.0.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers prev="1" num="1.0.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0580" published="2009-06-05" name="CVE-2009-0580" modified="2011-09-06" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Apache Tomcat 4.1.0 through 4.1.39, 5.5.0 through 5.5.27, and 6.0.0 through 6.0.18, when FORM authentication is used, allows remote attackers to enumerate valid usernames via requests to /j_security_check with malformed URL encoding of passwords, related to improper error checking in the (1) MemoryRealm, (2) DataSourceRealm, and (3) JDBCRealm authentication realms, as demonstrated by a % (percent) value for the j_password parameter.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2009/1496" source="VUPEN" patch="1" adv="1">ADV-2009-1496</ref>
      <ref url="http://tomcat.apache.org/security-6.html" source="CONFIRM" patch="1" adv="1">http://tomcat.apache.org/security-6.html</ref>
      <ref url="http://tomcat.apache.org/security-5.html" source="CONFIRM" patch="1" adv="1">http://tomcat.apache.org/security-5.html</ref>
      <ref url="http://tomcat.apache.org/security-4.html" source="CONFIRM" patch="1" adv="1">http://tomcat.apache.org/security-4.html</ref>
      <ref url="http://svn.apache.org/viewvc?rev=781382&amp;view=rev" source="CONFIRM" patch="1" adv="1">http://svn.apache.org/viewvc?rev=781382&amp;view=rev</ref>
      <ref url="http://svn.apache.org/viewvc?rev=781379&amp;view=rev" source="CONFIRM" patch="1" adv="1">http://svn.apache.org/viewvc?rev=781379&amp;view=rev</ref>
      <ref url="http://svn.apache.org/viewvc?rev=747840&amp;view=rev" source="CONFIRM" patch="1" adv="1">http://svn.apache.org/viewvc?rev=747840&amp;view=rev</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-November/msg01246.html" source="FEDORA">FEDORA-2009-11356</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-November/msg01216.html" source="FEDORA">FEDORA-2009-11352</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-November/msg01156.html" source="FEDORA">FEDORA-2009-11374</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/50930" source="XF">tomcat-jsecuritycheck-info-disclosure(50930)</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/3056" source="VUPEN">ADV-2010-3056</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/3316" source="VUPEN">ADV-2009-3316</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1856" source="VUPEN">ADV-2009-1856</ref>
      <ref url="http://www.vmware.com/security/advisories/VMSA-2009-0016.html" source="CONFIRM">http://www.vmware.com/security/advisories/VMSA-2009-0016.html</ref>
      <ref url="http://www.securityfocus.com/bid/35196" source="BID">35196</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/507985/100/0/threaded" source="BUGTRAQ">20091120 VMSA-2009-0016 VMware vCenter and ESX update release and vMA patch release address multiple security issue in third party components</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/504125/100/0/threaded" source="BUGTRAQ">20090605 [SECURITY] CVE-2009-0580 UPDATED Apache Tomcat User enumeration vulnerability with FORM authentication</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/504108/100/0/threaded" source="BUGTRAQ">20090604 Re: [SECURITY] CVE-2009-0580 Apache Tomcat User enumeration vulnerability with FORM authentication</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/504045/100/0/threaded" source="BUGTRAQ">20090603 [SECURITY] CVE-2009-0580 Apache Tomcat User enumeration vulnerability with FORM authentication</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2010:176" source="MANDRIVA">MDVSA-2010:176</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:138" source="MANDRIVA">MDVSA-2009:138</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:136" source="MANDRIVA">MDVSA-2009:136</ref>
      <ref url="http://www.debian.org/security/2011/dsa-2207" source="DEBIAN">DSA-2207</ref>
      <ref url="http://support.apple.com/kb/HT4077" source="CONFIRM">http://support.apple.com/kb/HT4077</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-263529-1" source="SUNALERT">263529</ref>
      <ref url="http://securitytracker.com/id?1022332" source="SECTRACK">1022332</ref>
      <ref url="http://secunia.com/advisories/42368" source="SECUNIA">42368</ref>
      <ref url="http://secunia.com/advisories/37460" source="SECUNIA">37460</ref>
      <ref url="http://secunia.com/advisories/35788" source="SECUNIA">35788</ref>
      <ref url="http://secunia.com/advisories/35685" source="SECUNIA">35685</ref>
      <ref url="http://secunia.com/advisories/35344" source="SECUNIA" adv="1">35344</ref>
      <ref url="http://secunia.com/advisories/35326" source="SECUNIA" adv="1">35326</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9101" source="OVAL">oval:org.mitre.oval:def:9101</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6628" source="OVAL">oval:org.mitre.oval:def:6628</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=129070310906557&amp;w=2" source="HP">HPSBUX02579</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=129070310906557&amp;w=2" source="HP">HPSBUX02579</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-07/msg00002.html" source="SUSE">SUSE-SR:2009:012</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Mar/msg00001.html" source="APPLE">APPLE-SA-2010-03-29-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apache" name="tomcat">
        <vers num="4.1.0" />
        <vers num="4.1.1" />
        <vers num="4.1.10" />
        <vers num="4.1.11" />
        <vers num="4.1.12" />
        <vers num="4.1.13" />
        <vers num="4.1.14" />
        <vers num="4.1.15" />
        <vers num="4.1.16" />
        <vers num="4.1.17" />
        <vers num="4.1.18" />
        <vers num="4.1.19" />
        <vers num="4.1.2" />
        <vers num="4.1.20" />
        <vers num="4.1.21" />
        <vers num="4.1.22" />
        <vers num="4.1.23" />
        <vers num="4.1.24" />
        <vers num="4.1.25" />
        <vers num="4.1.26" />
        <vers num="4.1.27" />
        <vers num="4.1.28" />
        <vers num="4.1.29" />
        <vers num="4.1.3" edition="beta" />
        <vers num="4.1.30" />
        <vers num="4.1.31" />
        <vers num="4.1.32" />
        <vers num="4.1.33" />
        <vers num="4.1.34" />
        <vers num="4.1.35" />
        <vers num="4.1.36" />
        <vers num="4.1.37" />
        <vers num="4.1.38" />
        <vers num="4.1.39" />
        <vers num="4.1.4" />
        <vers num="4.1.5" />
        <vers num="4.1.6" />
        <vers num="4.1.7" />
        <vers num="4.1.8" />
        <vers num="4.1.9" edition="beta" />
        <vers num="5.5.0" />
        <vers num="5.5.1" />
        <vers num="5.5.10" />
        <vers num="5.5.11" />
        <vers num="5.5.12" />
        <vers num="5.5.13" />
        <vers num="5.5.14" />
        <vers num="5.5.15" />
        <vers num="5.5.16" />
        <vers num="5.5.17" />
        <vers num="5.5.18" />
        <vers num="5.5.19" />
        <vers num="5.5.2" />
        <vers num="5.5.20" />
        <vers num="5.5.21" />
        <vers num="5.5.22" />
        <vers num="5.5.23" />
        <vers num="5.5.24" />
        <vers num="5.5.25" />
        <vers num="5.5.26" />
        <vers num="5.5.27" />
        <vers num="5.5.3" />
        <vers num="5.5.4" />
        <vers num="5.5.5" />
        <vers num="5.5.6" />
        <vers num="5.5.7" />
        <vers num="5.5.8" />
        <vers num="5.5.9" />
        <vers num="6.0.0" />
        <vers num="6.0.1" />
        <vers num="6.0.10" />
        <vers num="6.0.11" />
        <vers num="6.0.12" />
        <vers num="6.0.13" />
        <vers num="6.0.14" />
        <vers num="6.0.15" />
        <vers num="6.0.16" />
        <vers num="6.0.2" />
        <vers num="6.0.3" />
        <vers num="6.0.4" />
        <vers num="6.0.5" />
        <vers num="6.0.6" />
        <vers num="6.0.7" />
        <vers num="6.0.8" />
        <vers num="6.0.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0581" published="2009-03-23" name="CVE-2009-0581" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Memory leak in LittleCMS (aka lcms or liblcms) before 1.18beta2, as used in Firefox 3.1beta, OpenJDK, and GIMP, allows context-dependent attackers to cause a denial of service (memory consumption and application crash) via a crafted image file.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2009/0775" source="VUPEN" patch="1" adv="1">ADV-2009-0775</ref>
      <ref url="http://www.securityfocus.com/bid/34185" source="BID" patch="1">34185</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-March/msg00921.html" source="FEDORA">FEDORA-2009-3034</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-March/msg00857.html" source="FEDORA">FEDORA-2009-2983</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-March/msg00856.html" source="FEDORA">FEDORA-2009-2982</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-March/msg00851.html" source="FEDORA">FEDORA-2009-2970</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-March/msg00811.html" source="FEDORA">FEDORA-2009-2928</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-March/msg00799.html" source="FEDORA">FEDORA-2009-2910</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-March/msg00794.html" source="FEDORA">FEDORA-2009-2903</ref>
      <ref url="https://rhn.redhat.com/errata/RHSA-2009-0377.html" source="REDHAT">RHSA-2009:0377</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=487509" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=487509</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/49328" source="XF">littlecms-unspecified-dos(49328)</ref>
      <ref url="http://www.ubuntu.com/usn/USN-744-1" source="UBUNTU">USN-744-1</ref>
      <ref url="http://www.securitytracker.com/id?1021870" source="SECTRACK">1021870</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/502031/100/0/threaded" source="BUGTRAQ">20090320 [oCERT-2009-003] LittleCMS integer errors</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/502018/100/0/threaded" source="BUGTRAQ">20090320 LittleCMS vulnerabilities (OpenJDK, Firefox, GIMP, etc. impacted)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-0339.html" source="REDHAT">RHSA-2009:0339</ref>
      <ref url="http://www.ocert.org/advisories/ocert-2009-003.html" source="MISC">http://www.ocert.org/advisories/ocert-2009-003.html</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:162" source="MANDRIVA">MDVSA-2009:162</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:137" source="MANDRIVA">MDVSA-2009:137</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:121" source="MANDRIVA">MDVSA-2009:121</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1769" source="DEBIAN">DSA-1769</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1745" source="DEBIAN">DSA-1745</ref>
      <ref url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2009&amp;m=slackware-security.487438" source="SLACKWARE">SSA:2009-083-01</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200904-19.xml" source="GENTOO">GLSA-200904-19</ref>
      <ref url="http://secunia.com/advisories/34782" source="SECUNIA">34782</ref>
      <ref url="http://secunia.com/advisories/34675" source="SECUNIA">34675</ref>
      <ref url="http://secunia.com/advisories/34632" source="SECUNIA">34632</ref>
      <ref url="http://secunia.com/advisories/34463" source="SECUNIA">34463</ref>
      <ref url="http://secunia.com/advisories/34454" source="SECUNIA">34454</ref>
      <ref url="http://secunia.com/advisories/34450" source="SECUNIA">34450</ref>
      <ref url="http://secunia.com/advisories/34442" source="SECUNIA">34442</ref>
      <ref url="http://secunia.com/advisories/34418" source="SECUNIA">34418</ref>
      <ref url="http://secunia.com/advisories/34408" source="SECUNIA">34408</ref>
      <ref url="http://secunia.com/advisories/34400" source="SECUNIA" adv="1">34400</ref>
      <ref url="http://secunia.com/advisories/34382" source="SECUNIA" adv="1">34382</ref>
      <ref url="http://secunia.com/advisories/34367" source="SECUNIA" adv="1">34367</ref>
      <ref url="http://scarybeastsecurity.blogspot.com/2009/03/littlecms-vulnerabilities.html" source="MISC">http://scarybeastsecurity.blogspot.com/2009/03/littlecms-vulnerabilities.html</ref>
      <ref url="http://scary.beasts.org/security/CESA-2009-003.html" source="MISC">http://scary.beasts.org/security/CESA-2009-003.html</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10023" source="OVAL">oval:org.mitre.oval:def:10023</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-03/msg00004.html" source="SUSE">SUSE-SR:2009:007</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gimp" name="gimp">
        <vers num="" />
      </prod>
      <prod vendor="littlecms" name="lcms">
        <vers num="1.07" />
        <vers num="1.08" />
        <vers num="1.09" />
        <vers num="1.10" />
        <vers num="1.11" />
        <vers num="1.12" />
        <vers num="1.13" />
        <vers num="1.14" />
        <vers num="1.15" />
        <vers num="1.16" />
        <vers prev="1" num="1.17" />
      </prod>
      <prod vendor="mozilla" name="firefox">
        <vers num="3.1" edition="beta1" />
      </prod>
      <prod vendor="sun" name="openjdk">
        <vers prev="1" num="7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0582" published="2009-03-14" name="CVE-2009-0582" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:P)" CVSS_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_base_score="5.8">
    <desc>
      <descript source="cve">The ntlm_challenge function in the NTLM SASL authentication mechanism in camel/camel-sasl-ntlm.c in Camel in Evolution Data Server (aka evolution-data-server) 2.24.5 and earlier, and 2.25.92 and earlier 2.25.x versions, does not validate whether a certain length value is consistent with the amount of data in a challenge packet, which allows remote mail servers to read information from the process memory of a client, or cause a denial of service (client crash), via an NTLM authentication type 2 packet with a length value that exceeds the amount of packet data.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-March/msg00672.html" source="FEDORA">FEDORA-2009-2792</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-March/msg00666.html" source="FEDORA">FEDORA-2009-2784</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=487685" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=487685</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/49233" source="XF">evolution-ntlmsasl-info-disclosure(49233)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0716" source="VUPEN">ADV-2009-0716</ref>
      <ref url="http://www.securityfocus.com/bid/34109" source="BID">34109</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-0358.html" source="REDHAT">RHSA-2009:0358</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-0355.html" source="REDHAT">RHSA-2009:0355</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-0354.html" source="REDHAT">RHSA-2009:0354</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:078" source="MANDRIVA">MDVSA-2009:078</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1813" source="DEBIAN">DSA-1813</ref>
      <ref url="http://securitytracker.com/id?1021845" source="SECTRACK">1021845</ref>
      <ref url="http://secunia.com/advisories/35357" source="SECUNIA">35357</ref>
      <ref url="http://secunia.com/advisories/35065" source="SECUNIA">35065</ref>
      <ref url="http://secunia.com/advisories/34363" source="SECUNIA">34363</ref>
      <ref url="http://secunia.com/advisories/34348" source="SECUNIA">34348</ref>
      <ref url="http://secunia.com/advisories/34339" source="SECUNIA">34339</ref>
      <ref url="http://secunia.com/advisories/34338" source="SECUNIA">34338</ref>
      <ref url="http://secunia.com/advisories/34286" source="SECUNIA" adv="1">34286</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10081" source="OVAL">oval:org.mitre.oval:def:10081</ref>
      <ref url="http://osvdb.org/52673" source="OSVDB">52673</ref>
      <ref url="http://mail.gnome.org/archives/release-team/2009-March/msg00096.html" source="MLIST">[release-team] 20090312 Another Evolution-Data-Server freeze break</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-05/msg00000.html" source="SUSE">SUSE-SR:2009:010</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gnome" name="evolution-data-server">
        <vers prev="1" num="2.24.5" />
        <vers num="2.25.92" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0583" published="2009-03-23" name="CVE-2009-0583" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Multiple integer overflows in icc.c in the International Color Consortium (ICC) Format library (aka icclib), as used in Ghostscript 8.64 and earlier and Argyll Color Management System (CMS) 1.0.3 and earlier, allow context-dependent attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly execute arbitrary code by using a device file for a translation request that operates on a crafted image file and targets a certain "native color space," related to an ICC profile in a (1) PostScript or (2) PDF file with embedded images.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.auscert.org.au/render.html?it=10666" source="AUSCERT">ESB-2009.0259</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-March/msg00916.html" source="FEDORA">FEDORA-2009-3031</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-March/msg00887.html" source="FEDORA">FEDORA-2009-3011</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-March/msg00772.html" source="FEDORA" adv="1">FEDORA-2009-2885</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-March/msg00770.html" source="FEDORA" adv="1">FEDORA-2009-2883</ref>
      <ref url="https://issues.rpath.com/browse/RPL-2991" source="CONFIRM">https://issues.rpath.com/browse/RPL-2991</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=487742" source="CONFIRM" adv="1">https://bugzilla.redhat.com/show_bug.cgi?id=487742</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/49329" source="XF">ghostscript-icclib-native-color-bo(49329)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1708" source="VUPEN">ADV-2009-1708</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0816" source="VUPEN" adv="1">ADV-2009-0816</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0777" source="VUPEN" adv="1">ADV-2009-0777</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0776" source="VUPEN" adv="1">ADV-2009-0776</ref>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-757-1" source="UBUNTU">USN-757-1</ref>
      <ref url="http://www.ubuntu.com/usn/USN-743-1" source="UBUNTU">USN-743-1</ref>
      <ref url="http://www.securityfocus.com/bid/34184" source="BID">34184</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/501994/100/0/threaded" source="BUGTRAQ">20090319 rPSA-2009-0050-1 ghostscript</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-0345.html" source="REDHAT" adv="1">RHSA-2009:0345</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:096" source="MANDRIVA">MDVSA-2009:096</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:095" source="MANDRIVA">MDVSA-2009:095</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200903-37.xml" source="GENTOO">GLSA-200903-37</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1746" source="DEBIAN" adv="1">DSA-1746</ref>
      <ref url="http://wiki.rpath.com/wiki/Advisories:rPSA-2009-0050" source="CONFIRM" adv="1">http://wiki.rpath.com/wiki/Advisories:rPSA-2009-0050</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2009-098.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2009-098.htm</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-262288-1" source="SUNALERT">262288</ref>
      <ref url="http://securitytracker.com/id?1021868" source="SECTRACK">1021868</ref>
      <ref url="http://secunia.com/advisories/35569" source="SECUNIA">35569</ref>
      <ref url="http://secunia.com/advisories/35559" source="SECUNIA">35559</ref>
      <ref url="http://secunia.com/advisories/34729" source="SECUNIA">34729</ref>
      <ref url="http://secunia.com/advisories/34469" source="SECUNIA" adv="1">34469</ref>
      <ref url="http://secunia.com/advisories/34443" source="SECUNIA" adv="1">34443</ref>
      <ref url="http://secunia.com/advisories/34437" source="SECUNIA" adv="1">34437</ref>
      <ref url="http://secunia.com/advisories/34418" source="SECUNIA" adv="1">34418</ref>
      <ref url="http://secunia.com/advisories/34398" source="SECUNIA" adv="1">34398</ref>
      <ref url="http://secunia.com/advisories/34393" source="SECUNIA" adv="1">34393</ref>
      <ref url="http://secunia.com/advisories/34381" source="SECUNIA" adv="1">34381</ref>
      <ref url="http://secunia.com/advisories/34373" source="SECUNIA" adv="1">34373</ref>
      <ref url="http://secunia.com/advisories/34266" source="SECUNIA" adv="1">34266</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10795" source="OVAL">oval:org.mitre.oval:def:10795</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-03/msg00004.html" source="SUSE">SUSE-SR:2009:007</ref>
      <ref url="http://bugs.gentoo.org/show_bug.cgi?id=261087" source="CONFIRM">http://bugs.gentoo.org/show_bug.cgi?id=261087</ref>
    </refs>
    <vuln_soft>
      <prod vendor="argyllcms" name="argyllcms">
        <vers num="0.1.0" />
        <vers num="0.2.0" />
        <vers num="0.2.1" />
        <vers num="0.2.2" />
        <vers num="0.3.0" />
        <vers num="0.6.0" />
        <vers num="0.7.0" edition="beta_8" />
        <vers num="1.0.0" />
        <vers num="1.0.2" />
        <vers prev="1" num="1.0.3" />
      </prod>
      <prod vendor="ghostscript" name="ghostscript">
        <vers num="5.50" />
        <vers num="7.05" />
        <vers num="7.07" />
        <vers num="8.0.1" />
        <vers num="8.15" />
        <vers num="8.15.2" />
        <vers num="8.54" />
        <vers num="8.56" />
        <vers num="8.57" />
        <vers num="8.61" />
        <vers num="8.62" />
        <vers num="8.63" />
        <vers prev="1" num="8.64" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0584" published="2009-03-23" name="CVE-2009-0584" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">icc.c in the International Color Consortium (ICC) Format library (aka icclib), as used in Ghostscript 8.64 and earlier and Argyll Color Management System (CMS) 1.0.3 and earlier, allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code by using a device file for processing a crafted image file associated with large integer values for certain sizes, related to an ICC profile in a (1) PostScript or (2) PDF file with embedded images.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.auscert.org.au/render.html?it=10666" source="AUSCERT">ESB-2009.0259</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-March/msg00916.html" source="FEDORA">FEDORA-2009-3031</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-March/msg00887.html" source="FEDORA">FEDORA-2009-3011</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-March/msg00772.html" source="FEDORA" adv="1">FEDORA-2009-2885</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-March/msg00770.html" source="FEDORA" adv="1">FEDORA-2009-2883</ref>
      <ref url="https://issues.rpath.com/browse/RPL-2991" source="CONFIRM">https://issues.rpath.com/browse/RPL-2991</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=487744" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=487744</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/49327" source="XF">ghostscript-icclib-bo(49327)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1708" source="VUPEN">ADV-2009-1708</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0816" source="VUPEN" adv="1">ADV-2009-0816</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0777" source="VUPEN" adv="1">ADV-2009-0777</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0776" source="VUPEN" adv="1">ADV-2009-0776</ref>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-757-1" source="UBUNTU">USN-757-1</ref>
      <ref url="http://www.ubuntu.com/usn/USN-743-1" source="UBUNTU">USN-743-1</ref>
      <ref url="http://www.securityfocus.com/bid/34184" source="BID">34184</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/501994/100/0/threaded" source="BUGTRAQ">20090319 rPSA-2009-0050-1 ghostscript</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-0345.html" source="REDHAT" adv="1">RHSA-2009:0345</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:096" source="MANDRIVA">MDVSA-2009:096</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:095" source="MANDRIVA">MDVSA-2009:095</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200903-37.xml" source="GENTOO">GLSA-200903-37</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1746" source="DEBIAN">DSA-1746</ref>
      <ref url="http://wiki.rpath.com/wiki/Advisories:rPSA-2009-0050" source="CONFIRM">http://wiki.rpath.com/wiki/Advisories:rPSA-2009-0050</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2009-098.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2009-098.htm</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-262288-1" source="SUNALERT">262288</ref>
      <ref url="http://securitytracker.com/id?1021868" source="SECTRACK">1021868</ref>
      <ref url="http://secunia.com/advisories/35569" source="SECUNIA">35569</ref>
      <ref url="http://secunia.com/advisories/35559" source="SECUNIA">35559</ref>
      <ref url="http://secunia.com/advisories/34729" source="SECUNIA">34729</ref>
      <ref url="http://secunia.com/advisories/34469" source="SECUNIA">34469</ref>
      <ref url="http://secunia.com/advisories/34443" source="SECUNIA">34443</ref>
      <ref url="http://secunia.com/advisories/34437" source="SECUNIA" adv="1">34437</ref>
      <ref url="http://secunia.com/advisories/34418" source="SECUNIA">34418</ref>
      <ref url="http://secunia.com/advisories/34398" source="SECUNIA" adv="1">34398</ref>
      <ref url="http://secunia.com/advisories/34393" source="SECUNIA" adv="1">34393</ref>
      <ref url="http://secunia.com/advisories/34381" source="SECUNIA" adv="1">34381</ref>
      <ref url="http://secunia.com/advisories/34373" source="SECUNIA" adv="1">34373</ref>
      <ref url="http://secunia.com/advisories/34266" source="SECUNIA">34266</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10544" source="OVAL">oval:org.mitre.oval:def:10544</ref>
      <ref url="http://osvdb.org/52988" source="OSVDB">52988</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-03/msg00004.html" source="SUSE">SUSE-SR:2009:007</ref>
      <ref url="http://bugs.gentoo.org/show_bug.cgi?id=261087" source="CONFIRM">http://bugs.gentoo.org/show_bug.cgi?id=261087</ref>
    </refs>
    <vuln_soft>
      <prod vendor="argyllcms" name="cms">
        <vers prev="1" num="1.0.3" />
      </prod>
      <prod vendor="ghostscript" name="ghostscript">
        <vers num="0" />
        <vers num="5.50" />
        <vers num="7.05" />
        <vers num="7.07" />
        <vers num="8.0.1" />
        <vers num="8.15" />
        <vers num="8.15.2" />
        <vers num="8.54" />
        <vers num="8.56" />
        <vers num="8.57" />
        <vers num="8.60" />
        <vers num="8.61" />
        <vers prev="1" num="8.64" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0585" published="2009-03-14" name="CVE-2009-0585" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Integer overflow in the soup_base64_encode function in soup-misc.c in libsoup 2.x.x before 2.2.x, and 2.x before 2.24, allows context-dependent attackers to execute arbitrary code via a long string that is converted to a base64 representation.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/34100" source="BID" patch="1">34100</ref>
      <ref url="http://openwall.com/lists/oss-security/2009/03/12/2" source="MLIST" patch="1">[oss-security] 20090312 [oCERT-2008-015] glib and glib-predecessor heap overflows</ref>
      <ref url="http://ocert.org/patches/2008-015/libsoup-CVE-2009-0585.diff" source="MISC" patch="1">http://ocert.org/patches/2008-015/libsoup-CVE-2009-0585.diff</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/49273" source="XF">libsoup-soupmisc-bo(49273)</ref>
      <ref url="http://www.ubuntu.com/usn/USN-737-1" source="UBUNTU">USN-737-1</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/501712/100/0/threaded" source="BUGTRAQ">20090312 [oCERT-2008-015] glib and glib-predecessor heap overflows</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-0344.html" source="REDHAT">RHSA-2009:0344</ref>
      <ref url="http://www.ocert.org/advisories/ocert-2008-015.html" source="MISC">http://www.ocert.org/advisories/ocert-2008-015.html</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:081" source="MANDRIVA">MDVSA-2009:081</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1748" source="DEBIAN">DSA-1748</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2009-088.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2009-088.htm</ref>
      <ref url="http://secunia.com/advisories/35065" source="SECUNIA">35065</ref>
      <ref url="http://secunia.com/advisories/34401" source="SECUNIA">34401</ref>
      <ref url="http://secunia.com/advisories/34337" source="SECUNIA">34337</ref>
      <ref url="http://secunia.com/advisories/34310" source="SECUNIA">34310</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9599" source="OVAL">oval:org.mitre.oval:def:9599</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-05/msg00000.html" source="SUSE">SUSE-SR:2009:010</ref>
    </refs>
    <vuln_soft>
      <prod vendor="joe_shaw" name="libsoup">
        <vers num="2.1" />
        <vers num="2.23.1" />
        <vers num="2.23.6" />
        <vers num="2.23.91" />
        <vers num="2.23.92" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0586" published="2009-03-14" name="CVE-2009-0586" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Integer overflow in the gst_vorbis_tag_add_coverart function (gst-libs/gst/tag/gstvorbistag.c) in vorbistag in gst-plugins-base (aka gstreamer-plugins-base) before 0.10.23 in GStreamer allows context-dependent attackers to execute arbitrary code via a crafted COVERART tag that is converted from a base64 representation, which triggers a heap-based buffer overflow.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/34100" source="BID" patch="1">34100</ref>
      <ref url="http://openwall.com/lists/oss-security/2009/03/12/2" source="MLIST" patch="1">[oss-security] 20090312 [oCERT-2008-015] glib and glib-predecessor heap overflows</ref>
      <ref url="http://ocert.org/patches/2008-015/gst-plugins-base-CVE-2009-0586.diff" source="MISC" patch="1">http://ocert.org/patches/2008-015/gst-plugins-base-CVE-2009-0586.diff</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/49274" source="XF">gstreamer-gstvorbistagaddcoverart-bo(49274)</ref>
      <ref url="http://www.ubuntu.com/usn/USN-735-1" source="UBUNTU">USN-735-1</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/501712/100/0/threaded" source="BUGTRAQ">20090312 [oCERT-2008-015] glib and glib-predecessor heap overflows</ref>
      <ref url="http://www.ocert.org/advisories/ocert-2008-015.html" source="MISC">http://www.ocert.org/advisories/ocert-2008-015.html</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:085" source="MANDRIVA">MDVSA-2009:085</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200907-11.xml" source="GENTOO">GLSA-200907-11</ref>
      <ref url="http://secunia.com/advisories/35777" source="SECUNIA" adv="1">35777</ref>
      <ref url="http://secunia.com/advisories/34350" source="SECUNIA" adv="1">34350</ref>
      <ref url="http://secunia.com/advisories/34335" source="SECUNIA" adv="1">34335</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9694" source="OVAL">oval:org.mitre.oval:def:9694</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-04/msg00010.html" source="SUSE">SUSE-SR:2009:009</ref>
      <ref url="http://cgit.freedesktop.org/gstreamer/gst-plugins-base/commit/?id=566583e87147f774e7fc4c78b5f7e61d427e40a9" source="CONFIRM">http://cgit.freedesktop.org/gstreamer/gst-plugins-base/commit/?id=566583e87147f774e7fc4c78b5f7e61d427e40a9</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gstreamer" name="gst-plugins-base">
        <vers prev="1" num="0.10.22" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0587" published="2009-03-14" name="CVE-2009-0587" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple integer overflows in Evolution Data Server (aka evolution-data-server) before 2.24.5 allow context-dependent attackers to execute arbitrary code via a long string that is converted to a base64 representation in (1) addressbook/libebook/e-vcard.c in evc or (2) camel/camel-mime-utils.c in libcamel.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/34100" source="BID" patch="1">34100</ref>
      <ref url="http://openwall.com/lists/oss-security/2009/03/12/2" source="MLIST" patch="1">[oss-security] 20090312 [oCERT-2008-015] glib and glib-predecessor heap overflows</ref>
      <ref url="http://ocert.org/patches/2008-015/evc-CVE-2009-0587.diff" source="MISC" patch="1">http://ocert.org/patches/2008-015/evc-CVE-2009-0587.diff</ref>
      <ref url="http://ocert.org/patches/2008-015/camel-CVE-2009-0587.diff" source="MISC" patch="1">http://ocert.org/patches/2008-015/camel-CVE-2009-0587.diff</ref>
      <ref url="http://www.ubuntu.com/usn/USN-733-1" source="UBUNTU">USN-733-1</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/501712/100/0/threaded" source="BUGTRAQ">20090312 [oCERT-2008-015] glib and glib-predecessor heap overflows</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-0358.html" source="REDHAT">RHSA-2009:0358</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-0355.html" source="REDHAT">RHSA-2009:0355</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-0354.html" source="REDHAT">RHSA-2009:0354</ref>
      <ref url="http://www.ocert.org/advisories/ocert-2008-015.html" source="MISC">http://www.ocert.org/advisories/ocert-2008-015.html</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:078" source="MANDRIVA">MDVSA-2009:078</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1813" source="DEBIAN">DSA-1813</ref>
      <ref url="http://secunia.com/advisories/35357" source="SECUNIA">35357</ref>
      <ref url="http://secunia.com/advisories/34351" source="SECUNIA">34351</ref>
      <ref url="http://secunia.com/advisories/34348" source="SECUNIA">34348</ref>
      <ref url="http://secunia.com/advisories/34339" source="SECUNIA">34339</ref>
      <ref url="http://secunia.com/advisories/34338" source="SECUNIA">34338</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11385" source="OVAL">oval:org.mitre.oval:def:11385</ref>
      <ref url="http://osvdb.org/52703" source="OSVDB">52703</ref>
      <ref url="http://osvdb.org/52702" source="OSVDB">52702</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-05/msg00002.html" source="SUSE">SUSE-SR:2010:012</ref>
    </refs>
    <vuln_soft>
      <prod vendor="go-evolution" name="evolution-data-server">
        <vers prev="1" num="2.24.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0588" published="2009-05-27" name="CVE-2009-0588" modified="2009-06-09" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)" CVSS_score="6.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.0" CVSS_base_score="6.5">
    <desc>
      <descript source="cve">agent/request/op.cgi in the Registration Authority (RA) component in Red Hat Certificate System (RHCS) 7.3 and Dogtag Certificate System allows remote authenticated users to approve certificate requests queued for arbitrary agent groups via a modified request ID field.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=484828" source="CONFIRM" patch="1">https://bugzilla.redhat.com/show_bug.cgi?id=484828</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-1065.html" source="REDHAT" patch="1" adv="1">RHSA-2009:1065</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=488706" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=488706</ref>
      <ref url="http://www.securitytracker.com/id?1022278" source="SECTRACK">1022278</ref>
      <ref url="http://www.securityfocus.com/bid/35104" source="BID">35104</ref>
      <ref url="http://secunia.com/advisories/35263" source="SECUNIA">35263</ref>
      <ref url="http://secunia.com/advisories/35242" source="SECUNIA">35242</ref>
    </refs>
    <vuln_soft>
      <prod vendor="redhat" name="certificate_system">
        <vers num="7.3" />
      </prod>
      <prod vendor="redhat" name="dogtag_certificate_system">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" seq="2009-0589" reject="1" published="2009-03-26" name="CVE-2009-0589" modified="2009-03-26">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: none.  Reason: This candidate was withdrawn by its CNA.  Further investigation showed that it was not a security issue.  Notes: none.</descript>
    </desc>
    <refs />
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0590" published="2009-03-27" name="CVE-2009-0590" modified="2011-10-25" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The ASN1_STRING_print_ex function in OpenSSL before 0.9.8k allows remote attackers to cause a denial of service (invalid memory access and application crash) via vectors that trigger printing of a (1) BMPString or (2) UniversalString with an invalid encoded length.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2009/0850" source="VUPEN" patch="1" adv="1">ADV-2009-0850</ref>
      <ref url="http://www.securityfocus.com/bid/34256" source="BID" patch="1">34256</ref>
      <ref url="http://sourceforge.net/project/shownotes.php?release_id=671059&amp;group_id=116847" source="CONFIRM" patch="1">http://sourceforge.net/project/shownotes.php?release_id=671059&amp;group_id=116847</ref>
      <ref url="https://lists.balabit.com/pipermail/syslog-ng-announce/2011-January/000102.html" source="MLIST">[syslog-ng-announce] 20110110 syslog-ng Premium Edition 3.2.1a has been released</ref>
      <ref url="https://lists.balabit.com/pipermail/syslog-ng-announce/2011-January/000101.html" source="MLIST">[syslog-ng-announce] 20110110 syslog-ng Premium Edition 3.0.6a has been released</ref>
      <ref url="https://kb.bluecoat.com/index?page=content&amp;id=SA50" source="CONFIRM">https://kb.bluecoat.com/index?page=content&amp;id=SA50</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/49431" source="XF">openssl-asn1-stringprintex-dos(49431)</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/3126" source="VUPEN">ADV-2010-3126</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0528" source="VUPEN">ADV-2010-0528</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1548" source="VUPEN">ADV-2009-1548</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1220" source="VUPEN">ADV-2009-1220</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1175" source="VUPEN">ADV-2009-1175</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1020" source="VUPEN">ADV-2009-1020</ref>
      <ref url="http://www.vmware.com/security/advisories/VMSA-2010-0019.html" source="CONFIRM">http://www.vmware.com/security/advisories/VMSA-2010-0019.html</ref>
      <ref url="http://www.ubuntu.com/usn/usn-750-1" source="UBUNTU">USN-750-1</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/515055/100/0/threaded" source="BUGTRAQ">20101207 VMSA-2010-0019 VMware ESX third party updates for Service Console</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/502429/100/0/threaded" source="BUGTRAQ">20090403 rPSA-2009-0057-1 m2crypto openssl openssl-scripts</ref>
      <ref url="http://www.php.net/archive/2009.php#id2009-04-08-1" source="CONFIRM">http://www.php.net/archive/2009.php#id2009-04-08-1</ref>
      <ref url="http://www.osvdb.org/52864" source="OSVDB">52864</ref>
      <ref url="http://www.openssl.org/news/secadv_20090325.txt" source="CONFIRM" adv="1">http://www.openssl.org/news/secadv_20090325.txt</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:087" source="MANDRIVA">MDVSA-2009:087</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1763" source="DEBIAN">DSA-1763</ref>
      <ref url="http://wiki.rpath.com/wiki/Advisories:rPSA-2009-0057" source="MISC">http://wiki.rpath.com/wiki/Advisories:rPSA-2009-0057</ref>
      <ref url="http://wiki.rpath.com/Advisories:rPSA-2009-0057" source="CONFIRM">http://wiki.rpath.com/Advisories:rPSA-2009-0057</ref>
      <ref url="http://voodoo-circle.sourceforge.net/sa/sa-20090326-01.html" source="CONFIRM">http://voodoo-circle.sourceforge.net/sa/sa-20090326-01.html</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2009-172.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2009-172.htm</ref>
      <ref url="http://support.apple.com/kb/HT3865" source="CONFIRM">http://support.apple.com/kb/HT3865</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-258048-1" source="SUNALERT">258048</ref>
      <ref url="http://securitytracker.com/id?1021905" source="SECTRACK">1021905</ref>
      <ref url="http://security.FreeBSD.org/advisories/FreeBSD-SA-09:08.openssl.asc" source="FREEBSD">FreeBSD-SA-09:08</ref>
      <ref url="http://secunia.com/advisories/42733" source="SECUNIA">42733</ref>
      <ref url="http://secunia.com/advisories/42724" source="SECUNIA">42724</ref>
      <ref url="http://secunia.com/advisories/42467" source="SECUNIA">42467</ref>
      <ref url="http://secunia.com/advisories/38834" source="SECUNIA">38834</ref>
      <ref url="http://secunia.com/advisories/38794" source="SECUNIA">38794</ref>
      <ref url="http://secunia.com/advisories/36701" source="SECUNIA">36701</ref>
      <ref url="http://secunia.com/advisories/35729" source="SECUNIA">35729</ref>
      <ref url="http://secunia.com/advisories/35380" source="SECUNIA">35380</ref>
      <ref url="http://secunia.com/advisories/35181" source="SECUNIA">35181</ref>
      <ref url="http://secunia.com/advisories/35065" source="SECUNIA">35065</ref>
      <ref url="http://secunia.com/advisories/34960" source="SECUNIA">34960</ref>
      <ref url="http://secunia.com/advisories/34896" source="SECUNIA">34896</ref>
      <ref url="http://secunia.com/advisories/34666" source="SECUNIA">34666</ref>
      <ref url="http://secunia.com/advisories/34561" source="SECUNIA">34561</ref>
      <ref url="http://secunia.com/advisories/34509" source="SECUNIA">34509</ref>
      <ref url="http://secunia.com/advisories/34460" source="SECUNIA" adv="1">34460</ref>
      <ref url="http://secunia.com/advisories/34411" source="SECUNIA" adv="1">34411</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6996" source="OVAL">oval:org.mitre.oval:def:6996</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10198" source="OVAL">oval:org.mitre.oval:def:10198</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=125017764422557&amp;w=2" source="HP">SSRT090062</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=125017764422557&amp;w=2" source="HP">SSRT090062</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=124464882609472&amp;w=2" source="HP">SSRT090059</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=124464882609472&amp;w=2" source="HP">SSRT090059</ref>
      <ref url="http://lists.vmware.com/pipermail/security-announce/2010/000082.html" source="MLIST">[security-announce] 20100303 VMSA-2010-0004 ESX Service Console and vMA third party updates</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2011-07/msg00014.html" source="SUSE">SUSE-SU-2011:0847</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2011-07/msg00013.html" source="SUSE">openSUSE-SU-2011:0845</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-05/msg00000.html" source="SUSE">SUSE-SR:2009:010</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2009/Sep/msg00004.html" source="APPLE">APPLE-SA-2009-09-10-2</ref>
      <ref url="ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2009-008.txt.asc" source="NETBSD">NetBSD-SA2009-008</ref>
    </refs>
    <vuln_soft>
      <prod vendor="openssl" name="openssl">
        <vers num="" edition=":openvms" />
        <vers num="0.9.1c" />
        <vers num="0.9.2b" />
        <vers num="0.9.3" />
        <vers num="0.9.3a" />
        <vers num="0.9.4" />
        <vers num="0.9.5" edition="beta1" />
        <vers num="0.9.5" edition="beta2" />
        <vers num="0.9.5a" edition="beta1" />
        <vers num="0.9.5a" edition="beta2" />
        <vers num="0.9.6" edition="beta1" />
        <vers num="0.9.6" edition="beta2" />
        <vers num="0.9.6" edition="beta3" />
        <vers num="0.9.6a" edition="beta1" />
        <vers num="0.9.6a" edition="beta2" />
        <vers num="0.9.6a" edition="beta3" />
        <vers num="0.9.6b" />
        <vers num="0.9.6c" />
        <vers num="0.9.6d" />
        <vers num="0.9.6e" />
        <vers num="0.9.6f" />
        <vers num="0.9.6g" />
        <vers num="0.9.6h" />
        <vers num="0.9.6i" />
        <vers num="0.9.6j" />
        <vers num="0.9.6k" />
        <vers num="0.9.6l" />
        <vers num="0.9.6m" />
        <vers num="0.9.7" edition="beta1" />
        <vers num="0.9.7" edition="beta2" />
        <vers num="0.9.7" edition="beta3" />
        <vers num="0.9.7" edition="beta4" />
        <vers num="0.9.7" edition="beta5" />
        <vers num="0.9.7" edition="beta6" />
        <vers num="0.9.7a" />
        <vers num="0.9.7b" />
        <vers num="0.9.7c" />
        <vers num="0.9.7d" />
        <vers num="0.9.7e" />
        <vers num="0.9.7f" />
        <vers num="0.9.7g" />
        <vers num="0.9.7h" />
        <vers num="0.9.7i" />
        <vers num="0.9.7j" />
        <vers num="0.9.7k" />
        <vers num="0.9.7l" />
        <vers num="0.9.8" />
        <vers num="0.9.8a" />
        <vers num="0.9.8b" />
        <vers num="0.9.8c" />
        <vers num="0.9.8d" />
        <vers num="0.9.8e" />
        <vers num="0.9.8f" />
        <vers num="0.9.8g" />
        <vers num="0.9.8h" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2009-0591" published="2009-03-27" name="CVE-2009-0591" modified="2011-01-19" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">The CMS_verify function in OpenSSL 0.9.8h through 0.9.8j, when CMS is enabled, does not properly handle errors associated with malformed signed attributes, which allows remote attackers to repudiate a signature that originally appeared to be valid but was actually invalid.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="https://kb.bluecoat.com/index?page=content&amp;id=SA50" source="CONFIRM">https://kb.bluecoat.com/index?page=content&amp;id=SA50</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/49432" source="XF">openssl-cmsverify-security-bypass(49432)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1548" source="VUPEN">ADV-2009-1548</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1175" source="VUPEN">ADV-2009-1175</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1020" source="VUPEN">ADV-2009-1020</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0850" source="VUPEN" adv="1">ADV-2009-0850</ref>
      <ref url="http://www.securityfocus.com/bid/34256" source="BID">34256</ref>
      <ref url="http://www.php.net/archive/2009.php#id2009-04-08-1" source="CONFIRM">http://www.php.net/archive/2009.php#id2009-04-08-1</ref>
      <ref url="http://www.osvdb.org/52865" source="OSVDB">52865</ref>
      <ref url="http://www.openssl.org/news/secadv_20090325.txt" source="CONFIRM" adv="1">http://www.openssl.org/news/secadv_20090325.txt</ref>
      <ref url="http://voodoo-circle.sourceforge.net/sa/sa-20090326-01.html" source="CONFIRM" adv="1">http://voodoo-circle.sourceforge.net/sa/sa-20090326-01.html</ref>
      <ref url="http://support.apple.com/kb/HT3865" source="CONFIRM">http://support.apple.com/kb/HT3865</ref>
      <ref url="http://sourceforge.net/project/shownotes.php?release_id=671059&amp;group_id=116847" source="CONFIRM">http://sourceforge.net/project/shownotes.php?release_id=671059&amp;group_id=116847</ref>
      <ref url="http://securitytracker.com/id?1021907" source="SECTRACK">1021907</ref>
      <ref url="http://secunia.com/advisories/42733" source="SECUNIA">42733</ref>
      <ref url="http://secunia.com/advisories/42724" source="SECUNIA">42724</ref>
      <ref url="http://secunia.com/advisories/36701" source="SECUNIA">36701</ref>
      <ref url="http://secunia.com/advisories/35729" source="SECUNIA">35729</ref>
      <ref url="http://secunia.com/advisories/35380" source="SECUNIA">35380</ref>
      <ref url="http://secunia.com/advisories/35065" source="SECUNIA">35065</ref>
      <ref url="http://secunia.com/advisories/34666" source="SECUNIA">34666</ref>
      <ref url="http://secunia.com/advisories/34460" source="SECUNIA" adv="1">34460</ref>
      <ref url="http://secunia.com/advisories/34411" source="SECUNIA" adv="1">34411</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=124464882609472&amp;w=2" source="HP">SSRT090059</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=124464882609472&amp;w=2" source="HP">SSRT090059</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-05/msg00000.html" source="SUSE">SUSE-SR:2009:010</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2009/Sep/msg00004.html" source="APPLE">APPLE-SA-2009-09-10-2</ref>
      <ref url="ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2009-008.txt.asc" source="NETBSD">NetBSD-SA2009-008</ref>
    </refs>
    <vuln_soft>
      <prod vendor="openssl" name="openssl">
        <vers num="0.9.8h" />
        <vers num="0.9.8i" />
        <vers num="0.9.8j" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0592" published="2009-02-16" name="CVE-2009-0592" modified="2009-02-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple directory traversal vulnerabilities in PNphpBB2 1.2i and earlier allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the ModName parameter to (1) admin_words.php, (2) admin_groups_reapir.php, (3) admin_smilies.php, (4) admin_ranks.php, (5) admin_styles.php, and (6) admin_users.php in admin/.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/33103" source="BID">33103</ref>
      <ref url="http://www.milw0rm.com/exploits/7658" source="MILW0RM">7658</ref>
      <ref url="http://secunia.com/advisories/33365" source="SECUNIA" adv="1">33365</ref>
    </refs>
    <vuln_soft>
      <prod vendor="pnphpbb" name="pnphpbb2">
        <vers num="1.0" />
        <vers num="1.1" />
        <vers num="1.1a" />
        <vers num="1.2" />
        <vers num="1.2a" />
        <vers num="1.2d" />
        <vers num="1.2e" />
        <vers num="1.2f" />
        <vers num="1.2g" />
        <vers num="1.2h" edition="rc3b" />
        <vers prev="1" num="1.2i" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0593" published="2009-02-16" name="CVE-2009-0593" modified="2009-02-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)" CVSS_score="6.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.0" CVSS_base_score="6.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in members.php in plx Auto Reminder 3.7 allows remote authenticated users to execute arbitrary SQL commands via the id parameter in a newar action.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/33106" source="BID">33106</ref>
      <ref url="http://www.milw0rm.com/exploits/7663" source="MILW0RM">7663</ref>
      <ref url="http://secunia.com/advisories/33283" source="SECUNIA" adv="1">33283</ref>
    </refs>
    <vuln_soft>
      <prod vendor="plxwebdev" name="plx_auto_reminder">
        <vers num="3.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0594" published="2009-02-16" name="CVE-2009-0594" modified="2009-02-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in index.php in phpSkelSite 1.4 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/33092" source="BID">33092</ref>
      <ref url="http://www.milw0rm.com/exploits/7648" source="MILW0RM">7648</ref>
      <ref url="http://secunia.com/advisories/33382" source="SECUNIA" adv="1">33382</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apmuthu" name="phpskelsite">
        <vers num="1.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0595" published="2009-02-16" name="CVE-2009-0595" modified="2009-02-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in skysilver/login.tpl.php in phpSkelSite 1.4, when register_globals is enabled and magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary PHP code via a URL in the theme parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/33092" source="BID">33092</ref>
      <ref url="http://www.milw0rm.com/exploits/7648" source="MILW0RM">7648</ref>
      <ref url="http://secunia.com/advisories/33382" source="SECUNIA" adv="1">33382</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpskelsite" name="phpskelsite">
        <vers num="1.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0596" published="2009-02-16" name="CVE-2009-0596" modified="2009-02-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Directory traversal vulnerability in skysilver/login.tpl.php in phpSkelSite 1.4, when register_globals is enabled, allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the TplSuffix parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/33092" source="BID">33092</ref>
      <ref url="http://www.milw0rm.com/exploits/7648" source="MILW0RM">7648</ref>
      <ref url="http://secunia.com/advisories/33382" source="SECUNIA" adv="1">33382</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpskelsite" name="phpskelsite">
        <vers num="1.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0597" published="2009-02-16" name="CVE-2009-0597" modified="2009-02-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">SQL injection vulnerability in admin/index.php in w3b>cms (aka w3blabor CMS) before 3.4.0, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the benutzername parameter (aka Username field) in a login action.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/33082" source="BID" patch="1">33082</ref>
      <ref url="http://www.milw0rm.com/exploits/7640" source="MILW0RM">7640</ref>
      <ref url="http://secunia.com/advisories/33364" source="SECUNIA" adv="1">33364</ref>
      <ref url="http://osvdb.org/51108" source="OSVDB">51108</ref>
      <ref url="http://forum.w3bcms.de/viewtopic.php?f=5&amp;t=256" source="MISC" adv="1">http://forum.w3bcms.de/viewtopic.php?f=5&amp;t=256</ref>
    </refs>
    <vuln_soft>
      <prod vendor="w3b_cms" name="aka_w3blabor_cms">
        <vers prev="1" num="3.3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0598" published="2009-02-16" name="CVE-2009-0598" modified="2009-02-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in index.php in PhpMesFilms 1.0 and 1.8 allows remote attackers to execute arbitrary SQL commands via the id parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/33105" source="BID">33105</ref>
      <ref url="http://www.milw0rm.com/exploits/7660" source="MILW0RM">7660</ref>
      <ref url="http://secunia.com/advisories/33332" source="SECUNIA" adv="1">33332</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpmesfilms" name="phpmesfilms">
        <vers num="1.0" />
        <vers num="1.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0599" published="2009-02-16" name="CVE-2009-0599" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Buffer overflow in wiretap/netscreen.c in Wireshark 0.99.7 through 1.0.5 allows user-assisted remote attackers to cause a denial of service (application crash) via a malformed NetScreen snoop file.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/33690" source="BID" patch="1">33690</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-March/msg00652.html" source="FEDORA">FEDORA-2009-1877</ref>
      <ref url="https://issues.rpath.com/browse/RPL-2984" source="CONFIRM">https://issues.rpath.com/browse/RPL-2984</ref>
      <ref url="https://bugs.wireshark.org/bugzilla/attachment.cgi?id=2590" source="CONFIRM" adv="1">https://bugs.wireshark.org/bugzilla/attachment.cgi?id=2590</ref>
      <ref url="http://www.wireshark.org/security/wnpa-sec-2009-01.html" source="CONFIRM" adv="1">http://www.wireshark.org/security/wnpa-sec-2009-01.html</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0370" source="VUPEN">ADV-2009-0370</ref>
      <ref url="http://www.securitytracker.com/id?1021697" source="SECTRACK">1021697</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/501763/100/0/threaded" source="BUGTRAQ">20090312 rPSA-2009-0040-1 tshark wireshark</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-0313.html" source="REDHAT">RHSA-2009:0313</ref>
      <ref url="http://wiki.rpath.com/Advisories:rPSA-2009-0040" source="CONFIRM">http://wiki.rpath.com/Advisories:rPSA-2009-0040</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2009-082.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2009-082.htm</ref>
      <ref url="http://secunia.com/advisories/34344" source="SECUNIA">34344</ref>
      <ref url="http://secunia.com/advisories/34264" source="SECUNIA">34264</ref>
      <ref url="http://secunia.com/advisories/34144" source="SECUNIA">34144</ref>
      <ref url="http://secunia.com/advisories/33872" source="SECUNIA" adv="1">33872</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9677" source="OVAL">oval:org.mitre.oval:def:9677</ref>
      <ref url="http://osvdb.org/51815" source="OSVDB">51815</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-03/msg00000.html" source="SUSE">SUSE-SR:2009:005</ref>
    </refs>
    <vuln_soft>
      <prod vendor="wireshark" name="wireshark">
        <vers num="0.99.7" />
        <vers num="0.99.8" />
        <vers num="1.0" />
        <vers num="1.0.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0600" published="2009-02-16" name="CVE-2009-0600" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Wireshark 0.99.6 through 1.0.5 allows user-assisted remote attackers to cause a denial of service (application crash) via a crafted Tektronix K12 text capture file, as demonstrated by a file with exactly one frame.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-March/msg00652.html" source="FEDORA">FEDORA-2009-1877</ref>
      <ref url="https://issues.rpath.com/browse/RPL-2984" source="CONFIRM">https://issues.rpath.com/browse/RPL-2984</ref>
      <ref url="https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=1937" source="CONFIRM" adv="1">https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=1937</ref>
      <ref url="http://www.wireshark.org/security/wnpa-sec-2009-01.html" source="CONFIRM" adv="1">http://www.wireshark.org/security/wnpa-sec-2009-01.html</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0370" source="VUPEN">ADV-2009-0370</ref>
      <ref url="http://www.securitytracker.com/id?1021697" source="SECTRACK">1021697</ref>
      <ref url="http://www.securityfocus.com/bid/33690" source="BID">33690</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/501763/100/0/threaded" source="BUGTRAQ">20090312 rPSA-2009-0040-1 tshark wireshark</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-0313.html" source="REDHAT">RHSA-2009:0313</ref>
      <ref url="http://wiki.rpath.com/Advisories:rPSA-2009-0040" source="CONFIRM">http://wiki.rpath.com/Advisories:rPSA-2009-0040</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2009-082.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2009-082.htm</ref>
      <ref url="http://secunia.com/advisories/34344" source="SECUNIA">34344</ref>
      <ref url="http://secunia.com/advisories/34264" source="SECUNIA">34264</ref>
      <ref url="http://secunia.com/advisories/34144" source="SECUNIA">34144</ref>
      <ref url="http://secunia.com/advisories/33872" source="SECUNIA" adv="1">33872</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10853" source="OVAL">oval:org.mitre.oval:def:10853</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-03/msg00000.html" source="SUSE">SUSE-SR:2009:005</ref>
    </refs>
    <vuln_soft>
      <prod vendor="wireshark" name="wireshark">
        <vers num="0.99.6" />
        <vers num="0.99.6a" />
        <vers num="0.99.7" />
        <vers num="0.99.8" />
        <vers num="1.0" />
        <vers num="1.0.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2009-0601" published="2009-02-16" name="CVE-2009-0601" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Format string vulnerability in Wireshark 0.99.8 through 1.0.5 on non-Windows platforms allows local users to cause a denial of service (application crash) via format string specifiers in the HOME environment variable.</descript>
    </desc>
    <impacts>
      <impact source="nvd">Per http://www.vupen.com/english/advisories/2009/0370:

"Multiple vulnerabilities have been identified in Wireshark, which could be exploited by local or remote attackers to cause a denial of service or compromise a vulnerable system."</impact>
    </impacts>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/33690" source="BID" patch="1">33690</ref>
      <ref url="https://issues.rpath.com/browse/RPL-2984" source="CONFIRM">https://issues.rpath.com/browse/RPL-2984</ref>
      <ref url="https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=3150" source="CONFIRM">https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=3150</ref>
      <ref url="http://www.wireshark.org/security/wnpa-sec-2009-01.html" source="CONFIRM" adv="1">http://www.wireshark.org/security/wnpa-sec-2009-01.html</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0370" source="VUPEN">ADV-2009-0370</ref>
      <ref url="http://www.securitytracker.com/id?1021697" source="SECTRACK">1021697</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/501763/100/0/threaded" source="BUGTRAQ">20090312 rPSA-2009-0040-1 tshark wireshark</ref>
      <ref url="http://wiki.rpath.com/Advisories:rPSA-2009-0040" source="CONFIRM">http://wiki.rpath.com/Advisories:rPSA-2009-0040</ref>
      <ref url="http://secunia.com/advisories/34264" source="SECUNIA">34264</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-03/msg00000.html" source="SUSE">SUSE-SR:2009:005</ref>
    </refs>
    <vuln_soft>
      <prod vendor="wireshark" name="wireshark">
        <vers num="0.99.8" />
        <vers num="1.0.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0602" published="2009-02-16" name="CVE-2009-0602" modified="2009-02-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Unrestricted file upload vulnerability in upload.php in WikkiTikkiTavi 1.11 allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in img/.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/48571" source="XF">wikkitikkitavi-upload-file-upload(48571)</ref>
      <ref url="http://www.securityfocus.com/bid/33647" source="BID">33647</ref>
      <ref url="http://www.milw0rm.com/exploits/7998" source="MILW0RM">7998</ref>
    </refs>
    <vuln_soft>
      <prod vendor="wikkitikkitavi" name="wikkitikkitavi">
        <vers num="1.11" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2009-0603" published="2009-02-16" name="CVE-2009-0603" modified="2009-02-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:S/C:N/I:P/A:N)" CVSS_score="3.5" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="6.8" CVSS_base_score="3.5">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in index.php in the Link module 5.x-2.5 for Drupal 5.10 allows remote authenticated users, with "administer content types" privileges, to inject arbitrary web script or HTML via the description parameter (aka the Help field).  NOTE: some of these details are obtained from third party information.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/48553" source="XF">link-description-xss(48553)</ref>
      <ref url="http://www.securityfocus.com/bid/33642" source="BID">33642</ref>
      <ref url="http://secunia.com/advisories/33835" source="SECUNIA" adv="1">33835</ref>
      <ref url="http://osvdb.org/51780" source="OSVDB">51780</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2009-02/0036.html" source="FULLDISC">20090205 Drupal Link Module XSS Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="drupal" name="link_module">
        <vers num="5.x-2.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0604" published="2009-02-16" name="CVE-2009-0604" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in index.php in PHP Director 0.21 and earlier allows remote attackers to execute arbitrary SQL commands via the searching parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2009/0379" source="VUPEN">ADV-2009-0379</ref>
      <ref url="http://www.securityfocus.com/bid/33694" source="BID">33694</ref>
      <ref url="http://www.milw0rm.com/exploits/8014" source="MILW0RM">8014</ref>
    </refs>
    <vuln_soft>
      <prod vendor="php_director" name="php_director">
        <vers num="0.2" />
        <vers prev="1" num="0.21" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0605" published="2009-02-17" name="CVE-2009-0605" modified="2009-04-16" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="4.9" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="3.9" CVSS_base_score="4.9">
    <desc>
      <descript source="cve">Stack consumption vulnerability in the do_page_fault function in arch/x86/mm/fault.c in the Linux kernel before 2.6.28.5 allows local users to cause a denial of service (memory corruption) or possibly gain privileges via unspecified vectors that trigger page faults on a machine that has a registered Kprobes probe.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/33758" source="BID" patch="1">33758</ref>
      <ref url="http://www.ubuntu.com/usn/usn-751-1" source="UBUNTU">USN-751-1</ref>
      <ref url="http://kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.28.5" source="CONFIRM" adv="1">http://kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.28.5</ref>
      <ref url="http://git.kernel.org/?p=linux/kernel/git/stable/linux-2.6.27.y.git;a=commit;h=9be260a646bf76fa418ee519afa10196b3164681" source="CONFIRM" adv="1">http://git.kernel.org/?p=linux/kernel/git/stable/linux-2.6.27.y.git;a=commit;h=9be260a646bf76fa418ee519afa10196b3164681</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="kernel">
        <vers num="2.2.27" />
        <vers num="2.4.36" />
        <vers num="2.4.36.1" />
        <vers num="2.4.36.2" />
        <vers num="2.4.36.3" />
        <vers num="2.4.36.4" />
        <vers num="2.4.36.5" />
        <vers num="2.4.36.6" />
        <vers num="2.6" />
        <vers num="2.6.0" />
        <vers num="2.6.1" />
        <vers num="2.6.10" />
        <vers num="2.6.11" />
        <vers num="2.6.11.1" />
        <vers num="2.6.11.10" />
        <vers num="2.6.11.11" />
        <vers num="2.6.11.12" />
        <vers num="2.6.11.2" />
        <vers num="2.6.11.3" />
        <vers num="2.6.11.4" />
        <vers num="2.6.11.5" />
        <vers num="2.6.11.6" />
        <vers num="2.6.11.7" />
        <vers num="2.6.11.8" />
        <vers num="2.6.11.9" />
        <vers num="2.6.12" />
        <vers num="2.6.12.1" />
        <vers num="2.6.12.2" />
        <vers num="2.6.12.3" />
        <vers num="2.6.12.4" />
        <vers num="2.6.12.5" />
        <vers num="2.6.12.6" />
        <vers num="2.6.13" />
        <vers num="2.6.13.1" />
        <vers num="2.6.13.2" />
        <vers num="2.6.13.3" />
        <vers num="2.6.13.4" />
        <vers num="2.6.13.5" />
        <vers num="2.6.14" />
        <vers num="2.6.14.1" />
        <vers num="2.6.14.2" />
        <vers num="2.6.14.3" />
        <vers num="2.6.14.4" />
        <vers num="2.6.14.5" />
        <vers num="2.6.14.6" />
        <vers num="2.6.14.7" />
        <vers num="2.6.15" />
        <vers num="2.6.15.1" />
        <vers num="2.6.15.2" />
        <vers num="2.6.15.3" />
        <vers num="2.6.15.4" />
        <vers num="2.6.15.5" />
        <vers num="2.6.15.6" />
        <vers num="2.6.15.7" />
        <vers num="2.6.16" />
        <vers num="2.6.16.1" />
        <vers num="2.6.16.10" />
        <vers num="2.6.16.11" />
        <vers num="2.6.16.12" />
        <vers num="2.6.16.13" />
        <vers num="2.6.16.14" />
        <vers num="2.6.16.15" />
        <vers num="2.6.16.16" />
        <vers num="2.6.16.17" />
        <vers num="2.6.16.18" />
        <vers num="2.6.16.19" />
        <vers num="2.6.16.2" />
        <vers num="2.6.16.20" />
        <vers num="2.6.16.21" />
        <vers num="2.6.16.22" />
        <vers num="2.6.16.23" />
        <vers num="2.6.16.24" />
        <vers num="2.6.16.25" />
        <vers num="2.6.16.26" />
        <vers num="2.6.16.27" />
        <vers num="2.6.16.28" />
        <vers num="2.6.16.29" />
        <vers num="2.6.16.3" />
        <vers num="2.6.16.30" />
        <vers num="2.6.16.31" />
        <vers num="2.6.16.32" />
        <vers num="2.6.16.33" />
        <vers num="2.6.16.34" />
        <vers num="2.6.16.35" />
        <vers num="2.6.16.36" />
        <vers num="2.6.16.37" />
        <vers num="2.6.16.38" />
        <vers num="2.6.16.39" />
        <vers num="2.6.16.4" />
        <vers num="2.6.16.40" />
        <vers num="2.6.16.41" />
        <vers num="2.6.16.42" />
        <vers num="2.6.16.43" />
        <vers num="2.6.16.44" />
        <vers num="2.6.16.45" />
        <vers num="2.6.16.46" />
        <vers num="2.6.16.47" />
        <vers num="2.6.16.48" />
        <vers num="2.6.16.49" />
        <vers num="2.6.16.5" />
        <vers num="2.6.16.50" />
        <vers num="2.6.16.51" />
        <vers num="2.6.16.52" />
        <vers num="2.6.16.53" />
        <vers num="2.6.16.54" />
        <vers num="2.6.16.55" />
        <vers num="2.6.16.56" />
        <vers num="2.6.16.57" />
        <vers num="2.6.16.58" />
        <vers num="2.6.16.59" />
        <vers num="2.6.16.6" />
        <vers num="2.6.16.60" />
        <vers num="2.6.16.61" />
        <vers num="2.6.16.62" />
        <vers num="2.6.16.7" />
        <vers num="2.6.16.8" />
        <vers num="2.6.16.9" />
        <vers num="2.6.17" />
        <vers num="2.6.17.1" />
        <vers num="2.6.17.10" />
        <vers num="2.6.17.11" />
        <vers num="2.6.17.12" />
        <vers num="2.6.17.13" />
        <vers num="2.6.17.14" />
        <vers num="2.6.17.2" />
        <vers num="2.6.17.3" />
        <vers num="2.6.17.4" />
        <vers num="2.6.17.5" />
        <vers num="2.6.17.6" />
        <vers num="2.6.17.7" />
        <vers num="2.6.17.8" />
        <vers num="2.6.17.9" />
        <vers num="2.6.18" edition="rc1" />
        <vers num="2.6.18" edition="rc2" />
        <vers num="2.6.18" edition="rc3" />
        <vers num="2.6.18" edition="rc4" />
        <vers num="2.6.18" edition="rc5" />
        <vers num="2.6.18" edition="rc6" />
        <vers num="2.6.18" edition="rc7" />
        <vers num="2.6.18.1" />
        <vers num="2.6.18.2" />
        <vers num="2.6.18.3" />
        <vers num="2.6.18.4" />
        <vers num="2.6.18.5" />
        <vers num="2.6.18.6" />
        <vers num="2.6.18.7" />
        <vers num="2.6.18.8" />
        <vers num="2.6.19" />
        <vers num="2.6.19.1" />
        <vers num="2.6.19.2" />
        <vers num="2.6.19.3" />
        <vers num="2.6.19.4" />
        <vers num="2.6.19.5" />
        <vers num="2.6.19.6" />
        <vers num="2.6.19.7" />
        <vers num="2.6.2" />
        <vers num="2.6.20" />
        <vers num="2.6.20.1" />
        <vers num="2.6.20.10" />
        <vers num="2.6.20.11" />
        <vers num="2.6.20.12" />
        <vers num="2.6.20.13" />
        <vers num="2.6.20.14" />
        <vers num="2.6.20.15" />
        <vers num="2.6.20.16" />
        <vers num="2.6.20.17" />
        <vers num="2.6.20.18" />
        <vers num="2.6.20.19" />
        <vers num="2.6.20.2" />
        <vers num="2.6.20.20" />
        <vers num="2.6.20.21" />
        <vers num="2.6.20.3" />
        <vers num="2.6.20.4" />
        <vers num="2.6.20.5" />
        <vers num="2.6.20.6" />
        <vers num="2.6.20.7" />
        <vers num="2.6.20.8" />
        <vers num="2.6.20.9" />
        <vers num="2.6.21" />
        <vers num="2.6.21.1" />
        <vers num="2.6.21.2" />
        <vers num="2.6.21.3" />
        <vers num="2.6.21.4" />
        <vers num="2.6.21.5" />
        <vers num="2.6.21.6" />
        <vers num="2.6.21.7" />
        <vers num="2.6.22" />
        <vers num="2.6.22.1" />
        <vers num="2.6.22.10" />
        <vers num="2.6.22.11" />
        <vers num="2.6.22.12" />
        <vers num="2.6.22.13" />
        <vers num="2.6.22.14" />
        <vers num="2.6.22.15" />
        <vers num="2.6.22.16" />
        <vers num="2.6.22.17" />
        <vers num="2.6.22.18" />
        <vers num="2.6.22.19" />
        <vers num="2.6.22.2" />
        <vers num="2.6.22.20" />
        <vers num="2.6.22.21" />
        <vers num="2.6.22.22" />
        <vers num="2.6.22.3" />
        <vers num="2.6.22.4" />
        <vers num="2.6.22.5" />
        <vers num="2.6.22.6" />
        <vers num="2.6.22.7" />
        <vers num="2.6.22.8" />
        <vers num="2.6.22.9" />
        <vers num="2.6.22_rc1" />
        <vers num="2.6.22_rc7" />
        <vers num="2.6.23" edition="rc1" />
        <vers num="2.6.23" edition="rc2" />
        <vers num="2.6.23.1" />
        <vers num="2.6.23.10" />
        <vers num="2.6.23.11" />
        <vers num="2.6.23.12" />
        <vers num="2.6.23.13" />
        <vers num="2.6.23.14" />
        <vers num="2.6.23.15" />
        <vers num="2.6.23.16" />
        <vers num="2.6.23.17" />
        <vers num="2.6.23.2" />
        <vers num="2.6.23.3" />
        <vers num="2.6.23.4" />
        <vers num="2.6.23.5" />
        <vers num="2.6.23.6" />
        <vers num="2.6.23.7" />
        <vers num="2.6.23.8" />
        <vers num="2.6.23.9" />
        <vers num="2.6.24" edition="rc1" />
        <vers num="2.6.24" edition="rc2" />
        <vers num="2.6.24" edition="rc3" />
        <vers num="2.6.24" edition="rc4" />
        <vers num="2.6.24" edition="rc5" />
        <vers num="2.6.24.1" />
        <vers num="2.6.24.2" />
        <vers num="2.6.24.3" />
        <vers num="2.6.24.4" />
        <vers num="2.6.24.5" />
        <vers num="2.6.24.6" />
        <vers num="2.6.24.7" />
        <vers num="2.6.25" edition="" />
        <vers num="2.6.25" edition=":x86_64" />
        <vers num="2.6.25.1" edition="" />
        <vers num="2.6.25.1" edition=":x86_64" />
        <vers num="2.6.25.10" edition="" />
        <vers num="2.6.25.10" edition=":x86_64" />
        <vers num="2.6.25.11" edition="" />
        <vers num="2.6.25.11" edition=":x86_64" />
        <vers num="2.6.25.12" edition="" />
        <vers num="2.6.25.12" edition=":x86_64" />
        <vers num="2.6.25.13" />
        <vers num="2.6.25.14" />
        <vers num="2.6.25.15" />
        <vers num="2.6.25.16" />
        <vers num="2.6.25.17" />
        <vers num="2.6.25.18" />
        <vers num="2.6.25.19" />
        <vers num="2.6.25.2" edition="" />
        <vers num="2.6.25.2" edition=":x86_64" />
        <vers num="2.6.25.20" />
        <vers num="2.6.25.3" edition="" />
        <vers num="2.6.25.3" edition=":x86_64" />
        <vers num="2.6.25.4" edition="" />
        <vers num="2.6.25.4" edition=":x86_64" />
        <vers num="2.6.25.5" edition="" />
        <vers num="2.6.25.5" edition=":x86_64" />
        <vers num="2.6.25.6" edition="" />
        <vers num="2.6.25.6" edition=":x86_64" />
        <vers num="2.6.25.7" edition="" />
        <vers num="2.6.25.7" edition=":x86_64" />
        <vers num="2.6.25.8" edition="" />
        <vers num="2.6.25.8" edition=":x86_64" />
        <vers num="2.6.25.9" edition="" />
        <vers num="2.6.25.9" edition=":x86_64" />
        <vers num="2.6.26" edition="rc4" />
        <vers num="2.6.26.1" />
        <vers num="2.6.26.2" />
        <vers num="2.6.26.3" />
        <vers num="2.6.26.4" />
        <vers num="2.6.26.5" />
        <vers num="2.6.26.6" />
        <vers num="2.6.26.7" />
        <vers num="2.6.26.8" />
        <vers num="2.6.27" edition="rc1" />
        <vers num="2.6.27" edition="rc2" />
        <vers num="2.6.27" edition="rc3" />
        <vers num="2.6.27" edition="rc4" />
        <vers num="2.6.27" edition="rc5" />
        <vers num="2.6.27" edition="rc6" />
        <vers num="2.6.27" edition="rc7" />
        <vers num="2.6.27" edition="rc8" />
        <vers num="2.6.27" edition="rc9" />
        <vers num="2.6.27.1" />
        <vers num="2.6.27.10" />
        <vers num="2.6.27.11" />
        <vers num="2.6.27.12" />
        <vers num="2.6.27.2" />
        <vers num="2.6.27.3" />
        <vers num="2.6.27.4" />
        <vers num="2.6.27.5" />
        <vers num="2.6.27.6" />
        <vers num="2.6.27.7" />
        <vers num="2.6.27.8" />
        <vers num="2.6.27.9" />
        <vers num="2.6.28" edition="rc1" />
        <vers num="2.6.28" edition="rc2" />
        <vers num="2.6.28" edition="rc3" />
        <vers num="2.6.28" edition="rc4" />
        <vers num="2.6.28" edition="rc5" />
        <vers num="2.6.28" edition="rc6" />
        <vers num="2.6.28" edition="rc7" />
        <vers num="2.6.28.1" />
        <vers num="2.6.28.2" />
        <vers num="2.6.28.3" />
        <vers prev="1" num="2.6.28.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0606" published="2009-02-17" name="CVE-2009-0606" modified="2009-02-26" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">The link_image function in linker/linker.c in the dynamic linker in Bionic in Open Handset Alliance Android 1.0 on the T-Mobile G1 phone does not properly handle file descriptors 0, 1, and 2 for a setgid program, which allows local users to create arbitrary files owned by certain groups, possibly a related issue to CVE-2002-0820.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/48840" source="XF">android-dynamic-linker-privilege-escalation(48840)</ref>
      <ref url="http://www.securityfocus.com/bid/33695" source="BID">33695</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/500753/100/0/threaded" source="BUGTRAQ">20090208 rooting your own phone: android security</ref>
    </refs>
    <vuln_soft>
      <prod vendor="openhandsetalliance" name="android_sdk">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0607" published="2009-02-17" name="CVE-2009-0607" modified="2009-02-26" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Multiple integer overflows in malloc_leak.c in Bionic in Open Handset Alliance Android 1.0 have unknown impact and attack vectors, related to the (1) chk_calloc and (2) leak_calloc functions.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/48841" source="XF">android-malloc-overflow(48841)</ref>
      <ref url="http://www.securityfocus.com/bid/33695" source="BID">33695</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/500753/100/0/threaded" source="BUGTRAQ">20090208 rooting your own phone: android security</ref>
    </refs>
    <vuln_soft>
      <prod vendor="openhandsetalliance" name="android_sdk">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0608" published="2009-02-17" name="CVE-2009-0608" modified="2009-02-26" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Integer overflow in the showLog function in fake_log_device.c in liblog in Open Handset Alliance Android 1.0 allows attackers to trigger a buffer overflow and possibly have unspecified other impact by sending a large number of input lines.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/48842" source="XF">android-showlog-bo(48842)</ref>
      <ref url="http://www.securityfocus.com/bid/33695" source="BID">33695</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/500753/100/0/threaded" source="BUGTRAQ">20090208 rooting your own phone: android security</ref>
    </refs>
    <vuln_soft>
      <prod vendor="android" name="android_sdk">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0609" published="2009-02-17" name="CVE-2009-0609" modified="2009-02-18" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Sun Java System Directory Proxy Server in Sun Java System Directory Server Enterprise Edition 6.0 through 6.3, when a JDBC data source is used, does not properly handle (1) a long value in an ADD or (2) long string attributes, which allows remote attackers to cause a denial of service (JDBC backend outage) via crafted LDAP requests.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-251086-1" source="SUNALERT" patch="1" adv="1">251086</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-21-125276-08-1" source="CONFIRM" patch="1" adv="1">http://sunsolve.sun.com/search/document.do?assetkey=1-21-125276-08-1</ref>
      <ref url="http://www.securityfocus.com/bid/33761" source="BID">33761</ref>
      <ref url="http://secunia.com/advisories/33923" source="SECUNIA" adv="1">33923</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="java_system_directory_server">
        <vers num="6.0" edition="enterprise" />
        <vers num="6.1" edition="enterprise" />
        <vers num="6.2" edition="enterprise" />
        <vers num="6.3" edition="enterprise" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0610" published="2009-02-17" name="CVE-2009-0610" modified="2009-02-18" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple static code injection vulnerabilities in post.php in Simple PHP News 1.0 final allow remote attackers to inject arbitrary PHP code into news.txt via the (1) title or (2) date parameter, and then execute the code via a direct request to display.php.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/33814" source="SECUNIA" adv="1">33814</ref>
      <ref url="http://osvdb.org/51816" source="OSVDB">51816</ref>
    </refs>
    <vuln_soft>
      <prod vendor="dminnich" name="simple_php_news">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0611" published="2009-02-17" name="CVE-2009-0611" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in qfsearch/AdminServlet in QuickFinder Server in Novell Open Enterprise Server 1.x allow remote attackers to inject arbitrary web script or HTML via (1) the siteloc parameter in a displayaddsite action, the site parameter in a (2) generalproperties or (3) clusterserviceproperties action, (4) the adminurl parameter in a global action, or (5) the print-list parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/48619" source="XF">quickfinderserver-multiple-xss(48619)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0421" source="VUPEN">ADV-2009-0421</ref>
      <ref url="http://www.securitytracker.com/id?1021695" source="SECTRACK">1021695</ref>
      <ref url="http://www.securityfocus.com/bid/33708" source="BID">33708</ref>
      <ref url="http://secunia.com/advisories/33886" source="SECUNIA" adv="1">33886</ref>
      <ref url="http://packetstormsecurity.org/0902-exploits/nqfs-xss.txt" source="MISC">http://packetstormsecurity.org/0902-exploits/nqfs-xss.txt</ref>
      <ref url="http://osvdb.org/51941" source="OSVDB">51941</ref>
    </refs>
    <vuln_soft>
      <prod vendor="novell" name="open_enterprise_server">
        <vers num="1.x" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0612" published="2009-02-17" name="CVE-2009-0612" modified="2009-02-18" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Trend Micro InterScan Web Security Virtual Appliance (IWSVA) 3.x and InterScan Web Security Suite (IWSS) 3.x, when basic authorization is enabled on the standalone proxy, forwards the Proxy-Authorization header from Windows Media Player, which allows remote web servers to obtain credentials by offering a media stream and then capturing this header.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/48681" source="XF">interscan-proxyauthorization-info-disc(48681)</ref>
      <ref url="http://www.securitytracker.com/id?1021716" source="SECTRACK">1021716</ref>
      <ref url="http://www.securityfocus.com/bid/33687" source="BID">33687</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/500760/100/0/threaded" source="BUGTRAQ">20090209 Trend micro - IWSVA/IWSS - Authorization module password leak</ref>
      <ref url="http://secunia.com/advisories/33891" source="SECUNIA" adv="1">33891</ref>
    </refs>
    <vuln_soft>
      <prod vendor="trend_micro" name="interscan_web_security_suite">
        <vers num="2.5" />
        <vers num="3.1" />
      </prod>
      <prod vendor="trend_micro" name="interscan_web_security_virtual_appliance">
        <vers num="3.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0613" published="2009-02-17" name="CVE-2009-0613" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:S/C:P/I:P/A:P)" CVSS_score="6.0" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="6.8" CVSS_base_score="6.0">
    <desc>
      <descript source="cve">Trend Micro InterScan Web Security Suite (IWSS) 3.1 before build 1237 allows remote authenticated Auditor and Report Only users to bypass intended permission settings, and modify the system configuration, via requests to unspecified JSP pages.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2009/0369" source="VUPEN">ADV-2009-0369</ref>
      <ref url="http://www.trendmicro.com/ftp/documentation/readme/iwss_31_win_en_readme_CP_1237_EN.txt" source="CONFIRM" adv="1">http://www.trendmicro.com/ftp/documentation/readme/iwss_31_win_en_readme_CP_1237_EN.txt</ref>
      <ref url="http://www.securitytracker.com/id?1021694" source="SECTRACK">1021694</ref>
      <ref url="http://secunia.com/advisories/33867" source="SECUNIA" adv="1">33867</ref>
    </refs>
    <vuln_soft>
      <prod vendor="trend_micro" name="interscan_web_security_suite">
        <vers num="3.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0614" published="2009-02-26" name="CVE-2009-0614" modified="2009-03-03" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:C)" CVSS_score="9.0" CVSS_impact_subscore="8.5" CVSS_exploit_subscore="10.0" CVSS_base_score="9.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Web Server in Cisco Unified MeetingPlace Web Conferencing 6.0 before 6.0(517.0) (aka 6.0 MR4) and 7.0 before 7.0(2) (aka 7.0 MR1) allows remote attackers to bypass authentication and obtain administrative access via a crafted URL.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/48888" source="XF">cisco-meetingplace-unauth-access(48888)</ref>
      <ref url="http://www.securityfocus.com/bid/33901" source="BID">33901</ref>
      <ref url="http://www.cisco.com/en/US/products/products_security_advisory09186a0080a7bc86.shtml" source="CISCO" adv="1">20090225 Cisco Unified MeetingPlace Web Conferencing Authentication Bypass Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="meetingplace_web_confrencing">
        <vers prev="1" num="6.0" />
        <vers prev="1" num="7.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0615" published="2009-02-26" name="CVE-2009-0615" modified="2009-03-03" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:C/I:C/A:C)" CVSS_score="9.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.0" CVSS_base_score="9.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in Cisco Application Networking Manager (ANM) before 2.0 and Application Control Engine (ACE) Device Manager before A3(2.1) allows remote authenticated users to read or modify arbitrary files via unspecified vectors, related to "invalid directory permissions."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securitytracker.com/id?1021770" source="SECTRACK">1021770</ref>
      <ref url="http://www.securityfocus.com/bid/33903" source="BID">33903</ref>
      <ref url="http://www.cisco.com/en/US/products/products_security_advisory09186a0080a7bc84.shtml" source="CISCO" adv="1">20090225 Cisco ACE Application Control Engine Device Manager and Application Networking Manager Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="application_control_engine_device_manager">
        <vers num="1.1" />
        <vers prev="1" num="1.2" />
      </prod>
      <prod vendor="cisco" name="application_networking_manager">
        <vers num="1.1" />
        <vers prev="1" num="1.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0616" published="2009-02-26" name="CVE-2009-0616" modified="2009-03-03" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Cisco Application Networking Manager (ANM) before 2.0 uses default usernames and passwords, which makes it easier for remote attackers to access the application, or cause a denial of service via configuration changes, related to "default user credentials during installation."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securitytracker.com/id?1021771" source="SECTRACK">1021771</ref>
      <ref url="http://www.securityfocus.com/bid/33903" source="BID">33903</ref>
      <ref url="http://www.cisco.com/en/US/products/products_security_advisory09186a0080a7bc84.shtml" source="CISCO" adv="1">20090225 Cisco ACE Application Control Engine Device Manager and Application Networking Manager Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="application_networking_manager">
        <vers num="1.1" />
        <vers prev="1" num="1.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0617" published="2009-02-26" name="CVE-2009-0617" modified="2009-03-03" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Cisco Application Networking Manager (ANM) before 2.0 uses a default MySQL root password, which makes it easier for remote attackers to execute arbitrary operating-system commands or change system files.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securitytracker.com/id?1021771" source="SECTRACK">1021771</ref>
      <ref url="http://www.securityfocus.com/bid/33903" source="BID">33903</ref>
      <ref url="http://www.cisco.com/en/US/products/products_security_advisory09186a0080a7bc84.shtml" source="CISCO" adv="1">20090225 Cisco ACE Application Control Engine Device Manager and Application Networking Manager Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="application_networking_manager">
        <vers num="1.1" />
        <vers prev="1" num="1.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0618" published="2009-02-26" name="CVE-2009-0618" modified="2009-03-03" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:C)" CVSS_score="8.5" CVSS_impact_subscore="7.8" CVSS_exploit_subscore="10.0" CVSS_base_score="8.5">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Java agent in Cisco Application Networking Manager (ANM) before 2.0 Update A allows remote attackers to gain privileges, and cause a denial of service (service outage) by stopping processes, or obtain sensitive information by reading configuration files.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.cisco.com/en/US/products/products_security_advisory09186a0080a7bc84.shtml" source="CISCO" patch="1" adv="1">20090225 Cisco ACE Application Control Engine Device Manager and Application Networking Manager Vulnerabilities</ref>
      <ref url="http://www.securitytracker.com/id?1021772" source="SECTRACK">1021772</ref>
      <ref url="http://www.securityfocus.com/bid/33903" source="BID">33903</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="application_networking_manager">
        <vers num="1.1" />
        <vers num="1.2" />
        <vers prev="1" num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0619" published="2009-03-04" name="CVE-2009-0619" modified="2010-04-27" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Session Border Controller (SBC) before 3.0(2) for Cisco 7600 series routers allows remote attackers to cause a denial of service (SBC card reload) via crafted packets to TCP port 2000.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.cisco.com/en/US/products/products_security_advisory09186a0080a80faa.shtml" source="CISCO" patch="1" adv="1">20090304 Cisco 7600 Series Router Session Border Controller Denial of Service Vulnerability</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/49055" source="XF">cisco-sbc-dos(49055)</ref>
      <ref url="http://www.securitytracker.com/id?1021787" source="SECTRACK">1021787</ref>
      <ref url="http://www.securityfocus.com/bid/33975" source="BID">33975</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="session_border_controller">
        <vers num="3.0(1)" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0620" published="2009-02-26" name="CVE-2009-0620" modified="2009-02-27" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Cisco ACE Application Control Engine Module for Catalyst 6500 Switches and 7600 Routers before A2(1.1) uses default (1) usernames and (2) passwords for (a) the administrator and (b) web management, which makes it easier for remote attackers to perform configuration changes or obtain operating-system access.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/33900" source="BID">33900</ref>
      <ref url="http://www.cisco.com/en/US/products/products_security_advisory09186a0080a7bc82.shtml" source="CISCO" adv="1">20090225 Multiple Vulnerabilities in the Cisco ACE Application Control Engine Module and Cisco ACE 4710 Application Control Engine</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="application_control_engine_module">
        <vers prev="1" num="0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0621" published="2009-02-26" name="CVE-2009-0621" modified="2009-02-27" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Cisco ACE 4710 Application Control Engine Appliance before A1(8a) uses default (1) usernames and (2) passwords for (a) the administrator, (b) web management, and (c) device management, which makes it easier for remote attackers to perform configuration changes to the Device Manager and other components, or obtain operating-system access.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.cisco.com/en/US/products/products_security_advisory09186a0080a7bc82.shtml" source="CISCO" patch="1" adv="1">20090225 Multiple Vulnerabilities in the Cisco ACE Application Control Engine Module and Cisco ACE 4710 Application Control Engine</ref>
      <ref url="http://www.securityfocus.com/bid/33900" source="BID">33900</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="ace_4710">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0622" published="2009-02-26" name="CVE-2009-0622" modified="2009-02-27" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:C/I:C/A:C)" CVSS_score="9.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.0" CVSS_base_score="9.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in Cisco ACE Application Control Engine Module for Catalyst 6500 Switches and 7600 Routers before A2(1.2) and Cisco ACE 4710 Application Control Engine Appliance before A1(8a) allows remote authenticated users to execute arbitrary operating-system commands through a command line interface (CLI).</descript>
    </desc>
    <sols>
      <sol source="nvd">Per: http://www.cisco.com/en/US/products/products_security_advisory09186a0080a7bc82.shtml

Cisco ACE module software can be downloaded from:

http://tools.cisco.com/support/downloads/go/Redirect.x?mdfid=280557289

Cisco ACE 4710 Application Control Engine appliance software can be downloaded from:

http://tools.cisco.com/support/downloads/go/Redirect.x?mdfid=281222179 </sol>
    </sols>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.cisco.com/en/US/products/products_security_advisory09186a0080a7bc82.shtml" source="CISCO" patch="1" adv="1">20090225 Multiple Vulnerabilities in the Cisco ACE Application Control Engine Module and Cisco ACE 4710 Application Control Engine</ref>
      <ref url="http://www.securityfocus.com/bid/33900" source="BID">33900</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="ace_4710">
        <vers num="" />
      </prod>
      <prod vendor="cisco" name="application_control_engine_module">
        <vers num="1.0" />
        <vers prev="1" num="1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0623" published="2009-02-26" name="CVE-2009-0623" modified="2009-06-19" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Unspecified vulnerability in Cisco ACE Application Control Engine Module for Catalyst 6500 Switches and 7600 Routers before A2(1.3) and Cisco ACE 4710 Application Control Engine Appliance before A3(2.1) allows remote attackers to cause a denial of service (device reload) via a crafted SSH packet.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/33900" source="BID">33900</ref>
      <ref url="http://www.cisco.com/en/US/products/products_security_advisory09186a0080a7bc82.shtml" source="CISCO" adv="1">20090225 Multiple Vulnerabilities in the Cisco ACE Application Control Engine Module and Cisco ACE 4710 Application Control Engine</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="ace_4710">
        <vers num="a3(1.0)" />
        <vers prev="1" num="a3(2.0)" />
      </prod>
      <prod vendor="cisco" name="application_control_engine_module">
        <vers num="a2(1.1)" />
        <vers prev="1" num="a2(1.2)" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0624" published="2009-02-26" name="CVE-2009-0624" modified="2009-03-03" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:N/I:N/A:C)" CVSS_score="6.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="8.0" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Unspecified vulnerability in the SNMPv2c implementation in Cisco ACE Application Control Engine Module for Catalyst 6500 Switches and 7600 Routers before A2(1.3) and Cisco ACE 4710 Application Control Engine Appliance before A3(2.1) allows remote attackers to cause a denial of service (device reload) via a crafted SNMPv1 packet.</descript>
      <descript source="nvd">Per: http://www.cisco.com/en/US/products/products_security_advisory09186a0080a7bc82.shtml

"Note: SNMPv2c must be explicitly configured in an affected device in order to process any SNMPv2c transactions. SNMPv2c is not enabled by default."</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.cisco.com/en/US/products/products_security_advisory09186a0080a7bc82.shtml" source="CISCO" patch="1" adv="1">20090225 Multiple Vulnerabilities in the Cisco ACE Application Control Engine Module and Cisco ACE 4710 Application Control Engine</ref>
      <ref url="http://www.securitytracker.com/id?1021769" source="SECTRACK">1021769</ref>
      <ref url="http://www.securityfocus.com/bid/33900" source="BID">33900</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="ace_4710">
        <vers num="a1(2.0)" />
        <vers num="a1(8.0)" />
        <vers num="a3(1.0)" />
        <vers prev="1" num="a3(2.0)" />
      </prod>
      <prod vendor="cisco" name="application_control_engine_module">
        <vers num="1.0" />
        <vers num="1.1" />
        <vers prev="1" num="1.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0625" published="2009-02-26" name="CVE-2009-0625" modified="2009-03-03" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Unspecified vulnerability in Cisco ACE Application Control Engine Module for Catalyst 6500 Switches and 7600 Routers before A2(1.2) and Cisco ACE 4710 Application Control Engine Appliance before A1(8.0) allows remote attackers to cause a denial of service (device reload) via a crafted SNMPv3 packet.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securitytracker.com/id?1021769" source="SECTRACK">1021769</ref>
      <ref url="http://www.securityfocus.com/bid/33900" source="BID">33900</ref>
      <ref url="http://www.cisco.com/en/US/products/products_security_advisory09186a0080a7bc82.shtml" source="CISCO" adv="1">20090225 Multiple Vulnerabilities in the Cisco ACE Application Control Engine Module and Cisco ACE 4710 Application Control Engine</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="ace_4710">
        <vers prev="1" num="a1(2.0)" />
      </prod>
      <prod vendor="cisco" name="application_control_engine_module">
        <vers prev="1" num="a2(1.1)" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0626" published="2009-03-27" name="CVE-2009-0626" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">The SSLVPN feature in Cisco IOS 12.3 through 12.4 allows remote attackers to cause a denial of service (device reload or hang) via a crafted HTTPS packet.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/49425" source="XF">ios-sslvpn-dos(49425)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0851" source="VUPEN" adv="1">ADV-2009-0851</ref>
      <ref url="http://www.securityfocus.com/bid/34239" source="BID">34239</ref>
      <ref url="http://www.cisco.com/en/US/products/products_security_advisory09186a0080a90469.shtml" source="CONFIRM" adv="1">http://www.cisco.com/en/US/products/products_security_advisory09186a0080a90469.shtml</ref>
      <ref url="http://www.cisco.com/en/US/products/products_security_advisory09186a0080a90424.shtml" source="CISCO" adv="1">20090325 Cisco IOS Software WebVPN and SSLVPN Vulnerabilities</ref>
      <ref url="http://securitytracker.com/id?1021896" source="SECTRACK">1021896</ref>
      <ref url="http://secunia.com/advisories/34438" source="SECUNIA" adv="1">34438</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6919" source="OVAL">oval:org.mitre.oval:def:6919</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="ios">
        <vers num="12.3" />
        <vers num="12.3b" />
        <vers num="12.3bc" />
        <vers num="12.3bw" />
        <vers num="12.3ja" />
        <vers num="12.3jea" />
        <vers num="12.3jeb" />
        <vers num="12.3jec" />
        <vers num="12.3jk" />
        <vers num="12.3jl" />
        <vers num="12.3jx" />
        <vers num="12.3t" />
        <vers num="12.3tpc" />
        <vers num="12.3va" />
        <vers num="12.3xa" />
        <vers num="12.3xb" />
        <vers num="12.3xc" />
        <vers num="12.3xd" />
        <vers num="12.3xf" />
        <vers num="12.3xg" />
        <vers num="12.3xi" />
        <vers num="12.3xj" />
        <vers num="12.3xk" />
        <vers num="12.3xl" />
        <vers num="12.3xq" />
        <vers num="12.3xs" />
        <vers num="12.3xu" />
        <vers num="12.3xw" />
        <vers num="12.3xx" />
        <vers num="12.3xy" />
        <vers num="12.3xz" />
        <vers num="12.3ya" />
        <vers num="12.3yd" />
        <vers num="12.3yf" />
        <vers num="12.3yg" />
        <vers num="12.3yh" />
        <vers num="12.3yi" />
        <vers num="12.3yj" />
        <vers num="12.3yk" />
        <vers num="12.3ym" />
        <vers num="12.3yq" />
        <vers num="12.3ys" />
        <vers num="12.3yt" />
        <vers num="12.3yu" />
        <vers num="12.3yx" />
        <vers num="12.3yz" />
        <vers num="12.4" />
        <vers num="12.4ja" />
        <vers num="12.4jda" />
        <vers num="12.4jk" />
        <vers num="12.4jl" />
        <vers num="12.4jma" />
        <vers num="12.4jmb" />
        <vers num="12.4jx" />
        <vers num="12.4md" />
        <vers num="12.4mr" />
        <vers num="12.4sw" />
        <vers num="12.4t" />
        <vers num="12.4xa" />
        <vers num="12.4xb" />
        <vers num="12.4xc" />
        <vers num="12.4xd" />
        <vers num="12.4xf" />
        <vers num="12.4xg" />
        <vers num="12.4xj" />
        <vers num="12.4xk" />
        <vers num="12.4xl" />
        <vers num="12.4xm" />
        <vers num="12.4xn" />
        <vers num="12.4xp" />
        <vers num="12.4xq" />
        <vers num="12.4xt" />
        <vers num="12.4xv" />
        <vers num="12.4xw" />
        <vers num="12.4xy" />
        <vers num="12.4xz" />
        <vers num="12.4ya" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0627" published="2009-09-08" name="CVE-2009-0627" modified="2009-09-09" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Unspecified vulnerability in Cisco NX-OS before 4.0(1a)N2(1), when running on Nexus 5000 platforms, allows remote attackers to cause a denial of service (crash) via an unspecified "sequence of TCP packets" related to "TCP State manipulation," possibly related to separate attacks against CVE-2008-4609.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.cisco.com/en/US/products/products_security_advisory09186a0080af511d.shtml" source="CISCO" patch="1" adv="1">20090908 TCP State Manipulation Denial of Service Vulnerabilities in Multiple Cisco Products</ref>
      <ref url="http://www.securitytracker.com/id?1022847" source="SECTRACK">1022847</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="nexus_5000">
        <vers num="" />
      </prod>
      <prod vendor="cisco" name="nexus_7000">
        <vers num="" />
      </prod>
      <prod vendor="cisco" name="nx-os">
        <vers prev="1" num="4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0628" published="2009-03-27" name="CVE-2009-0628" modified="2011-07-18" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:C)" CVSS_score="9.0" CVSS_impact_subscore="8.5" CVSS_exploit_subscore="10.0" CVSS_base_score="9.0">
    <desc>
      <descript source="cve">Memory leak in the SSLVPN feature in Cisco IOS 12.3 through 12.4 allows remote attackers to cause a denial of service (memory consumption and device crash) by disconnecting an SSL session in an abnormal manner, leading to a Transmission Control Block (TCB) leak.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/49427" source="XF">ios-sslvpn-tcbleak-dos(49427)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0851" source="VUPEN" adv="1">ADV-2009-0851</ref>
      <ref url="http://www.securityfocus.com/bid/34239" source="BID">34239</ref>
      <ref url="http://www.cisco.com/en/US/products/products_security_advisory09186a0080a90469.shtml" source="CONFIRM" adv="1">http://www.cisco.com/en/US/products/products_security_advisory09186a0080a90469.shtml</ref>
      <ref url="http://www.cisco.com/en/US/products/products_security_advisory09186a0080a90424.shtml" source="CISCO" adv="1">20090325 Cisco IOS Software WebVPN and SSLVPN Vulnerabilities</ref>
      <ref url="http://securitytracker.com/id?1021896" source="SECTRACK">1021896</ref>
      <ref url="http://secunia.com/advisories/34438" source="SECUNIA" adv="1">34438</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:12092" source="OVAL">oval:org.mitre.oval:def:12092</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="cisco_ios">
        <vers num="12.3" edition="b" />
        <vers num="12.3" edition="bc" />
        <vers num="12.3" edition="bw" />
        <vers num="12.3" edition="eu" />
        <vers num="12.3" edition="ja" />
        <vers num="12.3" edition="jea" />
        <vers num="12.3" edition="jeb" />
        <vers num="12.3" edition="jec" />
        <vers num="12.3" edition="jk" />
        <vers num="12.3" edition="jl" />
        <vers num="12.3" edition="jx" />
        <vers num="12.3" edition="t" />
        <vers num="12.3" edition="tpc" />
        <vers num="12.3" edition="va" />
        <vers num="12.3" edition="xa" />
        <vers num="12.3" edition="xb" />
        <vers num="12.3" edition="xc" />
        <vers num="12.3" edition="xd" />
        <vers num="12.3" edition="xe" />
        <vers num="12.3" edition="xf" />
        <vers num="12.3" edition="xg" />
        <vers num="12.3" edition="xh" />
        <vers num="12.3" edition="xi" />
        <vers num="12.3" edition="xj" />
        <vers num="12.3" edition="xk" />
        <vers num="12.3" edition="xq" />
        <vers num="12.3" edition="xr" />
        <vers num="12.3" edition="xs" />
        <vers num="12.3" edition="xu" />
        <vers num="12.3" edition="xw" />
        <vers num="12.3" edition="xy" />
        <vers num="12.3" edition="ya" />
        <vers num="12.3" edition="yd" />
        <vers num="12.3" edition="yf" />
        <vers num="12.3" edition="yg" />
        <vers num="12.3" edition="yh" />
        <vers num="12.3" edition="yi" />
        <vers num="12.3" edition="yj" />
        <vers num="12.3" edition="yk" />
        <vers num="12.3" edition="ym" />
        <vers num="12.3" edition="yq" />
        <vers num="12.3" edition="ys" />
        <vers num="12.3" edition="yt" />
        <vers num="12.3" edition="yu" />
        <vers num="12.3" edition="yx" />
        <vers num="12.3" edition="yz" />
        <vers num="12.4" edition="ja" />
        <vers num="12.4" edition="jk" />
        <vers num="12.4" edition="jma" />
        <vers num="12.4" edition="jmb" />
        <vers num="12.4" edition="jmc" />
        <vers num="12.4" edition="jx" />
        <vers num="12.4" edition="md" />
        <vers num="12.4" edition="mr" />
        <vers num="12.4" edition="sw" />
        <vers num="12.4" edition="t" />
        <vers num="12.4" edition="xa" />
        <vers num="12.4" edition="xb" />
        <vers num="12.4" edition="xc" />
        <vers num="12.4" edition="xd" />
        <vers num="12.4" edition="xe" />
        <vers num="12.4" edition="xf" />
        <vers num="12.4" edition="xg" />
        <vers num="12.4" edition="xj" />
        <vers num="12.4" edition="xk" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0629" published="2009-03-27" name="CVE-2009-0629" modified="2009-07-24" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:N/A:C)" CVSS_score="5.4" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="4.9" CVSS_base_score="5.4">
    <desc>
      <descript source="cve">The (1) Airline Product Set (aka ALPS), (2) Serial Tunnel Code (aka STUN), (3) Block Serial Tunnel Code (aka BSTUN), (4) Native Client Interface Architecture (NCIA) support, (5) Data-link switching (aka DLSw), (6) Remote Source-Route Bridging (RSRB), (7) Point to Point Tunneling Protocol (PPTP), (8) X.25 for Record Boundary Preservation (RBP), (9) X.25 over TCP (XOT), and (10) X.25 Routing features in Cisco IOS 12.2 and 12.4 allows remote attackers to cause a denial of service (device reload) via a series of crafted TCP packets.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/49420" source="XF">ios-tcp-dos(49420)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0851" source="VUPEN" adv="1">ADV-2009-0851</ref>
      <ref url="http://www.securityfocus.com/bid/34238" source="BID">34238</ref>
      <ref url="http://www.cisco.com/en/US/products/products_security_advisory09186a0080a904cb.shtml" source="CISCO" adv="1">20090325 Cisco IOS Software Multiple Features Crafted TCP Sequence Vulnerability</ref>
      <ref url="http://www.cisco.com/en/US/products/products_security_advisory09186a0080a90469.shtml" source="CONFIRM" adv="1">http://www.cisco.com/en/US/products/products_security_advisory09186a0080a90469.shtml</ref>
      <ref url="http://securitytracker.com/id?1021903" source="SECTRACK">1021903</ref>
      <ref url="http://secunia.com/advisories/34438" source="SECUNIA" adv="1">34438</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="ios">
        <vers num="12.2" />
        <vers num="12.2b" />
        <vers num="12.2bc" />
        <vers num="12.2bw" />
        <vers num="12.2bx" />
        <vers num="12.2by" />
        <vers num="12.2bz" />
        <vers num="12.2ca" />
        <vers num="12.2cx" />
        <vers num="12.2cy" />
        <vers num="12.2cz" />
        <vers num="12.2da" />
        <vers num="12.2dd" />
        <vers num="12.2dx" />
        <vers num="12.2ew" />
        <vers num="12.2ewa" />
        <vers num="12.2ex" />
        <vers num="12.2ey" />
        <vers num="12.2ez" />
        <vers num="12.2fx" />
        <vers num="12.2fy" />
        <vers num="12.2fz" />
        <vers num="12.2irb" />
        <vers num="12.2ixa" />
        <vers num="12.2ixb" />
        <vers num="12.2ixc" />
        <vers num="12.2ixd" />
        <vers num="12.2ixe" />
        <vers num="12.2ixf" />
        <vers num="12.2ixg" />
        <vers num="12.2ja" />
        <vers num="12.2jk" />
        <vers num="12.2l" />
        <vers num="12.2mb" />
        <vers num="12.2mc" />
        <vers num="12.2rc" />
        <vers num="12.2s" />
        <vers num="12.2sb" />
        <vers num="12.2sbc" />
        <vers num="12.2sca" />
        <vers num="12.2sga" />
        <vers num="12.2sm" />
        <vers num="12.2so" />
        <vers num="12.2sr" />
        <vers num="12.2sra" />
        <vers num="12.2srb" />
        <vers num="12.2src" />
        <vers num="12.2su" />
        <vers num="12.2sv" />
        <vers num="12.2sva" />
        <vers num="12.2svc" />
        <vers num="12.2svd" />
        <vers num="12.2sve" />
        <vers num="12.2sw" />
        <vers num="12.2sx" />
        <vers num="12.2sxa" />
        <vers num="12.2sxb" />
        <vers num="12.2sxd" />
        <vers num="12.2sxe" />
        <vers num="12.2sxf" />
        <vers num="12.2sy" />
        <vers num="12.2sz" />
        <vers num="12.2t" />
        <vers num="12.2tpc" />
        <vers num="12.2xa" />
        <vers num="12.2xb" />
        <vers num="12.2xc" />
        <vers num="12.2xd" />
        <vers num="12.2xe" />
        <vers num="12.2xf" />
        <vers num="12.2xg" />
        <vers num="12.2xh" />
        <vers num="12.2xi" />
        <vers num="12.2xj" />
        <vers num="12.2xk" />
        <vers num="12.2xl" />
        <vers num="12.2xm" />
        <vers num="12.2xn" />
        <vers num="12.2xo" />
        <vers num="12.2xq" />
        <vers num="12.2xr" />
        <vers num="12.2xs" />
        <vers num="12.2xt" />
        <vers num="12.2xu" />
        <vers num="12.2xv" />
        <vers num="12.2xw" />
        <vers num="12.2ya" />
        <vers num="12.2yb" />
        <vers num="12.2yc" />
        <vers num="12.2yd" />
        <vers num="12.2ye" />
        <vers num="12.2yf" />
        <vers num="12.2yg" />
        <vers num="12.2yh" />
        <vers num="12.2yj" />
        <vers num="12.2yk" />
        <vers num="12.2yl" />
        <vers num="12.2ym" />
        <vers num="12.2yn" />
        <vers num="12.2yo" />
        <vers num="12.2yp" />
        <vers num="12.2yq" />
        <vers num="12.2yr" />
        <vers num="12.2ys" />
        <vers num="12.2yt" />
        <vers num="12.2yu" />
        <vers num="12.2yv" />
        <vers num="12.2yw" />
        <vers num="12.2yx" />
        <vers num="12.2yy" />
        <vers num="12.2yz" />
        <vers num="12.2za" />
        <vers num="12.2zb" />
        <vers num="12.2zc" />
        <vers num="12.2zd" />
        <vers num="12.2ze" />
        <vers num="12.2zf" />
        <vers num="12.2zg" />
        <vers num="12.2zh" />
        <vers num="12.2zj" />
        <vers num="12.2zl" />
        <vers num="12.2zp" />
        <vers num="12.2zu" />
        <vers num="12.2zx" />
        <vers num="12.2zy" />
        <vers num="12.2zya" />
        <vers num="12.4" />
        <vers num="12.4mr" />
        <vers num="12.4sw" />
        <vers num="12.4t" />
        <vers num="12.4xa" />
        <vers num="12.4xb" />
        <vers num="12.4xc" />
        <vers num="12.4xd" />
        <vers num="12.4xe" />
        <vers num="12.4xf" />
        <vers num="12.4xg" />
        <vers num="12.4xj" />
        <vers num="12.4xk" />
        <vers num="12.4xl" />
        <vers num="12.4xp" />
        <vers num="12.4xt" />
        <vers num="12.4xv" />
        <vers num="12.4xw" />
        <vers num="12.4xy" />
      </prod>
      <prod vendor="cisco" name="ios_s">
        <vers num="12.4" />
      </prod>
      <prod vendor="cisco" name="ios_t">
        <vers num="12.4" />
      </prod>
      <prod vendor="cisco" name="ios_xr">
        <vers num="12.4" />
      </prod>
      <prod vendor="cisco" name="ios">
        <vers num="12.4" />
        <vers num="12.4(1)" />
        <vers num="12.4(1b)" />
        <vers num="12.4(1c)" />
        <vers num="12.4(2)mr" />
        <vers num="12.4(2)mr1" />
        <vers num="12.4(2)t" />
        <vers num="12.4(2)t1" />
        <vers num="12.4(2)t2" />
        <vers num="12.4(2)t3" />
        <vers num="12.4(2)t4" />
        <vers num="12.4(2)xa" />
        <vers num="12.4(2)xb" />
        <vers num="12.4(2)xb2" />
        <vers num="12.4(23)" />
        <vers num="12.4(3)" />
        <vers num="12.4(3)t2" />
        <vers num="12.4(3a)" />
        <vers num="12.4(3b)" />
        <vers num="12.4(3d)" />
        <vers num="12.4(4)mr" />
        <vers num="12.4(4)t" />
        <vers num="12.4(4)t2" />
        <vers num="12.4(5)" />
        <vers num="12.4(5b)" />
        <vers num="12.4(6)t" />
        <vers num="12.4(6)t1" />
        <vers num="12.4(7)" />
        <vers num="12.4(7a)" />
        <vers num="12.4(8)" />
        <vers num="12.4(9)t" />
        <vers num="12.4ja" />
        <vers num="12.4jda" />
        <vers num="12.4jk" />
        <vers num="12.4jl" />
        <vers num="12.4jma" />
        <vers num="12.4jmb" />
        <vers num="12.4jx" />
        <vers num="12.4md" />
        <vers num="12.4mr" />
        <vers num="12.4sw" />
        <vers num="12.4t" />
        <vers num="12.4xa" />
        <vers num="12.4xb" />
        <vers num="12.4xc" />
        <vers num="12.4xd" />
        <vers num="12.4xe" />
        <vers num="12.4xf" />
        <vers num="12.4xg" />
        <vers num="12.4xj" />
        <vers num="12.4xk" />
        <vers num="12.4xl" />
        <vers num="12.4xm" />
        <vers num="12.4xn" />
        <vers num="12.4xp" />
        <vers num="12.4xt" />
        <vers num="12.4xv" />
        <vers num="12.4xw" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0630" published="2009-03-27" name="CVE-2009-0630" modified="2009-07-24" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:C)" CVSS_score="7.1" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="8.6" CVSS_base_score="7.1">
    <desc>
      <descript source="cve">The (1) Cisco Unified Communications Manager Express; (2) SIP Gateway Signaling Support Over Transport Layer Security (TLS) Transport; (3) Secure Signaling and Media Encryption; (4) Blocks Extensible Exchange Protocol (BEEP); (5) Network Admission Control HTTP Authentication Proxy; (6) Per-user URL Redirect for EAPoUDP, Dot1x, and MAC Authentication Bypass; (7) Distributed Director with HTTP Redirects; and (8) TCP DNS features in Cisco IOS 12.0 through 12.4 do not properly handle IP sockets, which allows remote attackers to cause a denial of service (outage or resource consumption) via a series of crafted TCP packets.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/49418" source="XF" adv="1">ios-ipsockets-dos(49418)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0851" source="VUPEN" adv="1">ADV-2009-0851</ref>
      <ref url="http://www.securityfocus.com/bid/34242" source="BID">34242</ref>
      <ref url="http://www.cisco.com/en/US/products/products_security_advisory09186a0080a904c6.shtml" source="CISCO" adv="1">20090325 Cisco IOS Software Multiple Features IP Sockets Vulnerability</ref>
      <ref url="http://www.cisco.com/en/US/products/products_security_advisory09186a0080a90469.shtml" source="CONFIRM" adv="1">http://www.cisco.com/en/US/products/products_security_advisory09186a0080a90469.shtml</ref>
      <ref url="http://securitytracker.com/id?1021897" source="SECTRACK">1021897</ref>
      <ref url="http://secunia.com/advisories/34438" source="SECUNIA" adv="1">34438</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="ios">
        <vers num="12.0" />
        <vers num="12.0da" />
        <vers num="12.0db" />
        <vers num="12.0dc" />
        <vers num="12.0s" />
        <vers num="12.0sc" />
        <vers num="12.0sl" />
        <vers num="12.0sp" />
        <vers num="12.0st" />
        <vers num="12.0sx" />
        <vers num="12.0sy" />
        <vers num="12.0sz" />
        <vers num="12.0t" />
        <vers num="12.0w" />
        <vers num="12.0wc" />
        <vers num="12.0wt" />
        <vers num="12.0wx" />
        <vers num="12.0xa" />
        <vers num="12.0xb" />
        <vers num="12.0xc" />
        <vers num="12.0xd" />
        <vers num="12.0xe" />
        <vers num="12.0xg" />
        <vers num="12.0xh" />
        <vers num="12.0xi" />
        <vers num="12.0xj" />
        <vers num="12.0xk" />
        <vers num="12.0xl" />
        <vers num="12.0xm" />
        <vers num="12.0xn" />
        <vers num="12.0xq" />
        <vers num="12.0xr" />
        <vers num="12.0xs" />
        <vers num="12.0xt" />
        <vers num="12.0xv" />
        <vers num="12.1" />
        <vers num="12.1aa" />
        <vers num="12.1ax" />
        <vers num="12.1ay" />
        <vers num="12.1az" />
        <vers num="12.1cx" />
        <vers num="12.1da" />
        <vers num="12.1db" />
        <vers num="12.1dc" />
        <vers num="12.1e" />
        <vers num="12.1ea" />
        <vers num="12.1eb" />
        <vers num="12.1ec" />
        <vers num="12.1eo" />
        <vers num="12.1eu" />
        <vers num="12.1ev" />
        <vers num="12.1ew" />
        <vers num="12.1ex" />
        <vers num="12.1ey" />
        <vers num="12.1ez" />
        <vers num="12.1ga" />
        <vers num="12.1gb" />
        <vers num="12.1t" />
        <vers num="12.1xa" />
        <vers num="12.1xb" />
        <vers num="12.1xc" />
        <vers num="12.1xd" />
        <vers num="12.1xe" />
        <vers num="12.1xf" />
        <vers num="12.1xg" />
        <vers num="12.1xh" />
        <vers num="12.1xi" />
        <vers num="12.1xj" />
        <vers num="12.1xl" />
        <vers num="12.1xm" />
        <vers num="12.1xp" />
        <vers num="12.1xq" />
        <vers num="12.1xr" />
        <vers num="12.1xs" />
        <vers num="12.1xt" />
        <vers num="12.1xu" />
        <vers num="12.1xv" />
        <vers num="12.1xw" />
        <vers num="12.1xx" />
        <vers num="12.1xy" />
        <vers num="12.1xz" />
        <vers num="12.1ya" />
        <vers num="12.1yb" />
        <vers num="12.1yc" />
        <vers num="12.1yd" />
        <vers num="12.1ye" />
        <vers num="12.1yf" />
        <vers num="12.1yh" />
        <vers num="12.1yi" />
        <vers num="12.1yj" />
        <vers num="12.2" />
        <vers num="12.2b" />
        <vers num="12.2bc" />
        <vers num="12.2bw" />
        <vers num="12.2bx" />
        <vers num="12.2by" />
        <vers num="12.2bz" />
        <vers num="12.2cx" />
        <vers num="12.2cy" />
        <vers num="12.2cz" />
        <vers num="12.2da" />
        <vers num="12.2dd" />
        <vers num="12.2dx" />
        <vers num="12.2ew" />
        <vers num="12.2ewa" />
        <vers num="12.2ex" />
        <vers num="12.2ey" />
        <vers num="12.2ez" />
        <vers num="12.2fx" />
        <vers num="12.2fy" />
        <vers num="12.2fz" />
        <vers num="12.2ira" />
        <vers num="12.2irb" />
        <vers num="12.2ixa" />
        <vers num="12.2ixb" />
        <vers num="12.2ixc" />
        <vers num="12.2ixd" />
        <vers num="12.2ixe" />
        <vers num="12.2ixf" />
        <vers num="12.2ixg" />
        <vers num="12.2ja" />
        <vers num="12.2jk" />
        <vers num="12.2mb" />
        <vers num="12.2mc" />
        <vers num="12.2s" />
        <vers num="12.2sb" />
        <vers num="12.2sbc" />
        <vers num="12.2sca" />
        <vers num="12.2scb" />
        <vers num="12.2se" />
        <vers num="12.2sea" />
        <vers num="12.2seb" />
        <vers num="12.2sec" />
        <vers num="12.2sed" />
        <vers num="12.2see" />
        <vers num="12.2sef" />
        <vers num="12.2seg" />
        <vers num="12.2sg" />
        <vers num="12.2sga" />
        <vers num="12.2sm" />
        <vers num="12.2so" />
        <vers num="12.2sq" />
        <vers num="12.2sra" />
        <vers num="12.2srb" />
        <vers num="12.2src" />
        <vers num="12.2srd" />
        <vers num="12.2ste" />
        <vers num="12.2su" />
        <vers num="12.2sv" />
        <vers num="12.2sva" />
        <vers num="12.2svc" />
        <vers num="12.2svd" />
        <vers num="12.2sve" />
        <vers num="12.2sw" />
        <vers num="12.2sx" />
        <vers num="12.2sxa" />
        <vers num="12.2sxb" />
        <vers num="12.2sxd" />
        <vers num="12.2sxe" />
        <vers num="12.2sxf" />
        <vers num="12.2sxh" />
        <vers num="12.2sxi" />
        <vers num="12.2sy" />
        <vers num="12.2sz" />
        <vers num="12.2t" />
        <vers num="12.2tpc" />
        <vers num="12.2xa" />
        <vers num="12.2xb" />
        <vers num="12.2xc" />
        <vers num="12.2xd" />
        <vers num="12.2xe" />
        <vers num="12.2xf" />
        <vers num="12.2xg" />
        <vers num="12.2xh" />
        <vers num="12.2xi" />
        <vers num="12.2xj" />
        <vers num="12.2xk" />
        <vers num="12.2xl" />
        <vers num="12.2xm" />
        <vers num="12.2xn" />
        <vers num="12.2xna" />
        <vers num="12.2xnb" />
        <vers num="12.2xo" />
        <vers num="12.2xq" />
        <vers num="12.2xr" />
        <vers num="12.2xs" />
        <vers num="12.2xt" />
        <vers num="12.2xu" />
        <vers num="12.2xv" />
        <vers num="12.2xw" />
        <vers num="12.2ya" />
        <vers num="12.2yb" />
        <vers num="12.2yc" />
        <vers num="12.2yd" />
        <vers num="12.2ye" />
        <vers num="12.2yf" />
        <vers num="12.2yg" />
        <vers num="12.2yh" />
        <vers num="12.2yj" />
        <vers num="12.2yk" />
        <vers num="12.2yl" />
        <vers num="12.2ym" />
        <vers num="12.2yn" />
        <vers num="12.2yo" />
        <vers num="12.2yp" />
        <vers num="12.2yq" />
        <vers num="12.2yr" />
        <vers num="12.2yt" />
        <vers num="12.2yu" />
        <vers num="12.2yv" />
        <vers num="12.2yw" />
        <vers num="12.2yx" />
        <vers num="12.2yy" />
        <vers num="12.2yz" />
        <vers num="12.2za" />
        <vers num="12.2zb" />
        <vers num="12.2zc" />
        <vers num="12.2zd" />
        <vers num="12.2ze" />
        <vers num="12.2zf" />
        <vers num="12.2zg" />
        <vers num="12.2zh" />
        <vers num="12.2zj" />
        <vers num="12.2zl" />
        <vers num="12.2zp" />
        <vers num="12.2zu" />
        <vers num="12.2zx" />
        <vers num="12.2zy" />
        <vers num="12.2zya" />
        <vers num="12.3" />
        <vers num="12.3b" />
        <vers num="12.3bc" />
        <vers num="12.3bw" />
        <vers num="12.3ja" />
        <vers num="12.3jea" />
        <vers num="12.3jeb" />
        <vers num="12.3jec" />
        <vers num="12.3jk" />
        <vers num="12.3jl" />
        <vers num="12.3jx" />
        <vers num="12.3t" />
        <vers num="12.3tpc" />
        <vers num="12.3va" />
        <vers num="12.3xa" />
        <vers num="12.3xb" />
        <vers num="12.3xc" />
        <vers num="12.3xd" />
        <vers num="12.3xe" />
        <vers num="12.3xf" />
        <vers num="12.3xg" />
        <vers num="12.3xi" />
        <vers num="12.3xj" />
        <vers num="12.3xk" />
        <vers num="12.3xl" />
        <vers num="12.3xq" />
        <vers num="12.3xr" />
        <vers num="12.3xs" />
        <vers num="12.3xu" />
        <vers num="12.3xw" />
        <vers num="12.3xx" />
        <vers num="12.3xy" />
        <vers num="12.3xz" />
        <vers num="12.3ya" />
        <vers num="12.3yd" />
        <vers num="12.3yf" />
        <vers num="12.3yg" />
        <vers num="12.3yh" />
        <vers num="12.3yi" />
        <vers num="12.3yj" />
        <vers num="12.3yk" />
        <vers num="12.3ym" />
        <vers num="12.3yq" />
        <vers num="12.3ys" />
        <vers num="12.3yt" />
        <vers num="12.3yu" />
        <vers num="12.3yx" />
        <vers num="12.3yz" />
        <vers num="12.4" />
        <vers num="12.4ja" />
        <vers num="12.4jda" />
        <vers num="12.4jk" />
        <vers num="12.4jl" />
        <vers num="12.4jma" />
        <vers num="12.4jmb" />
        <vers num="12.4jx" />
        <vers num="12.4md" />
        <vers num="12.4mr" />
        <vers num="12.4sw" />
        <vers num="12.4t" />
        <vers num="12.4xa" />
        <vers num="12.4xb" />
        <vers num="12.4xc" />
        <vers num="12.4xd" />
        <vers num="12.4xe" />
        <vers num="12.4xf" />
        <vers num="12.4xg" />
        <vers num="12.4xj" />
        <vers num="12.4xk" />
        <vers num="12.4xl" />
        <vers num="12.4xm" />
        <vers num="12.4xn" />
        <vers num="12.4xp" />
        <vers num="12.4xq" />
        <vers num="12.4xr" />
        <vers num="12.4xt" />
        <vers num="12.4xv" />
        <vers num="12.4xw" />
        <vers num="12.4xy" />
        <vers num="12.4xz" />
        <vers num="12.4ya" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0631" published="2009-03-27" name="CVE-2009-0631" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Unspecified vulnerability in Cisco IOS 12.0 through 12.4, when configured with (1) IP Service Level Agreements (SLAs) Responder, (2) Session Initiation Protocol (SIP), (3) H.323 Annex E Call Signaling Transport, or (4) Media Gateway Control Protocol (MGCP) allows remote attackers to cause a denial of service (blocked input queue on the inbound interface) via a crafted UDP packet.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.cisco.com/en/US/products/products_security_advisory09186a0080a90469.shtml" source="CONFIRM" patch="1" adv="1">http://www.cisco.com/en/US/products/products_security_advisory09186a0080a90469.shtml</ref>
      <ref url="http://www.cisco.com/en/US/products/products_security_advisory09186a0080a90426.shtml" source="CISCO" patch="1" adv="1">20090325 Cisco IOS Software Multiple Features Crafted UDP Packet Vulnerability</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/49419" source="XF">ios-udp-dos(49419)</ref>
      <ref url="http://www.securitytracker.com/id?1021904" source="SECTRACK">1021904</ref>
      <ref url="http://www.securityfocus.com/bid/34245" source="BID">34245</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6720" source="OVAL">oval:org.mitre.oval:def:6720</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="ios">
        <vers num="12.0" />
        <vers num="12.0da" />
        <vers num="12.0db" />
        <vers num="12.0dc" />
        <vers num="12.0s" />
        <vers num="12.0sc" />
        <vers num="12.0sl" />
        <vers num="12.0sp" />
        <vers num="12.0st" />
        <vers num="12.0sx" />
        <vers num="12.0sy" />
        <vers num="12.0sz" />
        <vers num="12.0t" />
        <vers num="12.0w" />
        <vers num="12.0wc" />
        <vers num="12.0wt" />
        <vers num="12.0wx" />
        <vers num="12.0xa" />
        <vers num="12.0xb" />
        <vers num="12.0xc" />
        <vers num="12.0xd" />
        <vers num="12.0xe" />
        <vers num="12.0xg" />
        <vers num="12.0xh" />
        <vers num="12.0xi" />
        <vers num="12.0xj" />
        <vers num="12.0xk" />
        <vers num="12.0xl" />
        <vers num="12.0xm" />
        <vers num="12.0xn" />
        <vers num="12.0xq" />
        <vers num="12.0xr" />
        <vers num="12.0xs" />
        <vers num="12.0xt" />
        <vers num="12.0xv" />
        <vers num="12.1" />
        <vers num="12.1aa" />
        <vers num="12.1ax" />
        <vers num="12.1ay" />
        <vers num="12.1az" />
        <vers num="12.1cx" />
        <vers num="12.1da" />
        <vers num="12.1db" />
        <vers num="12.1dc" />
        <vers num="12.1e" />
        <vers num="12.1ea" />
        <vers num="12.1eb" />
        <vers num="12.1ec" />
        <vers num="12.1eo" />
        <vers num="12.1eu" />
        <vers num="12.1ev" />
        <vers num="12.1ew" />
        <vers num="12.1ex" />
        <vers num="12.1ey" />
        <vers num="12.1ez" />
        <vers num="12.1ga" />
        <vers num="12.1gb" />
        <vers num="12.1t" />
        <vers num="12.1xa" />
        <vers num="12.1xb" />
        <vers num="12.1xc" />
        <vers num="12.1xd" />
        <vers num="12.1xe" />
        <vers num="12.1xf" />
        <vers num="12.1xg" />
        <vers num="12.1xh" />
        <vers num="12.1xi" />
        <vers num="12.1xj" />
        <vers num="12.1xl" />
        <vers num="12.1xm" />
        <vers num="12.1xp" />
        <vers num="12.1xq" />
        <vers num="12.1xr" />
        <vers num="12.1xs" />
        <vers num="12.1xt" />
        <vers num="12.1xu" />
        <vers num="12.1xv" />
        <vers num="12.1xw" />
        <vers num="12.1xx" />
        <vers num="12.1xy" />
        <vers num="12.1xz" />
        <vers num="12.1ya" />
        <vers num="12.1yb" />
        <vers num="12.1yc" />
        <vers num="12.1yd" />
        <vers num="12.1ye" />
        <vers num="12.1yf" />
        <vers num="12.1yh" />
        <vers num="12.1yi" />
        <vers num="12.1yj" />
        <vers num="12.2" />
        <vers num="12.2b" />
        <vers num="12.2bc" />
        <vers num="12.2bw" />
        <vers num="12.2bx" />
        <vers num="12.2by" />
        <vers num="12.2bz" />
        <vers num="12.2cx" />
        <vers num="12.2cy" />
        <vers num="12.2cz" />
        <vers num="12.2da" />
        <vers num="12.2dd" />
        <vers num="12.2dx" />
        <vers num="12.2ew" />
        <vers num="12.2ewa" />
        <vers num="12.2ex" />
        <vers num="12.2ey" />
        <vers num="12.2ez" />
        <vers num="12.2fx" />
        <vers num="12.2fy" />
        <vers num="12.2fz" />
        <vers num="12.2ira" />
        <vers num="12.2irb" />
        <vers num="12.2ixa" />
        <vers num="12.2ixb" />
        <vers num="12.2ixc" />
        <vers num="12.2ixd" />
        <vers num="12.2ixe" />
        <vers num="12.2ixf" />
        <vers num="12.2ixg" />
        <vers num="12.2ja" />
        <vers num="12.2jk" />
        <vers num="12.2mb" />
        <vers num="12.2mc" />
        <vers num="12.2s" />
        <vers num="12.2sb" />
        <vers num="12.2sbc" />
        <vers num="12.2sca" />
        <vers num="12.2scb" />
        <vers num="12.2se" />
        <vers num="12.2sea" />
        <vers num="12.2seb" />
        <vers num="12.2sec" />
        <vers num="12.2sed" />
        <vers num="12.2see" />
        <vers num="12.2sef" />
        <vers num="12.2seg" />
        <vers num="12.2sg" />
        <vers num="12.2sga" />
        <vers num="12.2sm" />
        <vers num="12.2so" />
        <vers num="12.2sq" />
        <vers num="12.2sra" />
        <vers num="12.2srb" />
        <vers num="12.2src" />
        <vers num="12.2srd" />
        <vers num="12.2ste" />
        <vers num="12.2su" />
        <vers num="12.2sv" />
        <vers num="12.2sva" />
        <vers num="12.2svc" />
        <vers num="12.2svd" />
        <vers num="12.2sve" />
        <vers num="12.2sw" />
        <vers num="12.2sx" />
        <vers num="12.2sxa" />
        <vers num="12.2sxb" />
        <vers num="12.2sxd" />
        <vers num="12.2sxe" />
        <vers num="12.2sxf" />
        <vers num="12.2sxh" />
        <vers num="12.2sxi" />
        <vers num="12.2sy" />
        <vers num="12.2sz" />
        <vers num="12.2t" />
        <vers num="12.2tpc" />
        <vers num="12.2xa" />
        <vers num="12.2xb" />
        <vers num="12.2xc" />
        <vers num="12.2xd" />
        <vers num="12.2xe" />
        <vers num="12.2xf" />
        <vers num="12.2xg" />
        <vers num="12.2xh" />
        <vers num="12.2xi" />
        <vers num="12.2xj" />
        <vers num="12.2xk" />
        <vers num="12.2xl" />
        <vers num="12.2xm" />
        <vers num="12.2xn" />
        <vers num="12.2xna" />
        <vers num="12.2xnb" />
        <vers num="12.2xo" />
        <vers num="12.2xq" />
        <vers num="12.2xr" />
        <vers num="12.2xs" />
        <vers num="12.2xt" />
        <vers num="12.2xu" />
        <vers num="12.2xv" />
        <vers num="12.2xw" />
        <vers num="12.2ya" />
        <vers num="12.2yb" />
        <vers num="12.2yc" />
        <vers num="12.2yd" />
        <vers num="12.2ye" />
        <vers num="12.2yf" />
        <vers num="12.2yg" />
        <vers num="12.2yh" />
        <vers num="12.2yj" />
        <vers num="12.2yk" />
        <vers num="12.2yl" />
        <vers num="12.2ym" />
        <vers num="12.2yn" />
        <vers num="12.2yo" />
        <vers num="12.2yp" />
        <vers num="12.2yq" />
        <vers num="12.2yr" />
        <vers num="12.2yt" />
        <vers num="12.2yu" />
        <vers num="12.2yv" />
        <vers num="12.2yw" />
        <vers num="12.2yx" />
        <vers num="12.2yy" />
        <vers num="12.2yz" />
        <vers num="12.2za" />
        <vers num="12.2zb" />
        <vers num="12.2zc" />
        <vers num="12.2zd" />
        <vers num="12.2ze" />
        <vers num="12.2zf" />
        <vers num="12.2zg" />
        <vers num="12.2zh" />
        <vers num="12.2zj" />
        <vers num="12.2zl" />
        <vers num="12.2zp" />
        <vers num="12.2zu" />
        <vers num="12.2zx" />
        <vers num="12.2zy" />
        <vers num="12.2zya" />
        <vers num="12.3" />
        <vers num="12.3b" />
        <vers num="12.3bc" />
        <vers num="12.3bw" />
        <vers num="12.3ja" />
        <vers num="12.3jea" />
        <vers num="12.3jeb" />
        <vers num="12.3jec" />
        <vers num="12.3jk" />
        <vers num="12.3jl" />
        <vers num="12.3jx" />
        <vers num="12.3t" />
        <vers num="12.3tpc" />
        <vers num="12.3va" />
        <vers num="12.3xa" />
        <vers num="12.3xb" />
        <vers num="12.3xc" />
        <vers num="12.3xd" />
        <vers num="12.3xe" />
        <vers num="12.3xf" />
        <vers num="12.3xg" />
        <vers num="12.3xi" />
        <vers num="12.3xj" />
        <vers num="12.3xk" />
        <vers num="12.3xl" />
        <vers num="12.3xq" />
        <vers num="12.3xr" />
        <vers num="12.3xs" />
        <vers num="12.3xu" />
        <vers num="12.3xw" />
        <vers num="12.3xx" />
        <vers num="12.3xy" />
        <vers num="12.3xz" />
        <vers num="12.3ya" />
        <vers num="12.3yd" />
        <vers num="12.3yf" />
        <vers num="12.3yg" />
        <vers num="12.3yh" />
        <vers num="12.3yi" />
        <vers num="12.3yj" />
        <vers num="12.3yk" />
        <vers num="12.3ym" />
        <vers num="12.3yq" />
        <vers num="12.3ys" />
        <vers num="12.3yt" />
        <vers num="12.3yu" />
        <vers num="12.3yx" />
        <vers num="12.3yz" />
        <vers num="12.4" />
        <vers num="12.4ja" />
        <vers num="12.4jda" />
        <vers num="12.4jk" />
        <vers num="12.4jl" />
        <vers num="12.4jma" />
        <vers num="12.4jmb" />
        <vers num="12.4jx" />
        <vers num="12.4md" />
        <vers num="12.4mr" />
        <vers num="12.4sw" />
        <vers num="12.4t" />
        <vers num="12.4xa" />
        <vers num="12.4xb" />
        <vers num="12.4xc" />
        <vers num="12.4xd" />
        <vers num="12.4xe" />
        <vers num="12.4xf" />
        <vers num="12.4xg" />
        <vers num="12.4xj" />
        <vers num="12.4xk" />
        <vers num="12.4xl" />
        <vers num="12.4xm" />
        <vers num="12.4xn" />
        <vers num="12.4xp" />
        <vers num="12.4xq" />
        <vers num="12.4xr" />
        <vers num="12.4xt" />
        <vers num="12.4xv" />
        <vers num="12.4xw" />
        <vers num="12.4xy" />
        <vers num="12.4xz" />
        <vers num="12.4ya" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0632" published="2009-03-12" name="CVE-2009-0632" modified="2009-03-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:C/I:C/A:C)" CVSS_score="9.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.0" CVSS_base_score="9.0">
    <desc>
      <descript source="cve">The IP Phone Personal Address Book (PAB) Synchronizer feature in Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 4.1, 4.2 before 4.2(3)SR4b, 4.3 before 4.3(2)SR1b, 5.x before 5.1(3e), 6.x before 6.1(3), and 7.0 before 7.0(2) sends privileged directory-service account credentials to the client in cleartext, which allows remote attackers to modify the CUCM configuration and perform other privileged actions by intercepting these credentials, and then using them in requests unrelated to the intended synchronization task, as demonstrated by (1) DC Directory account credentials in CUCM 4.x and (2) TabSyncSysUser account credentials in CUCM 5.x through 7.x.</descript>
    </desc>
    <impacts>
      <impact source="nvd">Per: http://www.cisco.com/en/US/products/products_security_advisory09186a0080a8643c.shtml

"Impact

Successful exploitation of this vulnerability may allow an attacker to intercept user credentials that allow the attacker to escalate their privilege level and obtain complete administrative access to a vulnerable Cisco Unified Communications Manager system. If integrated with an external directory service, the intercepted user credentials may allow an attacker to gain access to additional systems configured to use the directory service for authentication."</impact>
    </impacts>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2009/0675" source="VUPEN" patch="1" adv="1">ADV-2009-0675</ref>
      <ref url="http://www.cisco.com/en/US/products/products_security_advisory09186a0080a8643c.shtml" source="CISCO" patch="1" adv="1">20090311 Cisco Unified Communications Manager IP Phone Personal Address Book Synchronizer Privilege Escalation Vulnerability</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/49196" source="XF">cucm-pab-privilege-escalation(49196)</ref>
      <ref url="http://www.securitytracker.com/id?1021839" source="SECTRACK">1021839</ref>
      <ref url="http://www.securityfocus.com/bid/34082" source="BID">34082</ref>
      <ref url="http://www.cisco.com/en/US/products/products_applied_mitigation_bulletin09186a0080a86434.html" source="CISCO">20090311 Identifying and Mitigating Exploitation of the Cisco Unified Communications Manager IP Phone Personal Address Book Synchronizer Privilege Escalation Vulnerability</ref>
      <ref url="http://secunia.com/advisories/34238" source="SECUNIA">34238</ref>
      <ref url="http://osvdb.org/52589" source="OSVDB">52589</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="unified_communications_manager">
        <vers num="4.1" />
        <vers num="4.2" />
        <vers num="4.2(3)sr1" />
        <vers num="4.2(3)sr2b" />
        <vers num="4.2(3)sr3" />
        <vers num="4.2(3)sr4" />
        <vers num="4.3" />
        <vers num="4.3(1)sr.1" />
        <vers num="4.3(2)" />
        <vers num="4.3(2)sr1" />
        <vers num="5.0" />
        <vers num="5.1(1)" />
        <vers num="5.1(2)" />
        <vers num="5.1(2a)" />
        <vers num="5.1(2b)" />
        <vers num="5.1(3)" />
        <vers num="5.1(3a)" />
        <vers num="5.1(3c)" />
        <vers num="5.1(3d)" />
        <vers num="6.0" />
        <vers num="6.0(1)" />
        <vers num="6.0(1a)" />
        <vers num="6.1" />
        <vers num="6.1(1)" />
        <vers num="6.1(1a)" />
        <vers num="6.1(2)" />
        <vers num="6.1(2)su1" />
        <vers num="6.1(3)" />
        <vers num="7.0" />
        <vers num="7.0(1)" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0633" published="2009-03-27" name="CVE-2009-0633" modified="2011-07-18" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:C)" CVSS_score="7.1" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="8.6" CVSS_base_score="7.1">
    <desc>
      <descript source="cve">Multiple unspecified vulnerabilities in the (1) Mobile IP NAT Traversal feature and (2) Mobile IPv6 subsystem in Cisco IOS 12.3 through 12.4 allow remote attackers to cause a denial of service (input queue wedge and interface outage) via MIPv6 packets, aka Bug ID CSCsm97220.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/49424" source="XF">ios-mobile-dos(49424)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0851" source="VUPEN" adv="1">ADV-2009-0851</ref>
      <ref url="http://www.securityfocus.com/bid/34241" source="BID">34241</ref>
      <ref url="http://www.cisco.com/en/US/products/products_security_advisory09186a0080a90469.shtml" source="CONFIRM" adv="1">http://www.cisco.com/en/US/products/products_security_advisory09186a0080a90469.shtml</ref>
      <ref url="http://www.cisco.com/en/US/products/products_security_advisory09186a0080a9042f.shtml" source="CISCO" adv="1">20090325 Cisco IOS Software Mobile IP and Mobile IPv6 Vulnerabilities</ref>
      <ref url="http://securitytracker.com/id?1021898" source="SECTRACK">1021898</ref>
      <ref url="http://secunia.com/advisories/34438" source="SECUNIA" adv="1">34438</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:12290" source="OVAL">oval:org.mitre.oval:def:12290</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="cisco_ios">
        <vers num="12.3" edition="b" />
        <vers num="12.3" edition="bc" />
        <vers num="12.3" edition="bw" />
        <vers num="12.3" edition="eu" />
        <vers num="12.3" edition="ja" />
        <vers num="12.3" edition="jea" />
        <vers num="12.3" edition="jeb" />
        <vers num="12.3" edition="jec" />
        <vers num="12.3" edition="jk" />
        <vers num="12.3" edition="jl" />
        <vers num="12.3" edition="jx" />
        <vers num="12.3" edition="t" />
        <vers num="12.3" edition="tpc" />
        <vers num="12.3" edition="va" />
        <vers num="12.3" edition="xa" />
        <vers num="12.3" edition="xb" />
        <vers num="12.3" edition="xc" />
        <vers num="12.3" edition="xd" />
        <vers num="12.3" edition="xe" />
        <vers num="12.3" edition="xf" />
        <vers num="12.3" edition="xg" />
        <vers num="12.3" edition="xh" />
        <vers num="12.3" edition="xi" />
        <vers num="12.3" edition="xj" />
        <vers num="12.3" edition="xk" />
        <vers num="12.3" edition="xq" />
        <vers num="12.3" edition="xr" />
        <vers num="12.3" edition="xs" />
        <vers num="12.3" edition="xu" />
        <vers num="12.3" edition="xw" />
        <vers num="12.3" edition="xy" />
        <vers num="12.3" edition="ya" />
        <vers num="12.3" edition="yd" />
        <vers num="12.3" edition="yf" />
        <vers num="12.3" edition="yg" />
        <vers num="12.3" edition="yh" />
        <vers num="12.3" edition="yi" />
        <vers num="12.3" edition="yj" />
        <vers num="12.3" edition="yk" />
        <vers num="12.3" edition="ym" />
        <vers num="12.3" edition="yq" />
        <vers num="12.3" edition="ys" />
        <vers num="12.3" edition="yt" />
        <vers num="12.3" edition="yu" />
        <vers num="12.3" edition="yx" />
        <vers num="12.3" edition="yz" />
        <vers num="12.4" edition="ja" />
        <vers num="12.4" edition="jk" />
        <vers num="12.4" edition="jma" />
        <vers num="12.4" edition="jmb" />
        <vers num="12.4" edition="jmc" />
        <vers num="12.4" edition="jx" />
        <vers num="12.4" edition="md" />
        <vers num="12.4" edition="mr" />
        <vers num="12.4" edition="sw" />
        <vers num="12.4" edition="t" />
        <vers num="12.4" edition="xa" />
        <vers num="12.4" edition="xb" />
        <vers num="12.4" edition="xc" />
        <vers num="12.4" edition="xd" />
        <vers num="12.4" edition="xe" />
        <vers num="12.4" edition="xf" />
        <vers num="12.4" edition="xg" />
        <vers num="12.4" edition="xj" />
        <vers num="12.4" edition="xk" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0634" published="2009-03-27" name="CVE-2009-0634" modified="2011-07-18" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:C)" CVSS_score="7.1" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="8.6" CVSS_base_score="7.1">
    <desc>
      <descript source="cve">Multiple unspecified vulnerabilities in the home agent (HA) implementation in the (1) Mobile IP NAT Traversal feature and (2) Mobile IPv6 subsystem in Cisco IOS 12.3 through 12.4 allow remote attackers to cause a denial of service (input queue wedge and interface outage) via an ICMP packet, aka Bug ID CSCso05337.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/49585" source="XF">ios-mobile-ha-dos(49585)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/49424" source="XF">ios-mobile-dos(49424)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0851" source="VUPEN" adv="1">ADV-2009-0851</ref>
      <ref url="http://www.securityfocus.com/bid/34241" source="BID">34241</ref>
      <ref url="http://www.cisco.com/en/US/products/products_security_advisory09186a0080a90469.shtml" source="CONFIRM" adv="1">http://www.cisco.com/en/US/products/products_security_advisory09186a0080a90469.shtml</ref>
      <ref url="http://www.cisco.com/en/US/products/products_security_advisory09186a0080a9042f.shtml" source="CISCO" adv="1">20090325 Cisco IOS Software Mobile IP and Mobile IPv6 Vulnerabilities</ref>
      <ref url="http://securitytracker.com/id?1021898" source="SECTRACK">1021898</ref>
      <ref url="http://secunia.com/advisories/34438" source="SECUNIA" adv="1">34438</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:12043" source="OVAL">oval:org.mitre.oval:def:12043</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="cisco_ios">
        <vers num="12.3" edition="b" />
        <vers num="12.3" edition="bc" />
        <vers num="12.3" edition="bw" />
        <vers num="12.3" edition="eu" />
        <vers num="12.3" edition="ja" />
        <vers num="12.3" edition="jea" />
        <vers num="12.3" edition="jeb" />
        <vers num="12.3" edition="jec" />
        <vers num="12.3" edition="jk" />
        <vers num="12.3" edition="jl" />
        <vers num="12.3" edition="jx" />
        <vers num="12.3" edition="t" />
        <vers num="12.3" edition="tpc" />
        <vers num="12.3" edition="va" />
        <vers num="12.3" edition="xa" />
        <vers num="12.3" edition="xb" />
        <vers num="12.3" edition="xc" />
        <vers num="12.3" edition="xd" />
        <vers num="12.3" edition="xe" />
        <vers num="12.3" edition="xf" />
        <vers num="12.3" edition="xg" />
        <vers num="12.3" edition="xh" />
        <vers num="12.3" edition="xi" />
        <vers num="12.3" edition="xj" />
        <vers num="12.3" edition="xk" />
        <vers num="12.3" edition="xq" />
        <vers num="12.3" edition="xr" />
        <vers num="12.3" edition="xs" />
        <vers num="12.3" edition="xu" />
        <vers num="12.3" edition="xw" />
        <vers num="12.3" edition="xy" />
        <vers num="12.3" edition="ya" />
        <vers num="12.3" edition="yd" />
        <vers num="12.3" edition="yf" />
        <vers num="12.3" edition="yg" />
        <vers num="12.3" edition="yh" />
        <vers num="12.3" edition="yi" />
        <vers num="12.3" edition="yj" />
        <vers num="12.3" edition="yk" />
        <vers num="12.3" edition="ym" />
        <vers num="12.3" edition="yq" />
        <vers num="12.3" edition="ys" />
        <vers num="12.3" edition="yt" />
        <vers num="12.3" edition="yu" />
        <vers num="12.3" edition="yx" />
        <vers num="12.3" edition="yz" />
        <vers num="12.4" edition="ja" />
        <vers num="12.4" edition="jk" />
        <vers num="12.4" edition="jma" />
        <vers num="12.4" edition="jmb" />
        <vers num="12.4" edition="jmc" />
        <vers num="12.4" edition="jx" />
        <vers num="12.4" edition="md" />
        <vers num="12.4" edition="mr" />
        <vers num="12.4" edition="sw" />
        <vers num="12.4" edition="t" />
        <vers num="12.4" edition="xa" />
        <vers num="12.4" edition="xb" />
        <vers num="12.4" edition="xc" />
        <vers num="12.4" edition="xd" />
        <vers num="12.4" edition="xe" />
        <vers num="12.4" edition="xf" />
        <vers num="12.4" edition="xg" />
        <vers num="12.4" edition="xj" />
        <vers num="12.4" edition="xk" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0635" published="2009-03-27" name="CVE-2009-0635" modified="2009-04-02" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:C)" CVSS_score="7.1" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="8.6" CVSS_base_score="7.1">
    <desc>
      <descript source="cve">Memory leak in the Cisco Tunneling Control Protocol (cTCP) encapsulation feature in Cisco IOS 12.4, when an Easy VPN (aka EZVPN) server is enabled, allows remote attackers to cause a denial of service (memory consumption and device crash) via a sequence of TCP packets.</descript>
    </desc>
    <sols>
      <sol source="nvd">Per: http://www.cisco.com/en/US/products/products_security_advisory09186a0080a90469.shtml


Obtaining Fixed Software

Cisco has released free software updates that address these vulnerabilities. Prior to deploying software, customers should consult their maintenance provider or check the software for feature set compatibility and known issues specific to their environment.

Customers may only install and expect support for the feature sets they have purchased. By installing, downloading, accessing or otherwise using such software upgrades, customers agree to be bound by the terms of Cisco's software license terms found at http://www.cisco.com/en/US/docs/general/warranty/English/EU1KEN_.html , or as otherwise set forth at Cisco.com Downloads at http://www.cisco.com/public/sw-center/sw-usingswc.shtml . </sol>
    </sols>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.cisco.com/en/US/products/products_security_advisory09186a0080a90469.shtml" source="CONFIRM" patch="1" adv="1">http://www.cisco.com/en/US/products/products_security_advisory09186a0080a90469.shtml</ref>
      <ref url="http://www.cisco.com/en/US/products/products_security_advisory09186a0080a90459.shtml" source="CISCO" patch="1" adv="1">20090325 Cisco IOS cTCP Denial of Service Vulnerability</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/49417" source="XF">ios-ctcp-dos(49417)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0851" source="VUPEN" adv="1">ADV-2009-0851</ref>
      <ref url="http://www.securitytracker.com/id?1021895" source="SECTRACK">1021895</ref>
      <ref url="http://www.securityfocus.com/bid/34246" source="BID">34246</ref>
      <ref url="http://secunia.com/advisories/34438" source="SECUNIA" adv="1">34438</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="ios">
        <vers num="12.4t" />
        <vers num="12.4xz" />
        <vers num="12.4ya" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0636" published="2009-03-27" name="CVE-2009-0636" modified="2009-03-30" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Unspecified vulnerability in Cisco IOS 12.0 through 12.4, when SIP voice services are enabled, allows remote attackers to cause a denial of service (device crash) via a valid SIP message.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.cisco.com/en/US/products/products_security_advisory09186a0080a904c0.shtml" source="CISCO" patch="1" adv="1">20090325 Cisco IOS Software Session Initiation Protocol Denial of Service Vulnerability</ref>
      <ref url="http://www.cisco.com/en/US/products/products_security_advisory09186a0080a90469.shtml" source="CONFIRM" patch="1" adv="1">http://www.cisco.com/en/US/products/products_security_advisory09186a0080a90469.shtml</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/49421" source="XF">ios-sip-dos(49421)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0851" source="VUPEN" adv="1">ADV-2009-0851</ref>
      <ref url="http://www.securityfocus.com/bid/34243" source="BID">34243</ref>
      <ref url="http://securitytracker.com/id?1021902" source="SECTRACK">1021902</ref>
      <ref url="http://secunia.com/advisories/34438" source="SECUNIA" adv="1">34438</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="ios">
        <vers num="12.0" />
        <vers num="12.0da" />
        <vers num="12.0db" />
        <vers num="12.0dc" />
        <vers num="12.0s" />
        <vers num="12.0sc" />
        <vers num="12.0sl" />
        <vers num="12.0sp" />
        <vers num="12.0st" />
        <vers num="12.0sx" />
        <vers num="12.0sy" />
        <vers num="12.0sz" />
        <vers num="12.0t" />
        <vers num="12.0w" />
        <vers num="12.0wc" />
        <vers num="12.0wt" />
        <vers num="12.0wx" />
        <vers num="12.0xa" />
        <vers num="12.0xb" />
        <vers num="12.0xc" />
        <vers num="12.0xd" />
        <vers num="12.0xe" />
        <vers num="12.0xg" />
        <vers num="12.0xh" />
        <vers num="12.0xi" />
        <vers num="12.0xj" />
        <vers num="12.0xk" />
        <vers num="12.0xl" />
        <vers num="12.0xm" />
        <vers num="12.0xn" />
        <vers num="12.0xq" />
        <vers num="12.0xr" />
        <vers num="12.0xs" />
        <vers num="12.0xt" />
        <vers num="12.0xv" />
        <vers num="12.1" />
        <vers num="12.1aa" />
        <vers num="12.1ax" />
        <vers num="12.1ay" />
        <vers num="12.1az" />
        <vers num="12.1cx" />
        <vers num="12.1da" />
        <vers num="12.1db" />
        <vers num="12.1dc" />
        <vers num="12.1e" />
        <vers num="12.1ea" />
        <vers num="12.1eb" />
        <vers num="12.1ec" />
        <vers num="12.1eo" />
        <vers num="12.1eu" />
        <vers num="12.1ev" />
        <vers num="12.1ew" />
        <vers num="12.1ex" />
        <vers num="12.1ey" />
        <vers num="12.1ez" />
        <vers num="12.1ga" />
        <vers num="12.1gb" />
        <vers num="12.1t" />
        <vers num="12.1xa" />
        <vers num="12.1xb" />
        <vers num="12.1xc" />
        <vers num="12.1xd" />
        <vers num="12.1xe" />
        <vers num="12.1xf" />
        <vers num="12.1xg" />
        <vers num="12.1xh" />
        <vers num="12.1xi" />
        <vers num="12.1xj" />
        <vers num="12.1xl" />
        <vers num="12.1xm" />
        <vers num="12.1xp" />
        <vers num="12.1xq" />
        <vers num="12.1xr" />
        <vers num="12.1xs" />
        <vers num="12.1xt" />
        <vers num="12.1xu" />
        <vers num="12.1xv" />
        <vers num="12.1xw" />
        <vers num="12.1xx" />
        <vers num="12.1xy" />
        <vers num="12.1xz" />
        <vers num="12.1ya" />
        <vers num="12.1yb" />
        <vers num="12.1yc" />
        <vers num="12.1yd" />
        <vers num="12.1ye" />
        <vers num="12.1yf" />
        <vers num="12.1yh" />
        <vers num="12.1yi" />
        <vers num="12.1yj" />
        <vers num="12.2" />
        <vers num="12.2b" />
        <vers num="12.2bc" />
        <vers num="12.2bw" />
        <vers num="12.2bx" />
        <vers num="12.2by" />
        <vers num="12.2bz" />
        <vers num="12.2cx" />
        <vers num="12.2cy" />
        <vers num="12.2cz" />
        <vers num="12.2da" />
        <vers num="12.2dd" />
        <vers num="12.2dx" />
        <vers num="12.2ew" />
        <vers num="12.2ewa" />
        <vers num="12.2ex" />
        <vers num="12.2ey" />
        <vers num="12.2ez" />
        <vers num="12.2fx" />
        <vers num="12.2fy" />
        <vers num="12.2fz" />
        <vers num="12.2ira" />
        <vers num="12.2irb" />
        <vers num="12.2ixa" />
        <vers num="12.2ixb" />
        <vers num="12.2ixc" />
        <vers num="12.2ixd" />
        <vers num="12.2ixe" />
        <vers num="12.2ixf" />
        <vers num="12.2ixg" />
        <vers num="12.2ja" />
        <vers num="12.2jk" />
        <vers num="12.2mb" />
        <vers num="12.2mc" />
        <vers num="12.2s" />
        <vers num="12.2sb" />
        <vers num="12.2sbc" />
        <vers num="12.2sca" />
        <vers num="12.2scb" />
        <vers num="12.2se" />
        <vers num="12.2sea" />
        <vers num="12.2seb" />
        <vers num="12.2sec" />
        <vers num="12.2sed" />
        <vers num="12.2see" />
        <vers num="12.2sef" />
        <vers num="12.2seg" />
        <vers num="12.2sg" />
        <vers num="12.2sga" />
        <vers num="12.2sm" />
        <vers num="12.2so" />
        <vers num="12.2sq" />
        <vers num="12.2sra" />
        <vers num="12.2srb" />
        <vers num="12.2src" />
        <vers num="12.2srd" />
        <vers num="12.2ste" />
        <vers num="12.2su" />
        <vers num="12.2sv" />
        <vers num="12.2sva" />
        <vers num="12.2svc" />
        <vers num="12.2svd" />
        <vers num="12.2sve" />
        <vers num="12.2sw" />
        <vers num="12.2sx" />
        <vers num="12.2sxa" />
        <vers num="12.2sxb" />
        <vers num="12.2sxd" />
        <vers num="12.2sxe" />
        <vers num="12.2sxf" />
        <vers num="12.2sxh" />
        <vers num="12.2sxi" />
        <vers num="12.2sy" />
        <vers num="12.2sz" />
        <vers num="12.2t" />
        <vers num="12.2tpc" />
        <vers num="12.2xa" />
        <vers num="12.2xb" />
        <vers num="12.2xc" />
        <vers num="12.2xd" />
        <vers num="12.2xe" />
        <vers num="12.2xf" />
        <vers num="12.2xg" />
        <vers num="12.2xh" />
        <vers num="12.2xi" />
        <vers num="12.2xj" />
        <vers num="12.2xk" />
        <vers num="12.2xl" />
        <vers num="12.2xm" />
        <vers num="12.2xn" />
        <vers num="12.2xna" />
        <vers num="12.2xnb" />
        <vers num="12.2xo" />
        <vers num="12.2xq" />
        <vers num="12.2xr" />
        <vers num="12.2xs" />
        <vers num="12.2xt" />
        <vers num="12.2xu" />
        <vers num="12.2xv" />
        <vers num="12.2xw" />
        <vers num="12.2ya" />
        <vers num="12.2yb" />
        <vers num="12.2yc" />
        <vers num="12.2yd" />
        <vers num="12.2ye" />
        <vers num="12.2yf" />
        <vers num="12.2yg" />
        <vers num="12.2yh" />
        <vers num="12.2yj" />
        <vers num="12.2yk" />
        <vers num="12.2yl" />
        <vers num="12.2ym" />
        <vers num="12.2yn" />
        <vers num="12.2yo" />
        <vers num="12.2yp" />
        <vers num="12.2yq" />
        <vers num="12.2yr" />
        <vers num="12.2yt" />
        <vers num="12.2yu" />
        <vers num="12.2yv" />
        <vers num="12.2yw" />
        <vers num="12.2yx" />
        <vers num="12.2yy" />
        <vers num="12.2yz" />
        <vers num="12.2za" />
        <vers num="12.2zb" />
        <vers num="12.2zc" />
        <vers num="12.2zd" />
        <vers num="12.2ze" />
        <vers num="12.2zf" />
        <vers num="12.2zg" />
        <vers num="12.2zh" />
        <vers num="12.2zj" />
        <vers num="12.2zl" />
        <vers num="12.2zp" />
        <vers num="12.2zu" />
        <vers num="12.2zx" />
        <vers num="12.2zy" />
        <vers num="12.2zya" />
        <vers num="12.3" />
        <vers num="12.3b" />
        <vers num="12.3bc" />
        <vers num="12.3bw" />
        <vers num="12.3ja" />
        <vers num="12.3jea" />
        <vers num="12.3jeb" />
        <vers num="12.3jec" />
        <vers num="12.3jk" />
        <vers num="12.3jl" />
        <vers num="12.3jx" />
        <vers num="12.3t" />
        <vers num="12.3tpc" />
        <vers num="12.3va" />
        <vers num="12.3xa" />
        <vers num="12.3xb" />
        <vers num="12.3xc" />
        <vers num="12.3xd" />
        <vers num="12.3xe" />
        <vers num="12.3xf" />
        <vers num="12.3xg" />
        <vers num="12.3xi" />
        <vers num="12.3xj" />
        <vers num="12.3xk" />
        <vers num="12.3xl" />
        <vers num="12.3xq" />
        <vers num="12.3xr" />
        <vers num="12.3xs" />
        <vers num="12.3xu" />
        <vers num="12.3xw" />
        <vers num="12.3xx" />
        <vers num="12.3xy" />
        <vers num="12.3xz" />
        <vers num="12.3ya" />
        <vers num="12.3yd" />
        <vers num="12.3yf" />
        <vers num="12.3yg" />
        <vers num="12.3yh" />
        <vers num="12.3yi" />
        <vers num="12.3yj" />
        <vers num="12.3yk" />
        <vers num="12.3ym" />
        <vers num="12.3yq" />
        <vers num="12.3ys" />
        <vers num="12.3yt" />
        <vers num="12.3yu" />
        <vers num="12.3yx" />
        <vers num="12.3yz" />
        <vers num="12.4" />
        <vers num="12.4ja" />
        <vers num="12.4jda" />
        <vers num="12.4jk" />
        <vers num="12.4jl" />
        <vers num="12.4jma" />
        <vers num="12.4jmb" />
        <vers num="12.4jx" />
        <vers num="12.4md" />
        <vers num="12.4mr" />
        <vers num="12.4sw" />
        <vers num="12.4t" />
        <vers num="12.4xa" />
        <vers num="12.4xb" />
        <vers num="12.4xc" />
        <vers num="12.4xd" />
        <vers num="12.4xe" />
        <vers num="12.4xf" />
        <vers num="12.4xg" />
        <vers num="12.4xj" />
        <vers num="12.4xk" />
        <vers num="12.4xl" />
        <vers num="12.4xm" />
        <vers num="12.4xn" />
        <vers num="12.4xp" />
        <vers num="12.4xq" />
        <vers num="12.4xr" />
        <vers num="12.4xt" />
        <vers num="12.4xv" />
        <vers num="12.4xw" />
        <vers num="12.4xy" />
        <vers num="12.4xz" />
        <vers num="12.4ya" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0637" published="2009-03-27" name="CVE-2009-0637" modified="2009-07-24" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:S/C:C/I:C/A:C)" CVSS_score="7.1" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.1">
    <desc>
      <descript source="cve">The SCP server in Cisco IOS 12.2 through 12.4, when Role-Based CLI Access is enabled, does not enforce the CLI view configuration for file transfers, which allows remote authenticated users with an attached CLI view to (1) read or (2) overwrite arbitrary files via an SCP command.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/49423" source="XF">ios-scp-priv-escalation(49423)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0851" source="VUPEN" adv="1">ADV-2009-0851</ref>
      <ref url="http://www.securityfocus.com/bid/34247" source="BID">34247</ref>
      <ref url="http://www.cisco.com/en/US/products/products_security_advisory09186a0080a904c8.shtml" source="CISCO" adv="1">20090325 Cisco IOS Software Secure Copy Privilege Escalation Vulnerability</ref>
      <ref url="http://www.cisco.com/en/US/products/products_security_advisory09186a0080a90469.shtml" source="CONFIRM" adv="1">http://www.cisco.com/en/US/products/products_security_advisory09186a0080a90469.shtml</ref>
      <ref url="http://securitytracker.com/id?1021899" source="SECTRACK">1021899</ref>
      <ref url="http://secunia.com/advisories/34438" source="SECUNIA" adv="1">34438</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="ios">
        <vers num="12.2" />
        <vers num="12.2b" />
        <vers num="12.2bc" />
        <vers num="12.2bw" />
        <vers num="12.2bx" />
        <vers num="12.2by" />
        <vers num="12.2bz" />
        <vers num="12.2ca" />
        <vers num="12.2cx" />
        <vers num="12.2cy" />
        <vers num="12.2cz" />
        <vers num="12.2da" />
        <vers num="12.2dd" />
        <vers num="12.2dx" />
        <vers num="12.2ew" />
        <vers num="12.2ewa" />
        <vers num="12.2ex" />
        <vers num="12.2ey" />
        <vers num="12.2ez" />
        <vers num="12.2fx" />
        <vers num="12.2fy" />
        <vers num="12.2fz" />
        <vers num="12.2irb" />
        <vers num="12.2ixa" />
        <vers num="12.2ixb" />
        <vers num="12.2ixc" />
        <vers num="12.2ixd" />
        <vers num="12.2ixe" />
        <vers num="12.2ixf" />
        <vers num="12.2ixg" />
        <vers num="12.2ja" />
        <vers num="12.2jk" />
        <vers num="12.2l" />
        <vers num="12.2mb" />
        <vers num="12.2mc" />
        <vers num="12.2rc" />
        <vers num="12.2s" />
        <vers num="12.2sb" />
        <vers num="12.2sbc" />
        <vers num="12.2sca" />
        <vers num="12.2sga" />
        <vers num="12.2sm" />
        <vers num="12.2so" />
        <vers num="12.2sr" />
        <vers num="12.2sra" />
        <vers num="12.2srb" />
        <vers num="12.2src" />
        <vers num="12.2su" />
        <vers num="12.2sv" />
        <vers num="12.2sva" />
        <vers num="12.2svc" />
        <vers num="12.2svd" />
        <vers num="12.2sve" />
        <vers num="12.2sw" />
        <vers num="12.2sx" />
        <vers num="12.2sxa" />
        <vers num="12.2sxb" />
        <vers num="12.2sxd" />
        <vers num="12.2sxe" />
        <vers num="12.2sxf" />
        <vers num="12.2sy" />
        <vers num="12.2sz" />
        <vers num="12.2t" />
        <vers num="12.2tpc" />
        <vers num="12.2xa" />
        <vers num="12.2xb" />
        <vers num="12.2xc" />
        <vers num="12.2xd" />
        <vers num="12.2xe" />
        <vers num="12.2xf" />
        <vers num="12.2xg" />
        <vers num="12.2xh" />
        <vers num="12.2xi" />
        <vers num="12.2xj" />
        <vers num="12.2xk" />
        <vers num="12.2xl" />
        <vers num="12.2xm" />
        <vers num="12.2xn" />
        <vers num="12.2xo" />
        <vers num="12.2xq" />
        <vers num="12.2xr" />
        <vers num="12.2xs" />
        <vers num="12.2xt" />
        <vers num="12.2xu" />
        <vers num="12.2xv" />
        <vers num="12.2xw" />
        <vers num="12.2ya" />
        <vers num="12.2yb" />
        <vers num="12.2yc" />
        <vers num="12.2yd" />
        <vers num="12.2ye" />
        <vers num="12.2yf" />
        <vers num="12.2yg" />
        <vers num="12.2yh" />
        <vers num="12.2yj" />
        <vers num="12.2yk" />
        <vers num="12.2yl" />
        <vers num="12.2ym" />
        <vers num="12.2yn" />
        <vers num="12.2yo" />
        <vers num="12.2yp" />
        <vers num="12.2yq" />
        <vers num="12.2yr" />
        <vers num="12.2ys" />
        <vers num="12.2yt" />
        <vers num="12.2yu" />
        <vers num="12.2yv" />
        <vers num="12.2yw" />
        <vers num="12.2yx" />
        <vers num="12.2yy" />
        <vers num="12.2yz" />
        <vers num="12.2za" />
        <vers num="12.2zb" />
        <vers num="12.2zc" />
        <vers num="12.2zd" />
        <vers num="12.2ze" />
        <vers num="12.2zf" />
        <vers num="12.2zg" />
        <vers num="12.2zh" />
        <vers num="12.2zj" />
        <vers num="12.2zl" />
        <vers num="12.2zp" />
        <vers num="12.2zu" />
        <vers num="12.2zx" />
        <vers num="12.2zy" />
        <vers num="12.2zya" />
        <vers num="12.4" />
        <vers num="12.4mr" />
        <vers num="12.4sw" />
        <vers num="12.4t" />
        <vers num="12.4xa" />
        <vers num="12.4xb" />
        <vers num="12.4xc" />
        <vers num="12.4xd" />
        <vers num="12.4xe" />
        <vers num="12.4xf" />
        <vers num="12.4xg" />
        <vers num="12.4xj" />
        <vers num="12.4xk" />
        <vers num="12.4xl" />
        <vers num="12.4xp" />
        <vers num="12.4xt" />
        <vers num="12.4xv" />
        <vers num="12.4xw" />
        <vers num="12.4xy" />
      </prod>
      <prod vendor="cisco" name="ios_s">
        <vers num="12.4" />
      </prod>
      <prod vendor="cisco" name="ios_t">
        <vers num="12.4" />
      </prod>
      <prod vendor="cisco" name="ios_xr">
        <vers num="12.4" />
      </prod>
      <prod vendor="cisco" name="ios">
        <vers num="12.4" />
        <vers num="12.4(1)" />
        <vers num="12.4(1b)" />
        <vers num="12.4(1c)" />
        <vers num="12.4(2)mr" />
        <vers num="12.4(2)mr1" />
        <vers num="12.4(2)t" />
        <vers num="12.4(2)t1" />
        <vers num="12.4(2)t2" />
        <vers num="12.4(2)t3" />
        <vers num="12.4(2)t4" />
        <vers num="12.4(2)xa" />
        <vers num="12.4(2)xb" />
        <vers num="12.4(2)xb2" />
        <vers num="12.4(23)" />
        <vers num="12.4(3)" />
        <vers num="12.4(3)t2" />
        <vers num="12.4(3a)" />
        <vers num="12.4(3b)" />
        <vers num="12.4(3d)" />
        <vers num="12.4(4)mr" />
        <vers num="12.4(4)t" />
        <vers num="12.4(4)t2" />
        <vers num="12.4(5)" />
        <vers num="12.4(5b)" />
        <vers num="12.4(6)t" />
        <vers num="12.4(6)t1" />
        <vers num="12.4(7)" />
        <vers num="12.4(7a)" />
        <vers num="12.4(8)" />
        <vers num="12.4(9)t" />
        <vers num="12.4ja" />
        <vers num="12.4jda" />
        <vers num="12.4jk" />
        <vers num="12.4jl" />
        <vers num="12.4jma" />
        <vers num="12.4jmb" />
        <vers num="12.4jx" />
        <vers num="12.4md" />
        <vers num="12.4mr" />
        <vers num="12.4sw" />
        <vers num="12.4t" />
        <vers num="12.4xa" />
        <vers num="12.4xb" />
        <vers num="12.4xc" />
        <vers num="12.4xd" />
        <vers num="12.4xe" />
        <vers num="12.4xf" />
        <vers num="12.4xg" />
        <vers num="12.4xj" />
        <vers num="12.4xk" />
        <vers num="12.4xl" />
        <vers num="12.4xm" />
        <vers num="12.4xn" />
        <vers num="12.4xp" />
        <vers num="12.4xt" />
        <vers num="12.4xv" />
        <vers num="12.4xw" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0638" published="2009-08-21" name="CVE-2009-0638" modified="2009-08-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">The Cisco Firewall Services Module (FWSM) 2.x, 3.1 before 3.1(16), 3.2 before 3.2(13), and 4.0 before 4.0(6) for Cisco Catalyst 6500 switches and Cisco 7600 routers allows remote attackers to cause a denial of service (traffic-handling outage) via a series of malformed ICMP messages.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/36085" source="BID" patch="1">36085</ref>
      <ref url="http://www.cisco.com/en/US/products/products_security_advisory09186a0080af0d1d.shtml" source="CISCO" patch="1" adv="1">20090819 Firewall Services Module Crafted ICMP Message Vulnerability</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/52591" source="XF">cisco-fwsm-icmp-dos(52591)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/2329" source="VUPEN" adv="1">ADV-2009-2329</ref>
      <ref url="http://securitytracker.com/id?1022747" source="SECTRACK">1022747</ref>
      <ref url="http://secunia.com/advisories/36373" source="SECUNIA" adv="1">36373</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="firewall_services_module">
        <vers num="2.1_(0.208)" />
        <vers num="2.2" />
        <vers num="2.2(1)" />
        <vers num="2.3" />
        <vers num="2.3(1)" />
        <vers num="3.1" />
        <vers num="3.1(5)" />
        <vers num="3.1(6)" />
        <vers num="3.2" />
        <vers num="3.2(1)" />
        <vers num="3.2(2)" />
        <vers num="3.2(3)" />
        <vers num="4.0" />
        <vers num="4.0(4)" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0639" published="2009-02-18" name="CVE-2009-0639" modified="2009-03-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in moduli/libri/index.php in phpyabs 0.1.2 allows remote attackers to execute arbitrary PHP code via a URL in the Azione parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2009/0361" source="VUPEN">ADV-2009-0361</ref>
      <ref url="http://www.securityfocus.com/bid/33670" source="BID">33670</ref>
      <ref url="http://www.milw0rm.com/exploits/8005" source="MILW0RM">8005</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpyabs" name="phpyabs">
        <vers num="0.1.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0640" published="2009-02-20" name="CVE-2009-0640" modified="2009-02-20" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in the administrative web server in Swann DVR4-SecuraNet allows remote attackers to read arbitrary files via a .. (dot dot) in the URI, as demonstrated by reading the vy_netman.cfg file that contains passwords.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/33716" source="BID">33716</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/500789/100/0/threaded" source="BUGTRAQ">20090210 Remote Authentication Bypass - Swann DVR4 SecuraNet (possibly DVR9 as well)</ref>
      <ref url="http://secunia.com/advisories/33861" source="SECUNIA" adv="1">33861</ref>
      <ref url="http://packetstorm.linuxsecurity.com/0902-exploits/cctv-disclose.txt" source="MISC">http://packetstorm.linuxsecurity.com/0902-exploits/cctv-disclose.txt</ref>
      <ref url="http://osvdb.org/51897" source="OSVDB">51897</ref>
    </refs>
    <vuln_soft>
      <prod vendor="swannsecurity" name="dvr4-securanet">
        <vers num="-" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0641" published="2009-02-20" name="CVE-2009-0641" modified="2009-02-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">sys_term.c in telnetd in FreeBSD 7.0-RELEASE and other 7.x versions deletes dangerous environment variables with a method that was valid only in older FreeBSD distributions, which might allow remote attackers to execute arbitrary code by passing a crafted environment variable from a telnet client, as demonstrated by an LD_PRELOAD value that references a malicious library.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://security.freebsd.org/advisories/FreeBSD-SA-09:05.telnetd.asc" source="FREEBSD" patch="1">FreeBSD-SA-09:05</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/48780" source="XF">freebsd-telnet-ldpreload-code-execution(48780)</ref>
      <ref url="http://www.securityfocus.com/bid/33777" source="BID">33777</ref>
      <ref url="http://www.milw0rm.com/exploits/8055" source="MILW0RM">8055</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2009-February/067954.html" source="FULLDISC">20090214 FreeBSD zeroday</ref>
    </refs>
    <vuln_soft>
      <prod vendor="freebsd" name="freebsd">
        <vers num="7.0" edition="beta_4" />
        <vers num="7.0" edition="current" />
        <vers num="7.0-release" />
        <vers num="7.0_beta4" />
        <vers num="7.0_releng" />
        <vers num="7.1" edition="rc1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0642" published="2009-02-20" name="CVE-2009-0642" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">ext/openssl/ossl_ocsp.c in Ruby 1.8 and 1.9 does not properly check the return value from the OCSP_basic_verify function, which might allow remote attackers to successfully present an invalid X.509 certificate, possibly involving a revoked certificate.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/48761" source="XF">ruby-ocspbasicverify-spoofing(48761)</ref>
      <ref url="http://www.ubuntu.com/usn/USN-805-1" source="UBUNTU">USN-805-1</ref>
      <ref url="http://www.securitytracker.com/id?1022505" source="SECTRACK">1022505</ref>
      <ref url="http://www.securityfocus.com/bid/33769" source="BID">33769</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-1140.html" source="REDHAT">RHSA-2009:1140</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:193" source="MANDRIVA">MDVSA-2009:193</ref>
      <ref url="http://secunia.com/advisories/35937" source="SECUNIA">35937</ref>
      <ref url="http://secunia.com/advisories/35699" source="SECUNIA">35699</ref>
      <ref url="http://secunia.com/advisories/33750" source="SECUNIA">33750</ref>
      <ref url="http://redmine.ruby-lang.org/issues/show/1091" source="CONFIRM">http://redmine.ruby-lang.org/issues/show/1091</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11450" source="OVAL">oval:org.mitre.oval:def:11450</ref>
      <ref url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=513528" source="MISC">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=513528</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ruby-lang" name="ruby">
        <vers num="1.8" />
        <vers num="1.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0643" published="2009-02-20" name="CVE-2009-0643" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">Static code injection vulnerability in post.php in Simple PHP News 1.0 final allows remote attackers to inject arbitrary PHP code into news.txt via the post parameter, and then execute the code via a direct request to display.php.  NOTE: some of these details are obtained from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/48829" source="XF">simplephpnews-news-code-execution(48829)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0357" source="VUPEN">ADV-2009-0357</ref>
      <ref url="http://www.milw0rm.com/exploits/7999" source="MILW0RM">7999</ref>
      <ref url="http://secunia.com/advisories/33814" source="SECUNIA" adv="1">33814</ref>
      <ref url="http://osvdb.org/51816" source="OSVDB">51816</ref>
    </refs>
    <vuln_soft>
      <prod vendor="dminnich" name="simple_php_news">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0644" published="2009-02-18" name="CVE-2009-0644" modified="2009-02-20" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The HTTP interface in Swann DVR4-SecuraNet has a certain default administrative username and password, which makes it easier for remote attackers to obtain privileged access.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/500789/100/0/threaded" source="BUGTRAQ">20090210 Remote Authentication Bypass - Swann DVR4 SecuraNet (possibly DVR9 as well)</ref>
      <ref url="http://packetstorm.linuxsecurity.com/0902-exploits/cctv-disclose.txt" source="MISC">http://packetstorm.linuxsecurity.com/0902-exploits/cctv-disclose.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="swannsecurity" name="dvr4-securanet">
        <vers num="-" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0645" published="2009-02-18" name="CVE-2009-0645" modified="2009-02-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)" CVSS_score="6.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.0" CVSS_base_score="6.5">
    <desc>
      <descript source="cve">Directory traversal vulnerability in index.php in Jaws 0.8.8 allows remote authenticated users to read arbitrary files via a .. (dot dot) in the (1) language, (2) Introduction_complete, and (3) use_log parameters, different vectors than CVE-2004-2445.</descript>
      <descript source="nvd">Reference links indicate file inclusion and script or code execution in addition to information exposure.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.jaws-project.com/blog/show/jaws-089-released" source="MISC" patch="1" adv="1">http://www.jaws-project.com/blog/show/jaws-089-released</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/48476" source="XF">jaws-index-file-include(48476)</ref>
      <ref url="http://www.securityfocus.com/bid/33607" source="BID">33607</ref>
      <ref url="http://www.milw0rm.com/exploits/7976" source="MILW0RM">7976</ref>
    </refs>
    <vuln_soft>
      <prod vendor="jaws" name="jaws">
        <vers num="0.8.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0646" published="2009-02-18" name="CVE-2009-0646" modified="2010-11-06" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in 4Site CMS 2.6 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) login and (2) password parameters to pcgi/4site.pl, (3) page parameter to print/print.shtml, (4) s and (5) i parameters to portfolio/index.shtml, (6) h parameter to hotel/index.php, (7) id parameter to news/news1.shtml, and the (8) th parameter to faq/index.shtml.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/48488" source="XF">4sitecms-faq-sql-injection(48488)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/48487" source="XF">4sitecms-news-sql-injection(48487)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/48486" source="XF">4sitecms-hotels-sql-injection(48486)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/48483" source="XF">4sitecms-pages-sql-injection(48483)</ref>
      <ref url="http://www.securityfocus.com/bid/33594" source="BID">33594</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/514376/100/0/threaded" source="BUGTRAQ">20101019 SQL Injection in 4site CMS</ref>
      <ref url="http://www.osvdb.org/51809" source="OSVDB">51809</ref>
      <ref url="http://www.osvdb.org/51808" source="OSVDB">51808</ref>
      <ref url="http://www.osvdb.org/51807" source="OSVDB">51807</ref>
      <ref url="http://www.osvdb.org/51806" source="OSVDB">51806</ref>
      <ref url="http://www.milw0rm.com/exploits/7964" source="MILW0RM">7964</ref>
      <ref url="http://www.htbridge.ch/advisory/sql_injection_in_4site_cms.html" source="MISC">http://www.htbridge.ch/advisory/sql_injection_in_4site_cms.html</ref>
      <ref url="http://wsec.ru/wsec-09-002-4site-cms-26-multiple-sql-injections/" source="MISC">http://wsec.ru/wsec-09-002-4site-cms-26-multiple-sql-injections/</ref>
      <ref url="http://secunia.com/advisories/33733" source="SECUNIA" adv="1">33733</ref>
    </refs>
    <vuln_soft>
      <prod vendor="4site" name="4site_cms">
        <vers prev="1" num="2.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0647" published="2009-02-19" name="CVE-2009-0647" modified="2011-09-20" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">msnmsgr.exe in Windows Live Messenger (WLM) 2009 build 14.0.8064.206, and other 14.0.8064.x builds, allows remote attackers to cause a denial of service (application crash) via a modified header in a packet, as possibly demonstrated by a UTF-8.0 value of the charset field in the Content-Type header line.  NOTE: this has been reported as a format string vulnerability by some sources, but the provenance of that information is unknown.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/48810" source="XF">wlm-packets-dos(48810)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0466" source="VUPEN" adv="1">ADV-2009-0466</ref>
      <ref url="http://www.securityfocus.com/bid/33825" source="BID">33825</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/501043/100/0/threaded" source="BUGTRAQ">20090218 RE: hello bug in windows live messenger</ref>
      <ref url="http://secunia.com/advisories/33985" source="SECUNIA" adv="1">33985</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_live_messenger">
        <vers num="2009" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0648" published="2009-02-19" name="CVE-2009-0648" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple cross-site request forgery (CSRF) vulnerabilities in the manage_users handler in admin/index.php in Falt4 CMS (aka Falt4 Extreme) RC4 allow remote attackers to hijack the authentication of administrators for requests that change passwords via the (1) edit and (2) edit_now actions.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/48786" source="XF">falt4-unspecified-csrf(48786)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/48786" source="XF">falt4-admin-index-csrf(48786)</ref>
      <ref url="http://secunia.com/advisories/33973" source="SECUNIA" adv="1">33973</ref>
      <ref url="http://packetstorm.linuxsecurity.com/0902-exploits/falt4-cms-xsrf.txt" source="MISC">http://packetstorm.linuxsecurity.com/0902-exploits/falt4-cms-xsrf.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="falt4" name="falt4_extreme">
        <vers num="rc4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0649" published="2009-02-20" name="CVE-2009-0649" modified="2009-06-25" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">The web browser in Symbian OS on the Nokia N95 cell phone allows remote attackers to cause a denial of service (crash) via JavaScript code that calls the setAttributeNode method.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/48763" source="XF">nokian95-setattributenode-dos(48763)</ref>
      <ref url="http://www.securityfocus.com/bid/33767" source="BID">33767</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/500954/100/0/threaded" source="BUGTRAQ">20090213 Nokia N95 browser "setAttributeNode" method crash</ref>
      <ref url="http://www.milw0rm.com/exploits/8051" source="MILW0RM">8051</ref>
    </refs>
    <vuln_soft>
      <prod vendor="nokia" name="symbian_s60_browser">
        <vers num="" />
      </prod>
      <prod vendor="nokia" name="n95">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0650" published="2009-02-20" name="CVE-2009-0650" modified="2009-02-23" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Stack-based buffer overflow in the GetStatsFromLine function in TPTEST 3.1.7 and earlier, and possibly 5.02, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a STATS line with a long pwd field.  NOTE: some of these details are obtained from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/48781" source="XF">tptest-pwd-bo(48781)</ref>
      <ref url="http://www.securityfocus.com/bid/33785" source="BID">33785</ref>
      <ref url="http://www.milw0rm.com/exploits/8058" source="MILW0RM">8058</ref>
      <ref url="http://secunia.com/advisories/33972" source="SECUNIA" adv="1">33972</ref>
    </refs>
    <vuln_soft>
      <prod vendor="tptest" name="tptest">
        <vers prev="1" num="3.1.7" />
        <vers num="5.0.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0651" published="2009-02-20" name="CVE-2009-0651" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)" CVSS_score="6.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.0" CVSS_base_score="6.5">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Veritas network daemon (aka vnetd) in Symantec Veritas NetBackup Server / Enterprise Server 5.x, 6.0 before MP7 SP1, and 6.5 before 6.5.3.1 allows remote attackers to execute arbitrary code via unknown vectors related to "initial communications setup."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://seer.entsupport.symantec.com/docs/317828.htm" source="CONFIRM" patch="1" adv="1">http://seer.entsupport.symantec.com/docs/317828.htm</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/48795" source="XF">veritas-netbackup-vnetd-privilege-escalation(48795)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1097" source="VUPEN">ADV-2009-1097</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0461" source="VUPEN">ADV-2009-0461</ref>
      <ref url="http://www.securitytracker.com/id?1021734" source="SECTRACK">1021734</ref>
      <ref url="http://www.securityfocus.com/bid/33772" source="BID">33772</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-253287-1" source="SUNALERT">253287</ref>
      <ref url="http://securityresponse.symantec.com/avcenter/security/Content/2009.02.17.html" source="CONFIRM">http://securityresponse.symantec.com/avcenter/security/Content/2009.02.17.html</ref>
      <ref url="http://secunia.com/advisories/33953" source="SECUNIA" adv="1">33953</ref>
      <ref url="http://osvdb.org/52269" source="OSVDB">52269</ref>
    </refs>
    <vuln_soft>
      <prod vendor="symantec" name="veritas_netbackup_server_/enterprise_server">
        <vers num="5.1" />
        <vers prev="1" num="5.1mp7" />
        <vers num="6.0" />
        <vers prev="1" num="6.0mp7" />
        <vers num="6.5" />
        <vers prev="1" num="6.5.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0652" published="2009-02-20" name="CVE-2009-0652" modified="2012-01-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:P)" CVSS_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_base_score="5.8">
    <desc>
      <descript source="cve">The Internationalized Domain Names (IDN) blacklist in Mozilla Firefox 3.0.6 and other versions before 3.0.9; Thunderbird before 2.0.0.21; and SeaMonkey before 1.1.15 does not include box-drawing characters, which allows remote attackers to spoof URLs and conduct phishing attacks, as demonstrated by homoglyphs of the / (slash) and ? (question mark) characters in a subdomain of a .cn domain name, a different vulnerability than CVE-2005-0233.  NOTE: some third parties claim that 3.0.6 is not affected, but much older versions perhaps are affected.</descript>
    </desc>
    <loss_types>
      <avail />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-April/msg00683.html" source="FEDORA">FEDORA-2009-3875</ref>
      <ref url="https://www.blackhat.com/presentations/bh-dc-09/Marlinspike/BlackHat-DC-09-Marlinspike-Defeating-SSL.pdf" source="MISC">https://www.blackhat.com/presentations/bh-dc-09/Marlinspike/BlackHat-DC-09-Marlinspike-Defeating-SSL.pdf</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/48974" source="XF">mozilla-firefox-homoglyph-spoofing(48974)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1125" source="VUPEN" adv="1">ADV-2009-1125</ref>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-764-1" source="UBUNTU">USN-764-1</ref>
      <ref url="http://www.securityfocus.com/bid/33837" source="BID">33837</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-0436.html" source="REDHAT">RHSA-2009:0436</ref>
      <ref url="http://www.mozilla.org/security/announce/2009/mfsa2009-15.html" source="CONFIRM">http://www.mozilla.org/security/announce/2009/mfsa2009-15.html</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:111" source="MANDRIVA">MDVSA-2009:111</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1830" source="DEBIAN">DSA-1830</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1797" source="DEBIAN">DSA-1797</ref>
      <ref url="http://www.blackhat.com/html/bh-dc-09/bh-dc-09-speakers.html#Marlinspike" source="MISC">http://www.blackhat.com/html/bh-dc-09/bh-dc-09-speakers.html#Marlinspike</ref>
      <ref url="http://secunia.com/advisories/35065" source="SECUNIA" adv="1">35065</ref>
      <ref url="http://secunia.com/advisories/35042" source="SECUNIA" adv="1">35042</ref>
      <ref url="http://secunia.com/advisories/34894" source="SECUNIA" adv="1">34894</ref>
      <ref url="http://secunia.com/advisories/34844" source="SECUNIA" adv="1">34844</ref>
      <ref url="http://secunia.com/advisories/34843" source="SECUNIA" adv="1">34843</ref>
      <ref url="http://secunia.com/advisories/34096" source="SECUNIA" adv="1">34096</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2009-0437.html" source="REDHAT">RHSA-2009:0437</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11396" source="OVAL">oval:org.mitre.oval:def:11396</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-05/msg00000.html" source="SUSE">SUSE-SR:2009:010</ref>
      <ref url="http://lists.immunitysec.com/pipermail/dailydave/2009-February/005563.html" source="MLIST">[dailydave] 20090220 SSL MITM fun.</ref>
      <ref url="http://lists.immunitysec.com/pipermail/dailydave/2009-February/005556.html" source="MLIST">[dailydave] 20090219 SSL MITM fun.</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="1.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.5" />
        <vers num="1.0.6" />
        <vers num="1.0.7" />
        <vers num="1.0.8" />
        <vers num="1.5" />
        <vers num="1.5.0.1" />
        <vers num="1.5.0.10" />
        <vers num="1.5.0.11" />
        <vers num="1.5.0.12" />
        <vers num="1.5.0.2" />
        <vers num="1.5.0.3" />
        <vers num="1.5.0.4" />
        <vers num="1.5.0.5" />
        <vers num="1.5.0.6" />
        <vers num="1.5.0.7" />
        <vers num="1.5.0.8" />
        <vers num="1.5.0.9" />
        <vers num="2.0" />
        <vers num="2.0.0.1" />
        <vers num="2.0.0.10" />
        <vers num="2.0.0.11" />
        <vers num="2.0.0.12" />
        <vers num="2.0.0.13" />
        <vers num="2.0.0.14" />
        <vers num="2.0.0.15" />
        <vers num="2.0.0.16" />
        <vers num="2.0.0.17" />
        <vers num="2.0.0.18" />
        <vers num="2.0.0.19" />
        <vers num="2.0.0.2" />
        <vers num="2.0.0.20" />
        <vers num="2.0.0.3" />
        <vers num="2.0.0.4" />
        <vers num="2.0.0.5" />
        <vers num="2.0.0.6" />
        <vers num="2.0.0.7" />
        <vers num="2.0.0.8" />
        <vers num="2.0.0.9" />
        <vers num="3.0" />
        <vers num="3.0.1" />
        <vers num="3.0.2" />
        <vers num="3.0.3" />
        <vers num="3.0.4" />
        <vers num="3.0.5" />
        <vers prev="1" num="3.0.6" />
      </prod>
      <prod vendor="mozilla" name="seamonkey">
        <vers num="1.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.5" />
        <vers num="1.0.6" />
        <vers num="1.0.7" />
        <vers num="1.0.8" />
        <vers num="1.0.9" />
        <vers num="1.1" edition="alpha" />
        <vers num="1.1" edition="beta" />
        <vers num="1.1.1" />
        <vers num="1.1.10" />
        <vers num="1.1.11" />
        <vers num="1.1.12" />
        <vers num="1.1.13" />
        <vers prev="1" num="1.1.14" />
        <vers num="1.1.2" />
        <vers num="1.1.3" />
        <vers num="1.1.4" />
        <vers num="1.1.5" />
        <vers num="1.1.6" />
        <vers num="1.1.7" />
        <vers num="1.1.8" />
        <vers num="1.1.9" />
      </prod>
      <prod vendor="mozilla" name="thunderbird">
        <vers num="2.0.0.0" />
        <vers num="2.0.0.12" />
        <vers num="2.0.0.14" />
        <vers num="2.0.0.16" />
        <vers num="2.0.0.17" />
        <vers num="2.0.0.18" />
        <vers num="2.0.0.19" />
        <vers prev="1" num="2.0.0.20" />
        <vers num="2.0.0.4" />
        <vers num="2.0.0.5" />
        <vers num="2.0.0.6" />
        <vers num="2.0.0.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0653" published="2009-02-20" name="CVE-2009-0653" modified="2009-06-25" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">OpenSSL, probably 0.9.6, does not verify the Basic Constraints for an intermediate CA-signed certificate, which allows remote attackers to spoof the certificates of trusted sites via a man-in-the-middle attack, a related issue to CVE-2002-0970.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="https://www.blackhat.com/presentations/bh-dc-09/Marlinspike/BlackHat-DC-09-Marlinspike-Defeating-SSL.pdf" source="MISC">https://www.blackhat.com/presentations/bh-dc-09/Marlinspike/BlackHat-DC-09-Marlinspike-Defeating-SSL.pdf</ref>
      <ref url="http://www.blackhat.com/html/bh-dc-09/bh-dc-09-speakers.html#Marlinspike" source="MISC">http://www.blackhat.com/html/bh-dc-09/bh-dc-09-speakers.html#Marlinspike</ref>
    </refs>
    <vuln_soft>
      <prod vendor="openssl" name="openssl">
        <vers num="0.9.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0654" published="2009-02-20" name="CVE-2009-0654" modified="2009-02-25" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">Tor 0.2.0.28, and probably 0.2.0.34 and earlier, allows remote attackers, with control of an entry router and an exit router, to confirm that a sender and receiver are communicating via vectors involving (1) replaying, (2) modifying, (3) inserting, or (4) deleting a single cell, and then observing cell recognition errors at the exit router.  NOTE: the vendor disputes the significance of this issue, noting that the product's design "accepted end-to-end correlation as an attack that is too expensive to solve."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.blackhat.com/presentations/bh-dc-09/Fu/BlackHat-DC-09-Fu-Break-Tors-Anonymity.pdf" source="MISC">http://www.blackhat.com/presentations/bh-dc-09/Fu/BlackHat-DC-09-Fu-Break-Tors-Anonymity.pdf</ref>
      <ref url="http://www.blackhat.com/html/bh-dc-09/bh-dc-09-archives.html#Fu" source="MISC">http://www.blackhat.com/html/bh-dc-09/bh-dc-09-archives.html#Fu</ref>
      <ref url="http://blog.torproject.org/blog/one-cell-enough" source="MISC">http://blog.torproject.org/blog/one-cell-enough</ref>
    </refs>
    <vuln_soft>
      <prod vendor="tor" name="tor">
        <vers num="0.2.0.1" edition="alpha" />
        <vers num="0.2.0.10" edition="alpha" />
        <vers num="0.2.0.11" edition="alpha" />
        <vers num="0.2.0.12" edition="alpha" />
        <vers num="0.2.0.13" edition="alpha" />
        <vers num="0.2.0.14" edition="alpha" />
        <vers num="0.2.0.15" edition="alpha" />
        <vers num="0.2.0.16" edition="alpha" />
        <vers num="0.2.0.17" edition="alpha" />
        <vers num="0.2.0.18" edition="alpha" />
        <vers num="0.2.0.19" edition="alpha" />
        <vers num="0.2.0.2" edition="alpha" />
        <vers num="0.2.0.20" edition="alpha" />
        <vers num="0.2.0.21" edition="alpha" />
        <vers num="0.2.0.22" edition="alpha" />
        <vers num="0.2.0.23" edition="alpha" />
        <vers num="0.2.0.24" edition="alpha" />
        <vers num="0.2.0.25" edition="alpha" />
        <vers num="0.2.0.26" edition="alpha" />
        <vers num="0.2.0.27" edition="alpha" />
        <vers num="0.2.0.28" edition="alpha" />
        <vers num="0.2.0.29" edition="alpha" />
        <vers num="0.2.0.3" edition="alpha" />
        <vers num="0.2.0.30" edition="alpha" />
        <vers num="0.2.0.31" edition="alpha" />
        <vers num="0.2.0.32" edition="alpha" />
        <vers prev="1" num="0.2.0.34" edition="alpha" />
        <vers num="0.2.0.4" edition="alpha" />
        <vers num="0.2.0.5" edition="alpha" />
        <vers num="0.2.0.6" edition="alpha" />
        <vers num="0.2.0.7" edition="alpha" />
        <vers num="0.2.0.8" edition="alpha" />
        <vers num="0.2.0.9" edition="alpha" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0655" published="2009-02-20" name="CVE-2009-0655" modified="2009-09-10" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="6.9" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.4" CVSS_base_score="6.9">
    <desc>
      <descript source="cve">Lenovo Veriface III allows physically proximate attackers to login to a Windows account by presenting a "plain image" of the authorized user.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/48961" source="XF">lenovo-plainimage-unauth-access(48961)</ref>
      <ref url="http://www.securityfocus.com/bid/32700" source="BID">32700</ref>
      <ref url="http://www.securityfocus.com/archive/1/498997" source="BUGTRAQ">20081208 [SVRT-07-08] Vulnerability in Face Recognition Authentication Mechanism of Lenovo-Asus-Toshiba Laptops</ref>
      <ref url="http://www.blackhat.com/presentations/bh-dc-09/Nguyen/BlackHat-DC-09-Nguyen-Face-not-your-password.pdf" source="MISC">http://www.blackhat.com/presentations/bh-dc-09/Nguyen/BlackHat-DC-09-Nguyen-Face-not-your-password.pdf</ref>
      <ref url="http://www.blackhat.com/html/bh-dc-09/bh-dc-09-archives.html#Nguyen" source="MISC">http://www.blackhat.com/html/bh-dc-09/bh-dc-09-archives.html#Nguyen</ref>
      <ref url="http://security.bkis.vn/?p=292" source="MISC">http://security.bkis.vn/?p=292</ref>
    </refs>
    <vuln_soft>
      <prod vendor="lenovo" name="veriface">
        <vers num="iii" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0656" published="2009-02-20" name="CVE-2009-0656" modified="2009-06-09" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="6.9" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.4" CVSS_base_score="6.9">
    <desc>
      <descript source="cve">Asus SmartLogon 1.0.0005 allows physically proximate attackers to bypass "security functions" by presenting an image with a modified viewpoint that matches the posture of a stored image of the authorized notebook user.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/48962" source="XF">asus-image-security-bypass(48962)</ref>
      <ref url="http://www.securityfocus.com/bid/32700" source="BID">32700</ref>
      <ref url="http://www.securityfocus.com/archive/1/498997" source="BUGTRAQ">20081208 [SVRT-07-08] Vulnerability in Face Recognition Authentication Mechanism of Lenovo-Asus-Toshiba Laptops</ref>
      <ref url="http://www.blackhat.com/presentations/bh-dc-09/Nguyen/BlackHat-DC-09-Nguyen-Face-not-your-password.pdf" source="MISC">http://www.blackhat.com/presentations/bh-dc-09/Nguyen/BlackHat-DC-09-Nguyen-Face-not-your-password.pdf</ref>
      <ref url="http://www.blackhat.com/html/bh-dc-09/bh-dc-09-archives.html#Nguyen" source="MISC">http://www.blackhat.com/html/bh-dc-09/bh-dc-09-archives.html#Nguyen</ref>
      <ref url="http://security.bkis.vn/?p=292" source="MISC">http://security.bkis.vn/?p=292</ref>
    </refs>
    <vuln_soft>
      <prod vendor="asus" name="smartlogon">
        <vers num="1.0.0005" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0657" published="2009-02-20" name="CVE-2009-0657" modified="2009-06-09" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="6.9" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.4" CVSS_base_score="6.9">
    <desc>
      <descript source="cve">Toshiba Face Recognition 2.0.2.32 allows physically proximate attackers to obtain notebook access by presenting a large number of images for which the viewpoint and lighting have been modified to match a stored image of the authorized notebook user.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/48963" source="XF">toshibaface-notebook-unauth-access(48963)</ref>
      <ref url="http://www.securityfocus.com/bid/32700" source="BID">32700</ref>
      <ref url="http://www.securityfocus.com/archive/1/498997" source="BUGTRAQ">20081208 [SVRT-07-08] Vulnerability in Face Recognition Authentication Mechanism of Lenovo-Asus-Toshiba Laptops</ref>
      <ref url="http://www.blackhat.com/presentations/bh-dc-09/Nguyen/BlackHat-DC-09-Nguyen-Face-not-your-password.pdf" source="MISC">http://www.blackhat.com/presentations/bh-dc-09/Nguyen/BlackHat-DC-09-Nguyen-Face-not-your-password.pdf</ref>
      <ref url="http://www.blackhat.com/html/bh-dc-09/bh-dc-09-archives.html#Nguyen" source="MISC">http://www.blackhat.com/html/bh-dc-09/bh-dc-09-archives.html#Nguyen</ref>
      <ref url="http://security.bkis.vn/?p=292" source="MISC">http://security.bkis.vn/?p=292</ref>
    </refs>
    <vuln_soft>
      <prod vendor="toshiba" name="face_recognition">
        <vers num="2.0.2.32" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0658" published="2009-02-20" name="CVE-2009-0658" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Buffer overflow in Adobe Reader 9.0 and earlier, and Acrobat 9.0 and earlier, allows remote attackers to execute arbitrary code via a crafted PDF document, related to a non-JavaScript function call and possibly an embedded JBIG2 image stream, as exploited in the wild in February 2009 by Trojan.Pidief.E.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-051A.html" source="CERT">TA09-051A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/905281" source="CERT-VN">VU#905281</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/48825" source="XF">adobe-acrobat-reader-image-bo(48825)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1019" source="VUPEN">ADV-2009-1019</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0472" source="FRSIRT">ADV-2009-0472</ref>
      <ref url="http://www.symantec.com/security_response/writeup.jsp?docid=2009-021212-5523-99&amp;tabid=2" source="MISC">http://www.symantec.com/security_response/writeup.jsp?docid=2009-021212-5523-99&amp;tabid=2</ref>
      <ref url="http://www.shadowserver.org/wiki/pmwiki.php?n=Calendar.20090219" source="MISC">http://www.shadowserver.org/wiki/pmwiki.php?n=Calendar.20090219</ref>
      <ref url="http://www.securitytracker.com/id?1021739" source="SECTRACK">1021739</ref>
      <ref url="http://www.securityfocus.com/bid/33751" source="BID">33751</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-0376.html" source="REDHAT">RHSA-2009:0376</ref>
      <ref url="http://www.milw0rm.com/exploits/8099" source="MILW0RM">8099</ref>
      <ref url="http://www.milw0rm.com/exploits/8090" source="MILW0RM">8090</ref>
      <ref url="http://www.adobe.com/support/security/bulletins/apsb09-04.html" source="CONFIRM">http://www.adobe.com/support/security/bulletins/apsb09-04.html</ref>
      <ref url="http://www.adobe.com/support/security/advisories/apsa09-01.html" source="CONFIRM" adv="1">http://www.adobe.com/support/security/advisories/apsa09-01.html</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-256788-1" source="SUNALERT">256788</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200904-17.xml" source="GENTOO">GLSA-200904-17</ref>
      <ref url="http://secunia.com/advisories/34790" source="SECUNIA">34790</ref>
      <ref url="http://secunia.com/advisories/34706" source="SECUNIA">34706</ref>
      <ref url="http://secunia.com/advisories/34490" source="SECUNIA">34490</ref>
      <ref url="http://secunia.com/advisories/34392" source="SECUNIA">34392</ref>
      <ref url="http://secunia.com/advisories/33901" source="SECUNIA">33901</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5697" source="OVAL">oval:org.mitre.oval:def:5697</ref>
      <ref url="http://osvdb.org/52073" source="OSVDB">52073</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-04/msg00010.html" source="SUSE">SUSE-SR:2009:009</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-03/msg00005.html" source="SUSE">SUSE-SA:2009:014</ref>
      <ref url="http://isc.sans.org/diary.html?n&amp;storyid=5902" source="MISC">http://isc.sans.org/diary.html?n&amp;storyid=5902</ref>
    </refs>
    <vuln_soft>
      <prod vendor="adobe" name="acrobat">
        <vers num="6.0" />
        <vers num="6.0.1" />
        <vers num="6.0.2" />
        <vers num="6.0.3" />
        <vers num="6.0.4" />
        <vers num="6.0.5" />
        <vers num="7.0" />
        <vers num="7.0.1" />
        <vers num="7.0.2" />
        <vers num="7.0.3" />
        <vers num="7.0.4" />
        <vers num="7.0.5" />
        <vers num="7.0.6" />
        <vers num="7.0.7" />
        <vers num="7.0.8" />
        <vers num="7.0.9" />
        <vers num="8.0.0" />
        <vers num="8.1" />
        <vers num="8.1.1" />
        <vers num="8.1.2" />
        <vers num="9" />
      </prod>
      <prod vendor="adobe" name="acrobat_reader">
        <vers num="3.0" />
        <vers num="4.0" />
        <vers num="4.0.5" />
        <vers num="4.0.5a" />
        <vers num="4.0.5c" />
        <vers num="4.5" />
        <vers num="5.0" />
        <vers num="5.0.10" />
        <vers num="5.0.11" />
        <vers num="5.0.5" />
        <vers num="5.0.6" />
        <vers num="5.0.7" />
        <vers num="5.0.9" />
        <vers num="5.1" />
        <vers num="6.0" />
        <vers num="6.0.1" />
        <vers num="6.0.2" />
        <vers num="6.0.3" />
        <vers num="6.0.4" />
        <vers num="6.0.5" />
        <vers num="7.0" />
        <vers num="7.0.1" />
        <vers num="7.0.2" />
        <vers num="7.0.3" />
        <vers num="7.0.4" />
        <vers num="7.0.5" />
        <vers num="7.0.6" />
        <vers num="7.0.7" />
        <vers num="7.0.8" />
        <vers num="7.0.9" />
        <vers num="8.0" />
        <vers num="8.1" />
        <vers num="8.1.1" />
        <vers num="8.1.2" />
        <vers prev="1" num="9" />
      </prod>
      <prod vendor="adobe" name="reader">
        <vers num="8.1.1" />
        <vers num="8.1.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0659" published="2009-02-20" name="CVE-2009-0659" modified="2009-06-09" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Stack-based buffer overflow in the GetStatsFromLine function in TPTEST 3.1.7 allows remote attackers to have an unknown impact via a STATS line with a long email field.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/48953" source="XF">tptest-getstatsfromline-bo(48953)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/48781" source="XF">tptest-pwd-bo(48781)</ref>
      <ref url="http://secunia.com/advisories/33972" source="SECUNIA" adv="1">33972</ref>
    </refs>
    <vuln_soft>
      <prod vendor="tptest" name="tptest">
        <vers num="3.1.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0660" published="2009-03-11" name="CVE-2009-0660" modified="2009-03-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Mahara 1.0 before 1.0.10 and 1.1 before 1.1.2 allow remote attackers to inject arbitrary web script or HTML via a (1) profile and (2) blog, a different vulnerability than CVE-2009-0487.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/34064" source="BID" patch="1">34064</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/49168" source="XF">mahara-userprofile-xss(49168)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0665" source="VUPEN">ADV-2009-0665</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1736" source="DEBIAN">DSA-1736</ref>
      <ref url="http://wiki.mahara.org/Release_Notes/1.1.2" source="CONFIRM">http://wiki.mahara.org/Release_Notes/1.1.2</ref>
      <ref url="http://secunia.com/advisories/34231" source="SECUNIA" adv="1">34231</ref>
      <ref url="http://secunia.com/advisories/34222" source="SECUNIA" adv="1">34222</ref>
      <ref url="http://mahara.org/interaction/forum/topic.php?id=350" source="CONFIRM" adv="1">http://mahara.org/interaction/forum/topic.php?id=350</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mahara" name="mahara">
        <vers num="1.0.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.5" />
        <vers num="1.0.6" />
        <vers num="1.0.7" />
        <vers num="1.0.8" />
        <vers num="1.0.9" />
        <vers num="1.1.0" edition="alpha1" />
        <vers num="1.1.0" edition="alpha2" />
        <vers num="1.1.0" edition="alpha3" />
        <vers num="1.1.0" edition="beta1" />
        <vers num="1.1.0" edition="beta2" />
        <vers num="1.1.0" edition="beta3" />
        <vers num="1.1.0" edition="beta4" />
        <vers num="1.1.0" edition="rc1" />
        <vers num="1.1.0" edition="rc2" />
        <vers num="1.1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0661" published="2009-03-19" name="CVE-2009-0661" modified="2009-03-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Wee Enhanced Environment for Chat (WeeChat) 0.2.6 allows remote attackers to cause a denial of service (crash) via an IRC PRIVMSG command containing crafted color codes that trigger an out-of-bounds read.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2009/0758" source="VUPEN" patch="1" adv="1">ADV-2009-0758</ref>
      <ref url="http://www.securityfocus.com/bid/34148" source="BID" patch="1">34148</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/49295" source="XF">weechat-ircmessage-dos(49295)</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2009/03/17/8" source="MLIST">[oss-security] 20090317 Re: CVE request -- firefox, vlc, WeeChat</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1744" source="DEBIAN">DSA-1744</ref>
      <ref url="http://weechat.flashtux.org/" source="CONFIRM" adv="1">http://weechat.flashtux.org/</ref>
      <ref url="http://secunia.com/advisories/34328" source="SECUNIA" adv="1">34328</ref>
      <ref url="http://secunia.com/advisories/34304" source="SECUNIA" adv="1">34304</ref>
      <ref url="http://savannah.nongnu.org/bugs/index.php?25862" source="CONFIRM">http://savannah.nongnu.org/bugs/index.php?25862</ref>
      <ref url="http://osvdb.org/52763" source="OSVDB">52763</ref>
      <ref url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=519940" source="CONFIRM">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=519940</ref>
    </refs>
    <vuln_soft>
      <prod vendor="flashtux" name="weechat">
        <vers num="0.2.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0662" published="2009-04-23" name="CVE-2009-0662" modified="2009-04-30" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:S/C:P/I:P/A:P)" CVSS_score="6.0" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="6.8" CVSS_base_score="6.0">
    <desc>
      <descript source="cve">The PlonePAS product 3.x before 3.9 and 3.2.x before 3.2.2, a product for Plone, does not properly handle the login form, which allows remote authenticated users to acquire the identity of an arbitrary user via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://plone.org/products/plone/security/advisories/cve-2009-0662" source="CONFIRM" patch="1" adv="1">http://plone.org/products/plone/security/advisories/cve-2009-0662</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/50061" source="XF">plone-unspecified-session-hijacking(50061)</ref>
      <ref url="http://www.securityfocus.com/bid/34664" source="BID">34664</ref>
      <ref url="http://secunia.com/advisories/34840" source="SECUNIA" adv="1">34840</ref>
      <ref url="http://osvdb.org/53975" source="OSVDB">53975</ref>
    </refs>
    <vuln_soft>
      <prod vendor="plone" name="plonepas">
        <vers num="3.0" />
        <vers num="3.1" />
        <vers num="3.2" />
        <vers num="3.3" />
        <vers num="3.4" />
        <vers num="3.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0663" published="2009-04-30" name="CVE-2009-0663" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Heap-based buffer overflow in the DBD::Pg (aka DBD-Pg or libdbd-pg-perl) module 1.49 for Perl might allow context-dependent attackers to execute arbitrary code via unspecified input to an application that uses the getline and pg_getline functions to read database rows.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://security.debian.org/pool/updates/main/libd/libdbd-pg-perl/libdbd-pg-perl_1.49-2+etch1.diff.gz" source="CONFIRM" patch="1">http://security.debian.org/pool/updates/main/libd/libdbd-pg-perl/libdbd-pg-perl_1.49-2+etch1.diff.gz</ref>
      <ref url="https://launchpad.net/bugs/cve/2009-0663" source="MISC">https://launchpad.net/bugs/cve/2009-0663</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/50467" source="XF">libdbdpgperl-unspecified-bo(50467)</ref>
      <ref url="http://www.securityfocus.com/bid/34755" source="BID">34755</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-1067.html" source="REDHAT">RHSA-2009:1067</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-0479.html" source="REDHAT">RHSA-2009:0479</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1780" source="DEBIAN">DSA-1780</ref>
      <ref url="http://secunia.com/advisories/35685" source="SECUNIA">35685</ref>
      <ref url="http://secunia.com/advisories/35058" source="SECUNIA">35058</ref>
      <ref url="http://secunia.com/advisories/34909" source="SECUNIA">34909</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9499" source="OVAL">oval:org.mitre.oval:def:9499</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-07/msg00002.html" source="SUSE">SUSE-SR:2009:012</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cmu" name="dbd::pg">
        <vers num="1.49" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0664" published="2009-04-23" name="CVE-2009-0664" modified="2009-04-29" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Mahara 1.0.x before 1.0.11 and 1.1.x before 1.1.3 allow remote attackers to inject arbitrary web script or HTML via (1) the introduction field in a user profile or (2) an arbitrary text block in a user view.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/34677" source="BID" patch="1">34677</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1778" source="DEBIAN" adv="1">DSA-1778</ref>
      <ref url="http://secunia.com/advisories/34871" source="SECUNIA">34871</ref>
      <ref url="http://secunia.com/advisories/34789" source="SECUNIA" adv="1">34789</ref>
      <ref url="http://osvdb.org/53892" source="OSVDB">53892</ref>
      <ref url="http://osvdb.org/53891" source="OSVDB">53891</ref>
      <ref url="http://mahara.org/interaction/forum/topic.php?id=532" source="CONFIRM">http://mahara.org/interaction/forum/topic.php?id=532</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mahara" name="mahara">
        <vers num="1.0.0" />
        <vers num="1.0.1" />
        <vers num="1.0.10" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.5" />
        <vers num="1.0.6" />
        <vers num="1.0.7" />
        <vers num="1.0.8" />
        <vers num="1.0.9" />
        <vers num="1.1.0" edition="alpha1" />
        <vers num="1.1.0" edition="alpha2" />
        <vers num="1.1.0" edition="alpha3" />
        <vers num="1.1.0" edition="beta1" />
        <vers num="1.1.0" edition="beta2" />
        <vers num="1.1.0" edition="beta3" />
        <vers num="1.1.0" edition="beta4" />
        <vers num="1.1.0" edition="rc1" />
        <vers num="1.1.0" edition="rc2" />
        <vers num="1.1.1" />
        <vers num="1.1.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0667" published="2009-07-09" name="CVE-2009-0667" modified="2009-07-10" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Untrusted search path vulnerability in Agent/Backend.pm in Ocsinventory-Agent before 0.0.9.3, and 1.x before 1.0.1, in OCS Inventory allows local users to gain privileges via a Trojan horse Perl module in an arbitrary directory.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2009/1809" source="VUPEN" patch="1" adv="1">ADV-2009-1809</ref>
      <ref url="http://www.securityfocus.com/bid/35593" source="BID" patch="1">35593</ref>
      <ref url="http://www.ocsinventory-ng.org/index.php?mact=News,cntnt01,detail,0&amp;cntnt01articleid=144" source="CONFIRM" patch="1" adv="1">http://www.ocsinventory-ng.org/index.php?mact=News,cntnt01,detail,0&amp;cntnt01articleid=144</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1828" source="DEBIAN" patch="1">DSA-1828</ref>
      <ref url="http://security.debian.org/pool/updates/main/o/ocsinventory-agent/ocsinventory-agent_0.0.9.2repack1-4lenny1.diff.gz" source="CONFIRM" patch="1">http://security.debian.org/pool/updates/main/o/ocsinventory-agent/ocsinventory-agent_0.0.9.2repack1-4lenny1.diff.gz</ref>
      <ref url="http://nana.rulezlan.org/~goneri/ocsinventory-agent/Ocsinventory-Agent-0.0.9.3.tar.gz" source="CONFIRM" patch="1">http://nana.rulezlan.org/~goneri/ocsinventory-agent/Ocsinventory-Agent-0.0.9.3.tar.gz</ref>
      <ref url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=506416" source="CONFIRM" patch="1">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=506416</ref>
      <ref url="http://secunia.com/advisories/35768" source="SECUNIA">35768</ref>
      <ref url="http://secunia.com/advisories/35727" source="SECUNIA">35727</ref>
      <ref url="http://osvdb.org/55718" source="OSVDB">55718</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ocsinventory-ng" name="ocs_inventory_ng">
        <vers num="1.0" edition="beta" />
        <vers num="1.0" edition="rc1" />
        <vers num="1.0" edition="rc2" />
        <vers num="1.0" edition="rc3" />
        <vers num="1.0" edition="rc3-1" />
      </prod>
      <prod vendor="ocsinventory-ng" name="ocsinventory-agent">
        <vers prev="1" num="0.0.9.2" />
        <vers num="0.05" />
        <vers num="0.08" />
        <vers num="0.09" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0668" published="2009-08-07" name="CVE-2009-0668" modified="2009-08-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)" CVSS_score="6.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.0" CVSS_base_score="6.5">
    <desc>
      <descript source="cve">Unspecified vulnerability in Zope Object Database (ZODB) before 3.8.2, when certain Zope Enterprise Objects (ZEO) database sharing is enabled, allows remote attackers to execute arbitrary Python code via vectors involving the ZEO network protocol.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/52377" source="XF">zope-protocol-code-execution(52377)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/2217" source="VUPEN">ADV-2009-2217</ref>
      <ref url="http://www.securityfocus.com/bid/35987" source="BID">35987</ref>
      <ref url="http://secunia.com/advisories/36205" source="SECUNIA" adv="1">36205</ref>
      <ref url="http://secunia.com/advisories/36204" source="SECUNIA" adv="1">36204</ref>
      <ref url="http://pypi.python.org/pypi/ZODB3/3.8.2#whats-new-in-zodb-3-8-2" source="CONFIRM">http://pypi.python.org/pypi/ZODB3/3.8.2#whats-new-in-zodb-3-8-2</ref>
      <ref url="http://osvdb.org/56827" source="OSVDB">56827</ref>
      <ref url="http://mail.zope.org/pipermail/zope-announce/2009-August/002220.html" source="MLIST">[zope-announce] 20090806 CVE-2009-0668 and CVE-2009-0669: Releases to fix ZODB ZEO server vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="zope" name="zodb">
        <vers num="2.10.9" />
        <vers num="2.11.4" />
        <vers num="2.8.11" />
        <vers num="2.9.11" />
        <vers num="3.1" />
        <vers num="3.1.1" />
        <vers num="3.2" />
        <vers num="3.2.4" />
        <vers num="3.3" />
        <vers num="3.3.3" />
        <vers num="3.4" />
        <vers num="3.4.1" />
        <vers num="3.5" />
        <vers num="3.6" />
        <vers num="3.7" />
        <vers num="3.8.0" />
        <vers prev="1" num="3.8.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0669" published="2009-08-07" name="CVE-2009-0669" modified="2009-08-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Zope Object Database (ZODB) before 3.8.2, when certain Zope Enterprise Objects (ZEO) database sharing is enabled, allows remote attackers to bypass authentication via vectors involving the ZEO network protocol.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://pypi.python.org/pypi/ZODB3/3.8.2#whats-new-in-zodb-3-8-2" source="CONFIRM" patch="1" adv="1">http://pypi.python.org/pypi/ZODB3/3.8.2#whats-new-in-zodb-3-8-2</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/52379" source="XF">zope-protocol-auth-bypass(52379)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/2217" source="VUPEN">ADV-2009-2217</ref>
      <ref url="http://www.securityfocus.com/bid/35987" source="BID">35987</ref>
      <ref url="http://secunia.com/advisories/36205" source="SECUNIA" adv="1">36205</ref>
      <ref url="http://secunia.com/advisories/36204" source="SECUNIA" adv="1">36204</ref>
      <ref url="http://osvdb.org/56826" source="OSVDB">56826</ref>
      <ref url="http://mail.zope.org/pipermail/zope-announce/2009-August/002220.html" source="MLIST">[zope-announce] 20090806 CVE-2009-0668 and CVE-2009-0669: Releases to fix ZODB ZEO server vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="zope" name="zodb">
        <vers num="3.8" />
        <vers num="3.8.0" />
        <vers prev="1" num="3.8.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" seq="2009-0671" reject="1" published="2009-02-22" name="CVE-2009-0671" modified="2009-02-26">
    <desc>
      <descript source="cve">** REJECT **  Format string vulnerability in the University of Washington (UW) c-client library, as used by the UW IMAP toolkit imap-2007d and other applications, allows remote attackers to execute arbitrary code via format string specifiers in the initial request to the IMAP port (143/tcp).  NOTE: Red Hat has disputed the vulnerability, stating "The Red Hat Security Response Team have been unable to confirm the existence of this format string vulnerability in the toolkit, and the sample published exploit is not complete or functional."  CVE agrees that the exploit contains syntax errors and uses Unix-only include files while invoking Windows functions.</descript>
    </desc>
    <refs />
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0672" published="2009-02-22" name="CVE-2009-0672" modified="2009-06-09" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)" CVSS_score="6.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.0" CVSS_base_score="6.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in the Resend_Email module in Raven Web Services RavenNuke 2.30 allows remote authenticated administrators to execute arbitrary SQL commands via the user_prefix parameter to modules.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/33787" source="BID" patch="1">33787</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/48791" source="XF">ravennuke-modules-sql-injection(48791)</ref>
      <ref url="http://www.waraxe.us/advisory-72.html" source="MISC">http://www.waraxe.us/advisory-72.html</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/500988/100/0/threaded" source="BUGTRAQ">20090216 [waraxe-2009-SA#072] - Multiple Vulnerabilities in RavenNuke 2.3.0</ref>
      <ref url="http://www.milw0rm.com/exploits/8068" source="MILW0RM">8068</ref>
      <ref url="http://ravenphpscripts.com/postt17156.html" source="CONFIRM">http://ravenphpscripts.com/postt17156.html</ref>
      <ref url="http://osvdb.org/52298" source="OSVDB">52298</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ravenphpscripts" name="ravennuke">
        <vers num="2.30" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0673" published="2009-02-22" name="CVE-2009-0673" modified="2009-02-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)" CVSS_score="6.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.0" CVSS_base_score="6.5">
    <desc>
      <descript source="cve">Eval injection vulnerability in the Custom Fields feature in the Your Account module in Raven Web Services RavenNuke 2.30 allows remote authenticated administrators to execute arbitrary PHP code via the ID Field Name box in a yaCustomFields action to admin.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/48790" source="XF">ravennuke-admin-code-execution(48790)</ref>
      <ref url="http://www.waraxe.us/advisory-72.html" source="MISC">http://www.waraxe.us/advisory-72.html</ref>
      <ref url="http://www.securityfocus.com/bid/33787" source="BID">33787</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/500988/100/0/threaded" source="BUGTRAQ">20090216 [waraxe-2009-SA#072] - Multiple Vulnerabilities in RavenNuke 2.3.0</ref>
      <ref url="http://www.milw0rm.com/exploits/8068" source="MILW0RM">8068</ref>
      <ref url="http://ravenphpscripts.com/postt17156.html" source="CONFIRM">http://ravenphpscripts.com/postt17156.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ravenphpscripts" name="ravennuke">
        <vers num="2.30" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0674" published="2009-02-22" name="CVE-2009-0674" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:S/C:P/I:P/A:P)" CVSS_score="6.0" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="6.8" CVSS_base_score="6.0">
    <desc>
      <descript source="cve">images/captcha.php in Raven Web Services RavenNuke 2.30, when register_globals and display_errors are enabled, allows remote attackers to determine the existence of local files by sending requests with full pathnames in the aFonts array parameter, and then observing the error messages, which differ between existing and nonexistent pathnames.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/48983" source="XF">ravennuke-captcha-afonts-info-disclosure(48983)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/48983" source="XF">ravennuke-captcha-info-disc-var1(48983)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/48792" source="XF">ravennuke-captcha-info-disclosure(48792)</ref>
      <ref url="http://www.waraxe.us/advisory-72.html" source="MISC">http://www.waraxe.us/advisory-72.html</ref>
      <ref url="http://www.securityfocus.com/bid/33787" source="BID">33787</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/500988/100/0/threaded" source="BUGTRAQ">20090216 [waraxe-2009-SA#072] - Multiple Vulnerabilities in RavenNuke 2.3.0</ref>
      <ref url="http://www.milw0rm.com/exploits/8068" source="MILW0RM">8068</ref>
      <ref url="http://ravenphpscripts.com/postt17156.html" source="CONFIRM" adv="1">http://ravenphpscripts.com/postt17156.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ravenphpscripts" name="ravennuke">
        <vers num="2.30" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2009-0675" published="2009-02-22" name="CVE-2009-0675" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">The skfp_ioctl function in drivers/net/skfp/skfddi.c in the Linux kernel before 2.6.28.6 permits SKFP_CLR_STATS requests only when the CAP_NET_ADMIN capability is absent, instead of when this capability is present, which allows local users to reset the driver statistics, related to an "inverted logic" issue.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=486534" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=486534</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/3316" source="VUPEN">ADV-2009-3316</ref>
      <ref url="http://www.vmware.com/security/advisories/VMSA-2009-0016.html" source="CONFIRM">http://www.vmware.com/security/advisories/VMSA-2009-0016.html</ref>
      <ref url="http://www.ubuntu.com/usn/usn-751-1" source="UBUNTU">USN-751-1</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/507985/100/0/threaded" source="BUGTRAQ">20091120 VMSA-2009-0016 VMware vCenter and ESX update release and vMA patch release address multiple security issue in third party components</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-0360.html" source="REDHAT">RHSA-2009:0360</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-0326.html" source="REDHAT">RHSA-2009:0326</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:071" source="MANDRIVA">MDVSA-2009:071</ref>
      <ref url="http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.28.6" source="CONFIRM">http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.28.6</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1794" source="DEBIAN">DSA-1794</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1787" source="DEBIAN">DSA-1787</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1749" source="DEBIAN">DSA-1749</ref>
      <ref url="http://secunia.com/advisories/37471" source="SECUNIA">37471</ref>
      <ref url="http://secunia.com/advisories/35394" source="SECUNIA">35394</ref>
      <ref url="http://secunia.com/advisories/35011" source="SECUNIA">35011</ref>
      <ref url="http://secunia.com/advisories/34981" source="SECUNIA">34981</ref>
      <ref url="http://secunia.com/advisories/34680" source="SECUNIA">34680</ref>
      <ref url="http://secunia.com/advisories/34502" source="SECUNIA">34502</ref>
      <ref url="http://secunia.com/advisories/34394" source="SECUNIA">34394</ref>
      <ref url="http://secunia.com/advisories/33938" source="SECUNIA" adv="1">33938</ref>
      <ref url="http://secunia.com/advisories/33758" source="SECUNIA">33758</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:8685" source="OVAL">oval:org.mitre.oval:def:8685</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11529" source="OVAL">oval:org.mitre.oval:def:11529</ref>
      <ref url="http://openwall.com/lists/oss-security/2009/02/20/2" source="MLIST">[oss-security] 20090220 CVE request: kernel: skfp_ioctl inverted logic flaw</ref>
      <ref url="http://lists.openwall.net/netdev/2009/01/28/90" source="MLIST">[netdev] 20090128 [PATCH] drivers/net/skfp: if !capable(CAP_NET_ADMIN): inverted logic</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-06/msg00001.html" source="SUSE">SUSE-SA:2009:031</ref>
      <ref url="http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=c25b9abbc2c2c0da88e180c3933d6e773245815a" source="CONFIRM">http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=c25b9abbc2c2c0da88e180c3933d6e773245815a</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="kernel">
        <vers num="2.6" />
        <vers num="2.6.0" />
        <vers num="2.6.1" />
        <vers num="2.6.10" />
        <vers num="2.6.11" />
        <vers num="2.6.11.1" />
        <vers num="2.6.11.10" />
        <vers num="2.6.11.11" />
        <vers num="2.6.11.12" />
        <vers num="2.6.11.2" />
        <vers num="2.6.11.3" />
        <vers num="2.6.11.4" />
        <vers num="2.6.11.5" />
        <vers num="2.6.11.6" />
        <vers num="2.6.11.7" />
        <vers num="2.6.11.8" />
        <vers num="2.6.11.9" />
        <vers num="2.6.12" />
        <vers num="2.6.12.1" />
        <vers num="2.6.12.2" />
        <vers num="2.6.12.3" />
        <vers num="2.6.12.4" />
        <vers num="2.6.12.5" />
        <vers num="2.6.12.6" />
        <vers num="2.6.13" />
        <vers num="2.6.13.1" />
        <vers num="2.6.13.2" />
        <vers num="2.6.13.3" />
        <vers num="2.6.13.4" />
        <vers num="2.6.13.5" />
        <vers num="2.6.14" />
        <vers num="2.6.14.1" />
        <vers num="2.6.14.2" />
        <vers num="2.6.14.3" />
        <vers num="2.6.14.4" />
        <vers num="2.6.14.5" />
        <vers num="2.6.14.6" />
        <vers num="2.6.14.7" />
        <vers num="2.6.15" />
        <vers num="2.6.15.1" />
        <vers num="2.6.15.2" />
        <vers num="2.6.15.3" />
        <vers num="2.6.15.4" />
        <vers num="2.6.15.5" />
        <vers num="2.6.15.6" />
        <vers num="2.6.15.7" />
        <vers num="2.6.16" />
        <vers num="2.6.16.1" />
        <vers num="2.6.16.10" />
        <vers num="2.6.16.11" />
        <vers num="2.6.16.12" />
        <vers num="2.6.16.13" />
        <vers num="2.6.16.14" />
        <vers num="2.6.16.15" />
        <vers num="2.6.16.16" />
        <vers num="2.6.16.17" />
        <vers num="2.6.16.18" />
        <vers num="2.6.16.19" />
        <vers num="2.6.16.2" />
        <vers num="2.6.16.20" />
        <vers num="2.6.16.21" />
        <vers num="2.6.16.22" />
        <vers num="2.6.16.23" />
        <vers num="2.6.16.24" />
        <vers num="2.6.16.25" />
        <vers num="2.6.16.26" />
        <vers num="2.6.16.27" />
        <vers num="2.6.16.28" />
        <vers num="2.6.16.29" />
        <vers num="2.6.16.3" />
        <vers num="2.6.16.30" />
        <vers num="2.6.16.31" />
        <vers num="2.6.16.32" />
        <vers num="2.6.16.33" />
        <vers num="2.6.16.34" />
        <vers num="2.6.16.35" />
        <vers num="2.6.16.36" />
        <vers num="2.6.16.37" />
        <vers num="2.6.16.38" />
        <vers num="2.6.16.39" />
        <vers num="2.6.16.4" />
        <vers num="2.6.16.40" />
        <vers num="2.6.16.41" />
        <vers num="2.6.16.42" />
        <vers num="2.6.16.43" />
        <vers num="2.6.16.44" />
        <vers num="2.6.16.45" />
        <vers num="2.6.16.46" />
        <vers num="2.6.16.47" />
        <vers num="2.6.16.48" />
        <vers num="2.6.16.49" />
        <vers num="2.6.16.5" />
        <vers num="2.6.16.50" />
        <vers num="2.6.16.51" />
        <vers num="2.6.16.52" />
        <vers num="2.6.16.53" />
        <vers num="2.6.16.54" />
        <vers num="2.6.16.55" />
        <vers num="2.6.16.56" />
        <vers num="2.6.16.57" />
        <vers num="2.6.16.58" />
        <vers num="2.6.16.59" />
        <vers num="2.6.16.6" />
        <vers num="2.6.16.60" />
        <vers num="2.6.16.61" />
        <vers num="2.6.16.62" />
        <vers num="2.6.16.7" />
        <vers num="2.6.16.8" />
        <vers num="2.6.16.9" />
        <vers num="2.6.17" />
        <vers num="2.6.17.1" />
        <vers num="2.6.17.10" />
        <vers num="2.6.17.11" />
        <vers num="2.6.17.12" />
        <vers num="2.6.17.13" />
        <vers num="2.6.17.14" />
        <vers num="2.6.17.2" />
        <vers num="2.6.17.3" />
        <vers num="2.6.17.4" />
        <vers num="2.6.17.5" />
        <vers num="2.6.17.6" />
        <vers num="2.6.17.7" />
        <vers num="2.6.17.8" />
        <vers num="2.6.17.9" />
        <vers num="2.6.18" edition="rc1" />
        <vers num="2.6.18" edition="rc2" />
        <vers num="2.6.18" edition="rc3" />
        <vers num="2.6.18" edition="rc4" />
        <vers num="2.6.18" edition="rc5" />
        <vers num="2.6.18" edition="rc6" />
        <vers num="2.6.18" edition="rc7" />
        <vers num="2.6.18.1" />
        <vers num="2.6.18.2" />
        <vers num="2.6.18.3" />
        <vers num="2.6.18.4" />
        <vers num="2.6.18.5" />
        <vers num="2.6.18.6" />
        <vers num="2.6.18.7" />
        <vers num="2.6.18.8" />
        <vers num="2.6.19" />
        <vers num="2.6.19.1" />
        <vers num="2.6.19.2" />
        <vers num="2.6.19.3" />
        <vers num="2.6.19.4" />
        <vers num="2.6.19.5" />
        <vers num="2.6.19.6" />
        <vers num="2.6.19.7" />
        <vers num="2.6.2" />
        <vers num="2.6.20" />
        <vers num="2.6.20.1" />
        <vers num="2.6.20.10" />
        <vers num="2.6.20.11" />
        <vers num="2.6.20.12" />
        <vers num="2.6.20.13" />
        <vers num="2.6.20.14" />
        <vers num="2.6.20.15" />
        <vers num="2.6.20.16" />
        <vers num="2.6.20.17" />
        <vers num="2.6.20.18" />
        <vers num="2.6.20.19" />
        <vers num="2.6.20.2" />
        <vers num="2.6.20.20" />
        <vers num="2.6.20.21" />
        <vers num="2.6.20.3" />
        <vers num="2.6.20.4" />
        <vers num="2.6.20.5" />
        <vers num="2.6.20.6" />
        <vers num="2.6.20.7" />
        <vers num="2.6.20.8" />
        <vers num="2.6.20.9" />
        <vers num="2.6.21" />
        <vers num="2.6.21.1" />
        <vers num="2.6.21.2" />
        <vers num="2.6.21.3" />
        <vers num="2.6.21.4" />
        <vers num="2.6.21.5" />
        <vers num="2.6.21.6" />
        <vers num="2.6.21.7" />
        <vers num="2.6.22" />
        <vers num="2.6.22.1" />
        <vers num="2.6.22.10" />
        <vers num="2.6.22.11" />
        <vers num="2.6.22.12" />
        <vers num="2.6.22.13" />
        <vers num="2.6.22.14" />
        <vers num="2.6.22.15" />
        <vers num="2.6.22.16" />
        <vers num="2.6.22.17" />
        <vers num="2.6.22.18" />
        <vers num="2.6.22.19" />
        <vers num="2.6.22.2" />
        <vers num="2.6.22.20" />
        <vers num="2.6.22.21" />
        <vers num="2.6.22.22" />
        <vers num="2.6.22.3" />
        <vers num="2.6.22.4" />
        <vers num="2.6.22.5" />
        <vers num="2.6.22.6" />
        <vers num="2.6.22.7" />
        <vers num="2.6.22.8" />
        <vers num="2.6.22.9" />
        <vers num="2.6.23" edition="rc1" />
        <vers num="2.6.23" edition="rc2" />
        <vers num="2.6.23.1" />
        <vers num="2.6.23.10" />
        <vers num="2.6.23.11" />
        <vers num="2.6.23.12" />
        <vers num="2.6.23.13" />
        <vers num="2.6.23.14" />
        <vers num="2.6.23.15" />
        <vers num="2.6.23.16" />
        <vers num="2.6.23.17" />
        <vers num="2.6.23.2" />
        <vers num="2.6.23.3" />
        <vers num="2.6.23.4" />
        <vers num="2.6.23.5" />
        <vers num="2.6.23.6" />
        <vers num="2.6.23.7" />
        <vers num="2.6.23.8" />
        <vers num="2.6.23.9" />
        <vers num="2.6.24" edition="rc1" />
        <vers num="2.6.24" edition="rc2" />
        <vers num="2.6.24" edition="rc3" />
        <vers num="2.6.24" edition="rc4" />
        <vers num="2.6.24" edition="rc5" />
        <vers num="2.6.24.1" />
        <vers num="2.6.24.2" />
        <vers num="2.6.24.3" />
        <vers num="2.6.24.4" />
        <vers num="2.6.24.5" />
        <vers num="2.6.24.6" />
        <vers num="2.6.24.7" />
        <vers num="2.6.25" edition="" />
        <vers num="2.6.25" edition=":x86_64" />
        <vers num="2.6.25.1" edition="" />
        <vers num="2.6.25.1" edition=":x86_64" />
        <vers num="2.6.25.10" edition="" />
        <vers num="2.6.25.10" edition=":x86_64" />
        <vers num="2.6.25.11" edition="" />
        <vers num="2.6.25.11" edition=":x86_64" />
        <vers num="2.6.25.12" edition="" />
        <vers num="2.6.25.12" edition=":x86_64" />
        <vers num="2.6.25.13" />
        <vers num="2.6.25.14" />
        <vers num="2.6.25.15" />
        <vers num="2.6.25.16" />
        <vers num="2.6.25.17" />
        <vers num="2.6.25.18" />
        <vers num="2.6.25.19" />
        <vers num="2.6.25.2" edition="" />
        <vers num="2.6.25.2" edition=":x86_64" />
        <vers num="2.6.25.20" />
        <vers num="2.6.25.3" edition="" />
        <vers num="2.6.25.3" edition=":x86_64" />
        <vers num="2.6.25.4" edition="" />
        <vers num="2.6.25.4" edition=":x86_64" />
        <vers num="2.6.25.5" edition="" />
        <vers num="2.6.25.5" edition=":x86_64" />
        <vers num="2.6.25.6" edition="" />
        <vers num="2.6.25.6" edition=":x86_64" />
        <vers num="2.6.25.7" edition="" />
        <vers num="2.6.25.7" edition=":x86_64" />
        <vers num="2.6.25.8" edition="" />
        <vers num="2.6.25.8" edition=":x86_64" />
        <vers num="2.6.25.9" edition="" />
        <vers num="2.6.25.9" edition=":x86_64" />
        <vers num="2.6.26" edition="rc4" />
        <vers num="2.6.26.1" />
        <vers num="2.6.26.2" />
        <vers num="2.6.26.3" />
        <vers num="2.6.26.4" />
        <vers num="2.6.26.5" />
        <vers num="2.6.26.6" />
        <vers num="2.6.26.7" />
        <vers num="2.6.26.8" />
        <vers num="2.6.27" edition="rc1" />
        <vers num="2.6.27" edition="rc2" />
        <vers num="2.6.27" edition="rc3" />
        <vers num="2.6.27" edition="rc4" />
        <vers num="2.6.27" edition="rc5" />
        <vers num="2.6.27" edition="rc6" />
        <vers num="2.6.27" edition="rc7" />
        <vers num="2.6.27" edition="rc8" />
        <vers num="2.6.27" edition="rc9" />
        <vers num="2.6.27.1" />
        <vers num="2.6.27.10" />
        <vers num="2.6.27.11" />
        <vers num="2.6.27.12" />
        <vers num="2.6.27.2" />
        <vers num="2.6.27.3" />
        <vers num="2.6.27.4" />
        <vers num="2.6.27.5" />
        <vers num="2.6.27.6" />
        <vers num="2.6.27.7" />
        <vers num="2.6.27.8" />
        <vers num="2.6.27.9" />
        <vers num="2.6.28" edition="rc1" />
        <vers num="2.6.28" edition="rc2" />
        <vers num="2.6.28" edition="rc3" />
        <vers num="2.6.28" edition="rc4" />
        <vers num="2.6.28" edition="rc5" />
        <vers num="2.6.28" edition="rc6" />
        <vers num="2.6.28" edition="rc7" />
        <vers num="2.6.28.1" />
        <vers num="2.6.28.2" />
        <vers num="2.6.28.3" />
        <vers num="2.6.28.4" />
        <vers prev="1" num="2.6.28.5" />
        <vers num="2.6.3" />
        <vers num="2.6.4" />
        <vers num="2.6.5" />
        <vers num="2.6.6" />
        <vers num="2.6.7" />
        <vers num="2.6.8" />
        <vers num="2.6.8.1" />
        <vers num="2.6.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2009-0676" published="2009-02-22" name="CVE-2009-0676" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">The sock_getsockopt function in net/core/sock.c in the Linux kernel before 2.6.28.6 does not initialize a certain structure member, which allows local users to obtain potentially sensitive information from kernel memory via an SO_BSDCOMPAT getsockopt request.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/33846" source="BID" patch="1">33846</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=486305" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=486305</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/48847" source="XF">kernel-sock-information-disclosure(48847)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/3316" source="VUPEN">ADV-2009-3316</ref>
      <ref url="http://www.vmware.com/security/advisories/VMSA-2009-0016.html" source="CONFIRM">http://www.vmware.com/security/advisories/VMSA-2009-0016.html</ref>
      <ref url="http://www.ubuntu.com/usn/usn-751-1" source="UBUNTU">USN-751-1</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/507985/100/0/threaded" source="BUGTRAQ">20091120 VMSA-2009-0016 VMware vCenter and ESX update release and vMA patch release address multiple security issue in third party components</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-0360.html" source="REDHAT">RHSA-2009:0360</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-0326.html" source="REDHAT">RHSA-2009:0326</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2009/03/02/6" source="MLIST">[oss-security] 20090302 Re: CVE request: kernel: memory disclosure in SO_BSDCOMPAT gsopt</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2009/02/24/1" source="MLIST">[oss-security] 20090224 Re: CVE request: kernel: memory disclosure in SO_BSDCOMPAT gsopt</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:071" source="MANDRIVA">MDVSA-2009:071</ref>
      <ref url="http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.28.6" source="CONFIRM">http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.28.6</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1794" source="DEBIAN">DSA-1794</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1787" source="DEBIAN">DSA-1787</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1749" source="DEBIAN">DSA-1749</ref>
      <ref url="http://secunia.com/advisories/37471" source="SECUNIA">37471</ref>
      <ref url="http://secunia.com/advisories/35394" source="SECUNIA">35394</ref>
      <ref url="http://secunia.com/advisories/35390" source="SECUNIA">35390</ref>
      <ref url="http://secunia.com/advisories/35011" source="SECUNIA">35011</ref>
      <ref url="http://secunia.com/advisories/34981" source="SECUNIA">34981</ref>
      <ref url="http://secunia.com/advisories/34962" source="SECUNIA">34962</ref>
      <ref url="http://secunia.com/advisories/34786" source="SECUNIA">34786</ref>
      <ref url="http://secunia.com/advisories/34680" source="SECUNIA">34680</ref>
      <ref url="http://secunia.com/advisories/34502" source="SECUNIA">34502</ref>
      <ref url="http://secunia.com/advisories/34394" source="SECUNIA">34394</ref>
      <ref url="http://secunia.com/advisories/33758" source="SECUNIA">33758</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2009-0459.html" source="REDHAT">RHSA-2009:0459</ref>
      <ref url="http://patchwork.kernel.org/patch/6816/" source="CONFIRM">http://patchwork.kernel.org/patch/6816/</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:8618" source="OVAL">oval:org.mitre.oval:def:8618</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11653" source="OVAL">oval:org.mitre.oval:def:11653</ref>
      <ref url="http://openwall.com/lists/oss-security/2009/02/20/1" source="MLIST">[oss-security] 20090220 CVE request: kernel: memory disclosure in SO_BSDCOMPAT gsopt</ref>
      <ref url="http://marc.info/?l=linux-kernel&amp;m=123540732700371&amp;w=2" source="MLIST">[linux-kernel] 20090223 net: amend the fix for SO_BSDCOMPAT gsopt infoleak</ref>
      <ref url="http://lkml.org/lkml/2009/2/12/123" source="MLIST">[linux-kernel] 20090212 [PATCH] 4 bytes kernel memory disclosure in SO_BSDCOMPAT gsopt try #2</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-06/msg00001.html" source="SUSE">SUSE-SA:2009:031</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-06/msg00000.html" source="SUSE">SUSE-SA:2009:030</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-04/msg00007.html" source="SUSE">SUSE-SA:2009:021</ref>
      <ref url="http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=df0bca049d01c0ee94afb7cd5dfd959541e6c8da" source="CONFIRM">http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=df0bca049d01c0ee94afb7cd5dfd959541e6c8da</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="kernel">
        <vers num="2.6" />
        <vers num="2.6.0" />
        <vers num="2.6.1" />
        <vers num="2.6.10" />
        <vers num="2.6.11" />
        <vers num="2.6.11.1" />
        <vers num="2.6.11.10" />
        <vers num="2.6.11.11" />
        <vers num="2.6.11.12" />
        <vers num="2.6.11.2" />
        <vers num="2.6.11.3" />
        <vers num="2.6.11.4" />
        <vers num="2.6.11.5" />
        <vers num="2.6.11.6" />
        <vers num="2.6.11.7" />
        <vers num="2.6.11.8" />
        <vers num="2.6.11.9" />
        <vers num="2.6.12" />
        <vers num="2.6.12.1" />
        <vers num="2.6.12.2" />
        <vers num="2.6.12.3" />
        <vers num="2.6.12.4" />
        <vers num="2.6.12.5" />
        <vers num="2.6.12.6" />
        <vers num="2.6.13" />
        <vers num="2.6.13.1" />
        <vers num="2.6.13.2" />
        <vers num="2.6.13.3" />
        <vers num="2.6.13.4" />
        <vers num="2.6.13.5" />
        <vers num="2.6.14" />
        <vers num="2.6.14.1" />
        <vers num="2.6.14.2" />
        <vers num="2.6.14.3" />
        <vers num="2.6.14.4" />
        <vers num="2.6.14.5" />
        <vers num="2.6.14.6" />
        <vers num="2.6.14.7" />
        <vers num="2.6.15" />
        <vers num="2.6.15.1" />
        <vers num="2.6.15.2" />
        <vers num="2.6.15.3" />
        <vers num="2.6.15.4" />
        <vers num="2.6.15.5" />
        <vers num="2.6.15.6" />
        <vers num="2.6.15.7" />
        <vers num="2.6.16" />
        <vers num="2.6.16.1" />
        <vers num="2.6.16.10" />
        <vers num="2.6.16.11" />
        <vers num="2.6.16.12" />
        <vers num="2.6.16.13" />
        <vers num="2.6.16.14" />
        <vers num="2.6.16.15" />
        <vers num="2.6.16.16" />
        <vers num="2.6.16.17" />
        <vers num="2.6.16.18" />
        <vers num="2.6.16.19" />
        <vers num="2.6.16.2" />
        <vers num="2.6.16.20" />
        <vers num="2.6.16.21" />
        <vers num="2.6.16.22" />
        <vers num="2.6.16.23" />
        <vers num="2.6.16.24" />
        <vers num="2.6.16.25" />
        <vers num="2.6.16.26" />
        <vers num="2.6.16.27" />
        <vers num="2.6.16.28" />
        <vers num="2.6.16.29" />
        <vers num="2.6.16.3" />
        <vers num="2.6.16.30" />
        <vers num="2.6.16.31" />
        <vers num="2.6.16.32" />
        <vers num="2.6.16.33" />
        <vers num="2.6.16.34" />
        <vers num="2.6.16.35" />
        <vers num="2.6.16.36" />
        <vers num="2.6.16.37" />
        <vers num="2.6.16.38" />
        <vers num="2.6.16.39" />
        <vers num="2.6.16.4" />
        <vers num="2.6.16.40" />
        <vers num="2.6.16.41" />
        <vers num="2.6.16.42" />
        <vers num="2.6.16.43" />
        <vers num="2.6.16.44" />
        <vers num="2.6.16.45" />
        <vers num="2.6.16.46" />
        <vers num="2.6.16.47" />
        <vers num="2.6.16.48" />
        <vers num="2.6.16.49" />
        <vers num="2.6.16.5" />
        <vers num="2.6.16.50" />
        <vers num="2.6.16.51" />
        <vers num="2.6.16.52" />
        <vers num="2.6.16.53" />
        <vers num="2.6.16.54" />
        <vers num="2.6.16.55" />
        <vers num="2.6.16.56" />
        <vers num="2.6.16.57" />
        <vers num="2.6.16.58" />
        <vers num="2.6.16.59" />
        <vers num="2.6.16.6" />
        <vers num="2.6.16.60" />
        <vers num="2.6.16.61" />
        <vers num="2.6.16.62" />
        <vers num="2.6.16.7" />
        <vers num="2.6.16.8" />
        <vers num="2.6.16.9" />
        <vers num="2.6.17" />
        <vers num="2.6.17.1" />
        <vers num="2.6.17.10" />
        <vers num="2.6.17.11" />
        <vers num="2.6.17.12" />
        <vers num="2.6.17.13" />
        <vers num="2.6.17.14" />
        <vers num="2.6.17.2" />
        <vers num="2.6.17.3" />
        <vers num="2.6.17.4" />
        <vers num="2.6.17.5" />
        <vers num="2.6.17.6" />
        <vers num="2.6.17.7" />
        <vers num="2.6.17.8" />
        <vers num="2.6.17.9" />
        <vers num="2.6.18" edition="rc1" />
        <vers num="2.6.18" edition="rc2" />
        <vers num="2.6.18" edition="rc3" />
        <vers num="2.6.18" edition="rc4" />
        <vers num="2.6.18" edition="rc5" />
        <vers num="2.6.18" edition="rc6" />
        <vers num="2.6.18" edition="rc7" />
        <vers num="2.6.18.1" />
        <vers num="2.6.18.2" />
        <vers num="2.6.18.3" />
        <vers num="2.6.18.4" />
        <vers num="2.6.18.5" />
        <vers num="2.6.18.6" />
        <vers num="2.6.18.7" />
        <vers num="2.6.18.8" />
        <vers num="2.6.19" />
        <vers num="2.6.19.1" />
        <vers num="2.6.19.2" />
        <vers num="2.6.19.3" />
        <vers num="2.6.19.4" />
        <vers num="2.6.19.5" />
        <vers num="2.6.19.6" />
        <vers num="2.6.19.7" />
        <vers num="2.6.2" />
        <vers num="2.6.20" />
        <vers num="2.6.20.1" />
        <vers num="2.6.20.10" />
        <vers num="2.6.20.11" />
        <vers num="2.6.20.12" />
        <vers num="2.6.20.13" />
        <vers num="2.6.20.14" />
        <vers num="2.6.20.15" />
        <vers num="2.6.20.16" />
        <vers num="2.6.20.17" />
        <vers num="2.6.20.18" />
        <vers num="2.6.20.19" />
        <vers num="2.6.20.2" />
        <vers num="2.6.20.20" />
        <vers num="2.6.20.21" />
        <vers num="2.6.20.3" />
        <vers num="2.6.20.4" />
        <vers num="2.6.20.5" />
        <vers num="2.6.20.6" />
        <vers num="2.6.20.7" />
        <vers num="2.6.20.8" />
        <vers num="2.6.20.9" />
        <vers num="2.6.21" />
        <vers num="2.6.21.1" />
        <vers num="2.6.21.2" />
        <vers num="2.6.21.3" />
        <vers num="2.6.21.4" />
        <vers num="2.6.21.5" />
        <vers num="2.6.21.6" />
        <vers num="2.6.21.7" />
        <vers num="2.6.22" />
        <vers num="2.6.22.1" />
        <vers num="2.6.22.10" />
        <vers num="2.6.22.11" />
        <vers num="2.6.22.12" />
        <vers num="2.6.22.13" />
        <vers num="2.6.22.14" />
        <vers num="2.6.22.15" />
        <vers num="2.6.22.16" />
        <vers num="2.6.22.17" />
        <vers num="2.6.22.18" />
        <vers num="2.6.22.19" />
        <vers num="2.6.22.2" />
        <vers num="2.6.22.20" />
        <vers num="2.6.22.21" />
        <vers num="2.6.22.22" />
        <vers num="2.6.22.3" />
        <vers num="2.6.22.4" />
        <vers num="2.6.22.5" />
        <vers num="2.6.22.6" />
        <vers num="2.6.22.7" />
        <vers num="2.6.22.8" />
        <vers num="2.6.22.9" />
        <vers num="2.6.22_rc1" />
        <vers num="2.6.22_rc7" />
        <vers num="2.6.23" edition="rc1" />
        <vers num="2.6.23" edition="rc2" />
        <vers num="2.6.23.1" />
        <vers num="2.6.23.10" />
        <vers num="2.6.23.11" />
        <vers num="2.6.23.12" />
        <vers num="2.6.23.13" />
        <vers num="2.6.23.14" />
        <vers num="2.6.23.15" />
        <vers num="2.6.23.16" />
        <vers num="2.6.23.17" />
        <vers num="2.6.23.2" />
        <vers num="2.6.23.3" />
        <vers num="2.6.23.4" />
        <vers num="2.6.23.5" />
        <vers num="2.6.23.6" />
        <vers num="2.6.23.7" />
        <vers num="2.6.23.8" />
        <vers num="2.6.23.9" />
        <vers num="2.6.24" edition="rc1" />
        <vers num="2.6.24" edition="rc2" />
        <vers num="2.6.24" edition="rc3" />
        <vers num="2.6.24" edition="rc4" />
        <vers num="2.6.24" edition="rc5" />
        <vers num="2.6.24.1" />
        <vers num="2.6.24.2" />
        <vers num="2.6.24.3" />
        <vers num="2.6.24.4" />
        <vers num="2.6.24.5" />
        <vers num="2.6.24.6" />
        <vers num="2.6.24.7" />
        <vers num="2.6.24_rc1" />
        <vers num="2.6.25" edition="" />
        <vers num="2.6.25" edition=":x86_64" />
        <vers num="2.6.25.1" edition="" />
        <vers num="2.6.25.1" edition=":x86_64" />
        <vers num="2.6.25.10" edition="" />
        <vers num="2.6.25.10" edition=":x86_64" />
        <vers num="2.6.25.11" edition="" />
        <vers num="2.6.25.11" edition=":x86_64" />
        <vers num="2.6.25.12" edition="" />
        <vers num="2.6.25.12" edition=":x86_64" />
        <vers num="2.6.25.13" />
        <vers num="2.6.25.14" />
        <vers num="2.6.25.15" />
        <vers num="2.6.25.16" />
        <vers num="2.6.25.17" />
        <vers num="2.6.25.18" />
        <vers num="2.6.25.19" />
        <vers num="2.6.25.2" edition="" />
        <vers num="2.6.25.2" edition=":x86_64" />
        <vers num="2.6.25.20" />
        <vers num="2.6.25.3" edition="" />
        <vers num="2.6.25.3" edition=":x86_64" />
        <vers num="2.6.25.4" edition="" />
        <vers num="2.6.25.4" edition=":x86_64" />
        <vers num="2.6.25.5" edition="" />
        <vers num="2.6.25.5" edition=":x86_64" />
        <vers num="2.6.25.6" edition="" />
        <vers num="2.6.25.6" edition=":x86_64" />
        <vers num="2.6.25.7" edition="" />
        <vers num="2.6.25.7" edition=":x86_64" />
        <vers num="2.6.25.8" edition="" />
        <vers num="2.6.25.8" edition=":x86_64" />
        <vers num="2.6.25.9" edition="" />
        <vers num="2.6.25.9" edition=":x86_64" />
        <vers num="2.6.26" edition="rc4" />
        <vers num="2.6.26.1" />
        <vers num="2.6.26.2" />
        <vers num="2.6.26.3" />
        <vers num="2.6.26.4" />
        <vers num="2.6.26.5" />
        <vers num="2.6.26.6" />
        <vers num="2.6.26.7" />
        <vers num="2.6.26.8" />
        <vers num="2.6.27" edition="rc1" />
        <vers num="2.6.27" edition="rc2" />
        <vers num="2.6.27" edition="rc3" />
        <vers num="2.6.27" edition="rc4" />
        <vers num="2.6.27" edition="rc5" />
        <vers num="2.6.27" edition="rc6" />
        <vers num="2.6.27" edition="rc7" />
        <vers num="2.6.27" edition="rc8" />
        <vers num="2.6.27" edition="rc9" />
        <vers num="2.6.27.1" />
        <vers num="2.6.27.10" />
        <vers num="2.6.27.11" />
        <vers num="2.6.27.12" />
        <vers num="2.6.27.2" />
        <vers num="2.6.27.3" />
        <vers num="2.6.27.4" />
        <vers num="2.6.27.5" />
        <vers num="2.6.27.6" />
        <vers num="2.6.27.7" />
        <vers num="2.6.27.8" />
        <vers num="2.6.27.9" />
        <vers num="2.6.28" edition="rc1" />
        <vers num="2.6.28" edition="rc2" />
        <vers num="2.6.28" edition="rc3" />
        <vers num="2.6.28" edition="rc4" />
        <vers num="2.6.28" edition="rc5" />
        <vers num="2.6.28" edition="rc6" />
        <vers num="2.6.28" edition="rc7" />
        <vers num="2.6.28.1" />
        <vers num="2.6.28.2" />
        <vers num="2.6.28.3" />
        <vers num="2.6.28.4" />
        <vers prev="1" num="2.6.28.5" />
        <vers num="2.6.3" />
        <vers num="2.6.4" />
        <vers num="2.6.5" />
        <vers num="2.6.6" />
        <vers num="2.6.7" />
        <vers num="2.6.8" />
        <vers num="2.6.8.1" />
        <vers num="2.6.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0677" published="2009-02-22" name="CVE-2009-0677" modified="2009-02-23" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)" CVSS_score="6.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.0" CVSS_base_score="6.5">
    <desc>
      <descript source="cve">avatarlist.php in the Your Account module, reached through modules.php, in Raven Web Services RavenNuke 2.30 allows remote authenticated users to execute arbitrary code via PHP sequences in an element of the replacements array, which is processed by the preg_replace function with the eval switch, as specified in an element of the patterns array.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/48789" source="XF">ravennuke-avatarlist-code-execution(48789)</ref>
      <ref url="http://www.waraxe.us/advisory-72.html" source="MISC">http://www.waraxe.us/advisory-72.html</ref>
      <ref url="http://www.securityfocus.com/bid/33787" source="BID">33787</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/500988/100/0/threaded" source="BUGTRAQ">20090216 [waraxe-2009-SA#072] - Multiple Vulnerabilities in RavenNuke 2.3.0</ref>
      <ref url="http://www.osvdb.org/52007" source="OSVDB">52007</ref>
      <ref url="http://www.milw0rm.com/exploits/8068" source="MILW0RM">8068</ref>
      <ref url="http://secunia.com/advisories/33928" source="SECUNIA" adv="1">33928</ref>
      <ref url="http://ravenphpscripts.com/postt17156.html&amp;sid=12d1201371612260a42fa846ebce7bad" source="CONFIRM" adv="1">http://ravenphpscripts.com/postt17156.html&amp;sid=12d1201371612260a42fa846ebce7bad</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ravenphpscripts" name="ravennuke">
        <vers num="2.30" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0678" published="2009-02-22" name="CVE-2009-0678" modified="2009-02-23" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">images/captcha.php in RavenNuke 2.30 allows remote attackers to obtain sensitive information via an aFonts array parameter value that does not correspond to a valid font file, which reveals the installation path in an error message.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/48792" source="XF">ravennuke-captcha-info-disclosure(48792)</ref>
      <ref url="http://www.waraxe.us/advisory-72.html" source="MISC">http://www.waraxe.us/advisory-72.html</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/500988/100/0/threaded" source="BUGTRAQ">20090216 [waraxe-2009-SA#072] - Multiple Vulnerabilities in RavenNuke 2.3.0</ref>
      <ref url="http://www.milw0rm.com/exploits/8068" source="MILW0RM">8068</ref>
      <ref url="http://ravenphpscripts.com/postt17156.html" source="CONFIRM" adv="1">http://ravenphpscripts.com/postt17156.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ravenphpscripts" name="ravennuke">
        <vers num="2.30" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0679" published="2009-02-22" name="CVE-2009-0679" modified="2009-06-09" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the Your Account module in RavenNuke 2.30 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/48978" source="XF">ravennuke-youraccount-xss(48978)</ref>
      <ref url="http://ravenphpscripts.com/postt17156.html" source="CONFIRM" adv="1">http://ravenphpscripts.com/postt17156.html</ref>
      <ref url="http://osvdb.org/52299" source="OSVDB">52299</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ravenphpscripts" name="ravennuke">
        <vers num="2.30" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0680" published="2009-02-22" name="CVE-2009-0680" modified="2009-02-23" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">cgi-bin/welcome/VPN_only in the web interface in Netgear SSL312 allows remote attackers to cause a denial of service (device crash) via a crafted query string, as demonstrated using directory traversal sequences.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/48605" source="XF">netgear-ssl312-dos(48605)</ref>
      <ref url="http://www.securityfocus.com/bid/33675" source="BID">33675</ref>
      <ref url="http://www.milw0rm.com/exploits/8008" source="MILW0RM">8008</ref>
      <ref url="http://www.helith.net/txt/netgear_ssl312_remote_dos.txt" source="MISC">http://www.helith.net/txt/netgear_ssl312_remote_dos.txt</ref>
      <ref url="http://secunia.com/advisories/33896" source="SECUNIA" adv="1">33896</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2009-02/0084.html" source="FULLDISC">20090208 Netgear SSL312 Router - remote DoS</ref>
    </refs>
    <vuln_soft>
      <prod vendor="netgear" name="ssl312">
        <vers num="-" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0681" published="2009-04-15" name="CVE-2009-0681" modified="2009-04-15" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">PGP Desktop before 9.10 allows local users to (1) cause a denial of service (crash) via a crafted IOCTL request to pgpdisk.sys, and (2) cause a denial of service (crash) and execute arbitrary code via a crafted IRP in an IOCTL request to pgpwded.sys.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://en.securitylab.ru/lab/PT-2009-01" source="MISC" patch="1">http://en.securitylab.ru/lab/PT-2009-01</ref>
      <ref url="https://pgp.custhelp.com/cgi-bin/pgp.cfg/php/enduser/std_adp.php?p_faqid=1014&amp;p_topview=1" source="MISC" adv="1">https://pgp.custhelp.com/cgi-bin/pgp.cfg/php/enduser/std_adp.php?p_faqid=1014&amp;p_topview=1</ref>
      <ref url="http://www.securitytracker.com/id?1022034" source="SECTRACK">1022034</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/502633/100/0/threaded" source="BUGTRAQ">20090413 [Suspected Spam][Positive Technologies SA 2009-01] PGP Desktop Pgpdisk.sys And Pgpwded.sys Multiple Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="pgp" name="desktop">
        <vers num="8.0" edition="" />
        <vers num="8.0" edition=":pro" />
        <vers num="8.0" edition=":home" />
        <vers num="9.0" edition="" />
        <vers num="9.0" edition=":professional" />
        <vers num="9.0" edition=":home" />
        <vers num="9.0.6" edition="-" />
        <vers num="9.0.6" edition="-:pro" />
        <vers num="9.0.6" edition="-:home" />
        <vers prev="1" num="9.9.0" edition="-" />
        <vers prev="1" num="9.9.0" edition="-:pro" />
        <vers prev="1" num="9.9.0" edition="-:home" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2009-0682" published="2009-08-19" name="CVE-2009-0682" modified="2009-09-02" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">vetmonnt.sys in CA Internet Security Suite r3, vetmonnt.sys before 9.0.0.184 in Internet Security Suite r4, and vetmonnt.sys before 10.0.0.217 in Internet Security Suite r5 do not properly verify IOCTL calls, which allows local users to cause a denial of service (system crash) via a crafted call.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="https://support.ca.com/irj/portal/anonymous/phpsupcontent?contentID=214673" source="CONFIRM" adv="1">https://support.ca.com/irj/portal/anonymous/phpsupcontent?contentID=214673</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/506103/100/0/threaded" source="BUGTRAQ">20090826 [PT-2009-05] CA Internet Security Suite Denial of Service Vulnerability</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/505880/100/0/threaded" source="BUGTRAQ">20090818 CA20090818-02: Security Notice for CA Internet Security Suite</ref>
      <ref url="http://osvdb.org/57228" source="OSVDB">57228</ref>
      <ref url="http://en.securitylab.ru/lab/PT-2009-05" source="MISC">http://en.securitylab.ru/lab/PT-2009-05</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ca" name="internet_security_suite">
        <vers num="" edition="r3" />
        <vers num="10.0.0.217" edition="r5" />
        <vers num="10.0.0.217" edition="r5:32bit" />
        <vers num="9.0.0.184" edition="r4" />
        <vers num="9.0.0.184" edition="r4:32bit" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0686" published="2009-04-01" name="CVE-2009-0686" modified="2009-04-10" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">The TrendMicro Activity Monitor Module (tmactmon.sys) 2.52.0.1002 in Trend Micro Internet Pro 2008 and 2009, and Security Pro 2008 and 2009, allows local users to gain privileges via a crafted IRP in a METHOD_NEITHER IOCTL request to \Device\tmactmon that overwrites memory.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/49513" source="XF">trend-tmactmon-privilege-escalation(49513)</ref>
      <ref url="http://www.securitytracker.com/id?1021955" source="SECTRACK">1021955</ref>
      <ref url="http://www.securityfocus.com/bid/34304" source="BID">34304</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/502314/100/0/threaded" source="BUGTRAQ">20090331 [Positive Technologies SA 2009-09] Trend Micro Internet Security Pro 2009 tmactmon.sys Priviliege Escalation Vulnerabilities</ref>
      <ref url="http://www.milw0rm.com/exploits/8322" source="MILW0RM">8322</ref>
      <ref url="http://milw0rm.com/sploits/2009-trendmicro_local_expl_0day.zip" source="MISC">http://milw0rm.com/sploits/2009-trendmicro_local_expl_0day.zip</ref>
      <ref url="http://en.securitylab.ru/lab/PT-2009-09" source="MISC">http://en.securitylab.ru/lab/PT-2009-09</ref>
    </refs>
    <vuln_soft>
      <prod vendor="trendmicro" name="internet_security">
        <vers num="2008" edition="-" />
        <vers num="2008" edition="-:pro" />
        <vers num="2009" edition="-" />
        <vers num="2009" edition="-:pro" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0687" published="2009-08-11" name="CVE-2009-0687" modified="2009-08-11" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">The pf_test_rule function in OpenBSD Packet Filter (PF), as used in OpenBSD 4.2 through 4.5, NetBSD 5.0 before RC3, MirOS 10 and earlier, and MidnightBSD 0.3-current allows remote attackers to cause a denial of service (panic) via crafted IP packets that trigger a NULL pointer dereference during translation, related to an IPv4 packet with an ICMPv6 payload.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2009/1015" source="VUPEN" patch="1" adv="1">ADV-2009-1015</ref>
      <ref url="http://www.openbsd.org/errata45.html#002_pf" source="OPENBSD" patch="1" adv="1">[4.5] 002: RELIABILITY FIX: April 11, 2009</ref>
      <ref url="http://www.openbsd.org/errata44.html#013_pf" source="OPENBSD" patch="1" adv="1">[4.4] 013: RELIABILITY FIX: April 11, 2009</ref>
      <ref url="http://www.openbsd.org/errata43.html#013_pf" source="OPENBSD" patch="1" adv="1">[4.3] 013: RELIABILITY FIX: April 11, 2009</ref>
      <ref url="ftp://ftp.openbsd.org/pub/OpenBSD/patches/4.3/common/013_pf.patch" source="MISC" patch="1" adv="1">ftp://ftp.openbsd.org/pub/OpenBSD/patches/4.3/common/013_pf.patch</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/49837" source="XF">openbsd-packetfilter-dos(49837)</ref>
      <ref url="http://www.securityfocus.com/archive/1/502634" source="BUGTRAQ">20090413 OpenBSD 4.3 up to OpenBSD-current: PF null pointer dereference - remote DoS (kernel panic)</ref>
      <ref url="http://www.osvdb.org/53608" source="OSVDB">53608</ref>
      <ref url="http://www.milw0rm.com/exploits/8581" source="MILW0RM">8581</ref>
      <ref url="http://www.milw0rm.com/exploits/8406" source="MILW0RM">8406</ref>
      <ref url="http://www.helith.net/txt/multiple_vendor-PF_null_pointer_dereference.txt" source="MISC">http://www.helith.net/txt/multiple_vendor-PF_null_pointer_dereference.txt</ref>
      <ref url="http://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2009-001.txt.asc" source="NETBSD" adv="1">NetBSD-SA2009-001</ref>
    </refs>
    <vuln_soft>
      <prod vendor="midnightbsd" name="midnightbsd">
        <vers num="0.3-current" />
      </prod>
      <prod vendor="mirbsd" name="miros">
        <vers prev="1" num="10" />
      </prod>
      <prod vendor="netbsd" name="netbsd">
        <vers num="5.0" />
      </prod>
      <prod vendor="openbsd" name="openbsd">
        <vers num="4.2" />
        <vers num="4.3" />
        <vers num="4.4" />
        <vers num="4.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0688" published="2009-05-15" name="CVE-2009-0688" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple buffer overflows in the CMU Cyrus SASL library before 2.1.23 might allow remote attackers to execute arbitrary code or cause a denial of service (application crash) via strings that are used as input to the sasl_encode64 function in lib/saslutil.c.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/238019" source="CERT-VN" patch="1">VU#238019</ref>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA10-103B.html" source="CERT">TA10-103B</ref>
      <ref url="http://www.securityfocus.com/bid/34961" source="BID" patch="1">34961</ref>
      <ref url="ftp://ftp.andrew.cmu.edu/pub/cyrus-mail/cyrus-sasl-2.1.23.tar.gz" source="CONFIRM" patch="1">ftp://ftp.andrew.cmu.edu/pub/cyrus-mail/cyrus-sasl-2.1.23.tar.gz</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/50554" source="XF">solaris-sasl-saslencode64-bo(50554)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/2012" source="VUPEN">ADV-2009-2012</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1313" source="VUPEN">ADV-2009-1313</ref>
      <ref url="http://www.ubuntu.com/usn/usn-790-1" source="UBUNTU">USN-790-1</ref>
      <ref url="http://www.securitytracker.com/id?1022231" source="SECTRACK">1022231</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-1116.html" source="REDHAT">RHSA-2009:1116</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuapr2010.html" source="CONFIRM">http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuapr2010.html</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:113" source="MANDRIVA">MDVSA-2009:113</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1807" source="DEBIAN">DSA-1807</ref>
      <ref url="http://wiki.rpath.com/wiki/Advisories:rPSA-2009-0091" source="CONFIRM">http://wiki.rpath.com/wiki/Advisories:rPSA-2009-0091</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2009-184.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2009-184.htm</ref>
      <ref url="http://support.apple.com/kb/HT4077" source="CONFIRM">http://support.apple.com/kb/HT4077</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-77-1021699.1-1" source="SUNALERT">1021699</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-77-1020755.1-1" source="SUNALERT">1020755</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-273910-1" source="SUNALERT">273910</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-264248-1" source="SUNALERT">264248</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-259148-1" source="SUNALERT">259148</ref>
      <ref url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2009&amp;m=slackware-security.448834" source="SLACKWARE">SSA:2009-134-01</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200907-09.xml" source="GENTOO">GLSA-200907-09</ref>
      <ref url="http://secunia.com/advisories/39428" source="SECUNIA">39428</ref>
      <ref url="http://secunia.com/advisories/35746" source="SECUNIA">35746</ref>
      <ref url="http://secunia.com/advisories/35497" source="SECUNIA">35497</ref>
      <ref url="http://secunia.com/advisories/35416" source="SECUNIA">35416</ref>
      <ref url="http://secunia.com/advisories/35321" source="SECUNIA">35321</ref>
      <ref url="http://secunia.com/advisories/35239" source="SECUNIA">35239</ref>
      <ref url="http://secunia.com/advisories/35206" source="SECUNIA">35206</ref>
      <ref url="http://secunia.com/advisories/35102" source="SECUNIA">35102</ref>
      <ref url="http://secunia.com/advisories/35097" source="SECUNIA">35097</ref>
      <ref url="http://secunia.com/advisories/35094" source="SECUNIA">35094</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6136" source="OVAL">oval:org.mitre.oval:def:6136</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10687" source="OVAL">oval:org.mitre.oval:def:10687</ref>
      <ref url="http://osvdb.org/54515" source="OSVDB">54515</ref>
      <ref url="http://osvdb.org/54514" source="OSVDB">54514</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-06/msg00003.html" source="SUSE">SUSE-SR:2009:011</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Mar/msg00001.html" source="APPLE">APPLE-SA-2010-03-29-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="carnegie_mellon_university" name="cyrus-sasl">
        <vers num="1.4.1" />
        <vers num="1.5.0" />
        <vers num="1.5.10" />
        <vers num="1.5.11" />
        <vers num="1.5.13" />
        <vers num="1.5.15" />
        <vers num="1.5.16" />
        <vers num="1.5.2" />
        <vers num="1.5.20" />
        <vers num="1.5.21" />
        <vers num="1.5.22" />
        <vers num="1.5.23" />
        <vers num="1.5.24" />
        <vers num="1.5.26" />
        <vers num="1.5.27" />
        <vers num="1.5.28" />
        <vers num="1.5.3" />
        <vers num="1.5.5" />
        <vers num="2.0.0" />
        <vers num="2.0.1" />
        <vers num="2.0.2" />
        <vers num="2.0.3" />
        <vers num="2.0.4" />
        <vers num="2.0.5" />
        <vers num="2.1.0" />
        <vers num="2.1.1" />
        <vers num="2.1.10" />
        <vers num="2.1.11" />
        <vers num="2.1.12" />
        <vers num="2.1.13" />
        <vers num="2.1.14" />
        <vers num="2.1.15" />
        <vers num="2.1.16" />
        <vers num="2.1.17" />
        <vers num="2.1.18" />
        <vers num="2.1.19" />
        <vers num="2.1.2" />
        <vers num="2.1.20" />
        <vers num="2.1.21" />
        <vers prev="1" num="2.1.22" />
        <vers num="2.1.3" />
        <vers num="2.1.5" />
        <vers num="2.1.6" />
        <vers num="2.1.7" />
        <vers num="2.1.8" />
        <vers num="2.1.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0689" published="2009-07-01" name="CVE-2009-0689" modified="2010-11-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Array index error in the (1) dtoa implementation in dtoa.c (aka pdtoa.c) and the (2) gdtoa (aka new dtoa) implementation in gdtoa/misc.c in libc, as used in multiple operating systems and products including in FreeBSD 6.4 and 7.2, NetBSD 5.0, OpenBSD 4.5, Mozilla Firefox 3.0.x before 3.0.15 and 3.5.x before 3.5.4, K-Meleon 1.5.3, SeaMonkey 1.1.8, and other products, allows context-dependent attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a large precision value in the format argument to a printf function, which triggers incorrect memory allocation and a heap-based buffer overflow during conversion to a floating-point number.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/35510" source="BID" patch="1">35510</ref>
      <ref url="http://www.openbsd.org/cgi-bin/cvsweb/src/lib/libc/gdtoa/misc.c" source="CONFIRM" patch="1" adv="1">http://www.openbsd.org/cgi-bin/cvsweb/src/lib/libc/gdtoa/misc.c</ref>
      <ref url="http://securitytracker.com/id?1022478" source="SECTRACK" patch="1">1022478</ref>
      <ref url="http://cvsweb.netbsd.org/bsdweb.cgi/src/lib/libc/gdtoa/gdtoaimp.h" source="CONFIRM" patch="1">http://cvsweb.netbsd.org/bsdweb.cgi/src/lib/libc/gdtoa/gdtoaimp.h</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=516862" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=516862</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=516396" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=516396</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0650" source="VUPEN" adv="1">ADV-2010-0650</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0648" source="VUPEN" adv="1">ADV-2010-0648</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0094" source="VUPEN" adv="1">ADV-2010-0094</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/3334" source="VUPEN" adv="1">ADV-2009-3334</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/3299" source="VUPEN" adv="1">ADV-2009-3299</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/3297" source="VUPEN" adv="1">ADV-2009-3297</ref>
      <ref url="http://www.ubuntu.com/usn/USN-915-1" source="UBUNTU">USN-915-1</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/508423/100/0/threaded" source="BUGTRAQ">20091210 Camino 1.6.10 Remote Array Overrun (Arbitrary code execution)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/508417/100/0/threaded" source="BUGTRAQ">20091210 Flock 2.5.2 Remote Array Overrun (Arbitrary code execution)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/507979/100/0/threaded" source="BUGTRAQ">20091120 SeaMonkey 1.1.8 Remote Array Overrun (Arbitrary code execution)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/507977/100/0/threaded" source="BUGTRAQ">20091120 K-Meleon 1.5.3 Remote Array Overrun (Arbitrary code execution)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0154.html" source="REDHAT">RHSA-2010:0154</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0153.html" source="REDHAT">RHSA-2010:0153</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-1601.html" source="REDHAT">RHSA-2009:1601</ref>
      <ref url="http://www.opera.com/support/kb/view/942/" source="CONFIRM">http://www.opera.com/support/kb/view/942/</ref>
      <ref url="http://www.mozilla.org/security/announce/2009/mfsa2009-59.html" source="CONFIRM" adv="1">http://www.mozilla.org/security/announce/2009/mfsa2009-59.html</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:330" source="MANDRIVA">MDVSA-2009:330</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:294" source="MANDRIVA">MDVSA-2009:294</ref>
      <ref url="http://support.apple.com/kb/HT4225" source="CONFIRM">http://support.apple.com/kb/HT4225</ref>
      <ref url="http://support.apple.com/kb/HT4077" source="CONFIRM">http://support.apple.com/kb/HT4077</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-272909-1" source="SUNALERT">272909</ref>
      <ref url="http://securityreason.com/achievement_securityalert/81" source="SREASONRES">20100108 MacOS X 10.5/10.6 libc/strtod(3) buffer overflow</ref>
      <ref url="http://securityreason.com/achievement_securityalert/78" source="SREASONRES">20091211 Thunderbird 2.0.0.23 (lib) Remote Array Overrun (Arbitrary code execution)</ref>
      <ref url="http://securityreason.com/achievement_securityalert/77" source="SREASONRES">20091211 Sunbird 0.9 Array Overrun (code execution)</ref>
      <ref url="http://securityreason.com/achievement_securityalert/76" source="SREASONRES">20091211 Camino 1.6.10 Remote Array Overrun (Arbitrary code execution)</ref>
      <ref url="http://securityreason.com/achievement_securityalert/75" source="SREASONRES">20091211 Flock 2.5.2 Remote Array Overrun (Arbitrary code execution)</ref>
      <ref url="http://securityreason.com/achievement_securityalert/73" source="SREASONRES">20091120 Opera 10.01 Remote Array Overrun (Arbitrary code execution)</ref>
      <ref url="http://securityreason.com/achievement_securityalert/72" source="SREASONRES">20091120 K-Meleon 1.5.3 Remote Array Overrun (Arbitrary code execution)</ref>
      <ref url="http://securityreason.com/achievement_securityalert/71" source="SREASONRES">20091120 SeaMonkey 1.1.8 Remote Array Overrun (Arbitrary code execution)</ref>
      <ref url="http://securityreason.com/achievement_securityalert/69" source="SREASONRES">20091030 Multiple BSD printf(1) and multiple dtoa/*printf(3) vulnerabilities</ref>
      <ref url="http://securityreason.com/achievement_securityalert/63" source="SREASONRES">20090625 Multiple Vendors libc/gdtoa printf(3) Array Overrun</ref>
      <ref url="http://secunia.com/secunia_research/2009-35/" source="MISC" adv="1">http://secunia.com/secunia_research/2009-35/</ref>
      <ref url="http://secunia.com/advisories/39001" source="SECUNIA" adv="1">39001</ref>
      <ref url="http://secunia.com/advisories/38977" source="SECUNIA" adv="1">38977</ref>
      <ref url="http://secunia.com/advisories/38066" source="SECUNIA" adv="1">38066</ref>
      <ref url="http://secunia.com/advisories/37683" source="SECUNIA" adv="1">37683</ref>
      <ref url="http://secunia.com/advisories/37682" source="SECUNIA" adv="1">37682</ref>
      <ref url="http://secunia.com/advisories/37431" source="SECUNIA" adv="1">37431</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9541" source="OVAL">oval:org.mitre.oval:def:9541</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6528" source="OVAL">oval:org.mitre.oval:def:6528</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-06/msg00001.html" source="SUSE">SUSE-SR:2010:013</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-11/msg00004.html" source="SUSE">SUSE-SR:2009:018</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010/Jun/msg00003.html" source="APPLE">APPLE-SA-2010-06-21-1</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Mar/msg00001.html" source="APPLE" adv="1">APPLE-SA-2010-03-29-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="k-meleon_project" name="k-meleon">
        <vers num="1.5.3" />
      </prod>
      <prod vendor="mozilla" name="firefox">
        <vers num="3.0.1" />
        <vers num="3.0.10" />
        <vers num="3.0.11" />
        <vers num="3.0.12" />
        <vers num="3.0.13" />
        <vers num="3.0.14" />
        <vers num="3.0.2" />
        <vers num="3.0.3" />
        <vers num="3.0.4" />
        <vers num="3.0.5" />
        <vers num="3.0.6" />
        <vers num="3.0.7" />
        <vers num="3.0.8" />
        <vers num="3.0.9" />
        <vers num="3.5" />
        <vers num="3.5.1" />
        <vers num="3.5.2" />
        <vers num="3.5.3" />
      </prod>
      <prod vendor="mozilla" name="seamonkey">
        <vers num="1.1.8" />
      </prod>
      <prod vendor="freebsd" name="freebsd">
        <vers num="6.4" edition="release" />
        <vers num="6.4" edition="release_p2" />
        <vers num="6.4" edition="release_p3" />
        <vers num="6.4" edition="release_p4" />
        <vers num="6.4" edition="release_p5" />
        <vers num="6.4" edition="stable" />
        <vers num="7.2" edition="pre-release" />
        <vers num="7.2" edition="stable" />
      </prod>
      <prod vendor="netbsd" name="netbsd">
        <vers num="5.0" />
      </prod>
      <prod vendor="openbsd" name="openbsd">
        <vers num="4.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0690" published="2009-06-23" name="CVE-2009-0690" modified="2009-06-24" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">The Foxit JPEG2000/JBIG2 Decoder add-on before 2.0.2009.616 for Foxit Reader 3.0 before Build 1817 does not properly handle a negative value for the stream offset in a JPEG2000 (aka JPX) stream, which allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via a crafted PDF file that triggers an out-of-bounds read.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/251793" source="CERT-VN">VU#251793</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1640" source="VUPEN" patch="1" adv="1">ADV-2009-1640</ref>
      <ref url="http://www.securityfocus.com/bid/35442" source="BID" patch="1" adv="1">35442</ref>
      <ref url="http://www.foxitsoftware.com/pdf/reader/security.htm#0602" source="CONFIRM" patch="1" adv="1">http://www.foxitsoftware.com/pdf/reader/security.htm#0602</ref>
      <ref url="http://securitytracker.com/id?1022425" source="SECTRACK">1022425</ref>
      <ref url="http://secunia.com/advisories/35512" source="SECUNIA" adv="1">35512</ref>
    </refs>
    <vuln_soft>
      <prod vendor="foxitsoftware" name="foxit_reader">
        <vers num="3.0" />
        <vers num="3.0.2009.1301" />
      </prod>
      <prod vendor="foxitsoftware" name="jpeg2000/jbig2_decoder_add-on">
        <vers num="2.0.2009.303" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0691" published="2009-06-23" name="CVE-2009-0691" modified="2009-06-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">The Foxit JPEG2000/JBIG2 Decoder add-on before 2.0.2009.616 for Foxit Reader 3.0 before Build 1817 does not properly handle a fatal error during decoding of a JPEG2000 (aka JPX) header, which allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via a crafted PDF file that triggers an invalid memory access.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/251793" source="CERT-VN" patch="1">VU#251793</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1640" source="VUPEN" patch="1" adv="1">ADV-2009-1640</ref>
      <ref url="http://www.securityfocus.com/bid/35443" source="BID" patch="1">35443</ref>
      <ref url="http://www.foxitsoftware.com/pdf/reader/security.htm#0602" source="CONFIRM" patch="1" adv="1">http://www.foxitsoftware.com/pdf/reader/security.htm#0602</ref>
      <ref url="http://securitytracker.com/id?1022425" source="SECTRACK">1022425</ref>
      <ref url="http://secunia.com/advisories/35512" source="SECUNIA" adv="1">35512</ref>
    </refs>
    <vuln_soft>
      <prod vendor="foxitsoftware" name="foxit_reader">
        <vers num="3.0" />
      </prod>
      <prod vendor="foxitsoftware" name="jpeg2000_jbig2_decoder_add-on">
        <vers prev="1" num="2.0.2009.303" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0692" published="2009-07-14" name="CVE-2009-0692" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Stack-based buffer overflow in the script_write_params method in client/dhclient.c in ISC DHCP dhclient 4.1 before 4.1.0p1, 4.0 before 4.0.1p1, 3.1 before 3.1.2p1, 3.0, and 2.0 allows remote DHCP servers to execute arbitrary code via a crafted subnet-mask option.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/410676" source="CERT-VN">VU#410676</ref>
      <ref url="https://www.isc.org/node/468" source="CONFIRM" patch="1" adv="1">https://www.isc.org/node/468</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-November/msg00340.html" source="FEDORA">FEDORA-2009-9075</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-August/msg01177.html" source="FEDORA">FEDORA-2009-8344</ref>
      <ref url="https://www.isc.org/downloadables/12" source="CONFIRM">https://www.isc.org/downloadables/12</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=507717" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=507717</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1796" source="VUPEN">ADV-2010-1796</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1891" source="VUPEN">ADV-2009-1891</ref>
      <ref url="http://www.ubuntu.com/usn/usn-803-1" source="UBUNTU">USN-803-1</ref>
      <ref url="http://www.securitytracker.com/id?1022548" source="SECTRACK">1022548</ref>
      <ref url="http://www.securityfocus.com/bid/35668" source="BID">35668</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-1154.html" source="REDHAT">RHSA-2009:1154</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-1136.html" source="REDHAT">RHSA-2009:1136</ref>
      <ref url="http://www.osvdb.org/55819" source="OSVDB">55819</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:151" source="MANDRIVA">MDVSA-2009:151</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1833" source="DEBIAN">DSA-1833</ref>
      <ref url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2009&amp;m=slackware-security.561471" source="SLACKWARE">SSA:2009-195-01</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200907-12.xml" source="GENTOO">GLSA-200907-12</ref>
      <ref url="http://secunia.com/advisories/40551" source="SECUNIA">40551</ref>
      <ref url="http://secunia.com/advisories/37342" source="SECUNIA">37342</ref>
      <ref url="http://secunia.com/advisories/36457" source="SECUNIA">36457</ref>
      <ref url="http://secunia.com/advisories/35880" source="SECUNIA">35880</ref>
      <ref url="http://secunia.com/advisories/35851" source="SECUNIA">35851</ref>
      <ref url="http://secunia.com/advisories/35850" source="SECUNIA">35850</ref>
      <ref url="http://secunia.com/advisories/35849" source="SECUNIA">35849</ref>
      <ref url="http://secunia.com/advisories/35841" source="SECUNIA">35841</ref>
      <ref url="http://secunia.com/advisories/35832" source="SECUNIA">35832</ref>
      <ref url="http://secunia.com/advisories/35831" source="SECUNIA">35831</ref>
      <ref url="http://secunia.com/advisories/35830" source="SECUNIA">35830</ref>
      <ref url="http://secunia.com/advisories/35829" source="SECUNIA">35829</ref>
      <ref url="http://secunia.com/advisories/35785" source="SECUNIA" adv="1">35785</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5941" source="OVAL">oval:org.mitre.oval:def:5941</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10758" source="OVAL">oval:org.mitre.oval:def:10758</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-07/msg00003.html" source="SUSE">SUSE-SA:2009:037</ref>
      <ref url="http://itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c02286083" source="HP">SSRT100018</ref>
      <ref url="http://itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c02286083" source="HP">SSRT100018</ref>
      <ref url="http://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2009-010.txt.asc" source="NETBSD">NetBSD-SA2009-010</ref>
    </refs>
    <vuln_soft>
      <prod vendor="isc" name="dhcp">
        <vers num="2.0" />
        <vers num="3.0" />
        <vers num="3.1" />
        <vers num="4.0" />
        <vers num="4.1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0696" published="2009-07-29" name="CVE-2009-0696" modified="2011-07-18" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">The dns_db_findrdataset function in db.c in named in ISC BIND 9.4 before 9.4.3-P3, 9.5 before 9.5.1-P3, and 9.6 before 9.6.1-P1, when configured as a master server, allows remote attackers to cause a denial of service (assertion failure and daemon exit) via an ANY record in the prerequisite section of a crafted dynamic update message, as exploited in the wild in July 2009.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/725188" source="CERT-VN">VU#725188</ref>
      <ref url="https://www.isc.org/node/474" source="CONFIRM" patch="1" adv="1">https://www.isc.org/node/474</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-July/msg01265.html" source="FEDORA">FEDORA-2009-8119</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/3316" source="VUPEN">ADV-2009-3316</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/2247" source="VUPEN">ADV-2009-2247</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/2171" source="VUPEN">ADV-2009-2171</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/2088" source="VUPEN">ADV-2009-2088</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/2036" source="VUPEN">ADV-2009-2036</ref>
      <ref url="http://www.vmware.com/security/advisories/VMSA-2009-0016.html" source="CONFIRM">http://www.vmware.com/security/advisories/VMSA-2009-0016.html</ref>
      <ref url="http://www.ubuntu.com/usn/usn-808-1" source="UBUNTU">USN-808-1</ref>
      <ref url="http://www.slackware.com/security/viewer.php?l=slackware-security&amp;y=2009&amp;m=slackware-security.561499" source="SLACKWARE">SSA:2009-210-01</ref>
      <ref url="http://www.securitytracker.com/id?1022613" source="SECTRACK">1022613</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/507985/100/0/threaded" source="BUGTRAQ">20091120 VMSA-2009-0016 VMware vCenter and ESX update release and vMA patch release address multiple security issue in third party components</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/505403/100/0/threaded" source="BUGTRAQ">20090729 rPSA-2009-0113-1 bind bind-utils</ref>
      <ref url="http://www.openbsd.org/errata44.html#014_bind" source="OPENBSD">[4.4] 014: RELIABILITY FIX: July 29, 2009</ref>
      <ref url="http://wiki.rpath.com/Advisories:rPSA-2009-0113" source="CONFIRM">http://wiki.rpath.com/Advisories:rPSA-2009-0113</ref>
      <ref url="http://up2date.astaro.com/2009/08/up2date_7505_released.html" source="CONFIRM">http://up2date.astaro.com/2009/08/up2date_7505_released.html</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-77-1020788.1-1" source="SUNALERT">1020788</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-264828-1" source="SUNALERT">264828</ref>
      <ref url="http://secunia.com/advisories/39334" source="SECUNIA">39334</ref>
      <ref url="http://secunia.com/advisories/37471" source="SECUNIA">37471</ref>
      <ref url="http://secunia.com/advisories/36192" source="SECUNIA">36192</ref>
      <ref url="http://secunia.com/advisories/36098" source="SECUNIA">36098</ref>
      <ref url="http://secunia.com/advisories/36086" source="SECUNIA">36086</ref>
      <ref url="http://secunia.com/advisories/36063" source="SECUNIA">36063</ref>
      <ref url="http://secunia.com/advisories/36056" source="SECUNIA">36056</ref>
      <ref url="http://secunia.com/advisories/36053" source="SECUNIA">36053</ref>
      <ref url="http://secunia.com/advisories/36050" source="SECUNIA">36050</ref>
      <ref url="http://secunia.com/advisories/36038" source="SECUNIA">36038</ref>
      <ref url="http://secunia.com/advisories/36035" source="SECUNIA">36035</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7806" source="OVAL">oval:org.mitre.oval:def:7806</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:12245" source="OVAL">oval:org.mitre.oval:def:12245</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10414" source="OVAL">oval:org.mitre.oval:def:10414</ref>
      <ref url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=538975" source="CONFIRM">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=538975</ref>
      <ref url="http://aix.software.ibm.com/aix/efixes/security/bind_advisory.asc" source="CONFIRM">http://aix.software.ibm.com/aix/efixes/security/bind_advisory.asc</ref>
      <ref url="ftp://ftp.sco.com/pub/unixware7/714/security/p535243_uw7/p535243b.txt" source="CONFIRM">ftp://ftp.sco.com/pub/unixware7/714/security/p535243_uw7/p535243b.txt</ref>
      <ref url="ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2009-013.txt.asc" source="NETBSD">NetBSD-SA2009-013</ref>
    </refs>
    <vuln_soft>
      <prod vendor="isc" name="bind">
        <vers num="9.4" />
        <vers num="9.4.0" edition="rc1" />
        <vers num="9.4.0a1" />
        <vers num="9.4.0a2" />
        <vers num="9.4.0a3" />
        <vers num="9.4.0a4" />
        <vers num="9.4.0a5" />
        <vers num="9.4.0a6" />
        <vers num="9.4.0b1" />
        <vers num="9.4.0b2" />
        <vers num="9.4.0b3" />
        <vers num="9.4.0b4" />
        <vers num="9.4.1" />
        <vers num="9.4.2" />
        <vers num="9.4.2-p2-w1" edition="windows" />
        <vers num="9.4.3" edition="p2" />
        <vers num="9.4.3" edition="rc1" />
        <vers num="9.4.3b1" />
        <vers num="9.4.3b2" />
        <vers num="9.4.3b3" />
        <vers num="9.5" />
        <vers num="9.5.0" edition="rc1" />
        <vers num="9.5.0-p1" />
        <vers num="9.5.0-p2" />
        <vers num="9.5.0-p2-w1" edition="windows" />
        <vers num="9.5.0-p2-w2" />
        <vers num="9.5.0a1" edition="" />
        <vers num="9.5.0a1" edition=":bind_forum" />
        <vers num="9.5.0a2" />
        <vers num="9.5.0a3" />
        <vers num="9.5.0a4" />
        <vers num="9.5.0a5" />
        <vers num="9.5.0a6" />
        <vers num="9.5.0a7" />
        <vers num="9.5.0b1" />
        <vers num="9.5.0b2" />
        <vers num="9.5.0b3" />
        <vers num="9.5.1" edition="rc1" />
        <vers num="9.5.1" edition="rc2" />
        <vers num="9.5.1b1" />
        <vers num="9.5.1b2" />
        <vers num="9.5.1b3" />
        <vers num="9.6.0" edition="p1" />
        <vers num="9.6.0" edition="rc1" />
        <vers num="9.6.0" edition="rc2" />
        <vers num="9.6.0a1" />
        <vers num="9.6.0b1" />
        <vers num="9.6.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0698" published="2009-02-23" name="CVE-2009-0698" modified="2009-11-24" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Integer overflow in the 4xm demuxer (demuxers/demux_4xm.c) in xine-lib 1.1.16.1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a 4X movie file with a large current_track value, a similar issue to CVE-2009-0385.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://sourceforge.net/project/shownotes.php?release_id=660071" source="CONFIRM" patch="1">http://sourceforge.net/project/shownotes.php?release_id=660071</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/48954" source="XF">xinelib-4xmdemuxer-code-execution(48954)</ref>
      <ref url="http://www.ubuntu.com/usn/USN-746-1" source="UBUNTU">USN-746-1</ref>
      <ref url="http://www.trapkit.de/advisories/TKADV2009-004.txt" source="MISC">http://www.trapkit.de/advisories/TKADV2009-004.txt</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/500514/100/0/threaded" source="BUGTRAQ">20090128 [TKADV2009-004] FFmpeg Type Conversion Vulnerability</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:299" source="MANDRIVA">MDVSA-2009:299</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:298" source="MANDRIVA">MDVSA-2009:298</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-04/msg00010.html" source="SUSE">SUSE-SR:2009:009</ref>
      <ref url="http://bugs.xine-project.org/show_bug.cgi?id=205" source="CONFIRM">http://bugs.xine-project.org/show_bug.cgi?id=205</ref>
    </refs>
    <vuln_soft>
      <prod vendor="xine" name="xine-lib">
        <vers num="1.1.16.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2009-0699" published="2009-02-23" name="CVE-2009-0699" modified="2009-02-24" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:S/C:N/I:P/A:N)" CVSS_score="3.5" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="6.8" CVSS_base_score="3.5">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in pagesUTF8/auftrag_allgemeinauftrag.jsp in Plunet BusinessManager 4.1 and earlier allows remote authenticated users to inject arbitrary web script or HTML via the (1) QUB and (2) Bez74 parameters.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/47795" source="XF">businessmanager-qub-bez74-xss(47795)</ref>
      <ref url="http://www.securityfocus.com/bid/33153" source="BID">33153</ref>
      <ref url="http://www.securenetwork.it/ricerca/advisory/download/SN-2008-04.txt" source="MISC">http://www.securenetwork.it/ricerca/advisory/download/SN-2008-04.txt</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2009-01/0054.html" source="BUGTRAQ">20090109 Re: Plunet BusinessManager failure in access controls and multiple stored cross site scripting</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2009-01/0032.html" source="BUGTRAQ">20090107 Plunet BusinessManager failure in access controls and multiple stored cross site scripting</ref>
    </refs>
    <vuln_soft>
      <prod vendor="plunet" name="business_manager">
        <vers prev="1" num="4.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0700" published="2009-02-23" name="CVE-2009-0700" modified="2009-02-24" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:N/A:N)" CVSS_score="4.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.0" CVSS_base_score="4.0">
    <desc>
      <descript source="cve">Plunet BusinessManager 4.1 and earlier allows remote authenticated users to bypass access restrictions and (1) read sensitive Customer or Order data via a modified Pfad parameter to pagesUTF8/Sys_DirAnzeige.jsp, or (2) list sensitive Jobs via a direct request to pagesUTF8/auftrag_job.jsp.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/47794" source="XF">businessmanager-multiple-security-bypass(47794)</ref>
      <ref url="http://www.securityfocus.com/bid/33153" source="BID">33153</ref>
      <ref url="http://www.securenetwork.it/ricerca/advisory/download/SN-2008-04.txt" source="MISC">http://www.securenetwork.it/ricerca/advisory/download/SN-2008-04.txt</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2009-01/0054.html" source="BUGTRAQ">20090109 Re: Plunet BusinessManager failure in access controls and multiple stored cross site scripting</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2009-01/0032.html" source="BUGTRAQ">20090107 Plunet BusinessManager failure in access controls and multiple stored cross site scripting</ref>
    </refs>
    <vuln_soft>
      <prod vendor="plunet" name="business_manager">
        <vers prev="1" num="4.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0701" published="2009-02-23" name="CVE-2009-0701" modified="2009-02-24" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple PHP remote file inclusion vulnerabilities in index.php in Cybershade CMS 0.2b, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the (1) THEME_header and (2) THEME_footer parameters.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/47725" source="XF">cybershadecms-index-file-include(47725)</ref>
      <ref url="http://www.securityfocus.com/bid/33101" source="BID">33101</ref>
      <ref url="http://www.milw0rm.com/exploits/7668" source="MILW0RM">7668</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cybershade" name="cybershadecms">
        <vers num="0.2b" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0702" published="2009-02-23" name="CVE-2009-0702" modified="2009-02-24" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in the Phoca Documentation (com_phocadocumentation) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a section action to index.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2009/0026" source="VUPEN" adv="1">ADV-2009-0026</ref>
      <ref url="http://www.securityfocus.com/bid/33114" source="BID">33114</ref>
      <ref url="http://www.milw0rm.com/exploits/7670" source="MILW0RM">7670</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phoca" name="com_phocadocumentation">
        <vers num="-" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0703" published="2009-02-23" name="CVE-2009-0703" modified="2009-06-09" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in bview.asp in ASPThai.Net Webboard 6.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/47722" source="XF">webboard-bview-sql-injection(47722)</ref>
      <ref url="http://www.securityfocus.com/bid/33084" source="BID">33084</ref>
      <ref url="http://www.milw0rm.com/exploits/7635" source="MILW0RM">7635</ref>
      <ref url="http://secunia.com/advisories/34099" source="SECUNIA">34099</ref>
    </refs>
    <vuln_soft>
      <prod vendor="aspthai.net" name="aspthai.net_webboard">
        <vers num="6.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0704" published="2009-02-23" name="CVE-2009-0704" modified="2009-02-24" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in search.php in WSN Guest 1.23 allows remote attackers to execute arbitrary SQL commands via the search parameter in an advanced action.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/47723" source="XF">wsnguest-search-sql-injection(47723)</ref>
      <ref url="http://www.securityfocus.com/bid/33097" source="BID">33097</ref>
      <ref url="http://www.milw0rm.com/exploits/7659" source="MILW0RM">7659</ref>
    </refs>
    <vuln_soft>
      <prod vendor="webmastersite" name="wsn_guest">
        <vers num="1.23" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0705" published="2009-02-23" name="CVE-2009-0705" modified="2009-02-24" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">SQL injection vulnerability in news.php in PowerScripts PowerNews 2.5.4, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the newsid parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/47701" source="XF">powernews-news-sql-injection(47701)</ref>
      <ref url="http://www.securityfocus.com/bid/33081" source="BID">33081</ref>
      <ref url="http://www.milw0rm.com/exploits/7641" source="MILW0RM">7641</ref>
      <ref url="http://secunia.com/advisories/33363" source="SECUNIA" adv="1">33363</ref>
      <ref url="http://osvdb.org/51110" source="OSVDB">51110</ref>
    </refs>
    <vuln_soft>
      <prod vendor="powerscripts" name="powernews">
        <vers num="2.5.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0706" published="2009-02-23" name="CVE-2009-0706" modified="2009-02-24" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in the Simple Review (com_simple_review) component 1.3.5 for Joomla! and Mambo allows remote attackers to execute arbitrary SQL commands via the category parameter to index.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/47726" source="XF">simplereview-index-sql-injection(47726)</ref>
      <ref url="http://www.securityfocus.com/bid/33102" source="BID">33102</ref>
      <ref url="http://packetstormsecurity.org/0901-exploits/joomlasimplereview-sql.txt" source="MISC">http://packetstormsecurity.org/0901-exploits/joomlasimplereview-sql.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="simple-review" name="com_simple_review">
        <vers num="1.3.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0707" published="2009-02-23" name="CVE-2009-0707" modified="2009-02-24" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in admin/index.php in PowerClan 1.14a allows remote attackers to execute arbitrary SQL commands via the loginemail parameter (aka login field).  NOTE: some of these details are obtained from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/47702" source="XF">powerclan-index-sql-injection(47702)</ref>
      <ref url="http://www.securityfocus.com/bid/33083" source="BID">33083</ref>
      <ref url="http://www.milw0rm.com/exploits/7642" source="MILW0RM">7642</ref>
      <ref url="http://secunia.com/advisories/33362" source="SECUNIA" adv="1">33362</ref>
      <ref url="http://osvdb.org/51112" source="OSVDB">51112</ref>
    </refs>
    <vuln_soft>
      <prod vendor="powerscripts" name="powerclan">
        <vers num="1.14a" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0708" published="2009-02-23" name="CVE-2009-0708" modified="2012-01-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple cross-site request forgery (CSRF) vulnerabilities in SemanticScuttle before 0.91 allow remote attackers to (1) hijack the authentication of administrators via unknown vectors or (2) hijack the authentication of arbitrary users via vectors involving the profile page.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://sourceforge.net/project/shownotes.php?release_id=651587" source="CONFIRM" patch="1">http://sourceforge.net/project/shownotes.php?release_id=651587</ref>
      <ref url="http://secunia.com/advisories/33383" source="SECUNIA" adv="1">33383</ref>
    </refs>
    <vuln_soft>
      <prod vendor="semanticscuttle" name="semanticscuttle">
        <vers num="0.85" />
        <vers num="0.86" />
        <vers num="0.87" />
        <vers num="0.88" />
        <vers num="0.89" />
        <vers prev="1" num="0.90" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0709" published="2009-02-23" name="CVE-2009-0709" modified="2009-02-24" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in login.php in PHPFootball 1.6 allows remote attackers to execute arbitrary SQL commands via the user parameter.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/47720" source="XF">phpfootball-login-sql-injection(47720)</ref>
      <ref url="http://secunia.com/advisories/33367" source="SECUNIA" adv="1">33367</ref>
      <ref url="http://osvdb.org/51104" source="OSVDB">51104</ref>
    </refs>
    <vuln_soft>
      <prod vendor="vlad_alexa_mancini" name="phpfootball">
        <vers num="1.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0710" published="2009-02-23" name="CVE-2009-0710" modified="2009-02-24" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in PHPFootball 1.6 allow remote attackers to inject arbitrary web script or HTML via (1) the user parameter to login.php or (2) the dbfield parameter to filter.php.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/47721" source="XF">phpfootball-login-xss(47721)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/47719" source="XF">phpfootball-filter-xss(47719)</ref>
      <ref url="http://www.osvdb.org/51103" source="OSVDB">51103</ref>
      <ref url="http://secunia.com/advisories/33367" source="SECUNIA">33367</ref>
      <ref url="http://osvdb.org/51105" source="OSVDB">51105</ref>
    </refs>
    <vuln_soft>
      <prod vendor="vlad_alexa_mancini" name="phpfootball">
        <vers num="1.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0711" published="2009-02-23" name="CVE-2009-0711" modified="2009-06-23" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">filter.php in PHPFootball 1.6 and earlier allows remote attackers to retrieve password hashes via a request with an Accounts value for the dbtable parameter, in conjunction with a Password value for the dbfield parameter.  NOTE: this has been reported as a SQL injection vulnerability by some sources, but the provenance of that information is unknown.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.osvdb.org/51102" source="OSVDB">51102</ref>
      <ref url="http://www.milw0rm.com/exploits/7636" source="MILW0RM">7636</ref>
      <ref url="http://secunia.com/advisories/33367" source="SECUNIA" adv="1">33367</ref>
    </refs>
    <vuln_soft>
      <prod vendor="vlad_alexa_mancini" name="phpfootball">
        <vers num="1.5" />
        <vers num="1.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0712" published="2009-03-11" name="CVE-2009-0712" modified="2009-03-21" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Unspecified vulnerability in WMI Mapper for HP Systems Insight Manager before 2.5.2.0 allows local users to gain privileges via unknown vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01655638" source="HP" patch="1" adv="1">HPSBMA02412</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0671" source="VUPEN">ADV-2009-0671</ref>
      <ref url="http://www.securitytracker.com/id?1021835" source="SECTRACK">1021835</ref>
      <ref url="http://www.securityfocus.com/bid/34078" source="BID">34078</ref>
      <ref url="http://secunia.com/advisories/34276" source="SECUNIA">34276</ref>
      <ref url="http://secunia.com/advisories/34243" source="SECUNIA" adv="1">34243</ref>
      <ref url="http://osvdb.org/52592" source="OSVDB">52592</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=123688841217193&amp;w=2" source="HP">HPSBMA02413</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01655638" source="HP" adv="1">HPSBMA02412</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="wmi_mapper">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0713" published="2009-03-11" name="CVE-2009-0713" modified="2009-03-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in WMI Mapper for HP Systems Insight Manager before 2.5.2.0 allows remote attackers to obtain sensitive information via unknown vectors.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01655638" source="HP" patch="1" adv="1">SSRT080040</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01655638" source="HP" patch="1" adv="1">SSRT080040</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0671" source="VUPEN">ADV-2009-0671</ref>
      <ref url="http://www.securitytracker.com/id?1021836" source="SECTRACK">1021836</ref>
      <ref url="http://www.securityfocus.com/bid/34078" source="BID">34078</ref>
      <ref url="http://secunia.com/advisories/34276" source="SECUNIA">34276</ref>
      <ref url="http://osvdb.org/52591" source="OSVDB">52591</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=123688841217193&amp;w=2" source="HP">HPSBMA02413</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="systems_insight_manager">
        <vers prev="1" num="2.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0714" published="2009-05-14" name="CVE-2009-0714" modified="2009-07-22" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Unspecified vulnerability in the dpwinsup module (dpwinsup.dll) for dpwingad (dpwingad.exe) in HP Data Protector Express and Express SSE 3.x before build 47065, and Express and Express SSE 4.x before build 46537, allows remote attackers cause a denial of service (application crash) or read portions of memory via one or more crafted packets.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2009/1309" source="VUPEN">ADV-2009-1309</ref>
      <ref url="http://www.securitytracker.com/id?1022220" source="SECTRACK">1022220</ref>
      <ref url="http://www.securityfocus.com/bid/34955" source="BID">34955</ref>
      <ref url="http://www.milw0rm.com/exploits/9007" source="MILW0RM">9007</ref>
      <ref url="http://www.milw0rm.com/exploits/9006" source="MILW0RM">9006</ref>
      <ref url="http://secunia.com/advisories/35084" source="SECUNIA" adv="1">35084</ref>
      <ref url="http://ivizsecurity.com/security-advisory-iviz-sr-09002.html" source="MISC">http://ivizsecurity.com/security-advisory-iviz-sr-09002.html</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01697543" source="HP" adv="1">SSRT090031</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01697543" source="HP" adv="1">SSRT090031</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="data_protector_express">
        <vers num="3.5" edition="sp1" />
        <vers num="3.5" edition="sp2" />
        <vers num="3.5" edition="sp2:" />
        <vers num="3.5" edition="sp2::sse" />
        <vers num="4.0" edition="sp1" />
        <vers num="4.0" edition="sp1:sse" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0715" published="2009-04-21" name="CVE-2009-0715" modified="2009-04-29" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)" CVSS_score="6.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.0" CVSS_base_score="6.5">
    <desc>
      <descript source="cve">Unspecified vulnerability in Secure NaviCLI in HP Storage Essentials 6.0.2 through 6.0.4 allows remote authenticated users to obtain "access" or "extended privileges" via unknown vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2009/1109" source="VUPEN">ADV-2009-1109</ref>
      <ref url="http://www.securitytracker.com/id?1022084" source="SECTRACK">1022084</ref>
      <ref url="http://secunia.com/advisories/34807" source="SECUNIA">34807</ref>
      <ref url="http://osvdb.org/53881" source="OSVDB">53881</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=124025839111157&amp;w=2" source="HP" adv="1">HPSBMA02414</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="storage_essentials">
        <vers num="6.0.2" />
        <vers num="6.0.3" />
        <vers num="6.0.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0716" published="2009-04-21" name="CVE-2009-0716" modified="2009-04-28" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Unspecified vulnerability in HP StorageWorks Storage Mirroring 5 before 5.1.1.1090.15 allows remote attackers to cause a denial of service or obtain "access" via unknown vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2009/1108" source="VUPEN">ADV-2009-1108</ref>
      <ref url="http://www.securitytracker.com/id?1022085" source="SECTRACK">1022085</ref>
      <ref url="http://secunia.com/advisories/34808" source="SECUNIA">34808</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=124025929213175&amp;w=2" source="HP">SSRT080146</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=124025929213175&amp;w=2" source="HP">SSRT080146</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="storageworks_storage_mirroring">
        <vers num="5" />
        <vers num="5.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0717" published="2009-04-21" name="CVE-2009-0717" modified="2009-04-28" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in HP StorageWorks Storage Mirroring 5 before 5.1.1.1090.15 allows remote attackers to cause a denial of service via unknown vectors.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2009/1108" source="VUPEN">ADV-2009-1108</ref>
      <ref url="http://www.securitytracker.com/id?1022086" source="SECTRACK">1022086</ref>
      <ref url="http://secunia.com/advisories/34808" source="SECUNIA">34808</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=124025929213175&amp;w=2" source="HP" adv="1">SSRT080146</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="storageworks_storage_mirroring">
        <vers num="5" />
        <vers num="5.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0718" published="2009-04-21" name="CVE-2009-0718" modified="2009-04-28" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in HP StorageWorks Storage Mirroring 5 before 5.1.1.1090.15 allows remote attackers to execute arbitrary code via unknown vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2009/1108" source="VUPEN">ADV-2009-1108</ref>
      <ref url="http://www.securitytracker.com/id?1022087" source="SECTRACK">1022087</ref>
      <ref url="http://secunia.com/advisories/34808" source="SECUNIA">34808</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=124025929213175&amp;w=2" source="HP">SSRT080146</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=124025929213175&amp;w=2" source="HP">SSRT080146</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="storageworks_storage_mirroring">
        <vers num="5" />
        <vers num="5.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0719" published="2009-04-29" name="CVE-2009-0719" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:S/C:C/I:C/A:N)" CVSS_score="6.0" CVSS_impact_subscore="9.2" CVSS_exploit_subscore="2.7" CVSS_base_score="6.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in useradd in HP HP-UX B.11.11, B.11.23, and B.11.31 allows local users to access arbitrary files and directories via unknown vectors, a different issue than CVE-2008-1660.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/34748" source="BID" patch="1">34748</ref>
      <ref url="http://www.securityfocus.com/archive/1/503038" source="HP">HPSBUX02366</ref>
      <ref url="http://www.securityfocus.com/archive/1/503038" source="HP">HPSBUX02366</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5791" source="OVAL">oval:org.mitre.oval:def:5791</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="hp-ux">
        <vers num="b.11.11" />
        <vers num="b.11.23" />
        <vers num="b.11.31" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0720" published="2009-05-05" name="CVE-2009-0720" modified="2009-05-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in HP OpenView Network Node Manager (OV NNM) 7.01, 7.51, and 7.53 allows remote attackers to execute arbitrary code via unknown vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.info/?l=bugtraq&amp;m=124146030732511&amp;w=2" source="HP" patch="1">HPSBMA02425</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=124146030732511&amp;w=2" source="HP" patch="1">HPSBMA02425</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1250" source="VUPEN">ADV-2009-1250</ref>
      <ref url="http://www.securitytracker.com/id?1022163" source="SECTRACK">1022163</ref>
      <ref url="http://secunia.com/advisories/34942" source="SECUNIA">34942</ref>
      <ref url="http://osvdb.org/54222" source="OSVDB">54222</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="openview_network_node_manager">
        <vers num="7.01" />
        <vers num="7.51" />
        <vers num="7.53" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0721" published="2009-05-18" name="CVE-2009-0721" modified="2009-05-19" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in Easy Login in the Sender module in HP Remote Graphics Software (RGS) 4.0.0 through 5.2.4 allows remote attackers to execute arbitrary code via unknown vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2009/1323" source="VUPEN" patch="1" adv="1">ADV-2009-1323</ref>
      <ref url="http://securitytracker.com/id?1022221" source="SECTRACK" patch="1">1022221</ref>
      <ref url="http://www.securityfocus.com/bid/34980" source="BID">34980</ref>
      <ref url="http://www.itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c01731970" source="HP">HPSBMA02427</ref>
      <ref url="http://www.itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c01731970" source="HP">HPSBMA02427</ref>
      <ref url="http://secunia.com/advisories/35089" source="SECUNIA" adv="1">35089</ref>
      <ref url="http://secunia.com/advisories/35087" source="SECUNIA" adv="1">35087</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="remote_graphics_software">
        <vers num="4.0.0" />
        <vers num="4.0.1" />
        <vers num="4.0.2" />
        <vers num="4.0.3" />
        <vers num="4.1.3" />
        <vers num="4.1.4" />
        <vers num="4.2.0" />
        <vers num="4.2.1" />
        <vers num="4.2.2" />
        <vers num="4.2.3" />
        <vers num="4.2.4" />
        <vers num="5.0" />
        <vers num="5.1.1" />
        <vers num="5.1.3" />
        <vers num="5.1.5" />
        <vers num="5.2.0" />
        <vers num="5.2.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0722" published="2009-02-24" name="CVE-2009-0722" modified="2009-02-24" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Directory traversal vulnerability in admin.php in Potato News 1.0.0 allows remote attackers to include and execute arbitrary files via a .. (dot dot) in the user cookie parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/33729" source="BID">33729</ref>
      <ref url="http://www.milw0rm.com/exploits/8032" source="MILW0RM">8032</ref>
    </refs>
    <vuln_soft>
      <prod vendor="potato-scripts" name="potato_news">
        <vers num="1.0.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0723" published="2009-03-23" name="CVE-2009-0723" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Multiple integer overflows in LittleCMS (aka lcms or liblcms) before 1.18beta2, as used in Firefox 3.1beta, OpenJDK, and GIMP, allow context-dependent attackers to execute arbitrary code via a crafted image file that triggers a heap-based buffer overflow.  NOTE: some of these details are obtained from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/34185" source="BID" patch="1">34185</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-March/msg00921.html" source="FEDORA">FEDORA-2009-3034</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-March/msg00857.html" source="FEDORA">FEDORA-2009-2983</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-March/msg00856.html" source="FEDORA">FEDORA-2009-2982</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-March/msg00851.html" source="FEDORA">FEDORA-2009-2970</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-March/msg00811.html" source="FEDORA">FEDORA-2009-2928</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-March/msg00799.html" source="FEDORA">FEDORA-2009-2910</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-March/msg00794.html" source="FEDORA">FEDORA-2009-2903</ref>
      <ref url="https://rhn.redhat.com/errata/RHSA-2009-0377.html" source="REDHAT">RHSA-2009:0377</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=487508" source="CONFIRM" adv="1">https://bugzilla.redhat.com/show_bug.cgi?id=487508</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/49326" source="XF">littlecms-unspecified-bo(49326)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0775" source="VUPEN" adv="1">ADV-2009-0775</ref>
      <ref url="http://www.ubuntu.com/usn/USN-744-1" source="UBUNTU">USN-744-1</ref>
      <ref url="http://www.securitytracker.com/id?1021869" source="SECTRACK">1021869</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/502031/100/0/threaded" source="BUGTRAQ">20090320 [oCERT-2009-003] LittleCMS integer errors</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/502018/100/0/threaded" source="BUGTRAQ">20090320 LittleCMS vulnerabilities (OpenJDK, Firefox, GIMP, etc. impacted)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-0339.html" source="REDHAT" adv="1">RHSA-2009:0339</ref>
      <ref url="http://www.ocert.org/advisories/ocert-2009-003.html" source="MISC">http://www.ocert.org/advisories/ocert-2009-003.html</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:162" source="MANDRIVA">MDVSA-2009:162</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:137" source="MANDRIVA">MDVSA-2009:137</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:121" source="MANDRIVA">MDVSA-2009:121</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1769" source="DEBIAN">DSA-1769</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1745" source="DEBIAN">DSA-1745</ref>
      <ref url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2009&amp;m=slackware-security.487438" source="SLACKWARE">SSA:2009-083-01</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200904-19.xml" source="GENTOO">GLSA-200904-19</ref>
      <ref url="http://secunia.com/advisories/34782" source="SECUNIA">34782</ref>
      <ref url="http://secunia.com/advisories/34675" source="SECUNIA">34675</ref>
      <ref url="http://secunia.com/advisories/34632" source="SECUNIA">34632</ref>
      <ref url="http://secunia.com/advisories/34463" source="SECUNIA">34463</ref>
      <ref url="http://secunia.com/advisories/34454" source="SECUNIA">34454</ref>
      <ref url="http://secunia.com/advisories/34450" source="SECUNIA">34450</ref>
      <ref url="http://secunia.com/advisories/34442" source="SECUNIA">34442</ref>
      <ref url="http://secunia.com/advisories/34418" source="SECUNIA">34418</ref>
      <ref url="http://secunia.com/advisories/34408" source="SECUNIA">34408</ref>
      <ref url="http://secunia.com/advisories/34400" source="SECUNIA" adv="1">34400</ref>
      <ref url="http://secunia.com/advisories/34382" source="SECUNIA" adv="1">34382</ref>
      <ref url="http://secunia.com/advisories/34367" source="SECUNIA" adv="1">34367</ref>
      <ref url="http://scarybeastsecurity.blogspot.com/2009/03/littlecms-vulnerabilities.html" source="MISC">http://scarybeastsecurity.blogspot.com/2009/03/littlecms-vulnerabilities.html</ref>
      <ref url="http://scary.beasts.org/security/CESA-2009-003.html" source="MISC">http://scary.beasts.org/security/CESA-2009-003.html</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11780" source="OVAL">oval:org.mitre.oval:def:11780</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-03/msg00004.html" source="SUSE">SUSE-SR:2009:007</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gimp" name="gimp">
        <vers num="" />
      </prod>
      <prod vendor="littlecms" name="lcms">
        <vers num="1.07" />
        <vers num="1.08" />
        <vers num="1.09" />
        <vers num="1.10" />
        <vers num="1.11" />
        <vers num="1.12" />
        <vers num="1.13" />
        <vers num="1.14" />
        <vers num="1.15" />
        <vers num="1.16" />
        <vers prev="1" num="1.17" />
      </prod>
      <prod vendor="mozilla" name="firefox">
        <vers num="3.1" edition="beta1" />
      </prod>
      <prod vendor="sun" name="openjdk">
        <vers prev="1" num="7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0726" published="2009-02-24" name="CVE-2009-0726" modified="2009-02-25" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in the GigCalendar (com_gigcal) component 1.0 for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the gigcal_gigs_id parameter in a details action to index.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/47919" source="XF">gigcalendar-index-sql-injection(47919)</ref>
      <ref url="http://www.securityfocus.com/bid/33241" source="BID">33241</ref>
      <ref url="http://www.milw0rm.com/exploits/7746" source="MILW0RM">7746</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gigcalendar" name="com_gigcalendar">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0727" published="2009-02-24" name="CVE-2009-0727" modified="2009-06-09" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in jobdetails.php in taifajobs 1.0 and earlier allows remote attackers to execute arbitrary SQL commands via the jobid parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/33864" source="BID">33864</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/501183/100/0/threaded" source="BUGTRAQ">20090223 [ECHO_ADV_103$2009] taifajobs &lt;= 1.0 (jobid) Remote SQL Injection Vulnerability</ref>
      <ref url="http://www.milw0rm.com/exploits/8098" source="MILW0RM">8098</ref>
      <ref url="http://osvdb.org/52256" source="OSVDB">52256</ref>
      <ref url="http://e-rdc.org/v1/news.php?readmore=126" source="MISC">http://e-rdc.org/v1/news.php?readmore=126</ref>
    </refs>
    <vuln_soft>
      <prod vendor="tony_iha_kazungu" name="taifajobs">
        <vers prev="1" num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0728" published="2009-02-24" name="CVE-2009-0728" modified="2009-02-25" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in the My_eGallery module for MAXdev MDPro (MD-Pro) and Postnuke allows remote attackers to execute arbitrary SQL commands via the pid parameter in a showpic action to index.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/33871" source="BID">33871</ref>
      <ref url="http://www.milw0rm.com/exploits/8100" source="MILW0RM">8100</ref>
    </refs>
    <vuln_soft>
      <prod vendor="maxdev" name="my_egallery">
        <vers num="-" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0729" published="2009-02-24" name="CVE-2009-0729" modified="2009-06-23" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple directory traversal vulnerabilities in Page Engine CMS 2.0 Basic and Pro allow remote attackers to include and execute arbitrary local files via directory traversal sequences in the fPrefix parameter to (1) modules/recent_poll_include.php, (2) modules/login_include.php, and (3) modules/statistics_include.php and (4) configuration.inc.php in includes/.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/48856" source="XF">pageengine-fprefix-file-include(48856)</ref>
      <ref url="http://www.securityfocus.com/bid/33860" source="BID">33860</ref>
      <ref url="http://secunia.com/advisories/33983" source="SECUNIA" adv="1">33983</ref>
      <ref url="http://osvdb.org/52178" source="OSVDB">52178</ref>
      <ref url="http://osvdb.org/52177" source="OSVDB">52177</ref>
      <ref url="http://osvdb.org/52176" source="OSVDB">52176</ref>
      <ref url="http://osvdb.org/52175" source="OSVDB">52175</ref>
    </refs>
    <vuln_soft>
      <prod vendor="lingx" name="page_engine_cms">
        <vers num="2.0" edition="-" />
        <vers num="2.0" edition="-:basic" />
        <vers num="2.0" edition="-:pro" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0730" published="2009-02-24" name="CVE-2009-0730" modified="2009-06-23" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in the GigCalendar (com_gigcal) component 1.0 for Mambo and Joomla!, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via (1) the gigcal _venues_id parameter in a details action to index.php, which is not properly handled by venuedetails.php, and (2) the gigcal_bands_id parameter in a details action to index.php, which is not properly handled by banddetails.php, different vectors than CVE-2009-0726.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/48865" source="XF">gigcalendar-venuedetails-sql-injection(48865)</ref>
      <ref url="http://www.securityfocus.com/bid/33863" source="BID">33863</ref>
      <ref url="http://www.securityfocus.com/bid/33859" source="BID">33859</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/501176/100/0/threaded" source="BUGTRAQ">20090221 gigCalendar 1.0 (banddetails.php) Joomla Component SQL Injection</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/501175/100/0/threaded" source="BUGTRAQ">20090221 gigCalendar 1.0 (venuedetails.php) Joomla Component SQL Injection</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/501174/100/0/threaded" source="BUGTRAQ">20090221 gigCalendar Joomla Component 1.0 SQL Injection</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gigcalendar" name="com_gigcalendar">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0731" published="2009-02-24" name="CVE-2009-0731" modified="2009-02-25" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Directory traversal vulnerability in pages/play.php in Free Arcade Script 1.0 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the template parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/33869" source="BID">33869</ref>
      <ref url="http://www.milw0rm.com/exploits/8094" source="MILW0RM">8094</ref>
      <ref url="http://secunia.com/advisories/34023" source="SECUNIA" adv="1">34023</ref>
    </refs>
    <vuln_soft>
      <prod vendor="freearcadescript" name="free_arcade_script">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0732" published="2009-02-24" name="CVE-2009-0732" modified="2009-02-25" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Downloadcenter 2.1 stores common.h under the web root with insufficient access control, which allows remote attackers to obtain user credentials and other sensitive information via a direct request. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/48862" source="XF">downloadcenter-common-info-disclosure(48862)</ref>
      <ref url="http://secunia.com/advisories/33992" source="SECUNIA" adv="1">33992</ref>
      <ref url="http://osvdb.org/52180" source="OSVDB">52180</ref>
    </refs>
    <vuln_soft>
      <prod vendor="lingx" name="downloadcenter">
        <vers num="2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0733" published="2009-03-23" name="CVE-2009-0733" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Multiple stack-based buffer overflows in the ReadSetOfCurves function in LittleCMS (aka lcms or liblcms) before 1.18beta2, as used in Firefox 3.1beta, OpenJDK, and GIMP, allow context-dependent attackers to execute arbitrary code via a crafted image file associated with a large integer value for the (1) input or (2) output channel, related to the ReadLUT_A2B and ReadLUT_B2A functions.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-March/msg00921.html" source="FEDORA">FEDORA-2009-3034</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-March/msg00857.html" source="FEDORA">FEDORA-2009-2983</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-March/msg00856.html" source="FEDORA">FEDORA-2009-2982</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-March/msg00851.html" source="FEDORA">FEDORA-2009-2970</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-March/msg00811.html" source="FEDORA">FEDORA-2009-2928</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-March/msg00799.html" source="FEDORA">FEDORA-2009-2910</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-March/msg00794.html" source="FEDORA">FEDORA-2009-2903</ref>
      <ref url="https://rhn.redhat.com/errata/RHSA-2009-0377.html" source="REDHAT">RHSA-2009:0377</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=487512" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=487512</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/49330" source="XF">littlecms-readsetofcurves-bo(49330)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/49330" source="XF">littlecms-unspecified-code-execution(49330)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0775" source="VUPEN" adv="1">ADV-2009-0775</ref>
      <ref url="http://www.ubuntu.com/usn/USN-744-1" source="UBUNTU">USN-744-1</ref>
      <ref url="http://www.securitytracker.com/id?1021869" source="SECTRACK">1021869</ref>
      <ref url="http://www.securityfocus.com/bid/34185" source="BID">34185</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/502031/100/0/threaded" source="BUGTRAQ">20090320 [oCERT-2009-003] LittleCMS integer errors</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/502018/100/0/threaded" source="BUGTRAQ">20090320 LittleCMS vulnerabilities (OpenJDK, Firefox, GIMP, etc. impacted)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-0339.html" source="REDHAT">RHSA-2009:0339</ref>
      <ref url="http://www.ocert.org/advisories/ocert-2009-003.html" source="MISC">http://www.ocert.org/advisories/ocert-2009-003.html</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:162" source="MANDRIVA">MDVSA-2009:162</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:137" source="MANDRIVA">MDVSA-2009:137</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:121" source="MANDRIVA">MDVSA-2009:121</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1769" source="DEBIAN">DSA-1769</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1745" source="DEBIAN">DSA-1745</ref>
      <ref url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2009&amp;m=slackware-security.487438" source="SLACKWARE">SSA:2009-083-01</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200904-19.xml" source="GENTOO">GLSA-200904-19</ref>
      <ref url="http://secunia.com/advisories/34782" source="SECUNIA">34782</ref>
      <ref url="http://secunia.com/advisories/34675" source="SECUNIA">34675</ref>
      <ref url="http://secunia.com/advisories/34632" source="SECUNIA">34632</ref>
      <ref url="http://secunia.com/advisories/34463" source="SECUNIA">34463</ref>
      <ref url="http://secunia.com/advisories/34454" source="SECUNIA">34454</ref>
      <ref url="http://secunia.com/advisories/34450" source="SECUNIA">34450</ref>
      <ref url="http://secunia.com/advisories/34442" source="SECUNIA">34442</ref>
      <ref url="http://secunia.com/advisories/34418" source="SECUNIA">34418</ref>
      <ref url="http://secunia.com/advisories/34408" source="SECUNIA">34408</ref>
      <ref url="http://secunia.com/advisories/34400" source="SECUNIA" adv="1">34400</ref>
      <ref url="http://secunia.com/advisories/34382" source="SECUNIA" adv="1">34382</ref>
      <ref url="http://secunia.com/advisories/34367" source="SECUNIA" adv="1">34367</ref>
      <ref url="http://scarybeastsecurity.blogspot.com/2009/03/littlecms-vulnerabilities.html" source="MISC">http://scarybeastsecurity.blogspot.com/2009/03/littlecms-vulnerabilities.html</ref>
      <ref url="http://scary.beasts.org/security/CESA-2009-003.html" source="MISC">http://scary.beasts.org/security/CESA-2009-003.html</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9742" source="OVAL">oval:org.mitre.oval:def:9742</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-03/msg00004.html" source="SUSE">SUSE-SR:2009:007</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gimp" name="gimp">
        <vers num="" />
      </prod>
      <prod vendor="littlecms" name="lcms">
        <vers num="1.07" />
        <vers num="1.08" />
        <vers num="1.09" />
        <vers num="1.10" />
        <vers num="1.11" />
        <vers num="1.12" />
        <vers num="1.13" />
        <vers num="1.14" />
        <vers num="1.15" />
        <vers num="1.16" />
        <vers prev="1" num="1.17" />
      </prod>
      <prod vendor="mozilla" name="firefox">
        <vers num="3.1" edition="beta1" />
      </prod>
      <prod vendor="sun" name="openjdk">
        <vers prev="1" num="7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0734" published="2009-02-25" name="CVE-2009-0734" modified="2009-02-25" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Heap-based buffer overflow in MultimediaPlayer.exe 6.86.240.7 in Nokia PC Suite 6.86.9.3 allows remote attackers to execute arbitrary code via a long string in a .m3u playlist file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2009/0318" source="VUPEN" adv="1">ADV-2009-0318</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/500627/100/0/threaded" source="BUGTRAQ">20090203 Nokia Multimedia Player v1.1 .m3u Heap Overflow PoC exploit</ref>
      <ref url="http://secunia.com/advisories/33796" source="SECUNIA" adv="1">33796</ref>
      <ref url="http://osvdb.org/51739" source="OSVDB">51739</ref>
    </refs>
    <vuln_soft>
      <prod vendor="nokia" name="nokia_pc_suite">
        <vers num="6.86.9.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0735" published="2009-02-25" name="CVE-2009-0735" modified="2009-02-25" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">Directory traversal vulnerability in lib/classes/message_class.php in Papoo CMS 3.6, when register_globals is enabled and magic_quotes_gpc is disabled, allows remote attackers to read and possibly execute arbitrary files via a .. (dot dot) in the pfadhier parameter.  NOTE: some of these details are obtained from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/33718" source="BID">33718</ref>
      <ref url="http://www.milw0rm.com/exploits/8030" source="MILW0RM">8030</ref>
      <ref url="http://secunia.com/advisories/33911" source="SECUNIA" adv="1">33911</ref>
    </refs>
    <vuln_soft>
      <prod vendor="papoo" name="papoo">
        <vers num="3.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0736" published="2009-02-25" name="CVE-2009-0736" modified="2009-07-22" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Pebble before 2.3.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://sourceforge.net/project/shownotes.php?release_id=660130" source="CONFIRM" patch="1" adv="1">http://sourceforge.net/project/shownotes.php?release_id=660130</ref>
      <ref url="http://sourceforge.net/forum/forum.php?forum_id=917656" source="CONFIRM" patch="1" adv="1">http://sourceforge.net/forum/forum.php?forum_id=917656</ref>
      <ref url="http://www.securityfocus.com/bid/33733" source="BID">33733</ref>
      <ref url="http://secunia.com/advisories/33888" source="SECUNIA" adv="1">33888</ref>
    </refs>
    <vuln_soft>
      <prod vendor="simon_brown" name="pebble">
        <vers num="1.0" />
        <vers num="1.1" />
        <vers num="1.2" />
        <vers num="1.3" />
        <vers num="1.4" edition="beta1" />
        <vers num="1.4" edition="beta2" />
        <vers num="1.4" edition="beta3" />
        <vers num="1.4.1" />
        <vers num="1.4.1_01" />
        <vers num="1.4.2" />
        <vers num="1.4.2_01" />
        <vers num="1.5" edition="beta1" />
        <vers num="1.5" edition="beta2" />
        <vers num="1.5" edition="beta3" />
        <vers num="1.5.1" />
        <vers num="1.6" edition="beta1" />
        <vers num="1.6" edition="beta2" />
        <vers num="1.6" edition="beta3" />
        <vers num="1.6.1" />
        <vers num="1.7" edition="beta1" />
        <vers num="1.7.1" />
        <vers num="1.7.2" />
        <vers num="1.8" />
        <vers num="1.9" />
        <vers num="2.0" />
        <vers num="2.0.0" edition="m1" />
        <vers num="2.0.0" edition="m2" />
        <vers num="2.0.0" edition="m3" />
        <vers num="2.0.0" edition="rc1" />
        <vers num="2.0.0" edition="rc2" />
        <vers num="2.0.1" />
        <vers num="2.1" edition="rc1" />
        <vers num="2.2" />
        <vers num="2.3" />
        <vers prev="1" num="2.3.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2009-0737" published="2009-02-25" name="CVE-2009-0737" modified="2009-10-14" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in the web-based installer (config/index.php) in MediaWiki 1.6 before 1.6.12, 1.12 before 1.12.4, and 1.13 before 1.13.4, when the installer is in active use, allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2009/0368" source="VUPEN" patch="1" adv="1">ADV-2009-0368</ref>
      <ref url="http://www.securityfocus.com/bid/33681" source="BID" patch="1">33681</ref>
      <ref url="http://lists.wikimedia.org/pipermail/mediawiki-announce/2009-February/000083.html" source="MLIST" patch="1">[MediaWiki-announce] 20090207 MediaWiki releases: security update and new major branch</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1901" source="DEBIAN">DSA-1901</ref>
      <ref url="http://svn.wikimedia.org/svnroot/mediawiki/tags/REL1_6_12/phase3/RELEASE-NOTES" source="CONFIRM" adv="1">http://svn.wikimedia.org/svnroot/mediawiki/tags/REL1_6_12/phase3/RELEASE-NOTES</ref>
      <ref url="http://svn.wikimedia.org/svnroot/mediawiki/tags/REL1_13_4/phase3/RELEASE-NOTES" source="CONFIRM" adv="1">http://svn.wikimedia.org/svnroot/mediawiki/tags/REL1_13_4/phase3/RELEASE-NOTES</ref>
      <ref url="http://svn.wikimedia.org/svnroot/mediawiki/tags/REL1_12_4/phase3/RELEASE-NOTES" source="CONFIRM" adv="1">http://svn.wikimedia.org/svnroot/mediawiki/tags/REL1_12_4/phase3/RELEASE-NOTES</ref>
      <ref url="http://secunia.com/advisories/33881" source="SECUNIA" adv="1">33881</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mediawiki" name="mediawiki">
        <vers num="1.12.0" edition="rc1" />
        <vers num="1.12.1" />
        <vers num="1.12.2" />
        <vers num="1.12.3" />
        <vers num="1.13.0" edition="rc1" />
        <vers num="1.13.0" edition="rc2" />
        <vers num="1.13.1" />
        <vers num="1.13.2" />
        <vers num="1.13.3" />
        <vers num="1.6.0" />
        <vers num="1.6.1" />
        <vers num="1.6.10" />
        <vers num="1.6.11" />
        <vers num="1.6.2" />
        <vers num="1.6.3" />
        <vers num="1.6.4" />
        <vers num="1.6.5" />
        <vers num="1.6.6" />
        <vers num="1.6.7" />
        <vers num="1.6.8" />
        <vers num="1.6.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0738" published="2009-02-25" name="CVE-2009-0738" modified="2009-07-22" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in login.php in Auth Php 1.0 allows remote attackers to execute arbitrary SQL commands via the (1) username and (2) passwd parameters.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/33723" source="BID">33723</ref>
      <ref url="http://www.milw0rm.com/exploits/8033" source="MILW0RM">8033</ref>
      <ref url="http://secunia.com/advisories/33908" source="SECUNIA" adv="1">33908</ref>
    </refs>
    <vuln_soft>
      <prod vendor="frankmancuso" name="auth_php">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0739" published="2009-02-25" name="CVE-2009-0739" modified="2009-02-25" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in login.php in MyNews 0.10 allows remote attackers to execute arbitrary SQL commands via the (1) username and (2) passwd parameters.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/33728" source="BID">33728</ref>
      <ref url="http://www.milw0rm.com/exploits/8034" source="MILW0RM">8034</ref>
    </refs>
    <vuln_soft>
      <prod vendor="frankmancuso" name="mynews">
        <vers num="0.10" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0740" published="2009-02-25" name="CVE-2009-0740" modified="2009-07-22" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in login.php in BlueBird Prelease allows remote attackers to execute arbitrary SQL commands via the (1) username and (2) passwd parameters.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/33725" source="BID">33725</ref>
      <ref url="http://www.milw0rm.com/exploits/8035" source="MILW0RM">8035</ref>
    </refs>
    <vuln_soft>
      <prod vendor="frankmancuso" name="bluebird">
        <vers num="pre-release" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0741" published="2009-02-25" name="CVE-2009-0741" modified="2009-02-25" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in Login.asp in Craft Silicon Banking@Home 2.1 and earlier allows remote attackers to execute arbitrary SQL commands via the LoginName parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/33721" source="BID">33721</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/500824/100/0/threaded" source="BUGTRAQ">20090210 Craft Silicon Banking@Home SQL Injection</ref>
      <ref url="http://secunia.com/advisories/33907" source="SECUNIA" adv="1">33907</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2009-February/067879.html" source="FULLDISC">20090210 Craft Silicon Banking at Home SQL Injection</ref>
    </refs>
    <vuln_soft>
      <prod vendor="craftsilicon" name="banking@home">
        <vers prev="1" num="2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0742" published="2009-02-26" name="CVE-2009-0742" modified="2009-02-27" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:N/A:N)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">The username command in Cisco ACE Application Control Engine Module for Catalyst 6500 Switches and 7600 Routers and Cisco ACE 4710 Application Control Engine Appliance stores a cleartext password by default, which allows context-dependent attackers to obtain sensitive information.</descript>
      <descript source="nvd">Note that CVE-2009-0742 is not referenced on the vendor advisory page at:

http://www.cisco.com/en/US/products/products_security_advisory09186a0080a7bc82.shtml</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.cisco.com/en/US/products/products_security_advisory09186a0080a7bc82.shtml" source="CISCO" patch="1" adv="1">20090225 Multiple Vulnerabilities in the Cisco ACE Application Control Engine Module and Cisco ACE 4710 Application Control Engine</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="ace_4710">
        <vers num="" />
      </prod>
      <prod vendor="cisco" name="application_control_engine_module">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2009-0743" published="2009-02-27" name="CVE-2009-0743" modified="2009-03-06" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:S/C:N/I:P/A:N)" CVSS_score="3.5" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="6.8" CVSS_base_score="3.5">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the edit account page in the Web Server in Cisco Unified MeetingPlace Web Conferencing 6.0 before 6.0(517.0) (aka 6.0 MR4) and 7.0 before 7.0(2) (aka 7.0 MR1) allows remote authenticated users to inject arbitrary web script or HTML via the E-mail Address field.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.cisco.com/en/US/products/products_security_response09186a0080a7bc61.html" source="CISCO" patch="1" adv="1">20090226 Cisco Unified MeetingPlace Stored Cross-Site Scripting Vulnerability</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/48965" source="XF">cisco-meetingplace-emailaddress-xss(48965)</ref>
      <ref url="http://www.securitytracker.com/id?1021778" source="SECTRACK">1021778</ref>
      <ref url="http://www.securityfocus.com/bid/33915" source="BID">33915</ref>
      <ref url="http://www.securityfocus.com/archive/1/501251/30/0/threaded" source="BUGTRAQ">20090225 Cisco Unified MeetingPlace Web Conferencing Stored Cross Site Scripting Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="unified_meetingplace">
        <vers num="6.0" />
        <vers num="7.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0744" published="2009-02-27" name="CVE-2009-0744" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Apple Safari 4 Beta build 528.16 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a feeds: URI beginning with a (1) % (percent), (2) { (open curly bracket), (3) } (close curly bracket), (4) ^ (caret), (5) ` (backquote), or (6) | (pipe) character, followed by an &amp; (ampersand) character.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/48943" source="XF">safari-feedsuri-dos(48943)</ref>
      <ref url="http://www.securityfocus.com/bid/33909" source="BID">33909</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/501229/100/0/threaded" source="BUGTRAQ">20090225 Apple Safari 4 Beta feeds: URI NULL Pointer Dereference Denial of Service Vulnerability</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6066" source="OVAL">oval:org.mitre.oval:def:6066</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="safari">
        <vers num="4.0" edition="beta" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0745" published="2009-02-27" name="CVE-2009-0745" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="4.9" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="3.9" CVSS_base_score="4.9">
    <desc>
      <descript source="cve">The ext4_group_add function in fs/ext4/resize.c in the Linux kernel 2.6.27 before 2.6.27.19 and 2.6.28 before 2.6.28.7 does not properly initialize the group descriptor during a resize (aka resize2fs) operation, which might allow local users to cause a denial of service (OOPS) by arranging for crafted values to be present in available memory.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2009/3316" source="VUPEN">ADV-2009-3316</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0509" source="VUPEN" adv="1">ADV-2009-0509</ref>
      <ref url="http://www.vmware.com/security/advisories/VMSA-2009-0016.html" source="CONFIRM">http://www.vmware.com/security/advisories/VMSA-2009-0016.html</ref>
      <ref url="http://www.ubuntu.com/usn/usn-751-1" source="UBUNTU">USN-751-1</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/507985/100/0/threaded" source="BUGTRAQ">20091120 VMSA-2009-0016 VMware vCenter and ESX update release and vMA patch release address multiple security issue in third party components</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1787" source="DEBIAN">DSA-1787</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1749" source="DEBIAN">DSA-1749</ref>
      <ref url="http://secunia.com/advisories/37471" source="SECUNIA">37471</ref>
      <ref url="http://secunia.com/advisories/34981" source="SECUNIA">34981</ref>
      <ref url="http://secunia.com/advisories/34394" source="SECUNIA">34394</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7765" source="OVAL">oval:org.mitre.oval:def:7765</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10942" source="OVAL">oval:org.mitre.oval:def:10942</ref>
      <ref url="http://kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.28.7" source="CONFIRM">http://kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.28.7</ref>
      <ref url="http://kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.27.19" source="CONFIRM">http://kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.27.19</ref>
      <ref url="http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=fdff73f094e7220602cc3f8959c7230517976412" source="CONFIRM">http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=fdff73f094e7220602cc3f8959c7230517976412</ref>
      <ref url="http://bugzilla.kernel.org/show_bug.cgi?id=12433" source="CONFIRM">http://bugzilla.kernel.org/show_bug.cgi?id=12433</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="kernel">
        <vers num="2.6.27" />
        <vers num="2.6.27.1" />
        <vers num="2.6.27.10" />
        <vers num="2.6.27.11" />
        <vers num="2.6.27.12" />
        <vers num="2.6.27.13" />
        <vers num="2.6.27.14" />
        <vers num="2.6.27.15" />
        <vers num="2.6.27.16" />
        <vers num="2.6.27.17" />
        <vers num="2.6.27.18" />
        <vers num="2.6.27.2" />
        <vers num="2.6.27.3" />
        <vers num="2.6.27.4" />
        <vers num="2.6.27.5" />
        <vers num="2.6.27.6" />
        <vers num="2.6.27.7" />
        <vers num="2.6.27.8" />
        <vers num="2.6.27.9" />
        <vers num="2.6.28" />
        <vers num="2.6.28.1" />
        <vers num="2.6.28.2" />
        <vers num="2.6.28.3" />
        <vers num="2.6.28.4" />
        <vers num="2.6.28.5" />
        <vers num="2.6.28.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0746" published="2009-02-27" name="CVE-2009-0746" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="4.9" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="3.9" CVSS_base_score="4.9">
    <desc>
      <descript source="cve">The make_indexed_dir function in fs/ext4/namei.c in the Linux kernel 2.6.27 before 2.6.27.19 and 2.6.28 before 2.6.28.7 does not validate a certain rec_len field, which allows local users to cause a denial of service (OOPS) by attempting to mount a crafted ext4 filesystem.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/48872" source="XF">linux-kernel-makeindexeddir-ext4-dos(48872)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/3316" source="VUPEN">ADV-2009-3316</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0509" source="VUPEN" adv="1">ADV-2009-0509</ref>
      <ref url="http://www.vmware.com/security/advisories/VMSA-2009-0016.html" source="CONFIRM">http://www.vmware.com/security/advisories/VMSA-2009-0016.html</ref>
      <ref url="http://www.ubuntu.com/usn/usn-751-1" source="UBUNTU">USN-751-1</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/507985/100/0/threaded" source="BUGTRAQ">20091120 VMSA-2009-0016 VMware vCenter and ESX update release and vMA patch release address multiple security issue in third party components</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1749" source="DEBIAN">DSA-1749</ref>
      <ref url="http://secunia.com/advisories/37471" source="SECUNIA">37471</ref>
      <ref url="http://secunia.com/advisories/34394" source="SECUNIA">34394</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:8039" source="OVAL">oval:org.mitre.oval:def:8039</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10342" source="OVAL">oval:org.mitre.oval:def:10342</ref>
      <ref url="http://osvdb.org/52202" source="OSVDB">52202</ref>
      <ref url="http://kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.28.7" source="CONFIRM">http://kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.28.7</ref>
      <ref url="http://kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.27.19" source="CONFIRM">http://kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.27.19</ref>
      <ref url="http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=e6b8bc09ba2075cd91fbffefcd2778b1a00bd76f" source="CONFIRM">http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=e6b8bc09ba2075cd91fbffefcd2778b1a00bd76f</ref>
      <ref url="http://bugzilla.kernel.org/show_bug.cgi?id=12430" source="CONFIRM">http://bugzilla.kernel.org/show_bug.cgi?id=12430</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="kernel">
        <vers num="2.6.27" />
        <vers num="2.6.27.1" />
        <vers num="2.6.27.10" />
        <vers num="2.6.27.11" />
        <vers num="2.6.27.12" />
        <vers num="2.6.27.13" />
        <vers num="2.6.27.14" />
        <vers num="2.6.27.15" />
        <vers num="2.6.27.16" />
        <vers num="2.6.27.17" />
        <vers num="2.6.27.18" />
        <vers num="2.6.27.2" />
        <vers num="2.6.27.3" />
        <vers num="2.6.27.4" />
        <vers num="2.6.27.5" />
        <vers num="2.6.27.6" />
        <vers num="2.6.27.7" />
        <vers num="2.6.27.8" />
        <vers num="2.6.27.9" />
        <vers num="2.6.28" />
        <vers num="2.6.28.1" />
        <vers num="2.6.28.2" />
        <vers num="2.6.28.3" />
        <vers num="2.6.28.4" />
        <vers num="2.6.28.5" />
        <vers num="2.6.28.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0747" published="2009-02-27" name="CVE-2009-0747" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="4.9" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="3.9" CVSS_base_score="4.9">
    <desc>
      <descript source="cve">The ext4_isize function in fs/ext4/ext4.h in the Linux kernel 2.6.27 before 2.6.27.19 and 2.6.28 before 2.6.28.7 uses the i_size_high structure member during operations on arbitrary types of files, which allows local users to cause a denial of service (CPU consumption and error-message flood) by attempting to mount a crafted ext4 filesystem.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://bugzilla.kernel.org/show_bug.cgi?id=12375" source="CONFIRM" patch="1">http://bugzilla.kernel.org/show_bug.cgi?id=12375</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/3316" source="VUPEN">ADV-2009-3316</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0509" source="VUPEN" adv="1">ADV-2009-0509</ref>
      <ref url="http://www.vmware.com/security/advisories/VMSA-2009-0016.html" source="CONFIRM">http://www.vmware.com/security/advisories/VMSA-2009-0016.html</ref>
      <ref url="http://www.ubuntu.com/usn/usn-751-1" source="UBUNTU">USN-751-1</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/507985/100/0/threaded" source="BUGTRAQ">20091120 VMSA-2009-0016 VMware vCenter and ESX update release and vMA patch release address multiple security issue in third party components</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1749" source="DEBIAN">DSA-1749</ref>
      <ref url="http://secunia.com/advisories/37471" source="SECUNIA">37471</ref>
      <ref url="http://secunia.com/advisories/34394" source="SECUNIA">34394</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9200" source="OVAL">oval:org.mitre.oval:def:9200</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:8585" source="OVAL">oval:org.mitre.oval:def:8585</ref>
      <ref url="http://kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.28.7" source="CONFIRM">http://kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.28.7</ref>
      <ref url="http://kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.27.19" source="CONFIRM">http://kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.27.19</ref>
      <ref url="http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=06a279d636734da32bb62dd2f7b0ade666f65d7c" source="CONFIRM">http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=06a279d636734da32bb62dd2f7b0ade666f65d7c</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="kernel">
        <vers num="2.6.27" edition="rc1" />
        <vers num="2.6.27" edition="rc2" />
        <vers num="2.6.27" edition="rc3" />
        <vers num="2.6.27" edition="rc4" />
        <vers num="2.6.27" edition="rc5" />
        <vers num="2.6.27" edition="rc6" />
        <vers num="2.6.27" edition="rc7" />
        <vers num="2.6.27" edition="rc8" />
        <vers num="2.6.27" edition="rc9" />
        <vers num="2.6.27.1" />
        <vers num="2.6.27.10" />
        <vers num="2.6.27.11" />
        <vers num="2.6.27.12" />
        <vers num="2.6.27.13" />
        <vers num="2.6.27.14" />
        <vers num="2.6.27.15" />
        <vers num="2.6.27.16" />
        <vers num="2.6.27.17" />
        <vers num="2.6.27.18" />
        <vers num="2.6.27.2" />
        <vers num="2.6.27.3" />
        <vers num="2.6.27.4" />
        <vers num="2.6.27.5" />
        <vers num="2.6.27.6" />
        <vers num="2.6.27.7" />
        <vers num="2.6.27.8" />
        <vers num="2.6.27.9" />
        <vers num="2.6.28" edition="rc1" />
        <vers num="2.6.28" edition="rc2" />
        <vers num="2.6.28" edition="rc3" />
        <vers num="2.6.28" edition="rc4" />
        <vers num="2.6.28" edition="rc5" />
        <vers num="2.6.28" edition="rc6" />
        <vers num="2.6.28" edition="rc7" />
        <vers num="2.6.28.1" />
        <vers num="2.6.28.2" />
        <vers num="2.6.28.3" />
        <vers num="2.6.28.4" />
        <vers num="2.6.28.5" />
        <vers num="2.6.28.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0748" published="2009-02-27" name="CVE-2009-0748" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="4.9" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="3.9" CVSS_base_score="4.9">
    <desc>
      <descript source="cve">The ext4_fill_super function in fs/ext4/super.c in the Linux kernel 2.6.27 before 2.6.27.19 and 2.6.28 before 2.6.28.7 does not validate the superblock configuration, which allows local users to cause a denial of service (NULL pointer dereference and OOPS) by attempting to mount a crafted ext4 filesystem.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2009/3316" source="VUPEN">ADV-2009-3316</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0509" source="VUPEN" adv="1">ADV-2009-0509</ref>
      <ref url="http://www.vmware.com/security/advisories/VMSA-2009-0016.html" source="CONFIRM">http://www.vmware.com/security/advisories/VMSA-2009-0016.html</ref>
      <ref url="http://www.ubuntu.com/usn/usn-751-1" source="UBUNTU">USN-751-1</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/507985/100/0/threaded" source="BUGTRAQ">20091120 VMSA-2009-0016 VMware vCenter and ESX update release and vMA patch release address multiple security issue in third party components</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1749" source="DEBIAN">DSA-1749</ref>
      <ref url="http://secunia.com/advisories/37471" source="SECUNIA">37471</ref>
      <ref url="http://secunia.com/advisories/34394" source="SECUNIA">34394</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:8526" source="OVAL">oval:org.mitre.oval:def:8526</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10683" source="OVAL">oval:org.mitre.oval:def:10683</ref>
      <ref url="http://osvdb.org/52203" source="OSVDB">52203</ref>
      <ref url="http://kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.28.7" source="CONFIRM">http://kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.28.7</ref>
      <ref url="http://kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.27.19" source="CONFIRM">http://kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.27.19</ref>
      <ref url="http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=4ec110281379826c5cf6ed14735e47027c3c5765" source="CONFIRM">http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=4ec110281379826c5cf6ed14735e47027c3c5765</ref>
      <ref url="http://bugzilla.kernel.org/show_bug.cgi?id=12371" source="CONFIRM">http://bugzilla.kernel.org/show_bug.cgi?id=12371</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="kernel">
        <vers num="2.6.27" edition="rc1" />
        <vers num="2.6.27" edition="rc2" />
        <vers num="2.6.27" edition="rc3" />
        <vers num="2.6.27" edition="rc4" />
        <vers num="2.6.27" edition="rc5" />
        <vers num="2.6.27" edition="rc6" />
        <vers num="2.6.27" edition="rc7" />
        <vers num="2.6.27" edition="rc8" />
        <vers num="2.6.27" edition="rc9" />
        <vers num="2.6.27.1" />
        <vers num="2.6.27.10" />
        <vers num="2.6.27.11" />
        <vers num="2.6.27.12" />
        <vers num="2.6.27.13" />
        <vers num="2.6.27.14" />
        <vers num="2.6.27.15" />
        <vers num="2.6.27.16" />
        <vers num="2.6.27.17" />
        <vers num="2.6.27.18" />
        <vers num="2.6.27.2" />
        <vers num="2.6.27.3" />
        <vers num="2.6.27.4" />
        <vers num="2.6.27.5" />
        <vers num="2.6.27.6" />
        <vers num="2.6.27.7" />
        <vers num="2.6.27.8" />
        <vers num="2.6.27.9" />
        <vers num="2.6.28" edition="rc1" />
        <vers num="2.6.28" edition="rc2" />
        <vers num="2.6.28" edition="rc3" />
        <vers num="2.6.28" edition="rc4" />
        <vers num="2.6.28" edition="rc5" />
        <vers num="2.6.28" edition="rc6" />
        <vers num="2.6.28" edition="rc7" />
        <vers num="2.6.28.1" />
        <vers num="2.6.28.2" />
        <vers num="2.6.28.3" />
        <vers num="2.6.28.4" />
        <vers num="2.6.28.5" />
        <vers num="2.6.28.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0749" published="2009-03-02" name="CVE-2009-0749" modified="2009-07-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Use-after-free vulnerability in the GIFReadNextExtension function in lib/pngxtern/gif/gifread.c in OptiPNG 0.6.2 and earlier allows context-dependent attackers to cause a denial of service (application crash) via a crafted GIF image that causes the realloc function to return a new pointer, which triggers memory corruption when the old pointer is accessed.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2009/0510" source="VUPEN" patch="1" adv="1">ADV-2009-0510</ref>
      <ref url="http://www.securityfocus.com/bid/33873" source="BID" patch="1">33873</ref>
      <ref url="http://optipng.sourceforge.net" source="CONFIRM" patch="1" adv="1">http://optipng.sourceforge.net</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/48879" source="XF">optipng-gifreadnextextension-code-execution(48879)</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2009/02/25/4" source="MLIST">[oss-security] 20090225 Re: CVE request: optipng security release</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2009/02/24/2" source="MLIST">[oss-security] 20090224 CVE request: optipng security release</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200903-12.xml" source="GENTOO">GLSA-200903-12</ref>
      <ref url="http://sourceforge.net/tracker/index.php?func=detail&amp;aid=2582013&amp;group_id=151404&amp;atid=780913" source="CONFIRM">http://sourceforge.net/tracker/index.php?func=detail&amp;aid=2582013&amp;group_id=151404&amp;atid=780913</ref>
      <ref url="http://secunia.com/advisories/35685" source="SECUNIA">35685</ref>
      <ref url="http://secunia.com/advisories/34259" source="SECUNIA">34259</ref>
      <ref url="http://secunia.com/advisories/34201" source="SECUNIA">34201</ref>
      <ref url="http://secunia.com/advisories/34035" source="SECUNIA" adv="1">34035</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-07/msg00002.html" source="SUSE">SUSE-SR:2009:012</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-03/msg00001.html" source="SUSE">SUSE-SR:2009:006</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cosmin_truta" name="optipng">
        <vers num="0.0" />
        <vers num="0.1" />
        <vers num="0.2" />
        <vers num="0.3" />
        <vers num="0.3.1" />
        <vers num="0.3.2" />
        <vers num="0.4" />
        <vers num="0.4.1" />
        <vers num="0.4.2" />
        <vers num="0.4.3" />
        <vers num="0.4.4" />
        <vers num="0.4.5" />
        <vers num="0.4.6" />
        <vers num="0.4.7" />
        <vers num="0.4.8" />
        <vers num="0.5" />
        <vers num="0.5.1" />
        <vers num="0.5.2" />
        <vers num="0.5.3" />
        <vers num="0.5.4" />
        <vers num="0.5.5" />
        <vers num="0.6" />
        <vers num="0.6.1" />
        <vers prev="1" num="0.6.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0750" published="2009-03-02" name="CVE-2009-0750" modified="2009-03-03" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in login.php in the smNews example script for txtSQL 2.2 Final allows remote attackers to execute arbitrary SQL commands via the username parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/48813" source="XF">smnews-login-sql-injection(48813)</ref>
      <ref url="http://www.milw0rm.com/exploits/8076" source="MILW0RM">8076</ref>
    </refs>
    <vuln_soft>
      <prod vendor="tombstone" name="smnews">
        <vers num="-" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0751" published="2009-03-02" name="CVE-2009-0751" modified="2010-04-27" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Yaws before 1.80 allows remote attackers to cause a denial of service (memory consumption and crash) via a request with a large number of headers.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://yaws.hyber.org/" source="CONFIRM" adv="1">http://yaws.hyber.org/</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0590" source="VUPEN">ADV-2009-0590</ref>
      <ref url="http://www.securityfocus.com/bid/33834" source="BID">33834</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2009/02/19/1" source="MLIST">[oss-security] 20090219 CVE request for yaws</ref>
      <ref url="http://www.milw0rm.com/exploits/8148" source="MILW0RM">8148</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1740" source="DEBIAN">DSA-1740</ref>
      <ref url="http://secunia.com/advisories/34239" source="SECUNIA">34239</ref>
      <ref url="http://secunia.com/advisories/33979" source="SECUNIA" adv="1">33979</ref>
    </refs>
    <vuln_soft>
      <prod vendor="yaws" name="yaws">
        <vers num="1.50" />
        <vers num="1.51" />
        <vers num="1.52" />
        <vers num="1.53" />
        <vers num="1.54" />
        <vers num="1.55" />
        <vers num="1.56" />
        <vers num="1.57" />
        <vers num="1.58" />
        <vers num="1.61" />
        <vers num="1.62" />
        <vers num="1.63" />
        <vers num="1.64" />
        <vers num="1.65" />
        <vers num="1.66" />
        <vers num="1.67" />
        <vers num="1.68" />
        <vers num="1.70" />
        <vers num="1.71" />
        <vers num="1.72" />
        <vers num="1.73" />
        <vers num="1.74" />
        <vers num="1.75" />
        <vers num="1.76" />
        <vers num="1.77" />
        <vers num="1.78" />
        <vers prev="1" num="1.79" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0752" published="2009-03-02" name="CVE-2009-0752" modified="2009-03-04" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in Movable Type Pro and Community Solution 4.x before 4.24 has unknown impact and attack vectors, possibly related to the password recovery mechanism.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.movabletype.com/blog/2009/02/movable-type-424-get-updated-with-better-password-recovery.html" source="CONFIRM" patch="1" adv="1">http://www.movabletype.com/blog/2009/02/movable-type-424-get-updated-with-better-password-recovery.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sixapart" name="movable_type">
        <vers num="4.0" edition="-" />
        <vers num="4.0" edition="-:community_solution" />
        <vers num="4.0" edition="-:pro" />
        <vers num="4.01" edition="-" />
        <vers num="4.01" edition="-:community_solution" />
        <vers num="4.01" edition="-:pro" />
        <vers num="4.01" edition="b" />
        <vers num="4.01" edition="b:pro" />
        <vers num="4.01" edition="b:community_solution" />
        <vers num="4.1" edition="-" />
        <vers num="4.1" edition="-:community_solution" />
        <vers num="4.1" edition="-:pro" />
        <vers num="4.12" edition="-" />
        <vers num="4.12" edition="-:community_solution" />
        <vers num="4.12" edition="-:pro" />
        <vers num="4.2" edition="-" />
        <vers num="4.2" edition="-:pro" />
        <vers num="4.2" edition="-:community_solution" />
        <vers num="4.21" edition="-" />
        <vers num="4.21" edition="-:pro" />
        <vers num="4.21" edition="-:community_solution" />
        <vers num="4.23" edition="-" />
        <vers num="4.23" edition="-:pro" />
        <vers num="4.23" edition="-:community_solution" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0753" published="2009-03-03" name="CVE-2009-0753" modified="2009-06-09" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Absolute path traversal vulnerability in MLDonkey 2.8.4 through 2.9.7 allows remote attackers to read arbitrary files via a leading "//" (double slash) in the filename.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-March/msg00617.html" source="FEDORA">FEDORA-2009-2758</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-March/msg00542.html" source="FEDORA">FEDORA-2009-2703</ref>
      <ref url="http://www.securityfocus.com/bid/33865" source="BID">33865</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2009/02/23/1" source="MLIST">[oss-security] 20090223 CVE request: mldonkey arbitrary file download vulnerability</ref>
      <ref url="http://www.milw0rm.com/exploits/8097" source="MILW0RM">8097</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200903-36.xml" source="GENTOO">GLSA-200903-36</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1739" source="DEBIAN">DSA-1739</ref>
      <ref url="http://secunia.com/advisories/34436" source="SECUNIA">34436</ref>
      <ref url="http://secunia.com/advisories/34345" source="SECUNIA">34345</ref>
      <ref url="http://secunia.com/advisories/34306" source="SECUNIA">34306</ref>
      <ref url="http://secunia.com/advisories/34008" source="SECUNIA" adv="1">34008</ref>
      <ref url="http://savannah.nongnu.org/bugs/?25667" source="CONFIRM">http://savannah.nongnu.org/bugs/?25667</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mldonkey" name="mldonkey">
        <vers num="2.8.4" />
        <vers num="2.8.7" />
        <vers num="2.9" />
        <vers num="2.9.0-r3" />
        <vers num="2.9.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2009-0754" published="2009-03-03" name="CVE-2009-0754" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">PHP 4.4.4, 5.1.6, and other versions, when running on Apache, allows local users to modify behavior of other sites hosted on the same web server by modifying the mbstring.func_overload setting within .htaccess, which causes this setting to be applied to other virtual hosts on the same server.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-May/msg01465.html" source="FEDORA">FEDORA-2009-3848</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-May/msg01451.html" source="FEDORA">FEDORA-2009-3768</ref>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-761-1" source="UBUNTU">USN-761-1</ref>
      <ref url="http://www.securitytracker.com/id?1021979" source="SECTRACK">1021979</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-0350.html" source="REDHAT">RHSA-2009:0350</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2009/02/25/3" source="MLIST">[oss-security] 20090225 Re: CVE Request - php (PHP BZ#27421)</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2009/02/03/3" source="MLIST">[oss-security] 20090203 Re: CVE Request - php (PHP BZ#27421)</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2009/01/30/1" source="MLIST">[oss-security] 20090130 CVE Request - php (PHP BZ#27421)</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1789" source="DEBIAN">DSA-1789</ref>
      <ref url="http://secunia.com/advisories/35306" source="SECUNIA">35306</ref>
      <ref url="http://secunia.com/advisories/35007" source="SECUNIA">35007</ref>
      <ref url="http://secunia.com/advisories/35003" source="SECUNIA">35003</ref>
      <ref url="http://secunia.com/advisories/34830" source="SECUNIA">34830</ref>
      <ref url="http://secunia.com/advisories/34642" source="SECUNIA">34642</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11035" source="OVAL">oval:org.mitre.oval:def:11035</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-04/msg00003.html" source="SUSE">SUSE-SR:2009:008</ref>
      <ref url="http://bugs.php.net/bug.php?id=27421" source="CONFIRM" adv="1">http://bugs.php.net/bug.php?id=27421</ref>
    </refs>
    <vuln_soft>
      <prod vendor="php" name="php">
        <vers num="4.4.4" />
        <vers num="5.1.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0755" published="2009-03-03" name="CVE-2009-0755" modified="2009-12-19" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The FormWidgetChoice::loadDefaults function in Poppler before 0.10.4 allows remote attackers to cause a denial of service (crash) via a PDF file with an invalid Form Opt entry.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.ubuntu.com/usn/USN-850-1" source="UBUNTU">USN-850-1</ref>
      <ref url="http://www.securityfocus.com/bid/33749" source="BID">33749</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/502761/100/0/threaded" source="BUGTRAQ">20090417 rPSA-2009-0059-1 poppler</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2009/02/19/2" source="MLIST">[oss-security] 20090219 Re: CVE Request: Poppler -Two Denial of Service Vulnerabilities</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2009/02/13/1" source="MLIST">[oss-security] 20090213 CVE Request: Poppler -Two Denial of Service Vulnerabilities</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1941" source="DEBIAN">DSA-1941</ref>
      <ref url="http://wiki.rpath.com/Advisories:rPSA-2009-0059" source="CONFIRM">http://wiki.rpath.com/Advisories:rPSA-2009-0059</ref>
      <ref url="http://secunia.com/advisories/37114" source="SECUNIA">37114</ref>
      <ref url="http://secunia.com/advisories/35685" source="SECUNIA">35685</ref>
      <ref url="http://secunia.com/advisories/33853" source="SECUNIA" adv="1">33853</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-07/msg00002.html" source="SUSE">SUSE-SR:2009:012</ref>
      <ref url="http://lists.freedesktop.org/archives/poppler/2009-January/004406.html" source="MLIST">[poppler] 20090128 poppler/Form.cc</ref>
      <ref url="http://bugs.freedesktop.org/show_bug.cgi?id=19790" source="CONFIRM">http://bugs.freedesktop.org/show_bug.cgi?id=19790</ref>
    </refs>
    <vuln_soft>
      <prod vendor="poppler" name="poppler">
        <vers num="0.1" />
        <vers num="0.1.1" />
        <vers num="0.1.2" />
        <vers num="0.10.1" />
        <vers num="0.10.2" />
        <vers prev="1" num="0.10.3" />
        <vers num="0.2.0" />
        <vers num="0.3.0" />
        <vers num="0.3.1" />
        <vers num="0.3.2" />
        <vers num="0.3.3" />
        <vers num="0.4.0" />
        <vers num="0.4.1" />
        <vers num="0.4.2" />
        <vers num="0.4.3" />
        <vers num="0.4.4" />
        <vers num="0.5.0" />
        <vers num="0.5.1" />
        <vers num="0.5.2" />
        <vers num="0.5.3" />
        <vers num="0.5.4" />
        <vers num="0.5.9" />
        <vers num="0.5.90" />
        <vers num="0.5.91" />
        <vers num="0.6.0" />
        <vers num="0.6.1" />
        <vers num="0.6.2" />
        <vers num="0.6.3" />
        <vers num="0.6.4" />
        <vers num="0.7.0" />
        <vers num="0.7.1" />
        <vers num="0.7.2" />
        <vers num="0.7.3" />
        <vers num="0.8.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0756" published="2009-03-03" name="CVE-2009-0756" modified="2009-07-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The JBIG2Stream::readSymbolDictSeg function in Poppler before 0.10.4 allows remote attackers to cause a denial of service (crash) via a PDF file that triggers a parsing error, which is not properly handled by JBIG2SymbolDict::~JBIG2SymbolDict and triggers an invalid memory dereference.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/33749" source="BID">33749</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/502761/100/0/threaded" source="BUGTRAQ">20090417 rPSA-2009-0059-1 poppler</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2009/02/19/2" source="MLIST">[oss-security] 20090219 Re: CVE Request: Poppler -Two Denial of Service Vulnerabilities</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2009/02/13/1" source="MLIST">[oss-security] 20090213 CVE Request: Poppler -Two Denial of Service Vulnerabilities</ref>
      <ref url="http://wiki.rpath.com/Advisories:rPSA-2009-0059" source="CONFIRM">http://wiki.rpath.com/Advisories:rPSA-2009-0059</ref>
      <ref url="http://secunia.com/advisories/35685" source="SECUNIA">35685</ref>
      <ref url="http://secunia.com/advisories/33853" source="SECUNIA" adv="1">33853</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-07/msg00002.html" source="SUSE">SUSE-SR:2009:012</ref>
      <ref url="http://lists.freedesktop.org/archives/poppler/2009-January/004403.html" source="MLIST">[poppler] 20090123 poppler/JBIG2Stream.cc</ref>
      <ref url="http://bugs.freedesktop.org/show_bug.cgi?id=19702" source="CONFIRM">http://bugs.freedesktop.org/show_bug.cgi?id=19702</ref>
    </refs>
    <vuln_soft>
      <prod vendor="poppler" name="poppler">
        <vers num="0.1" />
        <vers num="0.1.1" />
        <vers num="0.1.2" />
        <vers num="0.10.1" />
        <vers num="0.10.2" />
        <vers prev="1" num="0.10.3" />
        <vers num="0.2.0" />
        <vers num="0.3.0" />
        <vers num="0.3.1" />
        <vers num="0.3.2" />
        <vers num="0.3.3" />
        <vers num="0.4.0" />
        <vers num="0.4.1" />
        <vers num="0.4.2" />
        <vers num="0.4.3" />
        <vers num="0.4.4" />
        <vers num="0.5.0" />
        <vers num="0.5.1" />
        <vers num="0.5.2" />
        <vers num="0.5.3" />
        <vers num="0.5.4" />
        <vers num="0.5.9" />
        <vers num="0.5.90" />
        <vers num="0.5.91" />
        <vers num="0.6.0" />
        <vers num="0.6.1" />
        <vers num="0.6.2" />
        <vers num="0.6.3" />
        <vers num="0.6.4" />
        <vers num="0.7.0" />
        <vers num="0.7.1" />
        <vers num="0.7.2" />
        <vers num="0.7.3" />
        <vers num="0.8.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0757" published="2009-03-03" name="CVE-2009-0757" modified="2009-05-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple buffer overflows in GNU MPFR 2.4.0 allow context-dependent attackers to cause a denial of service (crash) via the (1) mpfr_snprintf and (2) mpfr_vsnprintf functions.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.openwall.com/lists/oss-security/2009/03/02/4" source="MLIST" patch="1">[oss-security] 20090302 CVE Request: mpfr (Buffer Overflow)</ref>
      <ref url="http://mpfr.loria.fr/mpfr-2.4.1/" source="CONFIRM" patch="1" adv="1">http://mpfr.loria.fr/mpfr-2.4.1/</ref>
      <ref url="http://www.ubuntu.com/usn/USN-772-1" source="UBUNTU">USN-772-1</ref>
      <ref url="http://www.securityfocus.com/bid/33945" source="BID">33945</ref>
      <ref url="http://secunia.com/advisories/35028" source="SECUNIA">35028</ref>
      <ref url="http://secunia.com/advisories/34204" source="SECUNIA">34204</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mpfr" name="gnu_mpfr">
        <vers num="2.4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0758" published="2009-03-03" name="CVE-2009-0758" modified="2010-08-12" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">The originates_from_local_legacy_unicast_socket function in avahi-core/server.c in avahi-daemon 0.6.23 does not account for the network byte order of a port number when processing incoming multicast packets, which allows remote attackers to cause a denial of service (network bandwidth and CPU consumption) via a crafted legacy unicast mDNS query packet that triggers a multicast packet storm.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/33946" source="BID">33946</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2009/03/02/1" source="MLIST">[oss-security] 20090302 CVE id request: avahi</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:076" source="MANDRIVA">MDVSA-2009:076</ref>
      <ref url="http://www.debian.org/security/2010/dsa-2086" source="DEBIAN">DSA-2086</ref>
      <ref url="http://secunia.com/advisories/38420" source="SECUNIA">38420</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-02/msg00000.html" source="SUSE">SUSE-SR:2010:002</ref>
      <ref url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=517683" source="MISC">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=517683</ref>
    </refs>
    <vuln_soft>
      <prod vendor="avahi" name="avahi-daemon">
        <vers num="0.6.23" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0759" published="2009-03-03" name="CVE-2009-0759" modified="2009-06-09" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)" CVSS_score="6.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.0" CVSS_base_score="6.5">
    <desc>
      <descript source="cve">Multiple CRLF injection vulnerabilities in webadmin in ZNC before 0.066 allow remote authenticated users to modify the znc.conf configuration file and gain privileges via CRLF sequences in the quit message and other vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://znc.svn.sourceforge.net/viewvc/znc?view=rev&amp;sortby=rev&amp;sortdir=down&amp;revision=1396" source="CONFIRM" adv="1">http://znc.svn.sourceforge.net/viewvc/znc?view=rev&amp;sortby=rev&amp;sortdir=down&amp;revision=1396</ref>
      <ref url="http://znc.svn.sourceforge.net/viewvc/znc?view=rev&amp;sortby=rev&amp;sortdir=down&amp;revision=1395" source="CONFIRM" adv="1">http://znc.svn.sourceforge.net/viewvc/znc?view=rev&amp;sortby=rev&amp;sortdir=down&amp;revision=1395</ref>
      <ref url="http://znc.svn.sourceforge.net/viewvc/znc/trunk/modules/webadmin.cpp?view=log&amp;sortby=rev&amp;sortdir=down&amp;pathrev=1395" source="CONFIRM" adv="1">http://znc.svn.sourceforge.net/viewvc/znc/trunk/modules/webadmin.cpp?view=log&amp;sortby=rev&amp;sortdir=down&amp;pathrev=1395</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2009/03/01/2" source="MLIST">[oss-security] 20090301 CVE id request: znc</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1735" source="DEBIAN">DSA-1735</ref>
      <ref url="http://secunia.com/advisories/34230" source="SECUNIA">34230</ref>
      <ref url="http://osvdb.org/52295" source="OSVDB">52295</ref>
    </refs>
    <vuln_soft>
      <prod vendor="znc" name="znc">
        <vers num="0.056" />
        <vers num="0.058" />
        <vers prev="1" num="0.062" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0760" published="2009-03-06" name="CVE-2009-0760" modified="2009-07-22" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Team Board 1.x and 2.x stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing credentials via a direct request for data/team.mdb.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.osvdb.org/51752" source="OSVDB">51752</ref>
      <ref url="http://www.milw0rm.com/exploits/7982" source="MILW0RM">7982</ref>
      <ref url="http://secunia.com/advisories/33839" source="SECUNIA" adv="1">33839</ref>
      <ref url="http://packetstorm.linuxsecurity.com/0902-exploits/teamboard-ddxss.txt" source="MISC">http://packetstorm.linuxsecurity.com/0902-exploits/teamboard-ddxss.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="team5" name="team_board">
        <vers num="1.0.0" />
        <vers num="2.0.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0761" published="2009-03-06" name="CVE-2009-0761" modified="2009-03-06" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in online.asp in Team Board 1.x allows remote attackers to inject arbitrary web script or HTML via the lookname parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/33614" source="BID">33614</ref>
      <ref url="http://www.milw0rm.com/exploits/7982" source="MILW0RM">7982</ref>
    </refs>
    <vuln_soft>
      <prod vendor="team5.team_board" name="1.0">
        <vers num="" />
      </prod>
      <prod vendor="team5.team_board" name="1.0.1">
        <vers num="" />
      </prod>
      <prod vendor="team5.team_board" name="1.0.2">
        <vers num="" />
      </prod>
      <prod vendor="team5.team_board" name="1.0.3">
        <vers num="" />
      </prod>
      <prod vendor="team5.team_board" name="1.0.4">
        <vers num="" />
      </prod>
      <prod vendor="team5.team_board" name="1.0.5">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0762" published="2009-03-06" name="CVE-2009-0762" modified="2009-03-06" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in ScriptsEz Ez PHP Comment allows remote attackers to inject arbitrary web script or HTML via the name parameter.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/33587" source="BID">33587</ref>
      <ref url="http://secunia.com/advisories/33804" source="SECUNIA" adv="1">33804</ref>
      <ref url="http://osvdb.org/51738" source="OSVDB">51738</ref>
    </refs>
    <vuln_soft>
      <prod vendor="scriptsez" name="ez_php_comment">
        <vers num="-" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0763" published="2009-03-06" name="CVE-2009-0763" modified="2009-06-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in default.php in Kipper 2.01 allows remote attackers to inject arbitrary web script or HTML via the charm parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/33640" source="BID">33640</ref>
      <ref url="http://www.milw0rm.com/exploits/7993" source="MILW0RM">7993</ref>
      <ref url="http://secunia.com/advisories/33832" source="SECUNIA" adv="1">33832</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bookelves" name="kipper">
        <vers num="2.01" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0764" published="2009-03-06" name="CVE-2009-0764" modified="2009-06-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Kipper 2.01 allow remote attackers to inject arbitrary web script or HTML via the charm parameter to (1) index.php and (2) kipper.php.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/33832" source="SECUNIA" adv="1">33832</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bookelves" name="kipper">
        <vers num="2.01" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0765" published="2009-03-06" name="CVE-2009-0765" modified="2009-03-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Directory traversal vulnerability in index.php in Kipper 2.01 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the configfile parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/49271" source="XF">kipper-index-file-include(49271)</ref>
      <ref url="http://www.securityfocus.com/bid/33640" source="BID">33640</ref>
      <ref url="http://www.milw0rm.com/exploits/7993" source="MILW0RM">7993</ref>
      <ref url="http://secunia.com/advisories/33832" source="SECUNIA" adv="1">33832</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bookelves" name="kipper">
        <vers num="2.01" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0766" published="2009-03-06" name="CVE-2009-0766" modified="2009-03-06" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Directory traversal vulnerability in default.php in Kipper 2.01 allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the configfile parameter.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/33832" source="SECUNIA" adv="1">33832</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bookelves" name="kipper">
        <vers num="2.01" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0767" published="2009-03-06" name="CVE-2009-0767" modified="2009-03-06" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Kipper 2.01 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a file containing credentials via a direct request for job/config.data.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.milw0rm.com/exploits/7993" source="MILW0RM">7993</ref>
      <ref url="http://secunia.com/advisories/33832" source="SECUNIA" adv="1">33832</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bookelves" name="kipper">
        <vers num="2.01" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0768" published="2009-03-06" name="CVE-2009-0768" modified="2009-06-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in forumhop.php in YapBB 1.2 and earlier allows remote attackers to execute arbitrary SQL commands via the forumID parameter in a next action.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/33620" source="BID">33620</ref>
      <ref url="http://www.milw0rm.com/exploits/7984" source="MILW0RM">7984</ref>
    </refs>
    <vuln_soft>
      <prod vendor="yapbb" name="yapbb">
        <vers num="1.1" />
        <vers prev="1" num="1.2" edition="beta2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0769" published="2009-03-06" name="CVE-2009-0769" modified="2009-03-06" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">QIP 2005 build 8082 allows remote attackers to cause a denial of service (CPU consumption and application hang) via a crafted Rich Text Format (RTF) ICQ message, as demonstrated by an {\rtf\pict\&amp;&amp;} message.  NOTE: the vulnerability may be in Sergey Tkachenko TRichView. If so, then this should not be treated as a vulnerability in QIP.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/33609" source="BID">33609</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/500656/100/0/threaded" source="BUGTRAQ">20090204 QIP 2005 Denial of Service Vulnerability</ref>
      <ref url="http://www.osvdb.org/51755" source="OSVDB">51755</ref>
      <ref url="http://secunia.com/advisories/33851" source="SECUNIA" adv="1">33851</ref>
    </refs>
    <vuln_soft>
      <prod vendor="qip" name="qip">
        <vers num="2005" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0770" published="2009-03-06" name="CVE-2009-0770" modified="2009-06-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">dkim-milter 2.6.0 through 2.8.0 allows remote attackers to cause a denial of service (crash) by signing a message with a key that has been revoked in DNS, which triggers an assertion error.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/33337" source="BID" patch="1">33337</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1728" source="DEBIAN" patch="1">DSA-1728</ref>
      <ref url="http://sourceforge.net/project/shownotes.php?release_id=654247" source="CONFIRM" patch="1">http://sourceforge.net/project/shownotes.php?release_id=654247</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/48085" source="XF">dkimmilter-p-dos(48085)</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2009/03/01/1" source="MLIST">[oss-security] 20090302 CVE id request: dkim-milter</ref>
      <ref url="http://sourceforge.net/tracker/index.php?func=detail&amp;aid=2508602&amp;group_id=139420&amp;atid=744358" source="CONFIRM">http://sourceforge.net/tracker/index.php?func=detail&amp;aid=2508602&amp;group_id=139420&amp;atid=744358</ref>
      <ref url="http://secunia.com/advisories/34053" source="SECUNIA" adv="1">34053</ref>
      <ref url="http://secunia.com/advisories/33581" source="SECUNIA" adv="1">33581</ref>
    </refs>
    <vuln_soft>
      <prod vendor="dkim" name="dkim-milter">
        <vers num="2.6.0" />
        <vers num="2.7.0" />
        <vers num="2.7.1" />
        <vers num="2.7.2" />
        <vers num="2.8.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0771" published="2009-03-04" name="CVE-2009-0771" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">The layout engine in Mozilla Firefox before 3.0.7, Thunderbird before 2.0.0.21, and SeaMonkey 1.1.15 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via certain vectors that trigger memory corruption and assertion failures.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-March/msg01077.html" source="FEDORA">FEDORA-2009-3101</ref>
      <ref url="https://bugzilla.mozilla.org/buglist.cgi?bug_id=424276,435209,436965,460706,466057,468578,471594,472502" source="CONFIRM">https://bugzilla.mozilla.org/buglist.cgi?bug_id=424276,435209,436965,460706,466057,468578,471594,472502</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0632" source="VUPEN">ADV-2009-0632</ref>
      <ref url="http://www.securitytracker.com/id?1021795" source="SECTRACK">1021795</ref>
      <ref url="http://www.securityfocus.com/bid/33990" source="BID">33990</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-0315.html" source="REDHAT">RHSA-2009:0315</ref>
      <ref url="http://www.mozilla.org/security/announce/2009/mfsa2009-07.html" source="CONFIRM">http://www.mozilla.org/security/announce/2009/mfsa2009-07.html</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:083" source="MANDRIVA">MDVSA-2009:083</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:075" source="MANDRIVA">MDVSA-2009:075</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1830" source="DEBIAN">DSA-1830</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1751" source="DEBIAN">DSA-1751</ref>
      <ref url="http://support.avaya.com/japple/css/japple?temp.documentID=366362&amp;temp.productID=154235&amp;temp.releaseID=361845&amp;temp.bucketID=126655&amp;PAGE=Document" source="CONFIRM">http://support.avaya.com/japple/css/japple?temp.documentID=366362&amp;temp.productID=154235&amp;temp.releaseID=361845&amp;temp.bucketID=126655&amp;PAGE=Document</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2009-069.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2009-069.htm</ref>
      <ref url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2009&amp;m=slackware-security.433952" source="SLACKWARE">SSA:2009-083-03</ref>
      <ref url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2009&amp;m=slackware-security.405420" source="SLACKWARE">SSA:2009-083-02</ref>
      <ref url="http://secunia.com/advisories/34527" source="SECUNIA">34527</ref>
      <ref url="http://secunia.com/advisories/34464" source="SECUNIA">34464</ref>
      <ref url="http://secunia.com/advisories/34462" source="SECUNIA">34462</ref>
      <ref url="http://secunia.com/advisories/34383" source="SECUNIA">34383</ref>
      <ref url="http://secunia.com/advisories/34272" source="SECUNIA">34272</ref>
      <ref url="http://secunia.com/advisories/34145" source="SECUNIA">34145</ref>
      <ref url="http://secunia.com/advisories/34140" source="SECUNIA">34140</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6755" source="OVAL">oval:org.mitre.oval:def:6755</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6196" source="OVAL">oval:org.mitre.oval:def:6196</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6163" source="OVAL">oval:org.mitre.oval:def:6163</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5250" source="OVAL">oval:org.mitre.oval:def:5250</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11314" source="OVAL">oval:org.mitre.oval:def:11314</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-03/msg00002.html" source="SUSE">SUSE-SA:2009:012</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="1.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.5" />
        <vers num="1.0.6" />
        <vers num="1.0.7" />
        <vers num="1.0.8" />
        <vers num="1.5" />
        <vers num="1.5.0.1" />
        <vers num="1.5.0.10" />
        <vers num="1.5.0.11" />
        <vers num="1.5.0.12" />
        <vers num="1.5.0.2" />
        <vers num="1.5.0.3" />
        <vers num="1.5.0.4" />
        <vers num="1.5.0.5" />
        <vers num="1.5.0.6" />
        <vers num="1.5.0.7" />
        <vers num="1.5.0.8" />
        <vers num="1.5.0.9" />
        <vers num="2.0" />
        <vers num="2.0.0.1" />
        <vers num="2.0.0.10" />
        <vers num="2.0.0.11" />
        <vers num="2.0.0.12" />
        <vers num="2.0.0.13" />
        <vers num="2.0.0.14" />
        <vers num="2.0.0.15" />
        <vers num="2.0.0.16" />
        <vers num="2.0.0.17" />
        <vers num="2.0.0.18" />
        <vers num="2.0.0.19" />
        <vers num="2.0.0.2" />
        <vers num="2.0.0.20" />
        <vers num="2.0.0.3" />
        <vers num="2.0.0.4" />
        <vers num="2.0.0.5" />
        <vers num="2.0.0.6" />
        <vers num="2.0.0.7" />
        <vers num="2.0.0.8" />
        <vers num="2.0.0.9" />
        <vers num="3.0" />
        <vers num="3.0.1" />
        <vers num="3.0.2" />
        <vers num="3.0.3" />
        <vers num="3.0.4" />
        <vers num="3.0.5" />
        <vers prev="1" num="3.0.6" />
      </prod>
      <prod vendor="mozilla" name="seamonkey">
        <vers num="1.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.5" />
        <vers num="1.0.6" />
        <vers num="1.0.7" />
        <vers num="1.0.8" />
        <vers num="1.0.9" />
        <vers num="1.1" edition="alpha" />
        <vers num="1.1" edition="beta" />
        <vers num="1.1.1" />
        <vers num="1.1.10" />
        <vers num="1.1.11" />
        <vers num="1.1.12" />
        <vers num="1.1.13" />
        <vers prev="1" num="1.1.14" />
        <vers num="1.1.2" />
        <vers num="1.1.3" />
        <vers num="1.1.4" />
        <vers num="1.1.5" />
        <vers num="1.1.6" />
        <vers num="1.1.7" />
        <vers num="1.1.8" />
        <vers num="1.1.9" />
      </prod>
      <prod vendor="mozilla" name="thunderbird">
        <vers num="2.0.0.0" />
        <vers num="2.0.0.12" />
        <vers num="2.0.0.14" />
        <vers num="2.0.0.16" />
        <vers num="2.0.0.17" />
        <vers num="2.0.0.18" />
        <vers num="2.0.0.19" />
        <vers prev="1" num="2.0.0.20" />
        <vers num="2.0.0.4" />
        <vers num="2.0.0.5" />
        <vers num="2.0.0.6" />
        <vers num="2.0.0.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0772" published="2009-03-04" name="CVE-2009-0772" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">The layout engine in Mozilla Firefox 2 and 3 before 3.0.7, Thunderbird before 2.0.0.21, and SeaMonkey 1.1.15 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via vectors related to nsCSSStyleSheet::GetOwnerNode, events, and garbage collection, which triggers memory corruption.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-March/msg01077.html" source="FEDORA">FEDORA-2009-3101</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-March/msg00771.html" source="FEDORA">FEDORA-2009-2884</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-March/msg00769.html" source="FEDORA">FEDORA-2009-2882</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=475136" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=475136</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0632" source="VUPEN">ADV-2009-0632</ref>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-741-1" source="UBUNTU">USN-741-1</ref>
      <ref url="http://www.securitytracker.com/id?1021795" source="SECTRACK">1021795</ref>
      <ref url="http://www.securityfocus.com/bid/33990" source="BID">33990</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-0325.html" source="REDHAT">RHSA-2009:0325</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-0315.html" source="REDHAT">RHSA-2009:0315</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-0258.html" source="REDHAT">RHSA-2009:0258</ref>
      <ref url="http://www.mozilla.org/security/announce/2009/mfsa2009-07.html" source="CONFIRM" adv="1">http://www.mozilla.org/security/announce/2009/mfsa2009-07.html</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:083" source="MANDRIVA">MDVSA-2009:083</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:075" source="MANDRIVA">MDVSA-2009:075</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1830" source="DEBIAN">DSA-1830</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1751" source="DEBIAN">DSA-1751</ref>
      <ref url="http://support.avaya.com/japple/css/japple?temp.documentID=366362&amp;temp.productID=154235&amp;temp.releaseID=361845&amp;temp.bucketID=126655&amp;PAGE=Document" source="CONFIRM">http://support.avaya.com/japple/css/japple?temp.documentID=366362&amp;temp.productID=154235&amp;temp.releaseID=361845&amp;temp.bucketID=126655&amp;PAGE=Document</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2009-069.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2009-069.htm</ref>
      <ref url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2009&amp;m=slackware-security.433952" source="SLACKWARE">SSA:2009-083-03</ref>
      <ref url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2009&amp;m=slackware-security.405420" source="SLACKWARE">SSA:2009-083-02</ref>
      <ref url="http://secunia.com/advisories/34527" source="SECUNIA">34527</ref>
      <ref url="http://secunia.com/advisories/34464" source="SECUNIA">34464</ref>
      <ref url="http://secunia.com/advisories/34462" source="SECUNIA">34462</ref>
      <ref url="http://secunia.com/advisories/34417" source="SECUNIA">34417</ref>
      <ref url="http://secunia.com/advisories/34387" source="SECUNIA">34387</ref>
      <ref url="http://secunia.com/advisories/34383" source="SECUNIA">34383</ref>
      <ref url="http://secunia.com/advisories/34324" source="SECUNIA">34324</ref>
      <ref url="http://secunia.com/advisories/34272" source="SECUNIA">34272</ref>
      <ref url="http://secunia.com/advisories/34145" source="SECUNIA">34145</ref>
      <ref url="http://secunia.com/advisories/34140" source="SECUNIA">34140</ref>
      <ref url="http://secunia.com/advisories/34137" source="SECUNIA">34137</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9609" source="OVAL">oval:org.mitre.oval:def:9609</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6811" source="OVAL">oval:org.mitre.oval:def:6811</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6097" source="OVAL">oval:org.mitre.oval:def:6097</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5945" source="OVAL">oval:org.mitre.oval:def:5945</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5703" source="OVAL">oval:org.mitre.oval:def:5703</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-04/msg00009.html" source="SUSE">SUSE-SA:2009:023</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-03/msg00002.html" source="SUSE">SUSE-SA:2009:012</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="1.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.5" />
        <vers num="1.0.6" />
        <vers num="1.0.7" />
        <vers num="1.0.8" />
        <vers num="1.5" />
        <vers num="1.5.0.1" />
        <vers num="1.5.0.10" />
        <vers num="1.5.0.11" />
        <vers num="1.5.0.12" />
        <vers num="1.5.0.2" />
        <vers num="1.5.0.3" />
        <vers num="1.5.0.4" />
        <vers num="1.5.0.5" />
        <vers num="1.5.0.6" />
        <vers num="1.5.0.7" />
        <vers num="1.5.0.8" />
        <vers num="1.5.0.9" />
        <vers num="2.0" />
        <vers num="2.0.0.1" />
        <vers num="2.0.0.10" />
        <vers num="2.0.0.11" />
        <vers num="2.0.0.12" />
        <vers num="2.0.0.13" />
        <vers num="2.0.0.14" />
        <vers num="2.0.0.15" />
        <vers num="2.0.0.16" />
        <vers num="2.0.0.17" />
        <vers num="2.0.0.18" />
        <vers num="2.0.0.19" />
        <vers num="2.0.0.2" />
        <vers num="2.0.0.20" />
        <vers num="2.0.0.3" />
        <vers num="2.0.0.4" />
        <vers num="2.0.0.5" />
        <vers num="2.0.0.6" />
        <vers num="2.0.0.7" />
        <vers num="2.0.0.8" />
        <vers num="2.0.0.9" />
        <vers num="3.0" />
        <vers num="3.0.1" />
        <vers num="3.0.2" />
        <vers num="3.0.3" />
        <vers num="3.0.4" />
        <vers num="3.0.5" />
        <vers prev="1" num="3.0.6" />
      </prod>
      <prod vendor="mozilla" name="seamonkey">
        <vers num="1.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.5" />
        <vers num="1.0.6" />
        <vers num="1.0.7" />
        <vers num="1.0.8" />
        <vers num="1.0.9" />
        <vers num="1.1" edition="alpha" />
        <vers num="1.1" edition="beta" />
        <vers num="1.1.1" />
        <vers num="1.1.10" />
        <vers num="1.1.11" />
        <vers num="1.1.12" />
        <vers num="1.1.13" />
        <vers prev="1" num="1.1.14" />
        <vers num="1.1.2" />
        <vers num="1.1.3" />
        <vers num="1.1.4" />
        <vers num="1.1.5" />
        <vers num="1.1.6" />
        <vers num="1.1.7" />
        <vers num="1.1.8" />
        <vers num="1.1.9" />
      </prod>
      <prod vendor="mozilla" name="thunderbird">
        <vers num="2.0.0.0" />
        <vers num="2.0.0.12" />
        <vers num="2.0.0.14" />
        <vers num="2.0.0.16" />
        <vers num="2.0.0.17" />
        <vers num="2.0.0.18" />
        <vers num="2.0.0.19" />
        <vers prev="1" num="2.0.0.20" />
        <vers num="2.0.0.4" />
        <vers num="2.0.0.5" />
        <vers num="2.0.0.6" />
        <vers num="2.0.0.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0773" published="2009-03-04" name="CVE-2009-0773" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">The JavaScript engine in Mozilla Firefox before 3.0.7, Thunderbird before 2.0.0.21, and SeaMonkey 1.1.15 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via (1) a splice of an array that contains "some non-set elements," which causes jsarray.cpp to pass an incorrect argument to the ResizeSlots function, which triggers memory corruption; (2) vectors related to js_DecompileValueGenerator, jsopcode.cpp, __defineSetter__, and watch, which triggers an assertion failure or a segmentation fault; and (3) vectors related to gczeal, __defineSetter__, and watch, which triggers a hang.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=472787" source="CONFIRM" patch="1">https://bugzilla.mozilla.org/show_bug.cgi?id=472787</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-March/msg01077.html" source="FEDORA">FEDORA-2009-3101</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=467499" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=467499</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=457521" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=457521</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0632" source="VUPEN">ADV-2009-0632</ref>
      <ref url="http://www.securitytracker.com/id?1021795" source="SECTRACK">1021795</ref>
      <ref url="http://www.securityfocus.com/bid/33990" source="BID">33990</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-0315.html" source="REDHAT">RHSA-2009:0315</ref>
      <ref url="http://www.mozilla.org/security/announce/2009/mfsa2009-07.html" source="CONFIRM" adv="1">http://www.mozilla.org/security/announce/2009/mfsa2009-07.html</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:083" source="MANDRIVA">MDVSA-2009:083</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:075" source="MANDRIVA">MDVSA-2009:075</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1830" source="DEBIAN">DSA-1830</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1751" source="DEBIAN">DSA-1751</ref>
      <ref url="http://support.avaya.com/japple/css/japple?temp.documentID=366362&amp;temp.productID=154235&amp;temp.releaseID=361845&amp;temp.bucketID=126655&amp;PAGE=Document" source="CONFIRM">http://support.avaya.com/japple/css/japple?temp.documentID=366362&amp;temp.productID=154235&amp;temp.releaseID=361845&amp;temp.bucketID=126655&amp;PAGE=Document</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2009-069.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2009-069.htm</ref>
      <ref url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2009&amp;m=slackware-security.433952" source="SLACKWARE">SSA:2009-083-03</ref>
      <ref url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2009&amp;m=slackware-security.405420" source="SLACKWARE">SSA:2009-083-02</ref>
      <ref url="http://secunia.com/advisories/34527" source="SECUNIA">34527</ref>
      <ref url="http://secunia.com/advisories/34464" source="SECUNIA">34464</ref>
      <ref url="http://secunia.com/advisories/34462" source="SECUNIA">34462</ref>
      <ref url="http://secunia.com/advisories/34383" source="SECUNIA">34383</ref>
      <ref url="http://secunia.com/advisories/34272" source="SECUNIA">34272</ref>
      <ref url="http://secunia.com/advisories/34145" source="SECUNIA">34145</ref>
      <ref url="http://secunia.com/advisories/34140" source="SECUNIA">34140</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6708" source="OVAL">oval:org.mitre.oval:def:6708</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6141" source="OVAL">oval:org.mitre.oval:def:6141</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5980" source="OVAL">oval:org.mitre.oval:def:5980</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5856" source="OVAL">oval:org.mitre.oval:def:5856</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10491" source="OVAL">oval:org.mitre.oval:def:10491</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-03/msg00002.html" source="SUSE">SUSE-SA:2009:012</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="1.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.5" />
        <vers num="1.0.6" />
        <vers num="1.0.7" />
        <vers num="1.0.8" />
        <vers num="1.5" />
        <vers num="1.5.0.1" />
        <vers num="1.5.0.10" />
        <vers num="1.5.0.11" />
        <vers num="1.5.0.12" />
        <vers num="1.5.0.2" />
        <vers num="1.5.0.3" />
        <vers num="1.5.0.4" />
        <vers num="1.5.0.5" />
        <vers num="1.5.0.6" />
        <vers num="1.5.0.7" />
        <vers num="1.5.0.8" />
        <vers num="1.5.0.9" />
        <vers num="2.0" />
        <vers num="2.0.0.1" />
        <vers num="2.0.0.10" />
        <vers num="2.0.0.11" />
        <vers num="2.0.0.12" />
        <vers num="2.0.0.13" />
        <vers num="2.0.0.14" />
        <vers num="2.0.0.15" />
        <vers num="2.0.0.16" />
        <vers num="2.0.0.17" />
        <vers num="2.0.0.18" />
        <vers num="2.0.0.19" />
        <vers num="2.0.0.2" />
        <vers num="2.0.0.20" />
        <vers num="2.0.0.3" />
        <vers num="2.0.0.4" />
        <vers num="2.0.0.5" />
        <vers num="2.0.0.6" />
        <vers num="2.0.0.7" />
        <vers num="2.0.0.8" />
        <vers num="2.0.0.9" />
        <vers num="3.0" />
        <vers num="3.0.1" />
        <vers num="3.0.2" />
        <vers num="3.0.3" />
        <vers num="3.0.4" />
        <vers num="3.0.5" />
        <vers prev="1" num="3.0.6" />
      </prod>
      <prod vendor="mozilla" name="seamonkey">
        <vers num="1.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.5" />
        <vers num="1.0.6" />
        <vers num="1.0.7" />
        <vers num="1.0.8" />
        <vers num="1.0.9" />
        <vers num="1.1" edition="alpha" />
        <vers num="1.1" edition="beta" />
        <vers num="1.1.1" />
        <vers num="1.1.10" />
        <vers num="1.1.11" />
        <vers num="1.1.12" />
        <vers num="1.1.13" />
        <vers prev="1" num="1.1.14" />
        <vers num="1.1.2" />
        <vers num="1.1.3" />
        <vers num="1.1.4" />
        <vers num="1.1.5" />
        <vers num="1.1.6" />
        <vers num="1.1.7" />
        <vers num="1.1.8" />
        <vers num="1.1.9" />
      </prod>
      <prod vendor="mozilla" name="thunderbird">
        <vers num="2.0.0.0" />
        <vers num="2.0.0.12" />
        <vers num="2.0.0.14" />
        <vers num="2.0.0.16" />
        <vers num="2.0.0.17" />
        <vers num="2.0.0.18" />
        <vers num="2.0.0.19" />
        <vers prev="1" num="2.0.0.20" />
        <vers num="2.0.0.4" />
        <vers num="2.0.0.5" />
        <vers num="2.0.0.6" />
        <vers num="2.0.0.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0774" published="2009-03-04" name="CVE-2009-0774" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">The layout engine in Mozilla Firefox 2 and 3 before 3.0.7, Thunderbird before 2.0.0.21, and SeaMonkey 1.1.15 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via vectors related to gczeal, a different vulnerability than CVE-2009-0773.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-March/msg01077.html" source="FEDORA">FEDORA-2009-3101</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-March/msg00771.html" source="FEDORA">FEDORA-2009-2884</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-March/msg00769.html" source="FEDORA">FEDORA-2009-2882</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=473709" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=473709</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0632" source="VUPEN">ADV-2009-0632</ref>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-741-1" source="UBUNTU">USN-741-1</ref>
      <ref url="http://www.securitytracker.com/id?1021795" source="SECTRACK">1021795</ref>
      <ref url="http://www.securityfocus.com/bid/33990" source="BID">33990</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-0325.html" source="REDHAT">RHSA-2009:0325</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-0315.html" source="REDHAT">RHSA-2009:0315</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-0258.html" source="REDHAT">RHSA-2009:0258</ref>
      <ref url="http://www.mozilla.org/security/announce/2009/mfsa2009-07.html" source="CONFIRM">http://www.mozilla.org/security/announce/2009/mfsa2009-07.html</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:083" source="MANDRIVA">MDVSA-2009:083</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:075" source="MANDRIVA">MDVSA-2009:075</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1830" source="DEBIAN">DSA-1830</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1751" source="DEBIAN">DSA-1751</ref>
      <ref url="http://support.avaya.com/japple/css/japple?temp.documentID=366362&amp;temp.productID=154235&amp;temp.releaseID=361845&amp;temp.bucketID=126655&amp;PAGE=Document" source="CONFIRM">http://support.avaya.com/japple/css/japple?temp.documentID=366362&amp;temp.productID=154235&amp;temp.releaseID=361845&amp;temp.bucketID=126655&amp;PAGE=Document</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2009-069.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2009-069.htm</ref>
      <ref url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2009&amp;m=slackware-security.433952" source="SLACKWARE">SSA:2009-083-03</ref>
      <ref url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2009&amp;m=slackware-security.405420" source="SLACKWARE">SSA:2009-083-02</ref>
      <ref url="http://secunia.com/advisories/34527" source="SECUNIA">34527</ref>
      <ref url="http://secunia.com/advisories/34464" source="SECUNIA">34464</ref>
      <ref url="http://secunia.com/advisories/34462" source="SECUNIA">34462</ref>
      <ref url="http://secunia.com/advisories/34417" source="SECUNIA">34417</ref>
      <ref url="http://secunia.com/advisories/34387" source="SECUNIA">34387</ref>
      <ref url="http://secunia.com/advisories/34383" source="SECUNIA">34383</ref>
      <ref url="http://secunia.com/advisories/34324" source="SECUNIA">34324</ref>
      <ref url="http://secunia.com/advisories/34272" source="SECUNIA">34272</ref>
      <ref url="http://secunia.com/advisories/34145" source="SECUNIA">34145</ref>
      <ref url="http://secunia.com/advisories/34140" source="SECUNIA">34140</ref>
      <ref url="http://secunia.com/advisories/34137" source="SECUNIA">34137</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6945" source="OVAL">oval:org.mitre.oval:def:6945</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6121" source="OVAL">oval:org.mitre.oval:def:6121</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6057" source="OVAL">oval:org.mitre.oval:def:6057</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5947" source="OVAL">oval:org.mitre.oval:def:5947</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11138" source="OVAL">oval:org.mitre.oval:def:11138</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-04/msg00009.html" source="SUSE">SUSE-SA:2009:023</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-03/msg00002.html" source="SUSE">SUSE-SA:2009:012</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="1.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.5" />
        <vers num="1.0.6" />
        <vers num="1.0.7" />
        <vers num="1.0.8" />
        <vers num="1.5" />
        <vers num="1.5.0.1" />
        <vers num="1.5.0.10" />
        <vers num="1.5.0.11" />
        <vers num="1.5.0.12" />
        <vers num="1.5.0.2" />
        <vers num="1.5.0.3" />
        <vers num="1.5.0.4" />
        <vers num="1.5.0.5" />
        <vers num="1.5.0.6" />
        <vers num="1.5.0.7" />
        <vers num="1.5.0.8" />
        <vers num="1.5.0.9" />
        <vers num="2.0" />
        <vers num="2.0.0.1" />
        <vers num="2.0.0.10" />
        <vers num="2.0.0.11" />
        <vers num="2.0.0.12" />
        <vers num="2.0.0.13" />
        <vers num="2.0.0.14" />
        <vers num="2.0.0.15" />
        <vers num="2.0.0.16" />
        <vers num="2.0.0.17" />
        <vers num="2.0.0.18" />
        <vers num="2.0.0.19" />
        <vers num="2.0.0.2" />
        <vers num="2.0.0.20" />
        <vers num="2.0.0.3" />
        <vers num="2.0.0.4" />
        <vers num="2.0.0.5" />
        <vers num="2.0.0.6" />
        <vers num="2.0.0.7" />
        <vers num="2.0.0.8" />
        <vers num="2.0.0.9" />
        <vers num="3.0" />
        <vers num="3.0.1" />
        <vers num="3.0.2" />
        <vers num="3.0.3" />
        <vers num="3.0.4" />
        <vers num="3.0.5" />
        <vers prev="1" num="3.0.6" />
      </prod>
      <prod vendor="mozilla" name="seamonkey">
        <vers num="1.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.5" />
        <vers num="1.0.6" />
        <vers num="1.0.7" />
        <vers num="1.0.8" />
        <vers num="1.0.9" />
        <vers num="1.1" edition="alpha" />
        <vers num="1.1" edition="beta" />
        <vers num="1.1.1" />
        <vers num="1.1.10" />
        <vers num="1.1.11" />
        <vers num="1.1.12" />
        <vers num="1.1.13" />
        <vers prev="1" num="1.1.14" />
        <vers num="1.1.2" />
        <vers num="1.1.3" />
        <vers num="1.1.4" />
        <vers num="1.1.5" />
        <vers num="1.1.6" />
        <vers num="1.1.7" />
        <vers num="1.1.8" />
        <vers num="1.1.9" />
      </prod>
      <prod vendor="mozilla" name="thunderbird">
        <vers num="2.0.0.0" />
        <vers num="2.0.0.12" />
        <vers num="2.0.0.14" />
        <vers num="2.0.0.16" />
        <vers num="2.0.0.17" />
        <vers num="2.0.0.18" />
        <vers num="2.0.0.19" />
        <vers prev="1" num="2.0.0.20" />
        <vers num="2.0.0.4" />
        <vers num="2.0.0.5" />
        <vers num="2.0.0.6" />
        <vers num="2.0.0.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0775" published="2009-03-04" name="CVE-2009-0775" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Double free vulnerability in Mozilla Firefox before 3.0.7, Thunderbird before 2.0.0.21, and SeaMonkey before 1.1.15 allows remote attackers to execute arbitrary code via "cloned XUL DOM elements which were linked as a parent and child," which are not properly handled during garbage collection.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-March/msg00771.html" source="FEDORA">FEDORA-2009-2884</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-March/msg00769.html" source="FEDORA">FEDORA-2009-2882</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=474456" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=474456</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0632" source="VUPEN">ADV-2009-0632</ref>
      <ref url="http://www.securitytracker.com/id?1021796" source="SECTRACK">1021796</ref>
      <ref url="http://www.securityfocus.com/bid/33990" source="BID">33990</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-0325.html" source="REDHAT">RHSA-2009:0325</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-0315.html" source="REDHAT">RHSA-2009:0315</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-0258.html" source="REDHAT">RHSA-2009:0258</ref>
      <ref url="http://www.mozilla.org/security/announce/2009/mfsa2009-08.html" source="CONFIRM">http://www.mozilla.org/security/announce/2009/mfsa2009-08.html</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:075" source="MANDRIVA">MDVSA-2009:075</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1751" source="DEBIAN">DSA-1751</ref>
      <ref url="http://support.avaya.com/japple/css/japple?temp.documentID=366362&amp;temp.productID=154235&amp;temp.releaseID=361845&amp;temp.bucketID=126655&amp;PAGE=Document" source="CONFIRM">http://support.avaya.com/japple/css/japple?temp.documentID=366362&amp;temp.productID=154235&amp;temp.releaseID=361845&amp;temp.bucketID=126655&amp;PAGE=Document</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2009-069.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2009-069.htm</ref>
      <ref url="http://secunia.com/advisories/34417" source="SECUNIA">34417</ref>
      <ref url="http://secunia.com/advisories/34383" source="SECUNIA">34383</ref>
      <ref url="http://secunia.com/advisories/34324" source="SECUNIA">34324</ref>
      <ref url="http://secunia.com/advisories/34272" source="SECUNIA">34272</ref>
      <ref url="http://secunia.com/advisories/34145" source="SECUNIA">34145</ref>
      <ref url="http://secunia.com/advisories/34140" source="SECUNIA">34140</ref>
      <ref url="http://secunia.com/advisories/34137" source="SECUNIA">34137</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9681" source="OVAL">oval:org.mitre.oval:def:9681</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7584" source="OVAL">oval:org.mitre.oval:def:7584</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6207" source="OVAL">oval:org.mitre.oval:def:6207</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5816" source="OVAL">oval:org.mitre.oval:def:5816</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5806" source="OVAL">oval:org.mitre.oval:def:5806</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-03/msg00002.html" source="SUSE">SUSE-SA:2009:012</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="1.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.5" />
        <vers num="1.0.6" />
        <vers num="1.0.7" />
        <vers num="1.0.8" />
        <vers num="1.5" />
        <vers num="1.5.0.1" />
        <vers num="1.5.0.10" />
        <vers num="1.5.0.11" />
        <vers num="1.5.0.12" />
        <vers num="1.5.0.2" />
        <vers num="1.5.0.3" />
        <vers num="1.5.0.4" />
        <vers num="1.5.0.5" />
        <vers num="1.5.0.6" />
        <vers num="1.5.0.7" />
        <vers num="1.5.0.8" />
        <vers num="1.5.0.9" />
        <vers num="2.0" />
        <vers num="2.0.0.1" />
        <vers num="2.0.0.10" />
        <vers num="2.0.0.11" />
        <vers num="2.0.0.12" />
        <vers num="2.0.0.13" />
        <vers num="2.0.0.14" />
        <vers num="2.0.0.15" />
        <vers num="2.0.0.16" />
        <vers num="2.0.0.17" />
        <vers num="2.0.0.18" />
        <vers num="2.0.0.19" />
        <vers num="2.0.0.2" />
        <vers num="2.0.0.20" />
        <vers num="2.0.0.3" />
        <vers num="2.0.0.4" />
        <vers num="2.0.0.5" />
        <vers num="2.0.0.6" />
        <vers num="2.0.0.7" />
        <vers num="2.0.0.8" />
        <vers num="2.0.0.9" />
        <vers num="3.0" />
        <vers num="3.0.1" />
        <vers num="3.0.2" />
        <vers num="3.0.3" />
        <vers num="3.0.4" />
        <vers num="3.0.5" />
        <vers prev="1" num="3.0.6" />
      </prod>
      <prod vendor="mozilla" name="seamonkey">
        <vers num="1.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.5" />
        <vers num="1.0.6" />
        <vers num="1.0.7" />
        <vers num="1.0.8" />
        <vers num="1.0.9" />
        <vers num="1.1" edition="alpha" />
        <vers num="1.1" edition="beta" />
        <vers num="1.1.1" />
        <vers num="1.1.10" />
        <vers num="1.1.11" />
        <vers num="1.1.12" />
        <vers num="1.1.13" />
        <vers prev="1" num="1.1.14" />
        <vers num="1.1.2" />
        <vers num="1.1.3" />
        <vers num="1.1.4" />
        <vers num="1.1.5" />
        <vers num="1.1.6" />
        <vers num="1.1.7" />
        <vers num="1.1.8" />
        <vers num="1.1.9" />
      </prod>
      <prod vendor="mozilla" name="thunderbird">
        <vers num="2.0.0.0" />
        <vers num="2.0.0.12" />
        <vers num="2.0.0.14" />
        <vers num="2.0.0.16" />
        <vers num="2.0.0.17" />
        <vers num="2.0.0.18" />
        <vers num="2.0.0.19" />
        <vers prev="1" num="2.0.0.20" />
        <vers num="2.0.0.4" />
        <vers num="2.0.0.5" />
        <vers num="2.0.0.6" />
        <vers num="2.0.0.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0776" published="2009-03-04" name="CVE-2009-0776" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:N/A:N)" CVSS_score="7.1" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="8.6" CVSS_base_score="7.1">
    <desc>
      <descript source="cve">nsIRDFService in Mozilla Firefox before 3.0.7, Thunderbird before 2.0.0.21, and SeaMonkey before 1.1.15 allows remote attackers to bypass the same-origin policy and read XML data from another domain via a cross-domain redirect.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-March/msg01077.html" source="FEDORA">FEDORA-2009-3101</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-March/msg00771.html" source="FEDORA">FEDORA-2009-2884</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-March/msg00769.html" source="FEDORA">FEDORA-2009-2882</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=414540" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=414540</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0632" source="VUPEN">ADV-2009-0632</ref>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-741-1" source="UBUNTU">USN-741-1</ref>
      <ref url="http://www.securitytracker.com/id?1021797" source="SECTRACK">1021797</ref>
      <ref url="http://www.securityfocus.com/bid/33990" source="BID">33990</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-0325.html" source="REDHAT">RHSA-2009:0325</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-0315.html" source="REDHAT">RHSA-2009:0315</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-0258.html" source="REDHAT">RHSA-2009:0258</ref>
      <ref url="http://www.mozilla.org/security/announce/2009/mfsa2009-09.html" source="CONFIRM" adv="1">http://www.mozilla.org/security/announce/2009/mfsa2009-09.html</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:083" source="MANDRIVA">MDVSA-2009:083</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:075" source="MANDRIVA">MDVSA-2009:075</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1830" source="DEBIAN">DSA-1830</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1751" source="DEBIAN">DSA-1751</ref>
      <ref url="http://support.avaya.com/japple/css/japple?temp.documentID=366362&amp;temp.productID=154235&amp;temp.releaseID=361845&amp;temp.bucketID=126655&amp;PAGE=Document" source="CONFIRM">http://support.avaya.com/japple/css/japple?temp.documentID=366362&amp;temp.productID=154235&amp;temp.releaseID=361845&amp;temp.bucketID=126655&amp;PAGE=Document</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2009-069.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2009-069.htm</ref>
      <ref url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2009&amp;m=slackware-security.433952" source="SLACKWARE">SSA:2009-083-03</ref>
      <ref url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2009&amp;m=slackware-security.405420" source="SLACKWARE">SSA:2009-083-02</ref>
      <ref url="http://secunia.com/advisories/34527" source="SECUNIA">34527</ref>
      <ref url="http://secunia.com/advisories/34464" source="SECUNIA">34464</ref>
      <ref url="http://secunia.com/advisories/34462" source="SECUNIA">34462</ref>
      <ref url="http://secunia.com/advisories/34417" source="SECUNIA">34417</ref>
      <ref url="http://secunia.com/advisories/34387" source="SECUNIA">34387</ref>
      <ref url="http://secunia.com/advisories/34383" source="SECUNIA">34383</ref>
      <ref url="http://secunia.com/advisories/34324" source="SECUNIA">34324</ref>
      <ref url="http://secunia.com/advisories/34272" source="SECUNIA">34272</ref>
      <ref url="http://secunia.com/advisories/34145" source="SECUNIA">34145</ref>
      <ref url="http://secunia.com/advisories/34140" source="SECUNIA">34140</ref>
      <ref url="http://secunia.com/advisories/34137" source="SECUNIA">34137</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9241" source="OVAL">oval:org.mitre.oval:def:9241</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7390" source="OVAL">oval:org.mitre.oval:def:7390</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6191" source="OVAL">oval:org.mitre.oval:def:6191</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6017" source="OVAL">oval:org.mitre.oval:def:6017</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5956" source="OVAL">oval:org.mitre.oval:def:5956</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-04/msg00009.html" source="SUSE">SUSE-SA:2009:023</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-03/msg00002.html" source="SUSE">SUSE-SA:2009:012</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="1.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.5" />
        <vers num="1.0.6" />
        <vers num="1.0.7" />
        <vers num="1.0.8" />
        <vers num="1.5" />
        <vers num="1.5.0.1" />
        <vers num="1.5.0.10" />
        <vers num="1.5.0.11" />
        <vers num="1.5.0.12" />
        <vers num="1.5.0.2" />
        <vers num="1.5.0.3" />
        <vers num="1.5.0.4" />
        <vers num="1.5.0.5" />
        <vers num="1.5.0.6" />
        <vers num="1.5.0.7" />
        <vers num="1.5.0.8" />
        <vers num="1.5.0.9" />
        <vers num="2.0" />
        <vers num="2.0.0.1" />
        <vers num="2.0.0.10" />
        <vers num="2.0.0.11" />
        <vers num="2.0.0.12" />
        <vers num="2.0.0.13" />
        <vers num="2.0.0.14" />
        <vers num="2.0.0.15" />
        <vers num="2.0.0.16" />
        <vers num="2.0.0.17" />
        <vers num="2.0.0.18" />
        <vers num="2.0.0.19" />
        <vers num="2.0.0.2" />
        <vers num="2.0.0.20" />
        <vers num="2.0.0.3" />
        <vers num="2.0.0.4" />
        <vers num="2.0.0.5" />
        <vers num="2.0.0.6" />
        <vers num="2.0.0.7" />
        <vers num="2.0.0.8" />
        <vers num="2.0.0.9" />
        <vers num="3.0" />
        <vers num="3.0.1" />
        <vers num="3.0.2" />
        <vers num="3.0.3" />
        <vers num="3.0.4" />
        <vers num="3.0.5" />
        <vers prev="1" num="3.0.6" />
      </prod>
      <prod vendor="mozilla" name="seamonkey">
        <vers num="1.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.5" />
        <vers num="1.0.6" />
        <vers num="1.0.7" />
        <vers num="1.0.8" />
        <vers num="1.0.9" />
        <vers num="1.1" edition="alpha" />
        <vers num="1.1" edition="beta" />
        <vers num="1.1.1" />
        <vers num="1.1.10" />
        <vers num="1.1.11" />
        <vers num="1.1.12" />
        <vers num="1.1.13" />
        <vers prev="1" num="1.1.14" />
        <vers num="1.1.2" />
        <vers num="1.1.3" />
        <vers num="1.1.4" />
        <vers num="1.1.5" />
        <vers num="1.1.6" />
        <vers num="1.1.7" />
        <vers num="1.1.8" />
        <vers num="1.1.9" />
      </prod>
      <prod vendor="mozilla" name="thunderbird">
        <vers num="2.0.0.0" />
        <vers num="2.0.0.12" />
        <vers num="2.0.0.14" />
        <vers num="2.0.0.16" />
        <vers num="2.0.0.17" />
        <vers num="2.0.0.18" />
        <vers num="2.0.0.19" />
        <vers prev="1" num="2.0.0.20" />
        <vers num="2.0.0.4" />
        <vers num="2.0.0.5" />
        <vers num="2.0.0.6" />
        <vers num="2.0.0.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0777" published="2009-03-04" name="CVE-2009-0777" modified="2012-01-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:P)" CVSS_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_base_score="5.8">
    <desc>
      <descript source="cve">Mozilla Firefox before 3.0.7, Thunderbird before 2.0.0.21, and SeaMonkey before 1.1.15 decode invisible characters when they are displayed in the location bar, which causes an incorrect address to be displayed and makes it easier for remote attackers to spoof URLs and conduct phishing attacks.</descript>
    </desc>
    <loss_types>
      <avail />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=452979" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=452979</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/49087" source="XF">mozilla-invisible-url-spoofing(49087)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0632" source="VUPEN" adv="1">ADV-2009-0632</ref>
      <ref url="http://www.securityfocus.com/bid/33990" source="BID">33990</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-0315.html" source="REDHAT">RHSA-2009:0315</ref>
      <ref url="http://www.mozilla.org/security/announce/2009/mfsa2009-11.html" source="CONFIRM" adv="1">http://www.mozilla.org/security/announce/2009/mfsa2009-11.html</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:075" source="MANDRIVA">MDVSA-2009:075</ref>
      <ref url="http://support.avaya.com/japple/css/japple?temp.documentID=366362&amp;temp.productID=154235&amp;temp.releaseID=361845&amp;temp.bucketID=126655&amp;PAGE=Document" source="CONFIRM">http://support.avaya.com/japple/css/japple?temp.documentID=366362&amp;temp.productID=154235&amp;temp.releaseID=361845&amp;temp.bucketID=126655&amp;PAGE=Document</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2009-069.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2009-069.htm</ref>
      <ref url="http://securitytracker.com/alerts/2009/Mar/1021799.html" source="SECTRACK">1021799</ref>
      <ref url="http://secunia.com/advisories/34272" source="SECUNIA" adv="1">34272</ref>
      <ref url="http://secunia.com/advisories/34145" source="SECUNIA" adv="1">34145</ref>
      <ref url="http://secunia.com/advisories/34140" source="SECUNIA" adv="1">34140</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7435" source="OVAL">oval:org.mitre.oval:def:7435</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6229" source="OVAL">oval:org.mitre.oval:def:6229</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6157" source="OVAL">oval:org.mitre.oval:def:6157</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6039" source="OVAL">oval:org.mitre.oval:def:6039</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11222" source="OVAL">oval:org.mitre.oval:def:11222</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-03/msg00002.html" source="SUSE">SUSE-SA:2009:012</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="1.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.5" />
        <vers num="1.0.6" />
        <vers num="1.0.7" />
        <vers num="1.0.8" />
        <vers num="1.5" />
        <vers num="1.5.0.1" />
        <vers num="1.5.0.10" />
        <vers num="1.5.0.11" />
        <vers num="1.5.0.12" />
        <vers num="1.5.0.2" />
        <vers num="1.5.0.3" />
        <vers num="1.5.0.4" />
        <vers num="1.5.0.5" />
        <vers num="1.5.0.6" />
        <vers num="1.5.0.7" />
        <vers num="1.5.0.8" />
        <vers num="1.5.0.9" />
        <vers num="2.0" />
        <vers num="2.0.0.1" />
        <vers num="2.0.0.10" />
        <vers num="2.0.0.11" />
        <vers num="2.0.0.12" />
        <vers num="2.0.0.13" />
        <vers num="2.0.0.14" />
        <vers num="2.0.0.15" />
        <vers num="2.0.0.16" />
        <vers num="2.0.0.17" />
        <vers num="2.0.0.18" />
        <vers num="2.0.0.19" />
        <vers num="2.0.0.2" />
        <vers num="2.0.0.20" />
        <vers num="2.0.0.3" />
        <vers num="2.0.0.4" />
        <vers num="2.0.0.5" />
        <vers num="2.0.0.6" />
        <vers num="2.0.0.7" />
        <vers num="2.0.0.8" />
        <vers num="2.0.0.9" />
        <vers num="3.0" />
        <vers num="3.0.1" />
        <vers num="3.0.2" />
        <vers num="3.0.3" />
        <vers num="3.0.4" />
        <vers num="3.0.5" />
        <vers prev="1" num="3.0.6" />
      </prod>
      <prod vendor="mozilla" name="seamonkey">
        <vers num="1.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.5" />
        <vers num="1.0.6" />
        <vers num="1.0.7" />
        <vers num="1.0.8" />
        <vers num="1.0.9" />
        <vers num="1.1" edition="alpha" />
        <vers num="1.1" edition="beta" />
        <vers num="1.1.1" />
        <vers num="1.1.10" />
        <vers num="1.1.11" />
        <vers num="1.1.12" />
        <vers num="1.1.13" />
        <vers prev="1" num="1.1.14" />
        <vers num="1.1.2" />
        <vers num="1.1.3" />
        <vers num="1.1.4" />
        <vers num="1.1.5" />
        <vers num="1.1.6" />
        <vers num="1.1.7" />
        <vers num="1.1.8" />
        <vers num="1.1.9" />
      </prod>
      <prod vendor="mozilla" name="thunderbird">
        <vers num="2.0.0.0" />
        <vers num="2.0.0.12" />
        <vers num="2.0.0.14" />
        <vers num="2.0.0.16" />
        <vers num="2.0.0.17" />
        <vers num="2.0.0.18" />
        <vers num="2.0.0.19" />
        <vers prev="1" num="2.0.0.20" />
        <vers num="2.0.0.4" />
        <vers num="2.0.0.5" />
        <vers num="2.0.0.6" />
        <vers num="2.0.0.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0778" published="2009-03-12" name="CVE-2009-0778" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:C)" CVSS_score="7.1" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="8.6" CVSS_base_score="7.1">
    <desc>
      <descript source="cve">The icmp_send function in net/ipv4/icmp.c in the Linux kernel before 2.6.25, when configured as a router with a REJECT route, does not properly manage the Protocol Independent Destination Cache (aka DST) in some situations involving transmission of an ICMP Host Unreachable message, which allows remote attackers to cause a denial of service (connectivity outage) by sending a large series of packets to many destination IP addresses within this REJECT route, related to an "rt_cache leak."</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=485163" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=485163</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/49199" source="XF">linux-kernel-rtcache-dos(49199)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/3316" source="VUPEN">ADV-2009-3316</ref>
      <ref url="http://www.vmware.com/security/advisories/VMSA-2009-0016.html" source="CONFIRM">http://www.vmware.com/security/advisories/VMSA-2009-0016.html</ref>
      <ref url="http://www.securitytracker.com/id?1021958" source="SECTRACK">1021958</ref>
      <ref url="http://www.securityfocus.com/bid/34084" source="BID">34084</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/507985/100/0/threaded" source="BUGTRAQ">20091120 VMSA-2009-0016 VMware vCenter and ESX update release and vMA patch release address multiple security issue in third party components</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-0326.html" source="REDHAT">RHSA-2009:0326</ref>
      <ref url="http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.25" source="CONFIRM">http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.25</ref>
      <ref url="http://secunia.com/advisories/37471" source="SECUNIA">37471</ref>
      <ref url="http://secunia.com/advisories/33758" source="SECUNIA">33758</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7867" source="OVAL">oval:org.mitre.oval:def:7867</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10215" source="OVAL">oval:org.mitre.oval:def:10215</ref>
      <ref url="http://openwall.com/lists/oss-security/2009/03/11/2" source="MLIST">[oss-security] 20090311 CVE-2009-0778 kernel: rt_cache leak</ref>
      <ref url="http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=7c0ecc4c4f8fd90988aab8a95297b9c0038b6160" source="CONFIRM">http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=7c0ecc4c4f8fd90988aab8a95297b9c0038b6160</ref>
    </refs>
    <vuln_soft>
      <prod vendor="kernel" name="linux">
        <vers num="2.6.0" />
        <vers num="2.6.1" />
        <vers num="2.6.10" />
        <vers num="2.6.11" />
        <vers num="2.6.11.1" />
        <vers num="2.6.11.10" />
        <vers num="2.6.11.12" />
        <vers num="2.6.11.2" />
        <vers num="2.6.11.3" />
        <vers num="2.6.11.4" />
        <vers num="2.6.11.5" />
        <vers num="2.6.11.6" />
        <vers num="2.6.11.7" />
        <vers num="2.6.11.8" />
        <vers num="2.6.11.9" />
        <vers num="2.6.12" />
        <vers num="2.6.12.1" />
        <vers num="2.6.12.2" />
        <vers num="2.6.12.3" />
        <vers num="2.6.12.4" />
        <vers num="2.6.12.5" />
        <vers num="2.6.12.6" />
        <vers num="2.6.13" />
        <vers num="2.6.13.1" />
        <vers num="2.6.13.2" />
        <vers num="2.6.13.3" />
        <vers num="2.6.13.4" />
        <vers num="2.6.13.5" />
        <vers num="2.6.14" />
        <vers num="2.6.14.1" />
        <vers num="2.6.14.2" />
        <vers num="2.6.14.3" />
        <vers num="2.6.14.4" />
        <vers num="2.6.14.5" />
        <vers num="2.6.14.6" />
        <vers num="2.6.14.7" />
        <vers num="2.6.15" />
        <vers num="2.6.15.1" />
        <vers num="2.6.15.2" />
        <vers num="2.6.15.3" />
        <vers num="2.6.15.4" />
        <vers num="2.6.15.5" />
        <vers num="2.6.15.6" />
        <vers num="2.6.15.7" />
        <vers num="2.6.16" />
        <vers num="2.6.16.20" />
        <vers num="2.6.16.21" />
        <vers num="2.6.16.22" />
        <vers num="2.6.16.23" />
        <vers num="2.6.16.24" />
        <vers num="2.6.16.25" />
        <vers num="2.6.16.26" />
        <vers num="2.6.16.27" />
        <vers num="2.6.16.28" />
        <vers num="2.6.16.29" />
        <vers num="2.6.16.30" />
        <vers num="2.6.16.31" />
        <vers num="2.6.16.32" />
        <vers num="2.6.16.33" />
        <vers num="2.6.16.34" />
        <vers num="2.6.16.35" />
        <vers num="2.6.16.36" />
        <vers num="2.6.16.37" />
        <vers num="2.6.16.38" />
        <vers num="2.6.16.39" />
        <vers num="2.6.16.40" />
        <vers num="2.6.16.41" />
        <vers num="2.6.16.42" />
        <vers num="2.6.16.43" />
        <vers num="2.6.16.44" />
        <vers num="2.6.16.45" />
        <vers num="2.6.16.46" />
        <vers num="2.6.16.47" />
        <vers num="2.6.16.48" />
        <vers num="2.6.16.49" />
        <vers num="2.6.16.50" />
        <vers num="2.6.16.51" />
        <vers num="2.6.16.52" />
        <vers num="2.6.16.53" />
        <vers num="2.6.16.54" />
        <vers num="2.6.16.55" />
        <vers num="2.6.16.56" />
        <vers num="2.6.16.57" />
        <vers num="2.6.16.58" />
        <vers num="2.6.16.59" />
        <vers num="2.6.16.60" />
        <vers num="2.6.16.61" />
        <vers num="2.6.16.62" />
        <vers num="2.6.17" />
        <vers num="2.6.17.1" />
        <vers num="2.6.17.10" />
        <vers num="2.6.17.11" />
        <vers num="2.6.17.12" />
        <vers num="2.6.17.13" />
        <vers num="2.6.17.14" />
        <vers num="2.6.17.2" />
        <vers num="2.6.17.3" />
        <vers num="2.6.17.4" />
        <vers num="2.6.17.5" />
        <vers num="2.6.17.6" />
        <vers num="2.6.17.7" />
        <vers num="2.6.17.8" />
        <vers num="2.6.17.9" />
        <vers num="2.6.18" />
        <vers num="2.6.18.1" />
        <vers num="2.6.18.2" />
        <vers num="2.6.18.3" />
        <vers num="2.6.18.4" />
        <vers num="2.6.18.5" />
        <vers num="2.6.18.6" />
        <vers num="2.6.18.7" />
        <vers num="2.6.18.8" />
        <vers num="2.6.19" />
        <vers num="2.6.19.1" />
        <vers num="2.6.19.2" />
        <vers num="2.6.19.3" />
        <vers num="2.6.19.4" />
        <vers num="2.6.19.5" />
        <vers num="2.6.19.6" />
        <vers num="2.6.19.7" />
        <vers num="2.6.2" />
        <vers num="2.6.20" />
        <vers num="2.6.20.1" />
        <vers num="2.6.20.10" />
        <vers num="2.6.20.11" />
        <vers num="2.6.20.12" />
        <vers num="2.6.20.13" />
        <vers num="2.6.20.14" />
        <vers num="2.6.20.15" />
        <vers num="2.6.20.16" />
        <vers num="2.6.20.17" />
        <vers num="2.6.20.18" />
        <vers num="2.6.20.19" />
        <vers num="2.6.20.2" />
        <vers num="2.6.20.20" />
        <vers num="2.6.20.21" />
        <vers num="2.6.20.3" />
        <vers num="2.6.20.4" />
        <vers num="2.6.20.5" />
        <vers num="2.6.20.6" />
        <vers num="2.6.20.7" />
        <vers num="2.6.20.8" />
        <vers num="2.6.20.9" />
        <vers num="2.6.21" />
        <vers num="2.6.21.1" />
        <vers num="2.6.21.2" />
        <vers num="2.6.21.3" />
        <vers num="2.6.21.4" />
        <vers num="2.6.21.5" />
        <vers num="2.6.21.6" />
        <vers num="2.6.21.7" />
        <vers num="2.6.22" />
        <vers num="2.6.22.1" />
        <vers num="2.6.22.10" />
        <vers num="2.6.22.11" />
        <vers num="2.6.22.12" />
        <vers num="2.6.22.13" />
        <vers num="2.6.22.14" />
        <vers num="2.6.22.15" />
        <vers num="2.6.22.16" />
        <vers num="2.6.22.17" />
        <vers num="2.6.22.18" />
        <vers num="2.6.22.19" />
        <vers num="2.6.22.2" />
        <vers num="2.6.22.3" />
        <vers num="2.6.22.4" />
        <vers num="2.6.22.5" />
        <vers num="2.6.22.6" />
        <vers num="2.6.22.7" />
        <vers num="2.6.22.8" />
        <vers num="2.6.22.9" />
        <vers num="2.6.23" />
        <vers num="2.6.23.1" />
        <vers num="2.6.23.10" />
        <vers num="2.6.23.11" />
        <vers num="2.6.23.12" />
        <vers num="2.6.23.13" />
        <vers num="2.6.23.14" />
        <vers num="2.6.23.15" />
        <vers num="2.6.23.16" />
        <vers num="2.6.23.17" />
        <vers num="2.6.23.2" />
        <vers num="2.6.23.3" />
        <vers num="2.6.23.4" />
        <vers num="2.6.23.5" />
        <vers num="2.6.23.6" />
        <vers num="2.6.23.7" />
        <vers num="2.6.23.8" />
        <vers num="2.6.23.9" />
        <vers num="2.6.24" />
        <vers num="2.6.24.1" />
        <vers num="2.6.24.2" />
        <vers num="2.6.24.3" />
        <vers num="2.6.24.4" />
        <vers num="2.6.24.5" />
        <vers num="2.6.24.6" />
        <vers prev="1" num="2.6.24.7" />
        <vers num="2.6.28.2" />
        <vers num="2.6.3" />
        <vers num="2.6.4" />
        <vers num="2.6.5" />
        <vers num="2.6.6" />
        <vers num="2.6.7" />
        <vers num="2.6.8" />
        <vers num="2.6.8.1" />
        <vers num="2.6.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0779" published="2009-03-04" name="CVE-2009-0779" modified="2009-03-04" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in pppdial in IBM AIX 5.3 and 6.1 allows local users to gain privileges via a long "input string."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2009/0487" source="VUPEN" patch="1" adv="1">ADV-2009-0487</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=isg1IZ44388" source="AIXAPAR" patch="1" adv="1">IZ44388</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=isg1IZ44332" source="AIXAPAR" patch="1" adv="1">IZ44332</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=isg1IZ44220" source="AIXAPAR" patch="1" adv="1">IZ44220</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=isg1IZ44199" source="AIXAPAR" patch="1" adv="1">IZ44199</ref>
      <ref url="http://www.securityfocus.com/bid/33852" source="BID">33852</ref>
      <ref url="http://www.osvdb.org/52179" source="OSVDB">52179</ref>
      <ref url="http://securitytracker.com/id?1021741" source="SECTRACK">1021741</ref>
      <ref url="http://secunia.com/advisories/34005" source="SECUNIA" adv="1">34005</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="aix">
        <vers num="5.3" />
        <vers num="6.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0780" published="2009-03-04" name="CVE-2009-0780" modified="2010-04-27" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The aspath_prepend function in rde_attr.c in bgpd in OpenBSD 4.3 and 4.4 allows remote attackers to cause a denial of service (application crash) via an Autonomous System (AS) advertisement containing a long AS path.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://openbsd.org/errata44.html#010_bgpd" source="OPENBSD" patch="1" adv="1">[4.4] 010: RELIABILITY FIX: February 18, 2009</ref>
      <ref url="http://openbsd.org/errata43.html#010_bgpd" source="OPENBSD" patch="1" adv="1">[4.3] 010: RELIABILITY FIX: February 18, 2009</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/48812" source="XF">openbsd-aspathprepend-dos(48812)</ref>
      <ref url="http://www.securitytracker.com/id?1021736" source="SECTRACK">1021736</ref>
      <ref url="http://www.securityfocus.com/bid/33828" source="BID">33828</ref>
      <ref url="http://secunia.com/advisories/33975" source="SECUNIA" adv="1">33975</ref>
      <ref url="http://osvdb.org/52271" source="OSVDB">52271</ref>
    </refs>
    <vuln_soft>
      <prod vendor="openbsd" name="openbsd">
        <vers num="4.3" />
        <vers num="4.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0781" published="2009-03-09" name="CVE-2009-0781" modified="2011-09-06" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in jsp/cal/cal2.jsp in the calendar application in the examples web application in Apache Tomcat 4.1.0 through 4.1.39, 5.5.0 through 5.5.27, and 6.0.0 through 6.0.18 allows remote attackers to inject arbitrary web script or HTML via the time parameter, related to "invalid HTML."</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-November/msg01246.html" source="FEDORA">FEDORA-2009-11356</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-November/msg01216.html" source="FEDORA">FEDORA-2009-11352</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-November/msg01156.html" source="FEDORA">FEDORA-2009-11374</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/49213" source="XF">tomcat-cal2-xss(49213)</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/3056" source="VUPEN">ADV-2010-3056</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/3316" source="VUPEN">ADV-2009-3316</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1856" source="VUPEN">ADV-2009-1856</ref>
      <ref url="http://www.vmware.com/security/advisories/VMSA-2009-0016.html" source="CONFIRM">http://www.vmware.com/security/advisories/VMSA-2009-0016.html</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/507985/100/0/threaded" source="BUGTRAQ">20091120 VMSA-2009-0016 VMware vCenter and ESX update release and vMA patch release address multiple security issue in third party components</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/501538/100/0/threaded" source="BUGTRAQ">20090306 [SECURITY] CVE-2009-0781 XSS in Apache Tomcat examples web application</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:138" source="MANDRIVA">MDVSA-2009:138</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:136" source="MANDRIVA">MDVSA-2009:136</ref>
      <ref url="http://www.debian.org/security/2011/dsa-2207" source="DEBIAN">DSA-2207</ref>
      <ref url="http://tomcat.apache.org/security-6.html" source="CONFIRM" adv="1">http://tomcat.apache.org/security-6.html</ref>
      <ref url="http://tomcat.apache.org/security-5.html" source="CONFIRM" adv="1">http://tomcat.apache.org/security-5.html</ref>
      <ref url="http://tomcat.apache.org/security-4.html" source="CONFIRM" adv="1">http://tomcat.apache.org/security-4.html</ref>
      <ref url="http://support.apple.com/kb/HT4077" source="CONFIRM">http://support.apple.com/kb/HT4077</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-263529-1" source="SUNALERT">263529</ref>
      <ref url="http://secunia.com/advisories/42368" source="SECUNIA">42368</ref>
      <ref url="http://secunia.com/advisories/37460" source="SECUNIA">37460</ref>
      <ref url="http://secunia.com/advisories/35788" source="SECUNIA">35788</ref>
      <ref url="http://secunia.com/advisories/35685" source="SECUNIA">35685</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6564" source="OVAL">oval:org.mitre.oval:def:6564</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11041" source="OVAL">oval:org.mitre.oval:def:11041</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=129070310906557&amp;w=2" source="HP">HPSBUX02579</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=129070310906557&amp;w=2" source="HP">HPSBUX02579</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-07/msg00002.html" source="SUSE">SUSE-SR:2009:012</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Mar/msg00001.html" source="APPLE">APPLE-SA-2010-03-29-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apache" name="tomcat">
        <vers num="4.1.0" />
        <vers num="4.1.1" />
        <vers num="4.1.10" />
        <vers num="4.1.11" />
        <vers num="4.1.12" />
        <vers num="4.1.13" />
        <vers num="4.1.14" />
        <vers num="4.1.15" />
        <vers num="4.1.16" />
        <vers num="4.1.17" />
        <vers num="4.1.18" />
        <vers num="4.1.19" />
        <vers num="4.1.2" />
        <vers num="4.1.20" />
        <vers num="4.1.21" />
        <vers num="4.1.22" />
        <vers num="4.1.23" />
        <vers num="4.1.24" />
        <vers num="4.1.25" />
        <vers num="4.1.26" />
        <vers num="4.1.27" />
        <vers num="4.1.28" />
        <vers num="4.1.29" />
        <vers num="4.1.3" edition="beta" />
        <vers num="4.1.30" />
        <vers num="4.1.31" />
        <vers num="4.1.32" />
        <vers num="4.1.33" />
        <vers num="4.1.34" />
        <vers num="4.1.35" />
        <vers num="4.1.36" />
        <vers num="4.1.37" />
        <vers num="4.1.4" />
        <vers num="4.1.5" />
        <vers num="4.1.6" />
        <vers num="4.1.7" />
        <vers num="4.1.8" />
        <vers num="4.1.9" edition="beta" />
        <vers num="5.5.0" />
        <vers num="5.5.1" />
        <vers num="5.5.10" />
        <vers num="5.5.11" />
        <vers num="5.5.12" />
        <vers num="5.5.13" />
        <vers num="5.5.14" />
        <vers num="5.5.15" />
        <vers num="5.5.16" />
        <vers num="5.5.17" />
        <vers num="5.5.18" />
        <vers num="5.5.19" />
        <vers num="5.5.2" />
        <vers num="5.5.20" />
        <vers num="5.5.21" />
        <vers num="5.5.22" />
        <vers num="5.5.23" />
        <vers num="5.5.24" />
        <vers num="5.5.25" />
        <vers num="5.5.26" />
        <vers num="5.5.3" />
        <vers num="5.5.4" />
        <vers num="5.5.5" />
        <vers num="5.5.6" />
        <vers num="5.5.7" />
        <vers num="5.5.8" />
        <vers num="5.5.9" />
        <vers num="6.0" />
        <vers num="6.0.0" />
        <vers num="6.0.1" />
        <vers num="6.0.10" />
        <vers num="6.0.11" />
        <vers num="6.0.12" />
        <vers num="6.0.13" />
        <vers num="6.0.14" />
        <vers num="6.0.15" />
        <vers num="6.0.16" />
        <vers num="6.0.2" />
        <vers num="6.0.3" />
        <vers num="6.0.4" />
        <vers num="6.0.5" />
        <vers num="6.0.6" />
        <vers num="6.0.7" />
        <vers num="6.0.8" />
        <vers num="6.0.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" seq="2009-0782" reject="1" published="2009-03-26" name="CVE-2009-0782" modified="2009-03-26">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: none.  Reason: This candidate was withdrawn by its CNA.  Further investigation showed that it was not a security issue.  Notes: none.</descript>
    </desc>
    <refs />
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0783" published="2009-06-05" name="CVE-2009-0783" modified="2011-09-06" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">Apache Tomcat 4.1.0 through 4.1.39, 5.5.0 through 5.5.27, and 6.0.0 through 6.0.18 permits web applications to replace an XML parser used for other web applications, which allows local users to read or modify the (1) web.xml, (2) context.xml, or (3) tld files of arbitrary web applications via a crafted application that is loaded earlier than the target application.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="https://issues.apache.org/bugzilla/show_bug.cgi?id=29936" source="CONFIRM" patch="1">https://issues.apache.org/bugzilla/show_bug.cgi?id=29936</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/504090/100/0/threaded" source="BUGTRAQ" patch="1">20090604 [SECURITY] CVE-2009-0783 Apache Tomcat Information disclosure</ref>
      <ref url="http://tomcat.apache.org/security-6.html" source="CONFIRM" patch="1" adv="1">http://tomcat.apache.org/security-6.html</ref>
      <ref url="http://tomcat.apache.org/security-5.html" source="CONFIRM" patch="1" adv="1">http://tomcat.apache.org/security-5.html</ref>
      <ref url="http://tomcat.apache.org/security-4.html" source="CONFIRM" patch="1" adv="1">http://tomcat.apache.org/security-4.html</ref>
      <ref url="http://svn.apache.org/viewvc?rev=781708&amp;view=rev" source="CONFIRM" patch="1">http://svn.apache.org/viewvc?rev=781708&amp;view=rev</ref>
      <ref url="http://svn.apache.org/viewvc?rev=781542&amp;view=rev" source="CONFIRM" patch="1">http://svn.apache.org/viewvc?rev=781542&amp;view=rev</ref>
      <ref url="http://svn.apache.org/viewvc?rev=739522&amp;view=rev" source="CONFIRM" patch="1">http://svn.apache.org/viewvc?rev=739522&amp;view=rev</ref>
      <ref url="http://svn.apache.org/viewvc?rev=681156&amp;view=rev" source="CONFIRM" patch="1">http://svn.apache.org/viewvc?rev=681156&amp;view=rev</ref>
      <ref url="http://svn.apache.org/viewvc?rev=652592&amp;view=rev" source="CONFIRM" patch="1">http://svn.apache.org/viewvc?rev=652592&amp;view=rev</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-November/msg01246.html" source="FEDORA">FEDORA-2009-11356</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-November/msg01216.html" source="FEDORA">FEDORA-2009-11352</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-November/msg01156.html" source="FEDORA">FEDORA-2009-11374</ref>
      <ref url="https://issues.apache.org/bugzilla/show_bug.cgi?id=45933" source="CONFIRM">https://issues.apache.org/bugzilla/show_bug.cgi?id=45933</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/51195" source="XF">tomcat-xml-information-disclosure(51195)</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/3056" source="VUPEN" adv="1">ADV-2010-3056</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/3316" source="VUPEN" adv="1">ADV-2009-3316</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1856" source="VUPEN" adv="1">ADV-2009-1856</ref>
      <ref url="http://www.vmware.com/security/advisories/VMSA-2009-0016.html" source="CONFIRM">http://www.vmware.com/security/advisories/VMSA-2009-0016.html</ref>
      <ref url="http://www.securitytracker.com/id?1022336" source="SECTRACK">1022336</ref>
      <ref url="http://www.securityfocus.com/bid/35416" source="BID">35416</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/507985/100/0/threaded" source="BUGTRAQ">20091120 VMSA-2009-0016 VMware vCenter and ESX update release and vMA patch release address multiple security issue in third party components</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2010:176" source="MANDRIVA">MDVSA-2010:176</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:138" source="MANDRIVA">MDVSA-2009:138</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:136" source="MANDRIVA">MDVSA-2009:136</ref>
      <ref url="http://www.debian.org/security/2011/dsa-2207" source="DEBIAN">DSA-2207</ref>
      <ref url="http://support.apple.com/kb/HT4077" source="CONFIRM">http://support.apple.com/kb/HT4077</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-263529-1" source="SUNALERT">263529</ref>
      <ref url="http://secunia.com/advisories/42368" source="SECUNIA" adv="1">42368</ref>
      <ref url="http://secunia.com/advisories/37460" source="SECUNIA" adv="1">37460</ref>
      <ref url="http://secunia.com/advisories/35788" source="SECUNIA" adv="1">35788</ref>
      <ref url="http://secunia.com/advisories/35685" source="SECUNIA" adv="1">35685</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6450" source="OVAL">oval:org.mitre.oval:def:6450</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10716" source="OVAL">oval:org.mitre.oval:def:10716</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=129070310906557&amp;w=2" source="HP">HPSBUX02579</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=129070310906557&amp;w=2" source="HP">HPSBUX02579</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-07/msg00002.html" source="SUSE">SUSE-SR:2009:012</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Mar/msg00001.html" source="APPLE">APPLE-SA-2010-03-29-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apache" name="tomcat">
        <vers num="4.1.0" />
        <vers num="4.1.1" />
        <vers num="4.1.10" />
        <vers num="4.1.11" />
        <vers num="4.1.12" />
        <vers num="4.1.13" />
        <vers num="4.1.14" />
        <vers num="4.1.15" />
        <vers num="4.1.16" />
        <vers num="4.1.17" />
        <vers num="4.1.18" />
        <vers num="4.1.19" />
        <vers num="4.1.2" />
        <vers num="4.1.20" />
        <vers num="4.1.21" />
        <vers num="4.1.22" />
        <vers num="4.1.23" />
        <vers num="4.1.24" />
        <vers num="4.1.25" />
        <vers num="4.1.26" />
        <vers num="4.1.27" />
        <vers num="4.1.28" />
        <vers num="4.1.29" />
        <vers num="4.1.3" />
        <vers num="4.1.30" />
        <vers num="4.1.31" />
        <vers num="4.1.32" />
        <vers num="4.1.33" />
        <vers num="4.1.34" />
        <vers num="4.1.35" />
        <vers num="4.1.36" />
        <vers num="4.1.37" />
        <vers num="4.1.38" />
        <vers num="4.1.39" />
        <vers num="4.1.4" />
        <vers num="4.1.5" />
        <vers num="4.1.6" />
        <vers num="4.1.7" />
        <vers num="4.1.8" />
        <vers num="4.1.9" />
        <vers num="5.5.0" />
        <vers num="5.5.1" />
        <vers num="5.5.10" />
        <vers num="5.5.11" />
        <vers num="5.5.12" />
        <vers num="5.5.13" />
        <vers num="5.5.14" />
        <vers num="5.5.15" />
        <vers num="5.5.16" />
        <vers num="5.5.17" />
        <vers num="5.5.18" />
        <vers num="5.5.19" />
        <vers num="5.5.2" />
        <vers num="5.5.20" />
        <vers num="5.5.21" />
        <vers num="5.5.22" />
        <vers num="5.5.23" />
        <vers num="5.5.24" />
        <vers num="5.5.25" />
        <vers num="5.5.26" />
        <vers num="5.5.27" />
        <vers num="5.5.3" />
        <vers num="5.5.4" />
        <vers num="5.5.5" />
        <vers num="5.5.6" />
        <vers num="5.5.7" />
        <vers num="5.5.8" />
        <vers num="5.5.9" />
        <vers num="6.0.0" />
        <vers num="6.0.1" />
        <vers num="6.0.10" />
        <vers num="6.0.11" />
        <vers num="6.0.12" />
        <vers num="6.0.13" />
        <vers num="6.0.14" />
        <vers num="6.0.15" />
        <vers num="6.0.16" />
        <vers num="6.0.17" />
        <vers num="6.0.18" />
        <vers num="6.0.2" />
        <vers num="6.0.3" />
        <vers num="6.0.4" />
        <vers num="6.0.5" />
        <vers num="6.0.6" />
        <vers num="6.0.7" />
        <vers num="6.0.8" />
        <vers num="6.0.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0784" published="2009-03-25" name="CVE-2009-0784" modified="2010-11-30" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="6.9" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.4" CVSS_base_score="6.9">
    <desc>
      <descript source="cve">Race condition in the SystemTap stap tool 0.0.20080705 and 0.0.20090314 allows local users in the stapusr group to insert arbitrary SystemTap kernel modules and gain privileges via unknown vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2009/dsa-1755" source="DEBIAN" patch="1">DSA-1755</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0907" source="VUPEN" adv="1">ADV-2009-0907</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-0373.html" source="REDHAT">RHSA-2009:0373</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2009-110.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2009-110.htm</ref>
      <ref url="http://secunia.com/advisories/34548" source="SECUNIA" adv="1">34548</ref>
      <ref url="http://secunia.com/advisories/34479" source="SECUNIA" adv="1">34479</ref>
      <ref url="http://secunia.com/advisories/34441" source="SECUNIA" adv="1">34441</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11613" source="OVAL">oval:org.mitre.oval:def:11613</ref>
    </refs>
    <vuln_soft>
      <prod vendor="systemtap" name="systemtap">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" seq="2009-0786" reject="1" published="2009-05-22" name="CVE-2009-0786" modified="2009-05-22">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: none.  Reason: This was originally intended for a report about TCP Wrappers and the hosts_ctl API function, but further investigation showed that this was documented behavior by that function.  Notes: Future CVE identifiers might be assigned to applications that mis-use the API in a security-relevant fashion.</descript>
    </desc>
    <refs />
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0787" published="2009-03-24" name="CVE-2009-0787" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:N/A:N)" CVSS_score="4.9" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="3.9" CVSS_base_score="4.9">
    <desc>
      <descript source="cve">The ecryptfs_write_metadata_to_contents function in the eCryptfs functionality in the Linux kernel 2.6.28 before 2.6.28.9 uses an incorrect size when writing kernel memory to an eCryptfs file header, which triggers an out-of-bounds read and allows local users to obtain portions of kernel memory.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/34216" source="BID" patch="1">34216</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/49355" source="XF">linux-kernel-ecryptfs-information-disclosure(49355)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/3316" source="VUPEN">ADV-2009-3316</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0802" source="VUPEN" adv="1">ADV-2009-0802</ref>
      <ref url="http://www.vmware.com/security/advisories/VMSA-2009-0016.html" source="CONFIRM">http://www.vmware.com/security/advisories/VMSA-2009-0016.html</ref>
      <ref url="http://www.securitytracker.com/id?1022177" source="SECTRACK">1022177</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/507985/100/0/threaded" source="BUGTRAQ">20091120 VMSA-2009-0016 VMware vCenter and ESX update release and vMA patch release address multiple security issue in third party components</ref>
      <ref url="http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.28.9" source="CONFIRM" adv="1">http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.28.9</ref>
      <ref url="http://secunia.com/advisories/37471" source="SECUNIA">37471</ref>
      <ref url="http://secunia.com/advisories/35015" source="SECUNIA">35015</ref>
      <ref url="http://secunia.com/advisories/34422" source="SECUNIA" adv="1">34422</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2009-0473.html" source="REDHAT">RHSA-2009:0473</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:8319" source="OVAL">oval:org.mitre.oval:def:8319</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11068" source="OVAL">oval:org.mitre.oval:def:11068</ref>
      <ref url="http://osvdb.org/52860" source="OSVDB">52860</ref>
      <ref url="http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commitdiff;h=8faece5f906725c10e7a1f6caf84452abadbdc7b" source="CONFIRM">http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commitdiff;h=8faece5f906725c10e7a1f6caf84452abadbdc7b</ref>
    </refs>
    <vuln_soft>
      <prod vendor="kernel" name="linux">
        <vers num="2.6.28" />
        <vers num="2.6.28.1" />
        <vers num="2.6.28.2" />
        <vers num="2.6.28.3" />
        <vers num="2.6.28.4" />
        <vers num="2.6.28.5" />
        <vers num="2.6.28.6" />
        <vers num="2.6.28.7" />
        <vers num="2.6.28.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0788" published="2011-04-18" name="CVE-2009-0788" modified="2011-04-19" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">Red Hat Network (RHN) Satellite Server 5.3 and 5.4 does not properly rewrite unspecified URLs, which allows remote attackers to (1) obtain unspecified sensitive host information or (2) use the server as an inadvertent proxy to connect to arbitrary services and IP addresses via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=491365" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=491365</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/66691" source="XF">rhnss-url-security-bypass(66691)</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0967" source="VUPEN" adv="1">ADV-2011-0967</ref>
      <ref url="http://www.securitytracker.com/id?1025316" source="SECTRACK">1025316</ref>
      <ref url="http://www.securityfocus.com/bid/47316" source="BID">47316</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2011-0434.html" source="REDHAT">RHSA-2011:0434</ref>
      <ref url="http://secunia.com/advisories/44150" source="SECUNIA" adv="1">44150</ref>
    </refs>
    <vuln_soft>
      <prod vendor="redhat" name="network_satellite_server">
        <vers num="5.3" />
        <vers num="5.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0789" published="2009-03-27" name="CVE-2009-0789" modified="2011-10-25" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">OpenSSL before 0.9.8k on WIN64 and certain other platforms does not properly handle a malformed ASN.1 structure, which allows remote attackers to cause a denial of service (invalid memory access and application crash) by placing this structure in the public key of a certificate, as demonstrated by an RSA public key.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/34256" source="BID" patch="1">34256</ref>
      <ref url="https://kb.bluecoat.com/index?page=content&amp;id=SA50" source="CONFIRM">https://kb.bluecoat.com/index?page=content&amp;id=SA50</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/49433" source="XF">openssl-asn1-structure-dos(49433)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1548" source="VUPEN" adv="1">ADV-2009-1548</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1175" source="VUPEN" adv="1">ADV-2009-1175</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1020" source="VUPEN" adv="1">ADV-2009-1020</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0850" source="VUPEN" adv="1">ADV-2009-0850</ref>
      <ref url="http://www.php.net/archive/2009.php#id2009-04-08-1" source="CONFIRM">http://www.php.net/archive/2009.php#id2009-04-08-1</ref>
      <ref url="http://www.osvdb.org/52866" source="OSVDB">52866</ref>
      <ref url="http://www.openssl.org/news/secadv_20090325.txt" source="CONFIRM" adv="1">http://www.openssl.org/news/secadv_20090325.txt</ref>
      <ref url="http://voodoo-circle.sourceforge.net/sa/sa-20090326-01.html" source="CONFIRM">http://voodoo-circle.sourceforge.net/sa/sa-20090326-01.html</ref>
      <ref url="http://support.apple.com/kb/HT3865" source="CONFIRM">http://support.apple.com/kb/HT3865</ref>
      <ref url="http://sourceforge.net/project/shownotes.php?release_id=671059&amp;group_id=116847" source="CONFIRM">http://sourceforge.net/project/shownotes.php?release_id=671059&amp;group_id=116847</ref>
      <ref url="http://securitytracker.com/id?1021906" source="SECTRACK">1021906</ref>
      <ref url="http://secunia.com/advisories/42733" source="SECUNIA" adv="1">42733</ref>
      <ref url="http://secunia.com/advisories/42724" source="SECUNIA" adv="1">42724</ref>
      <ref url="http://secunia.com/advisories/36701" source="SECUNIA" adv="1">36701</ref>
      <ref url="http://secunia.com/advisories/35729" source="SECUNIA" adv="1">35729</ref>
      <ref url="http://secunia.com/advisories/35380" source="SECUNIA" adv="1">35380</ref>
      <ref url="http://secunia.com/advisories/35065" source="SECUNIA">35065</ref>
      <ref url="http://secunia.com/advisories/34666" source="SECUNIA">34666</ref>
      <ref url="http://secunia.com/advisories/34460" source="SECUNIA" adv="1">34460</ref>
      <ref url="http://secunia.com/advisories/34411" source="SECUNIA" adv="1">34411</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=124464882609472&amp;w=2" source="HP">SSRT090059</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=124464882609472&amp;w=2" source="HP">SSRT090059</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2011-07/msg00014.html" source="SUSE">SUSE-SU-2011:0847</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2011-07/msg00013.html" source="SUSE">openSUSE-SU-2011:0845</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-05/msg00000.html" source="SUSE">SUSE-SR:2009:010</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2009/Sep/msg00004.html" source="APPLE">APPLE-SA-2009-09-10-2</ref>
      <ref url="ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2009-008.txt.asc" source="NETBSD">NetBSD-SA2009-008</ref>
    </refs>
    <vuln_soft>
      <prod vendor="openssl" name="openssl">
        <vers num="0.9.1c" />
        <vers num="0.9.2b" />
        <vers num="0.9.3" />
        <vers num="0.9.3a" />
        <vers num="0.9.4" />
        <vers num="0.9.5" edition="beta1" />
        <vers num="0.9.5" edition="beta2" />
        <vers num="0.9.5a" edition="beta1" />
        <vers num="0.9.5a" edition="beta2" />
        <vers num="0.9.6" edition="beta1" />
        <vers num="0.9.6" edition="beta2" />
        <vers num="0.9.6" edition="beta3" />
        <vers num="0.9.6a" edition="beta1" />
        <vers num="0.9.6a" edition="beta2" />
        <vers num="0.9.6a" edition="beta3" />
        <vers num="0.9.6b" />
        <vers num="0.9.6c" />
        <vers num="0.9.6d" />
        <vers num="0.9.6e" />
        <vers num="0.9.6f" />
        <vers num="0.9.6g" />
        <vers num="0.9.6h" />
        <vers num="0.9.6i" />
        <vers num="0.9.6j" />
        <vers num="0.9.6k" />
        <vers num="0.9.6l" />
        <vers num="0.9.6m" />
        <vers num="0.9.7" edition="beta1" />
        <vers num="0.9.7" edition="beta2" />
        <vers num="0.9.7" edition="beta3" />
        <vers num="0.9.7" edition="beta4" />
        <vers num="0.9.7" edition="beta5" />
        <vers num="0.9.7" edition="beta6" />
        <vers num="0.9.7a" />
        <vers num="0.9.7b" />
        <vers num="0.9.7c" />
        <vers num="0.9.7d" />
        <vers num="0.9.7e" />
        <vers num="0.9.7f" />
        <vers num="0.9.7g" />
        <vers num="0.9.7h" />
        <vers num="0.9.7i" />
        <vers num="0.9.7j" />
        <vers num="0.9.7k" />
        <vers num="0.9.7l" />
        <vers num="0.9.7m" />
        <vers num="0.9.8" />
        <vers num="0.9.8a" />
        <vers num="0.9.8b" />
        <vers num="0.9.8c" />
        <vers num="0.9.8d" />
        <vers num="0.9.8e" />
        <vers num="0.9.8f" />
        <vers num="0.9.8g" />
        <vers num="0.9.8h" />
        <vers num="0.9.8i" />
        <vers prev="1" num="0.9.8j" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0790" published="2009-04-01" name="CVE-2009-0790" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The pluto IKE daemon in Openswan and Strongswan IPsec 2.6 before 2.6.21 and 2.4 before 2.4.14, and Strongswan 4.2 before 4.2.14 and 2.8 before 2.8.9, allows remote attackers to cause a denial of service (daemon crash and restart) via a crafted (1) R_U_THERE or (2) R_U_THERE_ACK Dead Peer Detection (DPD) IPsec IKE Notification message that triggers a NULL pointer dereference related to inconsistent ISAKMP state and the lack of a phase2 state association in DPD.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/34296" source="BID" patch="1">34296</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1760" source="DEBIAN" patch="1">DSA-1760</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1759" source="DEBIAN" patch="1">DSA-1759</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/49523" source="XF">openswan-strongswan-dpd-dos(49523)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0886" source="VUPEN">ADV-2009-0886</ref>
      <ref url="http://www.securitytracker.com/id?1021950" source="SECTRACK">1021950</ref>
      <ref url="http://www.securitytracker.com/id?1021949" source="SECTRACK">1021949</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/502270/100/0/threaded" source="BUGTRAQ">20090330 CVE-2009-0790: ISAKMP DPD Remote Vulnerability with Openswan &amp; Strongswan IPsec</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-0402.html" source="REDHAT">RHSA-2009:0402</ref>
      <ref url="http://www.openswan.org/CVE-2009-0790/CVE-2009-0790.txt" source="CONFIRM" adv="1">http://www.openswan.org/CVE-2009-0790/CVE-2009-0790.txt</ref>
      <ref url="http://secunia.com/advisories/34546" source="SECUNIA" adv="1">34546</ref>
      <ref url="http://secunia.com/advisories/34494" source="SECUNIA" adv="1">34494</ref>
      <ref url="http://secunia.com/advisories/34483" source="SECUNIA" adv="1">34483</ref>
      <ref url="http://secunia.com/advisories/34472" source="SECUNIA" adv="1">34472</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11171" source="OVAL">oval:org.mitre.oval:def:11171</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-04/msg00010.html" source="SUSE">SUSE-SR:2009:009</ref>
      <ref url="http://download.strongswan.org/CHANGES4.txt" source="CONFIRM" adv="1">http://download.strongswan.org/CHANGES4.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="openswan" name="openswan">
        <vers num="2.4" />
        <vers num="2.4.1" />
        <vers num="2.4.10" />
        <vers num="2.4.2" />
        <vers num="2.4.3" />
        <vers num="2.4.4" />
        <vers num="2.4.5" />
        <vers num="2.4.9" />
        <vers num="2.6.03" />
        <vers num="2.6.04" />
        <vers num="2.6.05" />
        <vers num="2.6.06" />
        <vers num="2.6.07" />
        <vers num="2.6.08" />
        <vers num="2.6.09" />
        <vers num="2.6.10" />
        <vers num="2.6.11" />
        <vers num="2.6.12" />
        <vers num="2.6.13" />
        <vers num="2.6.14" />
        <vers num="2.6.15" />
        <vers num="2.6.16" />
        <vers num="2.6.17" />
        <vers num="2.6.18" />
        <vers num="2.6.19" />
        <vers num="2.6.20" />
      </prod>
      <prod vendor="strongswan" name="strongswan">
        <vers num="2.4.0" />
        <vers num="2.4.0a" />
        <vers num="2.4.1" />
        <vers num="2.4.2" />
        <vers num="2.4.3" />
        <vers num="2.4.4" />
        <vers num="2.6.0" />
        <vers num="2.6.1" />
        <vers num="2.6.2" />
        <vers num="2.6.3" />
        <vers num="2.6.4" />
        <vers num="2.8.0" />
        <vers num="2.8.1" />
        <vers num="2.8.2" />
        <vers num="2.8.3" />
        <vers num="2.8.4" />
        <vers num="2.8.5" />
        <vers num="2.8.6" />
        <vers num="2.8.7" />
        <vers num="2.8.8" />
        <vers num="4.2.0" />
        <vers num="4.2.1" />
        <vers num="4.2.10" />
        <vers num="4.2.11" />
        <vers num="4.2.12" />
        <vers num="4.2.13" />
        <vers num="4.2.2" />
        <vers num="4.2.3" />
        <vers num="4.2.4" />
        <vers num="4.2.5" />
        <vers num="4.2.6" />
        <vers num="4.2.7" />
        <vers num="4.2.8" />
        <vers num="4.2.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0791" published="2009-06-09" name="CVE-2009-0791" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple integer overflows in Xpdf 2.x and 3.x and Poppler 0.x, as used in the pdftops filter in CUPS 1.1.17, 1.1.22, and 1.3.7, GPdf, and kdegraphics KPDF, allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PDF file that triggers a heap-based buffer overflow, possibly related to (1) Decrypt.cxx, (2) FoFiTrueType.cxx, (3) gmem.c, (4) JBIG2Stream.cxx, and (5) PSOutputDev.cxx in pdftops/. NOTE: the JBIG2Stream.cxx vector may overlap CVE-2009-1179.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=491840" source="CONFIRM" patch="1">https://bugzilla.redhat.com/show_bug.cgi?id=491840</ref>
      <ref url="https://rhn.redhat.com/errata/RHSA-2009-1512.html" source="REDHAT">RHSA-2009:1512</ref>
      <ref url="https://rhn.redhat.com/errata/RHSA-2009-1503.html" source="REDHAT">RHSA-2009:1503</ref>
      <ref url="https://rhn.redhat.com/errata/RHSA-2009-1502.html" source="REDHAT">RHSA-2009:1502</ref>
      <ref url="https://rhn.redhat.com/errata/RHSA-2009-1501.html" source="REDHAT">RHSA-2009:1501</ref>
      <ref url="https://rhn.redhat.com/errata/RHSA-2009-1500.html" source="REDHAT">RHSA-2009:1500</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/50941" source="XF">cups-pdftops-filter-bo(50941)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/2928" source="VUPEN">ADV-2009-2928</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1488" source="VUPEN" adv="1">ADV-2009-1488</ref>
      <ref url="http://www.securityfocus.com/bid/35195" source="BID">35195</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-1083.html" source="REDHAT">RHSA-2009:1083</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:334" source="MANDRIVA">MDVSA-2009:334</ref>
      <ref url="http://securitytracker.com/id?1022326" source="SECTRACK">1022326</ref>
      <ref url="http://secunia.com/advisories/37079" source="SECUNIA">37079</ref>
      <ref url="http://secunia.com/advisories/37077" source="SECUNIA">37077</ref>
      <ref url="http://secunia.com/advisories/37043" source="SECUNIA">37043</ref>
      <ref url="http://secunia.com/advisories/37037" source="SECUNIA">37037</ref>
      <ref url="http://secunia.com/advisories/37028" source="SECUNIA">37028</ref>
      <ref url="http://secunia.com/advisories/37023" source="SECUNIA">37023</ref>
      <ref url="http://secunia.com/advisories/35685" source="SECUNIA">35685</ref>
      <ref url="http://secunia.com/advisories/35340" source="SECUNIA" adv="1">35340</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10534" source="OVAL">oval:org.mitre.oval:def:10534</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-07/msg00002.html" source="SUSE">SUSE-SR:2009:012</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="cups">
        <vers num="1.1.17" />
        <vers num="1.1.22" />
        <vers num="1.3.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0792" published="2009-04-14" name="CVE-2009-0792" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Multiple integer overflows in icc.c in the International Color Consortium (ICC) Format library (aka icclib), as used in Ghostscript 8.64 and earlier and Argyll Color Management System (CMS) 1.0.3 and earlier, allow context-dependent attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly execute arbitrary code by using a device file for a translation request that operates on a crafted image file and targets a certain "native color space," related to an ICC profile in a (1) PostScript or (2) PDF file with embedded images.  NOTE: this issue exists because of an incomplete fix for CVE-2009-0583.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-April/msg00461.html" source="FEDORA">FEDORA-2009-3710</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-April/msg00460.html" source="FEDORA">FEDORA-2009-3709</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-April/msg00217.html" source="FEDORA">FEDORA-2009-3435</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-April/msg00211.html" source="FEDORA">FEDORA-2009-3430</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=491853" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=491853</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/50381" source="XF">ghostscript-icc-bo(50381)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1708" source="VUPEN">ADV-2009-1708</ref>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-757-1" source="UBUNTU">USN-757-1</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/502757/100/0/threaded" source="BUGTRAQ">20090417 rPSA-2009-0060-1 ghostscript</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-0421.html" source="REDHAT">RHSA-2009:0421</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-0420.html" source="REDHAT">RHSA-2009:0420</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:096" source="MANDRIVA">MDVSA-2009:096</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:095" source="MANDRIVA">MDVSA-2009:095</ref>
      <ref url="http://wiki.rpath.com/Advisories:rPSA-2009-0060" source="CONFIRM">http://wiki.rpath.com/Advisories:rPSA-2009-0060</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2009-155.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2009-155.htm</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-262288-1" source="SUNALERT">262288</ref>
      <ref url="http://secunia.com/advisories/35569" source="SECUNIA">35569</ref>
      <ref url="http://secunia.com/advisories/35559" source="SECUNIA">35559</ref>
      <ref url="http://secunia.com/advisories/35416" source="SECUNIA">35416</ref>
      <ref url="http://secunia.com/advisories/34732" source="SECUNIA">34732</ref>
      <ref url="http://secunia.com/advisories/34729" source="SECUNIA">34729</ref>
      <ref url="http://secunia.com/advisories/34726" source="SECUNIA">34726</ref>
      <ref url="http://secunia.com/advisories/34711" source="SECUNIA" adv="1">34711</ref>
      <ref url="http://secunia.com/advisories/34667" source="SECUNIA">34667</ref>
      <ref url="http://secunia.com/advisories/34373" source="SECUNIA" adv="1">34373</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11207" source="OVAL">oval:org.mitre.oval:def:11207</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-06/msg00003.html" source="SUSE">SUSE-SR:2009:011</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-04/msg00010.html" source="SUSE">SUSE-SR:2009:009</ref>
    </refs>
    <vuln_soft>
      <prod vendor="argyllcms" name="argyllcms">
        <vers num="0.1.0" />
        <vers num="0.2.0" />
        <vers num="0.2.1" />
        <vers num="0.2.2" />
        <vers num="0.3.0" />
        <vers num="0.6.0" />
        <vers num="0.7.0" edition="beta_8" />
        <vers num="1.0.0" />
        <vers num="1.0.2" />
        <vers prev="1" num="1.0.3" />
      </prod>
      <prod vendor="ghostscript" name="ghostscript">
        <vers num="5.50" />
        <vers num="7.05" />
        <vers num="7.07" />
        <vers num="8.0.1" />
        <vers num="8.15" />
        <vers num="8.15.2" />
        <vers num="8.54" />
        <vers num="8.56" />
        <vers num="8.57" />
        <vers num="8.61" />
        <vers num="8.62" />
        <vers num="8.63" />
        <vers prev="1" num="8.64" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0793" published="2009-04-09" name="CVE-2009-0793" modified="2011-01-20" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">cmsxform.c in LittleCMS (aka lcms or liblcms) 1.18, as used in OpenJDK and other products, allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted image that triggers execution of incorrect code for "transformations of monochrome profiles."</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-May/msg00285.html" source="FEDORA">FEDORA-2009-3967</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-May/msg00233.html" source="FEDORA">FEDORA-2009-3914</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-April/msg00204.html" source="FEDORA">FEDORA-2009-3426</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-April/msg00203.html" source="FEDORA">FEDORA-2009-3425</ref>
      <ref url="https://rhn.redhat.com/errata/RHSA-2009-0377.html" source="REDHAT">RHSA-2009:0377</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=492353" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=492353</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0087" source="VUPEN">ADV-2011-0087</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0964" source="VUPEN" adv="1">ADV-2009-0964</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0963" source="VUPEN" adv="1">ADV-2009-0963</ref>
      <ref url="http://www.ubuntu.com/usn/USN-1043-1" source="UBUNTU">USN-1043-1</ref>
      <ref url="http://www.securityfocus.com/bid/34420" source="BID">34420</ref>
      <ref url="http://www.securityfocus.com/bid/34411" source="BID">34411</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:162" source="MANDRIVA">MDVSA-2009:162</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:137" source="MANDRIVA">MDVSA-2009:137</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:121" source="MANDRIVA">MDVSA-2009:121</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1769" source="DEBIAN">DSA-1769</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200904-19.xml" source="GENTOO">GLSA-200904-19</ref>
      <ref url="http://secunia.com/advisories/42870" source="SECUNIA">42870</ref>
      <ref url="http://secunia.com/advisories/35048" source="SECUNIA">35048</ref>
      <ref url="http://secunia.com/advisories/34782" source="SECUNIA">34782</ref>
      <ref url="http://secunia.com/advisories/34675" source="SECUNIA">34675</ref>
      <ref url="http://secunia.com/advisories/34635" source="SECUNIA" adv="1">34635</ref>
      <ref url="http://secunia.com/advisories/34634" source="SECUNIA" adv="1">34634</ref>
      <ref url="http://secunia.com/advisories/34632" source="SECUNIA">34632</ref>
      <ref url="http://secunia.com/advisories/34623" source="SECUNIA">34623</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11340" source="OVAL">oval:org.mitre.oval:def:11340</ref>
    </refs>
    <vuln_soft>
      <prod vendor="littlecms" name="lcms">
        <vers num="1.18" />
      </prod>
      <prod vendor="sun" name="openjdk">
        <vers num="6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0794" published="2009-04-13" name="CVE-2009-0794" modified="2009-08-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Integer overflow in the PulseAudioTargetDataL class in src/java/org/classpath/icedtea/pulseaudio/PulseAudioTargetDataLine.java in Pulse-Java, as used in OpenJDK 1.6.0.0 and other products, allows remote attackers to cause a denial of service (applet crash) via a crafted Pulse Audio source data line.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-April/msg00204.html" source="FEDORA">FEDORA-2009-3426</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-April/msg00203.html" source="FEDORA">FEDORA-2009-3425</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=492367" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=492367</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/50383" source="XF">pulsejava--pulseaudiotargetdatal-dos(50383)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0965" source="VUPEN">ADV-2009-0965</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:162" source="MANDRIVA">MDVSA-2009:162</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:137" source="MANDRIVA">MDVSA-2009:137</ref>
      <ref url="http://secunia.com/advisories/34623" source="SECUNIA" adv="1">34623</ref>
      <ref url="http://mail.openjdk.java.net/pipermail/distro-pkg-dev/2009-February/004729.html" source="MLIST">[distro-pkg-dev] 20090211 changeset in /hg/icedtea6: 2009-02-11 Omair Majid &lt;omajid at redh...</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="openjdk">
        <vers num="1.6.0.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" seq="2009-0795" reject="1" published="2009-04-07" name="CVE-2009-0795" modified="2009-04-07">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2009-0796, CVE-2009-1265.  Reason: this candidate was intended for one issue, but a typo caused it to be associated with a different issue.  Notes: All CVE users should consult CVE-2009-0796 and CVE-2009-1265 to determine which ID is appropriate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript>
    </desc>
    <refs />
  </entry>
  <entry type="CVE" severity="Low" seq="2009-0796" published="2009-04-07" name="CVE-2009-0796" modified="2010-11-18" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Status.pm in Apache::Status and Apache2::Status in mod_perl1 and mod_perl2 for the Apache HTTP Server, when /perl-status is accessible, allows remote attackers to inject arbitrary web script or HTML via the URI.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://svn.apache.org/viewvc?view=rev&amp;revision=761081" source="CONFIRM" patch="1" adv="1">http://svn.apache.org/viewvc?view=rev&amp;revision=761081</ref>
      <ref url="https://launchpad.net/bugs/cve/2009-0796" source="MISC">https://launchpad.net/bugs/cve/2009-0796</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=494402" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=494402</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0943" source="VUPEN">ADV-2009-0943</ref>
      <ref url="http://www.securitytracker.com/id?1021988" source="SECTRACK">1021988</ref>
      <ref url="http://www.securityfocus.com/bid/34383" source="BID">34383</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/502709/100/0/threaded" source="BUGTRAQ">20090415 XSS with mod_perl perl_status utility</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:091" source="MANDRIVA">MDVSA-2009:091</ref>
      <ref url="http://www.gossamer-threads.com/lists/modperl/modperl/99475#99475" source="MLIST">[modperl] 20090401 [SECURITY] [CVE-2009-0796] Vulnerability found in Apache::Status and Apache2::Status</ref>
      <ref url="http://www.gossamer-threads.com/lists/modperl/modperl-cvs/99477#99477" source="MLIST">[modperl-cvs] 20090401 svn commit: r761081 - in /perl/modperl/branches/1.x: Changes lib/Apache/Status.pm</ref>
      <ref url="http://svn.apache.org/viewvc/perl/modperl/branches/1.x/lib/Apache/Status.pm?r1=177851&amp;r2=761081&amp;pathrev=761081&amp;diff_format=h" source="CONFIRM">http://svn.apache.org/viewvc/perl/modperl/branches/1.x/lib/Apache/Status.pm?r1=177851&amp;r2=761081&amp;pathrev=761081&amp;diff_format=h</ref>
      <ref url="http://support.apple.com/kb/HT4435" source="CONFIRM">http://support.apple.com/kb/HT4435</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-77-1021709.1-1" source="SUNALERT">1021709</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-77-1021508.1-1" source="SUNALERT">1021508</ref>
      <ref url="http://secunia.com/advisories/34597" source="SECUNIA">34597</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:8488" source="OVAL">oval:org.mitre.oval:def:8488</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Nov/msg00000.html" source="APPLE">APPLE-SA-2010-11-10-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apache" name="mod_perl">
        <vers num="1" />
        <vers num="2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0798" published="2009-04-24" name="CVE-2009-0798" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">ACPI Event Daemon (acpid) before 1.0.10 allows remote attackers to cause a denial of service (CPU consumption and connectivity loss) by opening a large number of UNIX sockets without closing them, which triggers an infinite loop.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=494443" source="CONFIRM" patch="1">https://bugzilla.redhat.com/show_bug.cgi?id=494443</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-May/msg01365.html" source="FEDORA">FEDORA-2009-5608</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-May/msg01342.html" source="FEDORA">FEDORA-2009-5578</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=502583" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=502583</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/50060" source="XF">acpid-socket-dos(50060)</ref>
      <ref url="http://www.ubuntu.com/usn/USN-766-1" source="UBUNTU">USN-766-1</ref>
      <ref url="http://www.securitytracker.com/id?1022182" source="SECTRACK">1022182</ref>
      <ref url="http://www.securityfocus.com/bid/34692" source="BID">34692</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-0474.html" source="REDHAT">RHSA-2009:0474</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:107" source="MANDRIVA">MDVSA-2009:107</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200905-06.xml" source="GENTOO">GLSA-200905-06</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1786" source="DEBIAN">DSA-1786</ref>
      <ref url="http://secunia.com/advisories/35231" source="SECUNIA">35231</ref>
      <ref url="http://secunia.com/advisories/35209" source="SECUNIA">35209</ref>
      <ref url="http://secunia.com/advisories/35010" source="SECUNIA">35010</ref>
      <ref url="http://secunia.com/advisories/34918" source="SECUNIA">34918</ref>
      <ref url="http://secunia.com/advisories/34914" source="SECUNIA">34914</ref>
      <ref url="http://secunia.com/advisories/34838" source="SECUNIA" adv="1">34838</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9955" source="OVAL">oval:org.mitre.oval:def:9955</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7560" source="OVAL">oval:org.mitre.oval:def:7560</ref>
    </refs>
    <vuln_soft>
      <prod vendor="tim_hockin" name="acpid">
        <vers num="0.99.0" />
        <vers num="0.99.1" />
        <vers num="0.99.4" />
        <vers num="1.0.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.6" />
        <vers prev="1" num="1.0.8" />
        <vers num="20010510" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0799" published="2009-04-23" name="CVE-2009-0799" modified="2012-01-18" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">The JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, Poppler before 0.10.6, and other products allows remote attackers to cause a denial of service (crash) via a crafted PDF file that triggers an out-of-bounds read.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/196617" source="CERT-VN">VU#196617</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1076" source="VUPEN" patch="1" adv="1">ADV-2009-1076</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1066" source="VUPEN" patch="1" adv="1">ADV-2009-1066</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1065" source="VUPEN" patch="1" adv="1">ADV-2009-1065</ref>
      <ref url="http://www.securityfocus.com/bid/34568" source="BID" patch="1">34568</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-0480.html" source="REDHAT" patch="1">RHSA-2009:0480</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-0431.html" source="REDHAT" patch="1">RHSA-2009:0431</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-0430.html" source="REDHAT" patch="1">RHSA-2009:0430</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-0429.html" source="REDHAT" patch="1">RHSA-2009:0429</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1793" source="DEBIAN" patch="1">DSA-1793</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1790" source="DEBIAN" patch="1">DSA-1790</ref>
      <ref url="http://poppler.freedesktop.org/releases.html" source="CONFIRM" patch="1" adv="1">http://poppler.freedesktop.org/releases.html</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-June/msg01291.html" source="FEDORA">FEDORA-2009-6982</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-June/msg01277.html" source="FEDORA">FEDORA-2009-6973</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-July/msg00567.html" source="FEDORA">FEDORA-2009-6972</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1040" source="VUPEN" adv="1">ADV-2010-1040</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1077" source="VUPEN" adv="1">ADV-2009-1077</ref>
      <ref url="http://www.securitytracker.com/id?1022072" source="SECTRACK">1022072</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2011:175" source="MANDRIVA">MDVSA-2011:175</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2010:087" source="MANDRIVA">MDVSA-2010:087</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:101" source="MANDRIVA">MDVSA-2009:101</ref>
      <ref url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2009&amp;m=slackware-security.578477" source="SLACKWARE">SSA:2009-129-01</ref>
      <ref url="http://secunia.com/advisories/35685" source="SECUNIA" adv="1">35685</ref>
      <ref url="http://secunia.com/advisories/35618" source="SECUNIA" adv="1">35618</ref>
      <ref url="http://secunia.com/advisories/35065" source="SECUNIA" adv="1">35065</ref>
      <ref url="http://secunia.com/advisories/35064" source="SECUNIA" adv="1">35064</ref>
      <ref url="http://secunia.com/advisories/35037" source="SECUNIA" adv="1">35037</ref>
      <ref url="http://secunia.com/advisories/34991" source="SECUNIA" adv="1">34991</ref>
      <ref url="http://secunia.com/advisories/34963" source="SECUNIA" adv="1">34963</ref>
      <ref url="http://secunia.com/advisories/34959" source="SECUNIA" adv="1">34959</ref>
      <ref url="http://secunia.com/advisories/34852" source="SECUNIA" adv="1">34852</ref>
      <ref url="http://secunia.com/advisories/34756" source="SECUNIA" adv="1">34756</ref>
      <ref url="http://secunia.com/advisories/34755" source="SECUNIA" adv="1">34755</ref>
      <ref url="http://secunia.com/advisories/34746" source="SECUNIA" adv="1">34746</ref>
      <ref url="http://secunia.com/advisories/34481" source="SECUNIA" adv="1">34481</ref>
      <ref url="http://secunia.com/advisories/34291" source="SECUNIA" adv="1">34291</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2009-0458.html" source="REDHAT">RHSA-2009:0458</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10204" source="OVAL">oval:org.mitre.oval:def:10204</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-07/msg00002.html" source="SUSE">SUSE-SR:2009:012</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-05/msg00000.html" source="SUSE">SUSE-SR:2009:010</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-04/msg00011.html" source="SUSE">SUSE-SA:2009:024</ref>
      <ref url="http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=495886" source="CONFIRM">http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=495886</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="cups">
        <vers num="1.1" />
        <vers num="1.1.1" />
        <vers num="1.1.10" />
        <vers num="1.1.10-1" />
        <vers num="1.1.11" />
        <vers num="1.1.12" />
        <vers num="1.1.13" />
        <vers num="1.1.14" />
        <vers num="1.1.15" />
        <vers num="1.1.16" />
        <vers num="1.1.17" />
        <vers num="1.1.18" />
        <vers num="1.1.19" edition="rc1" />
        <vers num="1.1.19" edition="rc2" />
        <vers num="1.1.19" edition="rc3" />
        <vers num="1.1.19" edition="rc4" />
        <vers num="1.1.19" edition="rc5" />
        <vers num="1.1.2" />
        <vers num="1.1.20" edition="rc1" />
        <vers num="1.1.20" edition="rc2" />
        <vers num="1.1.20" edition="rc3" />
        <vers num="1.1.20" edition="rc4" />
        <vers num="1.1.20" edition="rc5" />
        <vers num="1.1.20" edition="rc6" />
        <vers num="1.1.21" edition="rc1" />
        <vers num="1.1.21" edition="rc2" />
        <vers num="1.1.22" edition="rc1" />
        <vers num="1.1.22" edition="rc2" />
        <vers num="1.1.23" edition="rc1" />
        <vers num="1.1.3" />
        <vers num="1.1.4" />
        <vers num="1.1.5" />
        <vers num="1.1.5-1" />
        <vers num="1.1.5-2" />
        <vers num="1.1.6" />
        <vers num="1.1.6-1" />
        <vers num="1.1.6-2" />
        <vers num="1.1.6-3" />
        <vers num="1.1.7" />
        <vers num="1.1.8" />
        <vers num="1.1.9" />
        <vers num="1.1.9-1" />
        <vers num="1.2.0" />
        <vers num="1.2.1" />
        <vers num="1.2.10" />
        <vers num="1.2.11" />
        <vers num="1.2.12" />
        <vers num="1.2.2" />
        <vers num="1.2.3" />
        <vers num="1.2.4" />
        <vers num="1.2.5" />
        <vers num="1.2.6" />
        <vers num="1.2.7" />
        <vers num="1.2.8" />
        <vers num="1.2.9" />
        <vers num="1.3.0" />
        <vers num="1.3.1" />
        <vers num="1.3.10" />
        <vers num="1.3.11" />
        <vers num="1.3.2" />
        <vers num="1.3.3" />
        <vers num="1.3.4" />
        <vers num="1.3.5" />
        <vers num="1.3.6" />
        <vers num="1.3.7" />
        <vers num="1.3.8" />
        <vers prev="1" num="1.3.9" />
      </prod>
      <prod vendor="foolabs" name="xpdf">
        <vers num="0.2" />
        <vers num="0.3" />
        <vers num="0.4" />
        <vers num="0.5" />
        <vers num="0.5a" />
        <vers num="0.6" />
        <vers num="0.7" />
        <vers num="0.7a" />
        <vers num="0.80" />
        <vers num="0.90" />
        <vers num="0.91" />
        <vers num="0.91a" />
        <vers num="0.91b" />
        <vers num="0.91c" />
        <vers num="0.92" />
        <vers num="0.92a" />
        <vers num="0.92b" />
        <vers num="0.92c" />
        <vers num="0.92d" />
        <vers num="0.92e" />
        <vers num="0.93" />
        <vers num="0.93a" />
        <vers num="0.93b" />
        <vers num="0.93c" />
        <vers num="1.00" />
        <vers num="1.00a" />
        <vers num="1.01" />
        <vers num="2.00" />
        <vers num="2.01" />
        <vers num="2.02" />
        <vers num="2.03" />
        <vers num="3.00" />
        <vers num="3.01" />
        <vers prev="1" num="3.02" />
      </prod>
      <prod vendor="poppler" name="poppler">
        <vers num="0.1" />
        <vers num="0.1.1" />
        <vers num="0.1.2" />
        <vers num="0.10.0" />
        <vers num="0.10.1" />
        <vers num="0.10.2" />
        <vers num="0.10.3" />
        <vers num="0.10.4" />
        <vers prev="1" num="0.10.5" />
        <vers num="0.2.0" />
        <vers num="0.3.0" />
        <vers num="0.3.1" />
        <vers num="0.3.2" />
        <vers num="0.3.3" />
        <vers num="0.4.0" />
        <vers num="0.4.1" />
        <vers num="0.4.2" />
        <vers num="0.4.3" />
        <vers num="0.4.4" />
        <vers num="0.5.0" />
        <vers num="0.5.1" />
        <vers num="0.5.2" />
        <vers num="0.5.3" />
        <vers num="0.5.4" />
        <vers num="0.5.9" />
        <vers num="0.5.90" />
        <vers num="0.5.91" />
        <vers num="0.6.0" />
        <vers num="0.6.1" />
        <vers num="0.6.2" />
        <vers num="0.6.3" />
        <vers num="0.6.4" />
        <vers num="0.7.0" />
        <vers num="0.7.1" />
        <vers num="0.7.2" />
        <vers num="0.7.3" />
        <vers num="0.8.0" />
        <vers num="0.8.1" />
        <vers num="0.8.2" />
        <vers num="0.8.3" />
        <vers num="0.8.4" />
        <vers num="0.8.5" />
        <vers num="0.8.6" />
        <vers num="0.8.7" />
        <vers num="0.9.0" />
        <vers num="0.9.1" />
        <vers num="0.9.2" />
        <vers num="0.9.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0800" published="2009-04-23" name="CVE-2009-0800" modified="2012-01-18" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple "input validation flaws" in the JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, Poppler before 0.10.6, and other products allow remote attackers to execute arbitrary code via a crafted PDF file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/196617" source="CERT-VN">VU#196617</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-June/msg01291.html" source="FEDORA">FEDORA-2009-6982</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-June/msg01277.html" source="FEDORA">FEDORA-2009-6973</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-July/msg00567.html" source="FEDORA">FEDORA-2009-6972</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=495887" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=495887</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1040" source="VUPEN" adv="1">ADV-2010-1040</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1077" source="VUPEN" adv="1">ADV-2009-1077</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1076" source="VUPEN" adv="1">ADV-2009-1076</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1066" source="VUPEN" adv="1">ADV-2009-1066</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1065" source="VUPEN" adv="1">ADV-2009-1065</ref>
      <ref url="http://www.securitytracker.com/id?1022073" source="SECTRACK">1022073</ref>
      <ref url="http://www.securityfocus.com/bid/34568" source="BID">34568</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-0480.html" source="REDHAT">RHSA-2009:0480</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-0431.html" source="REDHAT">RHSA-2009:0431</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-0430.html" source="REDHAT">RHSA-2009:0430</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-0429.html" source="REDHAT">RHSA-2009:0429</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2011:175" source="MANDRIVA">MDVSA-2011:175</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2010:087" source="MANDRIVA">MDVSA-2010:087</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:101" source="MANDRIVA">MDVSA-2009:101</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1793" source="DEBIAN">DSA-1793</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1790" source="DEBIAN">DSA-1790</ref>
      <ref url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2009&amp;m=slackware-security.578477" source="SLACKWARE">SSA:2009-129-01</ref>
      <ref url="http://secunia.com/advisories/35685" source="SECUNIA">35685</ref>
      <ref url="http://secunia.com/advisories/35618" source="SECUNIA" adv="1">35618</ref>
      <ref url="http://secunia.com/advisories/35065" source="SECUNIA" adv="1">35065</ref>
      <ref url="http://secunia.com/advisories/35064" source="SECUNIA" adv="1">35064</ref>
      <ref url="http://secunia.com/advisories/35037" source="SECUNIA" adv="1">35037</ref>
      <ref url="http://secunia.com/advisories/34991" source="SECUNIA" adv="1">34991</ref>
      <ref url="http://secunia.com/advisories/34963" source="SECUNIA" adv="1">34963</ref>
      <ref url="http://secunia.com/advisories/34959" source="SECUNIA" adv="1">34959</ref>
      <ref url="http://secunia.com/advisories/34852" source="SECUNIA" adv="1">34852</ref>
      <ref url="http://secunia.com/advisories/34756" source="SECUNIA" adv="1">34756</ref>
      <ref url="http://secunia.com/advisories/34755" source="SECUNIA" adv="1">34755</ref>
      <ref url="http://secunia.com/advisories/34746" source="SECUNIA" adv="1">34746</ref>
      <ref url="http://secunia.com/advisories/34481" source="SECUNIA" adv="1">34481</ref>
      <ref url="http://secunia.com/advisories/34291" source="SECUNIA" adv="1">34291</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2009-0458.html" source="REDHAT">RHSA-2009:0458</ref>
      <ref url="http://poppler.freedesktop.org/releases.html" source="CONFIRM">http://poppler.freedesktop.org/releases.html</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11323" source="OVAL">oval:org.mitre.oval:def:11323</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-07/msg00002.html" source="SUSE">SUSE-SR:2009:012</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-05/msg00000.html" source="SUSE">SUSE-SR:2009:010</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-04/msg00011.html" source="SUSE">SUSE-SA:2009:024</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="cups">
        <vers num="1.1" />
        <vers num="1.1.1" />
        <vers num="1.1.10" />
        <vers num="1.1.10-1" />
        <vers num="1.1.11" />
        <vers num="1.1.12" />
        <vers num="1.1.13" />
        <vers num="1.1.14" />
        <vers num="1.1.15" />
        <vers num="1.1.16" />
        <vers num="1.1.17" />
        <vers num="1.1.18" />
        <vers num="1.1.19" edition="rc1" />
        <vers num="1.1.19" edition="rc2" />
        <vers num="1.1.19" edition="rc3" />
        <vers num="1.1.19" edition="rc4" />
        <vers num="1.1.19" edition="rc5" />
        <vers num="1.1.2" />
        <vers num="1.1.20" edition="rc1" />
        <vers num="1.1.20" edition="rc2" />
        <vers num="1.1.20" edition="rc3" />
        <vers num="1.1.20" edition="rc4" />
        <vers num="1.1.20" edition="rc5" />
        <vers num="1.1.20" edition="rc6" />
        <vers num="1.1.21" edition="rc1" />
        <vers num="1.1.21" edition="rc2" />
        <vers num="1.1.22" edition="rc1" />
        <vers num="1.1.22" edition="rc2" />
        <vers num="1.1.23" edition="rc1" />
        <vers num="1.1.3" />
        <vers num="1.1.4" />
        <vers num="1.1.5" />
        <vers num="1.1.5-1" />
        <vers num="1.1.5-2" />
        <vers num="1.1.6" />
        <vers num="1.1.6-1" />
        <vers num="1.1.6-2" />
        <vers num="1.1.6-3" />
        <vers num="1.1.7" />
        <vers num="1.1.8" />
        <vers num="1.1.9" />
        <vers num="1.1.9-1" />
        <vers num="1.2.0" />
        <vers num="1.2.1" />
        <vers num="1.2.10" />
        <vers num="1.2.11" />
        <vers num="1.2.12" />
        <vers num="1.2.2" />
        <vers num="1.2.3" />
        <vers num="1.2.4" />
        <vers num="1.2.5" />
        <vers num="1.2.6" />
        <vers num="1.2.7" />
        <vers num="1.2.8" />
        <vers num="1.2.9" />
        <vers num="1.3.0" />
        <vers num="1.3.1" />
        <vers num="1.3.10" />
        <vers num="1.3.11" />
        <vers num="1.3.2" />
        <vers num="1.3.3" />
        <vers num="1.3.4" />
        <vers num="1.3.5" />
        <vers num="1.3.6" />
        <vers num="1.3.7" />
        <vers num="1.3.8" />
        <vers prev="1" num="1.3.9" />
      </prod>
      <prod vendor="foolabs" name="xpdf">
        <vers num="0.2" />
        <vers num="0.3" />
        <vers num="0.4" />
        <vers num="0.5" />
        <vers num="0.5a" />
        <vers num="0.6" />
        <vers num="0.7" />
        <vers num="0.7a" />
        <vers num="0.80" />
        <vers num="0.90" />
        <vers num="0.91" />
        <vers num="0.91a" />
        <vers num="0.91b" />
        <vers num="0.91c" />
        <vers num="0.92" />
        <vers num="0.92a" />
        <vers num="0.92b" />
        <vers num="0.92c" />
        <vers num="0.92d" />
        <vers num="0.92e" />
        <vers num="0.93" />
        <vers num="0.93a" />
        <vers num="0.93b" />
        <vers num="0.93c" />
        <vers num="1.00" />
        <vers num="1.00a" />
        <vers num="1.01" />
        <vers num="2.00" />
        <vers num="2.01" />
        <vers num="2.02" />
        <vers num="2.03" />
        <vers num="3.00" />
        <vers num="3.01" />
        <vers prev="1" num="3.02" />
      </prod>
      <prod vendor="poppler" name="poppler">
        <vers num="0.1" />
        <vers num="0.1.1" />
        <vers num="0.1.2" />
        <vers num="0.10.0" />
        <vers num="0.10.1" />
        <vers num="0.10.2" />
        <vers num="0.10.3" />
        <vers num="0.10.4" />
        <vers prev="1" num="0.10.5" />
        <vers num="0.2.0" />
        <vers num="0.3.0" />
        <vers num="0.3.1" />
        <vers num="0.3.2" />
        <vers num="0.3.3" />
        <vers num="0.4.0" />
        <vers num="0.4.1" />
        <vers num="0.4.2" />
        <vers num="0.4.3" />
        <vers num="0.4.4" />
        <vers num="0.5.0" />
        <vers num="0.5.1" />
        <vers num="0.5.2" />
        <vers num="0.5.3" />
        <vers num="0.5.4" />
        <vers num="0.5.9" />
        <vers num="0.5.90" />
        <vers num="0.5.91" />
        <vers num="0.6.0" />
        <vers num="0.6.1" />
        <vers num="0.6.2" />
        <vers num="0.6.3" />
        <vers num="0.6.4" />
        <vers num="0.7.0" />
        <vers num="0.7.1" />
        <vers num="0.7.2" />
        <vers num="0.7.3" />
        <vers num="0.8.0" />
        <vers num="0.8.1" />
        <vers num="0.8.2" />
        <vers num="0.8.3" />
        <vers num="0.8.4" />
        <vers num="0.8.5" />
        <vers num="0.8.6" />
        <vers num="0.8.7" />
        <vers num="0.9.0" />
        <vers num="0.9.1" />
        <vers num="0.9.2" />
        <vers num="0.9.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0801" published="2009-03-04" name="CVE-2009-0801" modified="2009-06-18" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:N/A:N)" CVSS_score="5.4" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="4.9" CVSS_base_score="5.4">
    <desc>
      <descript source="cve">Squid, when transparent interception mode is enabled, uses the HTTP Host header to determine the remote endpoint, which allows remote attackers to bypass access controls for Flash, Java, Silverlight, and probably other technologies, and possibly communicate with restricted intranet sites, via a crafted web page that causes a client to send HTTP requests with a modified Host header.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/435052" source="CERT-VN" adv="1">VU#435052</ref>
      <ref url="http://www.securityfocus.com/bid/33858" source="BID">33858</ref>
    </refs>
    <vuln_soft>
      <prod vendor="squid" name="squid_web_proxy_cache">
        <vers num="2.7" />
        <vers num="2.7.stable5" />
        <vers num="2.7.stable6" />
        <vers num="3.0" />
        <vers num="3.0_pre1" />
        <vers num="3.0_pre2" />
        <vers num="3.0_pre3" />
        <vers num="3.0_stable1" />
        <vers num="3.0_stable12" />
        <vers num="3.0_stable13" />
        <vers num="3.0_stable2" />
        <vers num="3.0_stable3" />
        <vers num="3.0_stable4" />
        <vers num="3.0_stable5" />
        <vers num="3.0_stable6" />
        <vers num="3.0_stable7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0802" published="2009-03-04" name="CVE-2009-0802" modified="2009-06-18" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:N/A:N)" CVSS_score="5.4" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="4.9" CVSS_base_score="5.4">
    <desc>
      <descript source="cve">Qbik WinGate, when transparent interception mode is enabled, uses the HTTP Host header to determine the remote endpoint, which allows remote attackers to bypass access controls for Flash, Java, Silverlight, and probably other technologies, and possibly communicate with restricted intranet sites, via a crafted web page that causes a client to send HTTP requests with a modified Host header.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/435052" source="CERT-VN" adv="1">VU#435052</ref>
      <ref url="http://www.securityfocus.com/bid/33858" source="BID">33858</ref>
    </refs>
    <vuln_soft>
      <prod vendor="qbik" name="wingate">
        <vers num="6.0.0" />
        <vers num="6.0.1_build_993" />
        <vers num="6.0.1_build_995" />
        <vers num="6.0.2_build_1000" />
        <vers num="6.0.2_build_1001" />
        <vers num="6.0.3_build_1005" />
        <vers num="6.1" />
        <vers num="6.1.1.1077" />
        <vers num="6.1.2" />
        <vers num="6.1.3" />
        <vers num="6.1.4" />
        <vers num="6.2" />
        <vers num="6.2.1" />
        <vers num="6.2.2" />
        <vers num="6.5.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0803" published="2009-03-04" name="CVE-2009-0803" modified="2009-06-18" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:N/A:N)" CVSS_score="5.4" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="4.9" CVSS_base_score="5.4">
    <desc>
      <descript source="cve">SmoothWall SmoothGuardian, as used in SmoothWall Firewall, NetworkGuardian, and SchoolGuardian 2008, when transparent interception mode is enabled, uses the HTTP Host header to determine the remote endpoint, which allows remote attackers to bypass access controls for Flash, Java, Silverlight, and probably other technologies, and possibly communicate with restricted intranet sites, via a crafted web page that causes a client to send HTTP requests with a modified Host header.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/MAPG-7M6SM7" source="CONFIRM">http://www.kb.cert.org/vuls/id/MAPG-7M6SM7</ref>
      <ref url="http://www.kb.cert.org/vuls/id/435052" source="CERT-VN">VU#435052</ref>
      <ref url="http://www.securityfocus.com/bid/33858" source="BID" adv="1">33858</ref>
    </refs>
    <vuln_soft>
      <prod vendor="smoothwall" name="networkguardian">
        <vers num="2008" />
      </prod>
      <prod vendor="smoothwall" name="schoolguardian">
        <vers num="2008" />
      </prod>
      <prod vendor="smoothwall" name="smoothguardian">
        <vers num="2008" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0804" published="2009-03-04" name="CVE-2009-0804" modified="2009-06-18" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:N/A:N)" CVSS_score="5.4" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="4.9" CVSS_base_score="5.4">
    <desc>
      <descript source="cve">Ziproxy 2.6.0, when transparent interception mode is enabled, uses the HTTP Host header to determine the remote endpoint, which allows remote attackers to bypass access controls for Flash, Java, Silverlight, and probably other technologies, and possibly communicate with restricted intranet sites, via a crafted web page that causes a client to send HTTP requests with a modified Host header.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/435052" source="CERT-VN" adv="1">VU#435052</ref>
      <ref url="http://www.securityfocus.com/bid/33858" source="BID">33858</ref>
      <ref url="http://www.kb.cert.org/vuls/id/MAPG-7N9GN8" source="CONFIRM" adv="1">http://www.kb.cert.org/vuls/id/MAPG-7N9GN8</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ziproxy" name="ziproxy">
        <vers num="2.6.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0805" published="2009-03-04" name="CVE-2009-0805" modified="2009-03-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in piCal 0.91h and earlier, a module for XOOPS, allows remote attackers to inject arbitrary web script or HTML via the event_id parameter in index.php.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xoops.peak.ne.jp/md/news/index.php?page=article&amp;storyid=476&amp;easiestml_lang=xlang%3Aen" source="CONFIRM" patch="1" adv="1">http://xoops.peak.ne.jp/md/news/index.php?page=article&amp;storyid=476&amp;easiestml_lang=xlang%3Aen</ref>
      <ref url="http://xoops.peak.ne.jp/md/news/" source="CONFIRM" patch="1" adv="1">http://xoops.peak.ne.jp/md/news/</ref>
      <ref url="http://www.securityfocus.com/bid/33896" source="BID">33896</ref>
      <ref url="http://secunia.com/advisories/33986" source="SECUNIA" adv="1">33986</ref>
      <ref url="http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-000013.html" source="JVNDB">JVNDB-2009-000013</ref>
      <ref url="http://jvn.jp/en/jp/JVN91591874/index.html" source="JVN">JVN#91591874</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mihai_bazon" name="pical">
        <vers prev="1" num="0.91h" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0806" published="2009-03-04" name="CVE-2009-0806" modified="2009-03-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)" CVSS_score="6.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.0" CVSS_base_score="6.5">
    <desc>
      <descript source="cve">Unspecified vulnerability in OpenGoo before 1.2.1 allows remote authenticated users to modify their own permissions via unknown attack vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/33897" source="BID" patch="1">33897</ref>
      <ref url="http://sourceforge.net/project/shownotes.php?release_id=663706" source="CONFIRM">http://sourceforge.net/project/shownotes.php?release_id=663706</ref>
      <ref url="http://secunia.com/advisories/34044" source="SECUNIA" adv="1">34044</ref>
    </refs>
    <vuln_soft>
      <prod vendor="opengoo" name="opengoo">
        <vers num="0.1" edition="alpha" />
        <vers num="0.2" edition="alpha" />
        <vers num="0.3" edition="alpha" />
        <vers num="0.4" edition="alpha" />
        <vers num="0.5" edition="beta" />
        <vers num="0.5.1" edition="beta" />
        <vers num="0.5.2" edition="beta" />
        <vers num="0.6.0" />
        <vers num="0.6.2" />
        <vers num="0.6.4" />
        <vers num="0.6.6" />
        <vers num="0.7" />
        <vers num="0.7.1" />
        <vers num="0.8" />
        <vers num="0.9" edition="rc2" />
        <vers num="0.9.1" />
        <vers num="0.9.2" />
        <vers num="1.0" edition="rc1" />
        <vers num="1.0" edition="rc2" />
        <vers num="1.0" edition="rc3" />
        <vers num="1.1" edition="beta" />
        <vers num="1.1" edition="rc1" />
        <vers num="1.1" edition="rc2" />
        <vers prev="1" num="1.2" edition="beta" />
        <vers prev="1" num="1.2" edition="beta_2" />
        <vers prev="1" num="1.2" edition="rc1" />
        <vers prev="1" num="1.2" edition="rc2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0807" published="2009-03-04" name="CVE-2009-0807" modified="2009-03-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">zFeeder 1.6 allows remote attackers to gain administrative access via a direct request to admin.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/48866" source="XF">zfeeder-admin-security-bypass(48866)</ref>
      <ref url="http://www.milw0rm.com/exploits/8092" source="MILW0RM">8092</ref>
    </refs>
    <vuln_soft>
      <prod vendor="zfeeder" name="zfeeder">
        <vers num="1.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0808" published="2009-03-04" name="CVE-2009-0808" modified="2009-03-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in SimpleCMMS before 0.1.0 allow remote attackers to execute arbitrary SQL commands via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/48883" source="XF">simplecmms-unspecified-sql-injection(48883)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0490" source="VUPEN" adv="1">ADV-2009-0490</ref>
      <ref url="http://sourceforge.net/project/shownotes.php?release_id=661656&amp;group_id=245458" source="CONFIRM">http://sourceforge.net/project/shownotes.php?release_id=661656&amp;group_id=245458</ref>
    </refs>
    <vuln_soft>
      <prod vendor="simple_cmms" name="simplecmms">
        <vers num="0.1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2009-0809" published="2009-03-04" name="CVE-2009-0809" modified="2009-07-22" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:S/C:P/I:N/A:N)" CVSS_score="3.5" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="6.8" CVSS_base_score="3.5">
    <desc>
      <descript source="cve">The Web Editor in Dassault Systemes ENOVIA SmarTeam V5 before Release 18 Service Pack 8, and possibly CATIA and other products, allows remote authenticated users to read the profile card of an object in the document class via a link that is sent from the owner of the document object.</descript>
      <descript source="nvd">Per http://www-01.ibm.com/support/docview.wss?uid=swg1HD80332

"Scenario:
1. Create a document class and give permissions to joe only.
2. When someone else but joe logs onto Web editor, and does a
   search on this new class no results are returned as expected.
3. Login as joe and search for an object created for this new
   class. click on the email icon, and send the mail to bob.
4. When bob clicks on the link in the email, he can view the
   profile card of the object, but when he clicks on viewer he
   gets an unauthorized operation error. Bob shouldn't be able
   to view the profile card in the first place as he doesn't
   have any access to this class.  This is a security hole in
   the web editor."</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2009/0525" source="VUPEN" adv="1">ADV-2009-0525</ref>
      <ref url="http://www.securityfocus.com/bid/33895" source="BID">33895</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg1HD80332" source="AIXAPAR" adv="1">HD80332</ref>
      <ref url="http://secunia.com/advisories/34037" source="SECUNIA" adv="1">34037</ref>
    </refs>
    <vuln_soft>
      <prod vendor="3ds" name="enovia_smarteam">
        <vers prev="1" num="5.18" />
      </prod>
      <prod vendor="ibm" name="catia">
        <vers num="5.16" />
        <vers num="5.17" />
        <vers prev="1" num="5.18" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0810" published="2009-03-04" name="CVE-2009-0810" modified="2009-03-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in login.php in xGuestbook 2.0 allows remote attackers to execute arbitrary SQL commands via the user parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/48881" source="XF">xguestbook-login-sql-injection(48881)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0523" source="VUPEN" adv="1">ADV-2009-0523</ref>
      <ref url="http://www.securityfocus.com/bid/33875" source="BID">33875</ref>
      <ref url="http://www.milw0rm.com/exploits/8101" source="MILW0RM">8101</ref>
    </refs>
    <vuln_soft>
      <prod vendor="xatrix" name="xguestbook">
        <vers num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0811" published="2009-03-04" name="CVE-2009-0811" modified="2009-03-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Insecure method vulnerability in the SopCast SopCore ActiveX control in sopocx.ocx 3.0.3.501 allows remote attackers to execute arbitrary programs via an executable file name in the argument to the SetExternalPlayer method.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/48955" source="XF">sopcast-setexternalplayer-code-execution(48955)</ref>
      <ref url="http://www.securityfocus.com/bid/33920" source="BID">33920</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/501252/100/0/threaded" source="BUGTRAQ">20090226 Sopcast SopCore Control (sopocx.ocx 3.0.3.501) SetExternalPlayer() user assisted remote code execution poc</ref>
      <ref url="http://retrogod.altervista.org/9sg_sopcastia.html" source="MISC">http://retrogod.altervista.org/9sg_sopcastia.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sopcast" name="sopcore_activex_control">
        <vers num="3.0.3.501" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0812" published="2009-03-04" name="CVE-2009-0812" modified="2009-03-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Stack-based buffer overflow in BreakPoint Software Hex Workshop 4.23, 6.0.1.4603, and other 6.x and earlier versions allows remote attackers to execute arbitrary code via a crafted Intel Hex Code (.hex) file. NOTE: some of these details are obtained from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/48970" source="XF">hexworkshop-hex-bo(48970)</ref>
      <ref url="http://www.securityfocus.com/bid/33932" source="BID">33932</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/501300/100/0/threaded" source="BUGTRAQ">20090227 Hex Workshop &lt;= v6 (.hex) File Local Code</ref>
      <ref url="http://www.milw0rm.com/exploits/8121" source="MILW0RM">8121</ref>
      <ref url="http://secunia.com/advisories/34021" source="SECUNIA" adv="1">34021</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bpsoft" name="hex_workshop">
        <vers num="1.0" />
        <vers num="2.00" />
        <vers num="2.01" />
        <vers num="2.10" />
        <vers num="2.20" />
        <vers num="2.50" />
        <vers num="2.52" />
        <vers num="2.53" />
        <vers num="2.54" />
        <vers num="3.00" />
        <vers num="3.02" />
        <vers num="3.10" />
        <vers num="3.11" />
        <vers num="4.00" />
        <vers num="4.10" />
        <vers num="4.20" />
        <vers num="4.21" />
        <vers num="4.22" />
        <vers num="4.23" />
        <vers num="5.0" />
        <vers num="5.02" />
        <vers num="5.1" />
        <vers num="5.1.3" />
        <vers num="5.1.4" />
        <vers prev="1" num="6.0.0" />
        <vers num="6.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0813" published="2009-03-04" name="CVE-2009-0813" modified="2009-03-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Insecure method vulnerability in the ImeraIEPlugin ActiveX control (ImeraIEPlugin.dll 1.0.2.54) in Imera TeamLinks Client allows remote attackers to force the download and execution of arbitrary URLs via modified DownloadProtocol, DownloadHost, DownloadPort, and DownloadURI parameters.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/49028" source="XF">imera-imeraieplugin-code-execution(49028)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0591" source="VUPEN" adv="1">ADV-2009-0591</ref>
      <ref url="http://www.milw0rm.com/exploits/8144" source="MILW0RM">8144</ref>
      <ref url="http://secunia.com/advisories/34103" source="SECUNIA" adv="1">34103</ref>
    </refs>
    <vuln_soft>
      <prod vendor="imera" name="teamlinks">
        <vers num="-" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0814" published="2009-03-04" name="CVE-2009-0814" modified="2009-03-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Widgets.aspx in Blogsa 1.0 Beta 3 and earlier allows remote attackers to inject arbitrary web script or HTML via the searchText parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/49024" source="XF">blogsa-widgets-xss(49024)</ref>
      <ref url="http://www.securityfocus.com/bid/33957" source="BID">33957</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/501382/100/0/threaded" source="BUGTRAQ">20090302 Blogsa &lt;= 1.0 Beta 3 XSS Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="blogsa" name="blogsa">
        <vers prev="1" num="1.0beta3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0815" published="2009-03-04" name="CVE-2009-0815" modified="2010-04-27" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The jumpUrl mechanism in class.tslib_fe.php in TYPO3 3.3.x through 3.8.x, 4.0 before 4.0.12, 4.1 before 4.1.10, 4.2 before 4.2.6, and 4.3alpha1 leaks a hash secret (juHash) in an error message, which allows remote attackers to read arbitrary files by including the hash in a request.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2009/dsa-1720" source="DEBIAN" patch="1">DSA-1720</ref>
      <ref url="http://typo3.org/teams/security/security-bulletins/typo3-sa-2009-002/" source="CONFIRM" patch="1" adv="1">http://typo3.org/teams/security/security-bulletins/typo3-sa-2009-002/</ref>
      <ref url="http://www.securitytracker.com/id?1021710" source="SECTRACK">1021710</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2009/02/10/6" source="MLIST">[oss-security] 20090210 CVE request: typo3 xss (typo3-sa-2009-002)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="typo3" name="typo3">
        <vers num="3.3.x" />
        <vers num="3.5.x" />
        <vers num="3.6.x" />
        <vers num="3.7.x" />
        <vers num="3.8.x" />
        <vers num="4.0" />
        <vers num="4.1" />
        <vers num="4.1.0" />
        <vers num="4.1.2" />
        <vers num="4.1.3" />
        <vers num="4.1.4" />
        <vers num="4.1.5" />
        <vers num="4.1.6" />
        <vers num="4.1.7" />
        <vers num="4.1.8" />
        <vers num="4.1.9" />
        <vers num="4.2" />
        <vers num="4.2.0" />
        <vers num="4.2.1" />
        <vers num="4.2.2" />
        <vers num="4.2.3" />
        <vers num="4.2.4" />
        <vers num="4.2.5" />
        <vers num="4.3" edition="alpha1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0816" published="2009-03-04" name="CVE-2009-0816" modified="2010-04-27" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in the backend user interface in TYPO3 3.3.x through 3.8.x, 4.0 before 4.0.12, 4.1 before 4.1.10, 4.2 before 4.2.6, and 4.3alpha1 allow remote attackers to inject arbitrary web script or HTML via unspecified fields.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://typo3.org/teams/security/security-bulletins/typo3-sa-2009-002/" source="CONFIRM" patch="1" adv="1">http://typo3.org/teams/security/security-bulletins/typo3-sa-2009-002/</ref>
      <ref url="http://www.securitytracker.com/id?1021709" source="SECTRACK">1021709</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2009/02/10/6" source="MLIST">[oss-security] 20090210 CVE request: typo3 xss (typo3-sa-2009-002)</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1720" source="DEBIAN">DSA-1720</ref>
    </refs>
    <vuln_soft>
      <prod vendor="typo3" name="typo3">
        <vers num="4.0" />
        <vers num="4.0.1" />
        <vers num="4.0.10" />
        <vers num="4.0.11" />
        <vers num="4.0.2" />
        <vers num="4.0.3" />
        <vers num="4.0.4" />
        <vers num="4.0.5" />
        <vers num="4.0.6" />
        <vers num="4.0.7" />
        <vers num="4.0.8" />
        <vers num="4.0.9" />
        <vers num="4.1" />
        <vers num="4.1.1" />
        <vers num="4.1.2" />
        <vers num="4.1.3" />
        <vers num="4.1.4" />
        <vers num="4.1.5" />
        <vers num="4.1.6" />
        <vers num="4.1.7" />
        <vers num="4.1.8" />
        <vers num="4.1.9" />
        <vers num="4.2" />
        <vers num="4.2.1" />
        <vers num="4.2.2" />
        <vers num="4.2.3" />
        <vers num="4.2.4" />
        <vers num="4.2.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2009-0817" published="2009-03-04" name="CVE-2009-0817" modified="2009-06-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:S/C:N/I:P/A:N)" CVSS_score="3.5" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="6.8" CVSS_base_score="3.5">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the Protected Node module 5.x before 5.x-1.4 and 6.x before 6.x-1.5, a module for Drupal, allows remote authenticated users with "administer site configuration" permissions to inject arbitrary web script or HTML via the Password page info field, which is not properly handled by the protected_node_enterpassword function in protected_node.module.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2009/0572" source="VUPEN" patch="1" adv="1">ADV-2009-0572</ref>
      <ref url="http://drupal.org/node/386606" source="CONFIRM" patch="1" adv="1">http://drupal.org/node/386606</ref>
      <ref url="http://drupal.org/node/386604" source="CONFIRM" patch="1" adv="1">http://drupal.org/node/386604</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/48980" source="XF">protectednode-passwordpage-xss(48980)</ref>
      <ref url="http://secunia.com/advisories/34060" source="SECUNIA" adv="1">34060</ref>
      <ref url="http://osvdb.org/52300" source="OSVDB">52300</ref>
      <ref url="http://lampsecurity.org/node/28" source="MISC">http://lampsecurity.org/node/28</ref>
      <ref url="http://drupal.org/node/385950" source="CONFIRM" adv="1">http://drupal.org/node/385950</ref>
    </refs>
    <vuln_soft>
      <prod vendor="drupal" name="protected_node_module">
        <vers num="5.x" />
        <vers num="5.x-1.0" />
        <vers num="5.x-1.2" />
        <vers num="5.x-1.3" />
        <vers num="5.x-1.x-dev" />
        <vers num="6.x-1.0" />
        <vers num="6.x-1.2" />
        <vers num="6.x-1.3" />
        <vers num="6.x-1.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2009-0818" published="2009-03-04" name="CVE-2009-0818" modified="2009-03-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:S/C:N/I:P/A:N)" CVSS_score="3.5" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="6.8" CVSS_base_score="3.5">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the taxonomy_theme_admin_table_builder function (taxonomy_theme_admin.inc) in Taxonomy Theme module before 5.x-1.2, a module for Drupal, allows remote authenticated users with the "administer taxonomy" permission, or the ability to create pages when tagging is enabled, to inject arbitrary web script or HTML via the Vocabulary name (name parameter) to index.php.  NOTE: some of these details are obtained from third party information.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/33923" source="BID" patch="1">33923</ref>
      <ref url="http://drupal.org/node/386942" source="CONFIRM" patch="1" adv="1">http://drupal.org/node/386942</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/48979" source="XF">drupal-taxonomy-name-xss(48979)</ref>
      <ref url="http://secunia.com/advisories/34080" source="SECUNIA" adv="1">34080</ref>
      <ref url="http://osvdb.org/52285" source="OSVDB">52285</ref>
      <ref url="http://drupal.org/node/386940" source="CONFIRM">http://drupal.org/node/386940</ref>
    </refs>
    <vuln_soft>
      <prod vendor="drupal" name="taxonomy_theme_module">
        <vers prev="1" num="5.x-1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0819" published="2009-03-04" name="CVE-2009-0819" modified="2010-11-24" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:N/I:N/A:P)" CVSS_score="4.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.0" CVSS_base_score="4.0">
    <desc>
      <descript source="cve">sql/item_xmlfunc.cc in MySQL 5.1 before 5.1.32 and 6.0 before 6.0.10 allows remote authenticated users to cause a denial of service (crash) via "an XPath expression employing a scalar expression as a FilterExpr with ExtractValue() or UpdateXML()," which triggers an assertion failure.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://bugs.mysql.com/bug.php?id=42495" source="CONFIRM" patch="1" adv="1">http://bugs.mysql.com/bug.php?id=42495</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/49050" source="XF">mysql-xpath-dos(49050)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0594" source="VUPEN" adv="1">ADV-2009-0594</ref>
      <ref url="http://www.securitytracker.com/id?1021786" source="SECTRACK">1021786</ref>
      <ref url="http://www.securityfocus.com/bid/33972" source="BID">33972</ref>
      <ref url="http://secunia.com/advisories/34115" source="SECUNIA" adv="1">34115</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7544" source="OVAL">oval:org.mitre.oval:def:7544</ref>
      <ref url="http://dev.mysql.com/doc/refman/6.0/en/news-6-0-10.html" source="CONFIRM">http://dev.mysql.com/doc/refman/6.0/en/news-6-0-10.html</ref>
      <ref url="http://dev.mysql.com/doc/refman/5.1/en/news-5-1-32.html" source="CONFIRM" adv="1">http://dev.mysql.com/doc/refman/5.1/en/news-5-1-32.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mysql" name="mysql">
        <vers num="5.1" />
        <vers num="5.1.1" />
        <vers num="5.1.10" />
        <vers num="5.1.11" />
        <vers num="5.1.12" />
        <vers num="5.1.13" />
        <vers num="5.1.14" />
        <vers num="5.1.15" />
        <vers num="5.1.16" />
        <vers num="5.1.17" />
        <vers num="5.1.18" />
        <vers num="5.1.19" />
        <vers num="5.1.2" />
        <vers num="5.1.20" />
        <vers num="5.1.21" />
        <vers num="5.1.22" />
        <vers num="5.1.23" edition="a" />
        <vers num="5.1.23_bk" />
        <vers num="5.1.23a" />
        <vers num="5.1.24" />
        <vers num="5.1.25" />
        <vers num="5.1.26" />
        <vers num="5.1.27" />
        <vers num="5.1.28" />
        <vers num="5.1.29" />
        <vers num="5.1.3" />
        <vers num="5.1.30" />
        <vers num="5.1.31" edition="sp1" />
        <vers prev="1" num="5.1.32-bzr" />
        <vers num="6.0.0" />
        <vers num="6.0.1" />
        <vers num="6.0.10-bzr" />
        <vers num="6.0.2" />
        <vers num="6.0.3" />
        <vers num="6.0.4" />
        <vers num="6.0.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0820" published="2009-03-04" name="CVE-2009-0820" modified="2009-03-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple eval injection vulnerabilities in phpScheduleIt before 1.2.11 allow remote attackers to execute arbitrary code via (1) the end_date parameter to reserve.php and (2) the start_date and end_date parameters to check.php.  NOTE: the start_date/reserve.php vector is already covered by CVE-2008-6132.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2009/0491" source="VUPEN" patch="1" adv="1">ADV-2009-0491</ref>
      <ref url="http://sourceforge.net/project/shownotes.php?release_id=662749" source="CONFIRM" patch="1">http://sourceforge.net/project/shownotes.php?release_id=662749</ref>
      <ref url="http://phpscheduleit.svn.sourceforge.net/viewvc/phpscheduleit/1.2.11/reserve.php?r1=318&amp;r2=328" source="CONFIRM" patch="1" adv="1">http://phpscheduleit.svn.sourceforge.net/viewvc/phpscheduleit/1.2.11/reserve.php?r1=318&amp;r2=328</ref>
      <ref url="http://phpscheduleit.svn.sourceforge.net/viewvc/phpscheduleit/1.2.11/check.php?r1=318&amp;r2=332" source="CONFIRM" patch="1" adv="1">http://phpscheduleit.svn.sourceforge.net/viewvc/phpscheduleit/1.2.11/check.php?r1=318&amp;r2=332</ref>
      <ref url="http://secunia.com/advisories/33991" source="SECUNIA" adv="1">33991</ref>
    </refs>
    <vuln_soft>
      <prod vendor="php.brickhost" name="phpscheduleit">
        <vers num="1.0" />
        <vers num="1.0.0rc1" />
        <vers num="1.0_rc1" />
        <vers num="1.2.0" edition="beta" />
        <vers num="1.2.0" edition="rc1" />
        <vers num="1.2.1" />
        <vers prev="1" num="1.2.10" />
        <vers num="1.2.2" />
        <vers num="1.2.3" />
        <vers num="1.2.4" />
        <vers num="1.2.5" />
        <vers num="1.2.6" />
        <vers num="1.2.7" />
        <vers num="1.2.8" />
        <vers num="1.2.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0821" published="2009-03-04" name="CVE-2009-0821" modified="2009-03-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Mozilla Firefox 2.0.0.20 and earlier allows remote attackers to cause a denial of service (application crash) via nested calls to the window.print function, as demonstrated by a window.print(window.print()) in the onclick attribute of an INPUT element.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/33969" source="BID">33969</ref>
      <ref url="http://downloads.securityfocus.com/vulnerabilities/exploits/33969.html" source="MISC">http://downloads.securityfocus.com/vulnerabilities/exploits/33969.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="0.1" />
        <vers num="0.10" />
        <vers num="0.10.1" />
        <vers num="0.2" />
        <vers num="0.3" />
        <vers num="0.4" />
        <vers num="0.5" />
        <vers num="0.6" />
        <vers num="0.6.1" />
        <vers num="0.7" />
        <vers num="0.7.1" />
        <vers num="0.8" />
        <vers num="0.9" edition="rc" />
        <vers num="0.9.1" />
        <vers num="0.9.2" />
        <vers num="0.9.3" />
        <vers num="0.9_rc" />
        <vers num="1.0" edition="preview_release" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.5" />
        <vers num="1.0.6" edition="" />
        <vers num="1.0.6" edition=":linux" />
        <vers num="1.0.7" />
        <vers num="1.0.8" />
        <vers num="1.5" edition="beta1" />
        <vers num="1.5" edition="beta2" />
        <vers num="1.5.0.1" />
        <vers num="1.5.0.10" />
        <vers num="1.5.0.11" />
        <vers num="1.5.0.12" />
        <vers num="1.5.0.2" />
        <vers num="1.5.0.3" />
        <vers num="1.5.0.4" />
        <vers num="1.5.0.5" />
        <vers num="1.5.0.6" />
        <vers num="1.5.0.7" />
        <vers num="1.5.0.8" />
        <vers num="1.5.0.9" />
        <vers num="1.5.1" />
        <vers num="1.5.2" />
        <vers num="1.5.3" />
        <vers num="1.5.4" />
        <vers num="1.5.5" />
        <vers num="1.5.6" />
        <vers num="1.5.7" />
        <vers num="1.5.8" />
        <vers num="1.8" />
        <vers num="2.0" edition="beta1" />
        <vers num="2.0" edition="beta_1" />
        <vers num="2.0" edition="rc2" />
        <vers num="2.0" edition="rc3" />
        <vers num="2.0.0.1" />
        <vers num="2.0.0.10" />
        <vers num="2.0.0.11" />
        <vers num="2.0.0.12" />
        <vers num="2.0.0.13" />
        <vers num="2.0.0.14" />
        <vers num="2.0.0.15" />
        <vers num="2.0.0.16" />
        <vers num="2.0.0.17" />
        <vers num="2.0.0.18" />
        <vers num="2.0.0.19" />
        <vers num="2.0.0.2" />
        <vers prev="1" num="2.0.0.20" />
        <vers num="2.0.0.3" />
        <vers num="2.0.0.4" />
        <vers num="2.0.0.5" />
        <vers num="2.0.0.6" />
        <vers num="2.0.0.7" />
        <vers num="2.0.0.8" />
        <vers num="2.0.0.9" />
        <vers num="2.0_.1" />
        <vers num="2.0_.10" />
        <vers num="2.0_.4" />
        <vers num="2.0_.5" />
        <vers num="2.0_.6" />
        <vers num="2.0_.7" />
        <vers num="2.0_.9" />
        <vers num="2.0_8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0824" published="2009-03-14" name="CVE-2009-0824" modified="2009-03-25" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="4.9" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="3.9" CVSS_base_score="4.9">
    <desc>
      <descript source="cve">Elaborate Bytes ElbyCDIO.sys 6.0.2.0 and earlier, as distributed in SlySoft AnyDVD before 6.5.2.6, Virtual CloneDrive 5.4.2.3 and earlier, CloneDVD 2.9.2.0 and earlier, and CloneCD 5.3.1.3 and earlier, uses the METHOD_NEITHER communication method for IOCTLs and does not properly validate a buffer associated with the Irp object, which allows local users to cause a denial of service (system crash) via a crafted IOCTL call.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/49232" source="XF">slysoft-elbycdio-dos(49232)</ref>
      <ref url="http://www.slysoft.com/download/changes_clonedvd.txt" source="CONFIRM">http://www.slysoft.com/download/changes_clonedvd.txt</ref>
      <ref url="http://www.slysoft.com/download/changes_anydvd.txt" source="CONFIRM">http://www.slysoft.com/download/changes_anydvd.txt</ref>
      <ref url="http://www.securityfocus.com/bid/34103" source="BID">34103</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/501713/100/0/threaded" source="BUGTRAQ">20090312 [Suspected Spam][PT-2009-11] SlySoft Multiple Products ElbyCDIO.sys Denial of Service</ref>
      <ref url="http://secunia.com/advisories/34289" source="SECUNIA">34289</ref>
      <ref url="http://secunia.com/advisories/34288" source="SECUNIA">34288</ref>
      <ref url="http://secunia.com/advisories/34287" source="SECUNIA">34287</ref>
      <ref url="http://secunia.com/advisories/34269" source="SECUNIA">34269</ref>
      <ref url="http://osvdb.org/52679" source="OSVDB">52679</ref>
      <ref url="http://en.securitylab.ru/lab/PT-2009-11" source="MISC">http://en.securitylab.ru/lab/PT-2009-11</ref>
    </refs>
    <vuln_soft>
      <prod vendor="slysoft" name="anydvd">
        <vers prev="1" num="6.5.2.2" />
      </prod>
      <prod vendor="slysoft" name="clonecd">
        <vers prev="1" num="5.3.1.3" />
      </prod>
      <prod vendor="slysoft" name="clonedvd">
        <vers prev="1" num="2.9.2.0" />
      </prod>
      <prod vendor="slysoft" name="virtualclonedrive">
        <vers prev="1" num="5.4.2.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0825" published="2009-03-09" name="CVE-2009-0825" modified="2009-03-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in system/rss.php in TinX/cms 3.x before 3.5.1 allows remote attackers to execute arbitrary SQL commands via the id parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/34021" source="BID" patch="1">34021</ref>
      <ref url="http://sourceforge.net/project/showfiles.php?group_id=133415" source="CONFIRM" patch="1">http://sourceforge.net/project/showfiles.php?group_id=133415</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/49115" source="XF">tinxcms-rss-sql-injection(49115)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/501547/100/0/threaded" source="BUGTRAQ">20090306 [Positive Technologies SA:2009-13] TinX CMS 3.x SQL Injection Vulnerability</ref>
      <ref url="http://sourceforge.net/project/shownotes.php?group_id=133415&amp;release_id=658540" source="CONFIRM">http://sourceforge.net/project/shownotes.php?group_id=133415&amp;release_id=658540</ref>
      <ref url="http://secunia.com/advisories/34178" source="SECUNIA">34178</ref>
      <ref url="http://en.securitylab.ru/lab/PT-2009-13" source="MISC">http://en.securitylab.ru/lab/PT-2009-13</ref>
    </refs>
    <vuln_soft>
      <prod vendor="torben_sorensen" name="tinx/cms">
        <vers num="3.0" />
        <vers prev="1" num="3.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0826" published="2009-03-05" name="CVE-2009-0826" modified="2009-03-06" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">BlogHelper stores common_db.inc under the web root with insufficient access control, which allows remote attackers to download the database file containing user credentials via a direct request.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/47799" source="XF">bloghelper-commondb-info-disclosure(47799)</ref>
      <ref url="http://www.milw0rm.com/exploits/7689" source="MILW0RM">7689</ref>
      <ref url="http://secunia.com/advisories/33384" source="SECUNIA" adv="1">33384</ref>
    </refs>
    <vuln_soft>
      <prod vendor="freedville" name="bloghelper">
        <vers num="-" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0827" published="2009-03-05" name="CVE-2009-0827" modified="2009-03-06" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">PollHelper stores poll.inc under the web root with insufficient access control, which allows remote attackers to download the database file containing user credentials via a direct request.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/47797" source="XF">pollhelper-poll-info-disclosure(47797)</ref>
      <ref url="http://www.milw0rm.com/exploits/7690" source="MILW0RM">7690</ref>
      <ref url="http://secunia.com/advisories/33378" source="SECUNIA" adv="1">33378</ref>
      <ref url="http://osvdb.org/51185" source="OSVDB">51185</ref>
    </refs>
    <vuln_soft>
      <prod vendor="freedville" name="pollhelper">
        <vers num="-" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0828" published="2009-03-05" name="CVE-2009-0828" modified="2009-03-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">QuoteBook stores quotes.inc under the web root with insufficient access control, which allows remote attackers to obtain sensitive database information, including user credentials, via a direct request.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/33166" source="BID">33166</ref>
      <ref url="http://www.milw0rm.com/exploits/7699" source="MILW0RM">7699</ref>
      <ref url="http://secunia.com/advisories/33420" source="SECUNIA" adv="1">33420</ref>
    </refs>
    <vuln_soft>
      <prod vendor="freedville" name="quotebook">
        <vers num="-" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0829" published="2009-03-05" name="CVE-2009-0829" modified="2009-03-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in QuoteBook allow remote attackers to execute arbitrary SQL commands via the (1) MyBox and (2) selectFavorites parameters to (a) quotes.php and the (3) QuoteName and (4) QuoteText parameters to (b) quotesadd.php.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/33166" source="BID">33166</ref>
      <ref url="http://secunia.com/advisories/33420" source="SECUNIA" adv="1">33420</ref>
    </refs>
    <vuln_soft>
      <prod vendor="andrew_freed" name="quotebook">
        <vers num="-" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0830" published="2009-03-05" name="CVE-2009-0830" modified="2009-03-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in QuoteBook allows remote attackers to inject arbitrary web script or HTML via the (1) QuoteName and (2) QuoteText parameters to quotesadd.php.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/33166" source="BID">33166</ref>
      <ref url="http://secunia.com/advisories/33420" source="SECUNIA" adv="1">33420</ref>
    </refs>
    <vuln_soft>
      <prod vendor="andrew_freed" name="quotebook">
        <vers num="-" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0831" published="2009-03-05" name="CVE-2009-0831" modified="2009-03-06" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:S/C:P/I:P/A:P)" CVSS_score="6.0" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="6.8" CVSS_base_score="6.0">
    <desc>
      <descript source="cve">SQL injection vulnerability in members.php in the Members CV (job) module 1.0 for PHP-Fusion, when magic_quotes_gpc is disabled, allows remote authenticated users to execute arbitrary SQL commands via the sortby parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/33156" source="BID">33156</ref>
      <ref url="http://www.milw0rm.com/exploits/7697" source="MILW0RM">7697</ref>
      <ref url="http://secunia.com/advisories/33424" source="SECUNIA" adv="1">33424</ref>
    </refs>
    <vuln_soft>
      <prod vendor="php-fusion" name="members_cv_module">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0832" published="2009-03-05" name="CVE-2009-0832" modified="2009-03-06" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in items.php in the E-Cart module 1.3 for PHP-Fusion allows remote attackers to execute arbitrary SQL commands via the CA parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/33155" source="BID">33155</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/499835/100/0/threaded" source="BUGTRAQ">20090107 PHP-Fusion Mod E-Cart Sql Injection</ref>
      <ref url="http://www.milw0rm.com/exploits/7698" source="MILW0RM">7698</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ausimods" name="e-cart">
        <vers num="1.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0833" published="2009-03-05" name="CVE-2009-0833" modified="2009-03-06" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Heap-based buffer overflow in gen_msn.dll in the gen_msn plugin 0.31 for Winamp 5.541 allows remote attackers to execute arbitrary code via a playlist (.pls) file with a long URL in the File1 field.  NOTE: some of these details are obtained from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/33159" source="BID">33159</ref>
      <ref url="http://www.milw0rm.com/exploits/7696" source="MILW0RM">7696</ref>
      <ref url="http://secunia.com/advisories/33425" source="SECUNIA" adv="1">33425</ref>
    </refs>
    <vuln_soft>
      <prod vendor="myplugins" name="gen_msn">
        <vers num="0.31" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2009-0834" published="2009-03-06" name="CVE-2009-0834" modified="2010-12-28" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="3.6" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="3.9" CVSS_base_score="3.6">
    <desc>
      <descript source="cve">The audit_syscall_entry function in the Linux kernel 2.6.28.7 and earlier on the x86_64 platform does not properly handle (1) a 32-bit process making a 64-bit syscall or (2) a 64-bit process making a 32-bit syscall, which allows local users to bypass certain syscall audit configurations via crafted syscalls, a related issue to CVE-2009-0342 and CVE-2009-0343.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=487990" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=487990</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/49061" source="XF">linux-kernel-auditsyscallentry-sec-bypass(49061)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/3316" source="VUPEN" adv="1">ADV-2009-3316</ref>
      <ref url="http://www.vmware.com/security/advisories/VMSA-2009-0016.html" source="CONFIRM">http://www.vmware.com/security/advisories/VMSA-2009-0016.html</ref>
      <ref url="http://www.ubuntu.com/usn/usn-751-1" source="UBUNTU">USN-751-1</ref>
      <ref url="http://www.securitytracker.com/id?1022153" source="SECTRACK">1022153</ref>
      <ref url="http://www.securityfocus.com/bid/33951" source="BID">33951</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/507985/100/0/threaded" source="BUGTRAQ">20091120 VMSA-2009-0016 VMware vCenter and ESX update release and vMA patch release address multiple security issue in third party components</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/503610/100/0/threaded" source="BUGTRAQ">20090516 rPSA-2009-0084-1 kernel</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-0451.html" source="REDHAT">RHSA-2009:0451</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:118" source="MANDRIVA">MDVSA-2009:118</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1800" source="DEBIAN">DSA-1800</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1794" source="DEBIAN">DSA-1794</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1787" source="DEBIAN">DSA-1787</ref>
      <ref url="http://wiki.rpath.com/Advisories:rPSA-2009-0084" source="CONFIRM">http://wiki.rpath.com/Advisories:rPSA-2009-0084</ref>
      <ref url="http://secunia.com/advisories/37471" source="SECUNIA" adv="1">37471</ref>
      <ref url="http://secunia.com/advisories/35394" source="SECUNIA" adv="1">35394</ref>
      <ref url="http://secunia.com/advisories/35390" source="SECUNIA" adv="1">35390</ref>
      <ref url="http://secunia.com/advisories/35185" source="SECUNIA" adv="1">35185</ref>
      <ref url="http://secunia.com/advisories/35121" source="SECUNIA" adv="1">35121</ref>
      <ref url="http://secunia.com/advisories/35120" source="SECUNIA" adv="1">35120</ref>
      <ref url="http://secunia.com/advisories/35015" source="SECUNIA" adv="1">35015</ref>
      <ref url="http://secunia.com/advisories/35011" source="SECUNIA" adv="1">35011</ref>
      <ref url="http://secunia.com/advisories/34981" source="SECUNIA" adv="1">34981</ref>
      <ref url="http://secunia.com/advisories/34962" source="SECUNIA" adv="1">34962</ref>
      <ref url="http://secunia.com/advisories/34917" source="SECUNIA" adv="1">34917</ref>
      <ref url="http://secunia.com/advisories/34084" source="SECUNIA" adv="1">34084</ref>
      <ref url="http://scary.beasts.org/security/CESA-2009-001.html" source="MISC">http://scary.beasts.org/security/CESA-2009-001.html</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2009-0473.html" source="REDHAT">RHSA-2009:0473</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2009-0459.html" source="REDHAT">RHSA-2009:0459</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9600" source="OVAL">oval:org.mitre.oval:def:9600</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:8508" source="OVAL">oval:org.mitre.oval:def:8508</ref>
      <ref url="http://marc.info/?l=oss-security&amp;m=123597642832637&amp;w=2" source="MLIST">[oss-security] 20090302 CVE request: kernel: x86-64: syscall-audit: 32/64 syscall hole</ref>
      <ref url="http://marc.info/?l=linux-kernel&amp;m=123579065130246&amp;w=2" source="MLIST">[linux-kernel] 20090228 [PATCH 1/2] x86-64: syscall-audit: fix 32/64 syscall hole</ref>
      <ref url="http://marc.info/?l=linux-kernel&amp;m=123579056530191&amp;w=2" source="MLIST">[linux-kernel] 20090228 [PATCH 0/2] x86-64: 32/64 syscall arch holes</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-06/msg00001.html" source="SUSE">SUSE-SA:2009:031</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-06/msg00000.html" source="SUSE">SUSE-SA:2009:030</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-05/msg00002.html" source="SUSE">SUSE-SA:2009:028</ref>
      <ref url="http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=ccbe495caa5e604b04d5a31d7459a6f6a76a756c" source="CONFIRM" adv="1">http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=ccbe495caa5e604b04d5a31d7459a6f6a76a756c</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="kernel">
        <vers num="2.6.0" />
        <vers num="2.6.1" />
        <vers num="2.6.10" />
        <vers num="2.6.11" />
        <vers num="2.6.11.1" />
        <vers num="2.6.11.10" />
        <vers num="2.6.11.11" />
        <vers num="2.6.11.12" />
        <vers num="2.6.11.2" />
        <vers num="2.6.11.3" />
        <vers num="2.6.11.4" />
        <vers num="2.6.11.5" />
        <vers num="2.6.11.6" />
        <vers num="2.6.11.7" />
        <vers num="2.6.11.8" />
        <vers num="2.6.11.9" />
        <vers num="2.6.12" />
        <vers num="2.6.12.1" />
        <vers num="2.6.12.2" />
        <vers num="2.6.12.3" />
        <vers num="2.6.12.4" />
        <vers num="2.6.12.5" />
        <vers num="2.6.12.6" />
        <vers num="2.6.13" />
        <vers num="2.6.13.1" />
        <vers num="2.6.13.2" />
        <vers num="2.6.13.3" />
        <vers num="2.6.13.4" />
        <vers num="2.6.13.5" />
        <vers num="2.6.14" />
        <vers num="2.6.14.1" />
        <vers num="2.6.14.2" />
        <vers num="2.6.14.3" />
        <vers num="2.6.14.4" />
        <vers num="2.6.14.5" />
        <vers num="2.6.14.6" />
        <vers num="2.6.14.7" />
        <vers num="2.6.15" />
        <vers num="2.6.15.1" />
        <vers num="2.6.15.2" />
        <vers num="2.6.15.3" />
        <vers num="2.6.15.4" />
        <vers num="2.6.15.5" />
        <vers num="2.6.15.6" />
        <vers num="2.6.15.7" />
        <vers num="2.6.16" edition="rc1" />
        <vers num="2.6.16.1" />
        <vers num="2.6.16.10" />
        <vers num="2.6.16.11" />
        <vers num="2.6.16.12" />
        <vers num="2.6.16.13" />
        <vers num="2.6.16.14" />
        <vers num="2.6.16.15" />
        <vers num="2.6.16.16" />
        <vers num="2.6.16.17" />
        <vers num="2.6.16.18" />
        <vers num="2.6.16.19" />
        <vers num="2.6.16.2" />
        <vers num="2.6.16.20" />
        <vers num="2.6.16.21" />
        <vers num="2.6.16.22" />
        <vers num="2.6.16.23" />
        <vers num="2.6.16.24" />
        <vers num="2.6.16.25" />
        <vers num="2.6.16.26" />
        <vers num="2.6.16.27" />
        <vers num="2.6.16.28" />
        <vers num="2.6.16.29" />
        <vers num="2.6.16.3" />
        <vers num="2.6.16.30" />
        <vers num="2.6.16.31" />
        <vers num="2.6.16.32" />
        <vers num="2.6.16.33" />
        <vers num="2.6.16.34" />
        <vers num="2.6.16.35" />
        <vers num="2.6.16.36" />
        <vers num="2.6.16.37" />
        <vers num="2.6.16.38" />
        <vers num="2.6.16.39" />
        <vers num="2.6.16.4" />
        <vers num="2.6.16.40" />
        <vers num="2.6.16.41" />
        <vers num="2.6.16.42" />
        <vers num="2.6.16.43" />
        <vers num="2.6.16.44" />
        <vers num="2.6.16.45" />
        <vers num="2.6.16.46" />
        <vers num="2.6.16.47" />
        <vers num="2.6.16.48" />
        <vers num="2.6.16.49" />
        <vers num="2.6.16.5" />
        <vers num="2.6.16.50" />
        <vers num="2.6.16.51" />
        <vers num="2.6.16.52" />
        <vers num="2.6.16.53" />
        <vers num="2.6.16.54" />
        <vers num="2.6.16.55" />
        <vers num="2.6.16.56" />
        <vers num="2.6.16.57" />
        <vers num="2.6.16.58" />
        <vers num="2.6.16.59" />
        <vers num="2.6.16.6" />
        <vers num="2.6.16.60" />
        <vers num="2.6.16.61" />
        <vers num="2.6.16.62" />
        <vers num="2.6.16.7" />
        <vers num="2.6.16.8" />
        <vers num="2.6.16.9" />
        <vers num="2.6.17" edition="rc1" />
        <vers num="2.6.17" edition="rc2" />
        <vers num="2.6.17" edition="rc3" />
        <vers num="2.6.17" edition="rc4" />
        <vers num="2.6.17" edition="rc5" />
        <vers num="2.6.17" edition="rc6" />
        <vers num="2.6.17.1" />
        <vers num="2.6.17.10" />
        <vers num="2.6.17.11" />
        <vers num="2.6.17.12" />
        <vers num="2.6.17.13" />
        <vers num="2.6.17.14" />
        <vers num="2.6.17.2" />
        <vers num="2.6.17.3" />
        <vers num="2.6.17.4" />
        <vers num="2.6.17.5" />
        <vers num="2.6.17.6" />
        <vers num="2.6.17.7" />
        <vers num="2.6.17.8" />
        <vers num="2.6.17.9" />
        <vers num="2.6.18" edition="rc1" />
        <vers num="2.6.18" edition="rc2" />
        <vers num="2.6.18" edition="rc3" />
        <vers num="2.6.18" edition="rc4" />
        <vers num="2.6.18" edition="rc5" />
        <vers num="2.6.18" edition="rc6" />
        <vers num="2.6.18" edition="rc7" />
        <vers num="2.6.18.1" />
        <vers num="2.6.18.2" />
        <vers num="2.6.18.3" />
        <vers num="2.6.18.4" />
        <vers num="2.6.18.5" />
        <vers num="2.6.18.6" />
        <vers num="2.6.18.7" />
        <vers num="2.6.18.8" />
        <vers num="2.6.19" />
        <vers num="2.6.19.1" />
        <vers num="2.6.19.2" />
        <vers num="2.6.19.3" />
        <vers num="2.6.19.4" />
        <vers num="2.6.19.5" />
        <vers num="2.6.19.6" />
        <vers num="2.6.19.7" />
        <vers num="2.6.2" />
        <vers num="2.6.20" />
        <vers num="2.6.20.1" />
        <vers num="2.6.20.10" />
        <vers num="2.6.20.11" />
        <vers num="2.6.20.12" />
        <vers num="2.6.20.13" />
        <vers num="2.6.20.14" />
        <vers num="2.6.20.15" />
        <vers num="2.6.20.16" />
        <vers num="2.6.20.17" />
        <vers num="2.6.20.18" />
        <vers num="2.6.20.19" />
        <vers num="2.6.20.2" />
        <vers num="2.6.20.20" />
        <vers num="2.6.20.21" />
        <vers num="2.6.20.3" />
        <vers num="2.6.20.4" />
        <vers num="2.6.20.5" />
        <vers num="2.6.20.6" />
        <vers num="2.6.20.7" />
        <vers num="2.6.20.8" />
        <vers num="2.6.20.9" />
        <vers num="2.6.21" />
        <vers num="2.6.21.1" />
        <vers num="2.6.21.2" />
        <vers num="2.6.21.3" />
        <vers num="2.6.21.4" />
        <vers num="2.6.21.5" />
        <vers num="2.6.21.6" />
        <vers num="2.6.21.7" />
        <vers num="2.6.22" />
        <vers num="2.6.22.1" />
        <vers num="2.6.22.10" />
        <vers num="2.6.22.11" />
        <vers num="2.6.22.12" />
        <vers num="2.6.22.13" />
        <vers num="2.6.22.14" />
        <vers num="2.6.22.15" />
        <vers num="2.6.22.16" />
        <vers num="2.6.22.17" />
        <vers num="2.6.22.18" />
        <vers num="2.6.22.19" />
        <vers num="2.6.22.2" />
        <vers num="2.6.22.20" />
        <vers num="2.6.22.21" />
        <vers num="2.6.22.22" />
        <vers num="2.6.22.3" />
        <vers num="2.6.22.4" />
        <vers num="2.6.22.5" />
        <vers num="2.6.22.6" />
        <vers num="2.6.22.7" />
        <vers num="2.6.22.8" />
        <vers num="2.6.22.9" />
        <vers num="2.6.23" edition="rc1" />
        <vers num="2.6.23" edition="rc2" />
        <vers num="2.6.23.1" />
        <vers num="2.6.23.10" />
        <vers num="2.6.23.11" />
        <vers num="2.6.23.12" />
        <vers num="2.6.23.13" />
        <vers num="2.6.23.14" />
        <vers num="2.6.23.15" />
        <vers num="2.6.23.16" />
        <vers num="2.6.23.17" />
        <vers num="2.6.23.2" />
        <vers num="2.6.23.3" />
        <vers num="2.6.23.4" />
        <vers num="2.6.23.5" />
        <vers num="2.6.23.6" />
        <vers num="2.6.23.7" />
        <vers num="2.6.23.8" />
        <vers num="2.6.23.9" />
        <vers num="2.6.24" edition="rc1" />
        <vers num="2.6.24" edition="rc2" />
        <vers num="2.6.24" edition="rc3" />
        <vers num="2.6.24" edition="rc4" />
        <vers num="2.6.24" edition="rc5" />
        <vers num="2.6.24.1" />
        <vers num="2.6.24.2" />
        <vers num="2.6.24.3" />
        <vers num="2.6.24.4" />
        <vers num="2.6.24.5" />
        <vers num="2.6.24.6" />
        <vers num="2.6.24.7" />
        <vers num="2.6.25" />
        <vers num="2.6.25.1" />
        <vers num="2.6.25.10" />
        <vers num="2.6.25.11" />
        <vers num="2.6.25.12" />
        <vers num="2.6.25.13" />
        <vers num="2.6.25.14" />
        <vers num="2.6.25.15" />
        <vers num="2.6.25.16" />
        <vers num="2.6.25.17" />
        <vers num="2.6.25.18" />
        <vers num="2.6.25.19" />
        <vers num="2.6.25.2" />
        <vers num="2.6.25.20" />
        <vers num="2.6.25.3" />
        <vers num="2.6.25.4" />
        <vers num="2.6.25.5" />
        <vers num="2.6.25.6" />
        <vers num="2.6.25.7" />
        <vers num="2.6.25.8" />
        <vers num="2.6.25.9" />
        <vers num="2.6.26" edition="rc4" />
        <vers num="2.6.26.1" />
        <vers num="2.6.26.2" />
        <vers num="2.6.26.3" />
        <vers num="2.6.26.4" />
        <vers num="2.6.26.5" />
        <vers num="2.6.26.6" />
        <vers num="2.6.26.7" />
        <vers num="2.6.26.8" />
        <vers num="2.6.27" edition="rc1" />
        <vers num="2.6.27" edition="rc2" />
        <vers num="2.6.27" edition="rc3" />
        <vers num="2.6.27" edition="rc4" />
        <vers num="2.6.27" edition="rc5" />
        <vers num="2.6.27" edition="rc6" />
        <vers num="2.6.27" edition="rc7" />
        <vers num="2.6.27" edition="rc8" />
        <vers num="2.6.27" edition="rc9" />
        <vers num="2.6.27.1" />
        <vers num="2.6.27.10" />
        <vers num="2.6.27.11" />
        <vers num="2.6.27.12" />
        <vers num="2.6.27.13" />
        <vers num="2.6.27.14" />
        <vers num="2.6.27.15" />
        <vers num="2.6.27.16" />
        <vers num="2.6.27.17" />
        <vers num="2.6.27.18" />
        <vers num="2.6.27.19" />
        <vers num="2.6.27.2" />
        <vers num="2.6.27.20" />
        <vers num="2.6.27.21" />
        <vers num="2.6.27.22" />
        <vers num="2.6.27.23" />
        <vers num="2.6.27.24" />
        <vers num="2.6.27.25" />
        <vers num="2.6.27.26" />
        <vers num="2.6.27.27" />
        <vers num="2.6.27.28" />
        <vers num="2.6.27.29" />
        <vers num="2.6.27.3" />
        <vers num="2.6.27.30" />
        <vers num="2.6.27.31" />
        <vers num="2.6.27.32" />
        <vers num="2.6.27.33" />
        <vers num="2.6.27.34" />
        <vers num="2.6.27.35" />
        <vers num="2.6.27.36" />
        <vers num="2.6.27.37" />
        <vers num="2.6.27.38" />
        <vers num="2.6.27.39" />
        <vers num="2.6.27.4" />
        <vers num="2.6.27.40" />
        <vers num="2.6.27.41" />
        <vers num="2.6.27.42" />
        <vers num="2.6.27.43" />
        <vers num="2.6.27.44" />
        <vers num="2.6.27.45" />
        <vers num="2.6.27.5" />
        <vers num="2.6.27.51" />
        <vers num="2.6.27.52" />
        <vers num="2.6.27.53" />
        <vers num="2.6.27.54" />
        <vers num="2.6.27.6" />
        <vers num="2.6.27.7" />
        <vers num="2.6.27.8" />
        <vers num="2.6.27.9" />
        <vers num="2.6.28" />
        <vers num="2.6.28.1" />
        <vers num="2.6.28.2" />
        <vers num="2.6.28.3" />
        <vers num="2.6.28.4" />
        <vers num="2.6.28.5" />
        <vers num="2.6.28.6" />
        <vers prev="1" num="2.6.28.7" />
        <vers num="2.6.3" />
        <vers num="2.6.4" />
        <vers num="2.6.5" />
        <vers num="2.6.6" />
        <vers num="2.6.7" />
        <vers num="2.6.8" />
        <vers num="2.6.8.1" />
        <vers num="2.6.9" edition="rc1" />
        <vers num="2.6.9" edition="rc2" />
        <vers num="2.6.9" edition="rc3" />
        <vers num="2.6.9" edition="rc4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2009-0835" published="2009-03-06" name="CVE-2009-0835" modified="2009-06-12" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="3.6" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="3.9" CVSS_base_score="3.6">
    <desc>
      <descript source="cve">The __secure_computing function in kernel/seccomp.c in the seccomp subsystem in the Linux kernel 2.6.28.7 and earlier on the x86_64 platform, when CONFIG_SECCOMP is enabled, does not properly handle (1) a 32-bit process making a 64-bit syscall or (2) a 64-bit process making a 32-bit syscall, which allows local users to bypass intended access restrictions via crafted syscalls that are misinterpreted as (a) stat or (b) chmod, a related issue to CVE-2009-0342 and CVE-2009-0343.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=487255" source="MISC">https://bugzilla.redhat.com/show_bug.cgi?id=487255</ref>
      <ref url="http://www.ubuntu.com/usn/usn-751-1" source="UBUNTU">USN-751-1</ref>
      <ref url="http://www.securityfocus.com/bid/33948" source="BID">33948</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-0451.html" source="REDHAT">RHSA-2009:0451</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:118" source="MANDRIVA">MDVSA-2009:118</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1800" source="DEBIAN">DSA-1800</ref>
      <ref url="http://secunia.com/advisories/35394" source="SECUNIA" adv="1">35394</ref>
      <ref url="http://secunia.com/advisories/35390" source="SECUNIA" adv="1">35390</ref>
      <ref url="http://secunia.com/advisories/35185" source="SECUNIA" adv="1">35185</ref>
      <ref url="http://secunia.com/advisories/35121" source="SECUNIA" adv="1">35121</ref>
      <ref url="http://secunia.com/advisories/34917" source="SECUNIA" adv="1">34917</ref>
      <ref url="http://secunia.com/advisories/34786" source="SECUNIA">34786</ref>
      <ref url="http://secunia.com/advisories/34084" source="SECUNIA" adv="1">34084</ref>
      <ref url="http://scarybeastsecurity.blogspot.com/2009/02/linux-kernel-minor-seccomp.html" source="MISC">http://scarybeastsecurity.blogspot.com/2009/02/linux-kernel-minor-seccomp.html</ref>
      <ref url="http://scary.beasts.org/security/CESA-2009-004.html" source="MISC">http://scary.beasts.org/security/CESA-2009-004.html</ref>
      <ref url="http://scary.beasts.org/security/CESA-2009-001.html" source="MISC">http://scary.beasts.org/security/CESA-2009-001.html</ref>
      <ref url="http://marc.info/?l=oss-security&amp;m=123597627132485&amp;w=2" source="MLIST">[oss-security] 20090302 CVE request: kernel: x86-64: seccomp: 32/64 syscall hole</ref>
      <ref url="http://marc.info/?l=linux-kernel&amp;m=123579069630311&amp;w=2" source="MLIST">[linux-kernel] 20090228 [PATCH 2/2] x86-64: seccomp: fix 32/64 syscall hole</ref>
      <ref url="http://marc.info/?l=linux-kernel&amp;m=123579056530191&amp;w=2" source="MLIST">[linux-kernel] 20090228 [PATCH 0/2] x86-64: 32/64 syscall arch holes</ref>
      <ref url="http://lkml.org/lkml/2009/2/28/23" source="MLIST">[linux-kernel] 20090227 Re: [PATCH 2/2] x86-64: seccomp: fix 32/64 syscall hole</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-06/msg00001.html" source="SUSE">SUSE-SA:2009:031</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-06/msg00000.html" source="SUSE">SUSE-SA:2009:030</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-05/msg00002.html" source="SUSE">SUSE-SA:2009:028</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-04/msg00007.html" source="SUSE">SUSE-SA:2009:021</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="kernel">
        <vers num="2.6.25" edition="" />
        <vers num="2.6.25" edition=":x86_64" />
        <vers num="2.6.25.1" edition="" />
        <vers num="2.6.25.1" edition=":x86_64" />
        <vers num="2.6.25.10" edition="" />
        <vers num="2.6.25.10" edition=":x86_64" />
        <vers num="2.6.25.11" edition="" />
        <vers num="2.6.25.11" edition=":x86_64" />
        <vers num="2.6.25.12" edition="" />
        <vers num="2.6.25.12" edition=":x86_64" />
        <vers num="2.6.25.2" edition="" />
        <vers num="2.6.25.2" edition=":x86_64" />
        <vers num="2.6.25.3" edition="" />
        <vers num="2.6.25.3" edition=":x86_64" />
        <vers num="2.6.25.4" edition="" />
        <vers num="2.6.25.4" edition=":x86_64" />
        <vers num="2.6.25.5" edition="" />
        <vers num="2.6.25.5" edition=":x86_64" />
        <vers num="2.6.25.6" edition="" />
        <vers num="2.6.25.6" edition=":x86_64" />
        <vers num="2.6.25.7" edition="" />
        <vers num="2.6.25.7" edition=":x86_64" />
        <vers num="2.6.25.8" edition="" />
        <vers num="2.6.25.8" edition=":x86_64" />
        <vers num="2.6.25.9" edition="" />
        <vers num="2.6.25.9" edition=":x86_64" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0836" published="2009-03-10" name="CVE-2009-0836" modified="2010-04-06" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Foxit Reader 2.3 before Build 3902 and 3.0 before Build 1506, including 1120 and 1301, does not require user confirmation before performing dangerous actions defined in a PDF file, which allows remote attackers to execute arbitrary programs and have unspecified other impact via a crafted file, as demonstrated by the "Open/Execute a file" action.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.foxitsoftware.com/pdf/reader/security.htm#bypass" source="CONFIRM" patch="1" adv="1">http://www.foxitsoftware.com/pdf/reader/security.htm#bypass</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0634" source="VUPEN" adv="1">ADV-2009-0634</ref>
      <ref url="http://www.securitytracker.com/id?1021824" source="SECTRACK">1021824</ref>
      <ref url="http://www.securityfocus.com/bid/34035" source="BID" adv="1">34035</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/501623/100/0/threaded" source="BUGTRAQ">20090309 Foxit Reader Multiple Vulnerabilities (CORE-2009-0218)</ref>
      <ref url="http://www.coresecurity.com/content/foxit-reader-vulnerabilities" source="MISC" adv="1">http://www.coresecurity.com/content/foxit-reader-vulnerabilities</ref>
      <ref url="http://secunia.com/advisories/34036" source="SECUNIA" adv="1">34036</ref>
      <ref url="http://lists.immunitysec.com/pipermail/dailydave/2010-April/006079.html" source="MLIST">[dailydave] 20100402 0day, it may not be</ref>
      <ref url="http://blog.zoller.lu/2009/03/remote-code-execution-in-pdf-still.html" source="MISC">http://blog.zoller.lu/2009/03/remote-code-execution-in-pdf-still.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="foxitsoftware" name="reader">
        <vers num="2.3" />
        <vers num="3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0837" published="2009-03-10" name="CVE-2009-0837" modified="2009-03-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Stack-based buffer overflow in Foxit Reader 3.0 before Build 1506, including 1120 and 1301, allows remote attackers to execute arbitrary code via a long (1) relative path or (2) absolute path in the filename argument in an action, as demonstrated by the "Open/Execute a file" action.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/49136" source="XF">foxitreader-pdf-bo(49136)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0634" source="VUPEN" adv="1">ADV-2009-0634</ref>
      <ref url="http://www.securitytracker.com/id?1021824" source="SECTRACK">1021824</ref>
      <ref url="http://www.securityfocus.com/bid/34035" source="BID">34035</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/501623/100/0/threaded" source="BUGTRAQ">20090309 Foxit Reader Multiple Vulnerabilities (CORE-2009-0218)</ref>
      <ref url="http://www.foxitsoftware.com/pdf/reader/security.htm#Stackbased" source="CONFIRM" adv="1">http://www.foxitsoftware.com/pdf/reader/security.htm#Stackbased</ref>
      <ref url="http://www.coresecurity.com/content/foxit-reader-vulnerabilities" source="MISC" adv="1">http://www.coresecurity.com/content/foxit-reader-vulnerabilities</ref>
      <ref url="http://secunia.com/advisories/34036" source="SECUNIA" adv="1">34036</ref>
    </refs>
    <vuln_soft>
      <prod vendor="foxit" name="reader3.0">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0838" published="2009-03-06" name="CVE-2009-0838" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="4.9" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="3.9" CVSS_base_score="4.9">
    <desc>
      <descript source="cve">The crypto pseudo device driver in Sun Solaris 10, and OpenSolaris snv_88 through snv_102, does not properly free memory, which allows local users to cause a denial of service (panic) via unspecified vectors, related to the vmem_hash_delete function.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-254088-1" source="SUNALERT" patch="1" adv="1">254088</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-21-139498-04-1" source="CONFIRM" patch="1" adv="1">http://sunsolve.sun.com/search/document.do?assetkey=1-21-139498-04-1</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/49105" source="XF">sun-solaris-cryptodriver-dos(49105)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0815" source="VUPEN">ADV-2009-0815</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0606" source="VUPEN" adv="1">ADV-2009-0606</ref>
      <ref url="http://www.securityfocus.com/bid/34000" source="BID">34000</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2009-097.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2009-097.htm</ref>
      <ref url="http://securitytracker.com/id?1021810" source="SECTRACK">1021810</ref>
      <ref url="http://secunia.com/advisories/34455" source="SECUNIA">34455</ref>
      <ref url="http://secunia.com/advisories/34149" source="SECUNIA" adv="1">34149</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5641" source="OVAL">oval:org.mitre.oval:def:5641</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="opensolaris">
        <vers num="snv_100" edition="" />
        <vers num="snv_100" edition=":x86" />
        <vers num="snv_100" edition=":sparc" />
        <vers num="snv_101" edition="" />
        <vers num="snv_101" edition=":x86" />
        <vers num="snv_101" edition=":sparc" />
        <vers num="snv_101b" />
        <vers num="snv_102" edition="" />
        <vers num="snv_102" edition=":x86" />
        <vers num="snv_102" edition=":sparc" />
        <vers num="snv_88" edition="" />
        <vers num="snv_88" edition=":x86" />
        <vers num="snv_88" edition=":sparc" />
        <vers num="snv_89" edition="" />
        <vers num="snv_89" edition=":x86" />
        <vers num="snv_89" edition=":sparc" />
        <vers num="snv_90" edition="" />
        <vers num="snv_90" edition=":sparc" />
        <vers num="snv_90" edition="x86" />
        <vers num="snv_91" edition="" />
        <vers num="snv_91" edition=":x86" />
        <vers num="snv_91" edition=":sparc" />
        <vers num="snv_92" edition="" />
        <vers num="snv_92" edition=":sparc" />
        <vers num="snv_92" edition=":x86" />
        <vers num="snv_93" edition="" />
        <vers num="snv_93" edition=":x86" />
        <vers num="snv_93" edition=":sparc" />
        <vers num="snv_94" edition="" />
        <vers num="snv_94" edition=":x86" />
        <vers num="snv_94" edition=":sparc" />
        <vers num="snv_95" edition="" />
        <vers num="snv_95" edition=":x86" />
        <vers num="snv_95" edition=":sparc" />
        <vers num="snv_96" edition="" />
        <vers num="snv_96" edition=":sparc" />
        <vers num="snv_96" edition=":x86" />
        <vers num="snv_97" edition="" />
        <vers num="snv_97" edition=":x86" />
        <vers num="snv_97" edition=":sparc" />
        <vers num="snv_98" edition="" />
        <vers num="snv_98" edition=":x86" />
        <vers num="snv_98" edition=":sparc" />
        <vers num="snv_99" edition="" />
        <vers num="snv_99" edition=":sparc" />
        <vers num="snv_99" edition=":x86" />
      </prod>
      <prod vendor="sun" name="solaris">
        <vers num="10" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0839" published="2009-03-31" name="CVE-2009-0839" modified="2009-10-27" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Stack-based buffer overflow in mapserv.c in mapserv in MapServer 4.x before 4.10.4 and 5.x before 5.2.2, when the server has a map with a long IMAGEPATH or NAME attribute, allows remote attackers to execute arbitrary code via a crafted id parameter in a query action.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-April/msg00170.html" source="FEDORA">FEDORA-2009-3383</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-April/msg00147.html" source="FEDORA">FEDORA-2009-3357</ref>
      <ref url="http://www.securitytracker.com/id?1021952" source="SECTRACK">1021952</ref>
      <ref url="http://www.securityfocus.com/bid/34306" source="BID">34306</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/502271/100/0/threaded" source="BUGTRAQ">20090330 Positron Security Advisory #2009-000: Multiple Vulnerabilities in MapServer v5.2.1 and v4.10.3</ref>
      <ref url="http://www.positronsecurity.com/advisories/2009-000.html" source="MISC">http://www.positronsecurity.com/advisories/2009-000.html</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1914" source="DEBIAN">DSA-1914</ref>
      <ref url="http://trac.osgeo.org/mapserver/ticket/2944" source="CONFIRM" adv="1">http://trac.osgeo.org/mapserver/ticket/2944</ref>
      <ref url="http://secunia.com/advisories/34603" source="SECUNIA">34603</ref>
      <ref url="http://secunia.com/advisories/34520" source="SECUNIA">34520</ref>
      <ref url="http://lists.osgeo.org/pipermail/mapserver-users/2009-March/060600.html" source="MLIST">[mapserver-users] 20090326 MapServer 5.2.2 and 4.10.4 released with security fixes</ref>
    </refs>
    <vuln_soft>
      <prod vendor="umn" name="mapserver">
        <vers num="4.0" edition="beta1" />
        <vers num="4.0" edition="beta2" />
        <vers num="4.10" edition="beta1" />
        <vers num="4.10" edition="beta2" />
        <vers num="4.10" edition="beta3" />
        <vers num="4.10" edition="rc1" />
        <vers num="4.10.0" />
        <vers num="4.10.1" />
        <vers num="4.10.2" />
        <vers num="4.10.3" />
        <vers num="4.2" edition="beta1" />
        <vers num="4.4.0" edition="beta1" />
        <vers num="4.4.0" edition="beta2" />
        <vers num="4.4.0" edition="beta3" />
        <vers num="4.6.0" edition="beta1" />
        <vers num="4.6.0" edition="beta2" />
        <vers num="4.6.0" edition="beta3" />
        <vers num="4.6.0" edition="rc1" />
        <vers num="4.8" edition="beta1" />
        <vers num="4.8" edition="beta2" />
        <vers num="4.8" edition="beta3" />
        <vers num="4.8" edition="rc1" />
        <vers num="4.8" edition="rc2" />
        <vers num="5.0.0" edition="beta1" />
        <vers num="5.0.0" edition="beta2" />
        <vers num="5.0.0" edition="beta3" />
        <vers num="5.0.0" edition="beta4" />
        <vers num="5.0.0" edition="beta5" />
        <vers num="5.0.0" edition="beta6" />
        <vers num="5.0.0" edition="rc1" />
        <vers num="5.0.0" edition="rc2" />
        <vers num="5.2.0" edition="beta1" />
        <vers num="5.2.0" edition="beta2" />
        <vers num="5.2.0" edition="beta3" />
        <vers num="5.2.0" edition="beta4" />
        <vers num="5.2.0" edition="rc1" />
        <vers num="5.2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0840" published="2009-03-31" name="CVE-2009-0840" modified="2009-10-27" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Heap-based buffer underflow in the readPostBody function in cgiutil.c in mapserv in MapServer 4.x before 4.10.4 and 5.x before 5.2.2 allows remote attackers to have an unknown impact via a negative value in the Content-Length HTTP header.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://lists.osgeo.org/pipermail/mapserver-users/2009-March/060600.html" source="MLIST" patch="1">[mapserver-users] 20090326 MapServer 5.2.2 and 4.10.4 released with security fixes</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-April/msg00170.html" source="FEDORA">FEDORA-2009-3383</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-April/msg00147.html" source="FEDORA">FEDORA-2009-3357</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/49545" source="XF">mapserver-contentlength-bo(49545)</ref>
      <ref url="http://www.securitytracker.com/id?1021952" source="SECTRACK">1021952</ref>
      <ref url="http://www.securityfocus.com/bid/34306" source="BID">34306</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/502271/100/0/threaded" source="BUGTRAQ">20090330 Positron Security Advisory #2009-000: Multiple Vulnerabilities in MapServer v5.2.1 and v4.10.3</ref>
      <ref url="http://www.positronsecurity.com/advisories/2009-000.html" source="MISC">http://www.positronsecurity.com/advisories/2009-000.html</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1914" source="DEBIAN">DSA-1914</ref>
      <ref url="http://trac.osgeo.org/mapserver/ticket/2943" source="CONFIRM" adv="1">http://trac.osgeo.org/mapserver/ticket/2943</ref>
      <ref url="http://secunia.com/advisories/34603" source="SECUNIA">34603</ref>
      <ref url="http://secunia.com/advisories/34520" source="SECUNIA">34520</ref>
    </refs>
    <vuln_soft>
      <prod vendor="umn" name="mapserver">
        <vers num="4.0" edition="beta1" />
        <vers num="4.0" edition="beta2" />
        <vers num="4.10" edition="beta1" />
        <vers num="4.10" edition="beta2" />
        <vers num="4.10" edition="beta3" />
        <vers num="4.10" edition="rc1" />
        <vers num="4.10.0" />
        <vers num="4.10.1" />
        <vers num="4.10.2" />
        <vers num="4.10.3" />
        <vers num="4.2" edition="beta1" />
        <vers num="4.4.0" edition="beta1" />
        <vers num="4.4.0" edition="beta2" />
        <vers num="4.4.0" edition="beta3" />
        <vers num="4.6.0" edition="beta1" />
        <vers num="4.6.0" edition="beta2" />
        <vers num="4.6.0" edition="beta3" />
        <vers num="4.6.0" edition="rc1" />
        <vers num="4.8" edition="beta1" />
        <vers num="4.8" edition="beta2" />
        <vers num="4.8" edition="beta3" />
        <vers num="4.8" edition="rc1" />
        <vers num="4.8" edition="rc2" />
        <vers num="5.0.0" edition="beta1" />
        <vers num="5.0.0" edition="beta2" />
        <vers num="5.0.0" edition="beta3" />
        <vers num="5.0.0" edition="beta4" />
        <vers num="5.0.0" edition="beta5" />
        <vers num="5.0.0" edition="beta6" />
        <vers num="5.0.0" edition="rc1" />
        <vers num="5.0.0" edition="rc2" />
        <vers num="5.2.0" edition="beta1" />
        <vers num="5.2.0" edition="beta2" />
        <vers num="5.2.0" edition="beta3" />
        <vers num="5.2.0" edition="beta4" />
        <vers num="5.2.0" edition="rc1" />
        <vers num="5.2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0841" published="2009-03-31" name="CVE-2009-0841" modified="2009-10-27" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in mapserv.c in mapserv in MapServer 4.x before 4.10.4 and 5.x before 5.2.2, when running on Windows with Cygwin, allows remote attackers to create arbitrary files via a .. (dot dot) in the id parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://lists.osgeo.org/pipermail/mapserver-users/2009-March/060600.html" source="MLIST" patch="1">[mapserver-users] 20090326 MapServer 5.2.2 and 4.10.4 released with security fixes</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-April/msg00170.html" source="FEDORA">FEDORA-2009-3383</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-April/msg00147.html" source="FEDORA">FEDORA-2009-3357</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/49548" source="XF">mapserver-mapserv-dir-traversal(49548)</ref>
      <ref url="http://www.securitytracker.com/id?1021952" source="SECTRACK">1021952</ref>
      <ref url="http://www.securityfocus.com/bid/34306" source="BID">34306</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/502271/100/0/threaded" source="BUGTRAQ">20090330 Positron Security Advisory #2009-000: Multiple Vulnerabilities in MapServer v5.2.1 and v4.10.3</ref>
      <ref url="http://www.positronsecurity.com/advisories/2009-000.html" source="MISC">http://www.positronsecurity.com/advisories/2009-000.html</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1914" source="DEBIAN">DSA-1914</ref>
      <ref url="http://trac.osgeo.org/mapserver/ticket/2942" source="CONFIRM" adv="1">http://trac.osgeo.org/mapserver/ticket/2942</ref>
      <ref url="http://secunia.com/advisories/34603" source="SECUNIA">34603</ref>
      <ref url="http://secunia.com/advisories/34520" source="SECUNIA">34520</ref>
    </refs>
    <vuln_soft>
      <prod vendor="umn" name="mapserver">
        <vers num="4.0" edition="beta1" />
        <vers num="4.0" edition="beta2" />
        <vers num="4.10" edition="beta1" />
        <vers num="4.10" edition="beta2" />
        <vers num="4.10" edition="beta3" />
        <vers num="4.10" edition="rc1" />
        <vers num="4.10.0" />
        <vers num="4.10.1" />
        <vers num="4.10.2" />
        <vers num="4.10.3" />
        <vers num="4.2" edition="beta1" />
        <vers num="4.4.0" edition="beta1" />
        <vers num="4.4.0" edition="beta2" />
        <vers num="4.4.0" edition="beta3" />
        <vers num="4.6.0" edition="beta1" />
        <vers num="4.6.0" edition="beta2" />
        <vers num="4.6.0" edition="beta3" />
        <vers num="4.6.0" edition="rc1" />
        <vers num="4.8" edition="beta1" />
        <vers num="4.8" edition="beta2" />
        <vers num="4.8" edition="beta3" />
        <vers num="4.8" edition="rc1" />
        <vers num="4.8" edition="rc2" />
        <vers num="5.0.0" edition="beta1" />
        <vers num="5.0.0" edition="beta2" />
        <vers num="5.0.0" edition="beta3" />
        <vers num="5.0.0" edition="beta4" />
        <vers num="5.0.0" edition="beta5" />
        <vers num="5.0.0" edition="beta6" />
        <vers num="5.0.0" edition="rc1" />
        <vers num="5.0.0" edition="rc2" />
        <vers num="5.2.0" edition="beta1" />
        <vers num="5.2.0" edition="beta2" />
        <vers num="5.2.0" edition="beta3" />
        <vers num="5.2.0" edition="beta4" />
        <vers num="5.2.0" edition="rc1" />
        <vers num="5.2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0842" published="2009-03-31" name="CVE-2009-0842" modified="2009-10-27" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">mapserv in MapServer 4.x before 4.10.4 and 5.x before 5.2.2 allows remote attackers to read arbitrary invalid .map files via a full pathname in the map parameter, which triggers the display of partial file contents within an error message, as demonstrated by a /tmp/sekrut.map symlink.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://lists.osgeo.org/pipermail/mapserver-users/2009-March/060600.html" source="MLIST" patch="1" adv="1">[mapserver-users] 20090326 MapServer 5.2.2 and 4.10.4 released with security fixes</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-April/msg00170.html" source="FEDORA">FEDORA-2009-3383</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-April/msg00147.html" source="FEDORA">FEDORA-2009-3357</ref>
      <ref url="http://www.securitytracker.com/id?1021952" source="SECTRACK">1021952</ref>
      <ref url="http://www.securityfocus.com/bid/34306" source="BID">34306</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/502271/100/0/threaded" source="BUGTRAQ">20090330 Positron Security Advisory #2009-000: Multiple Vulnerabilities in MapServer v5.2.1 and v4.10.3</ref>
      <ref url="http://www.positronsecurity.com/advisories/2009-000.html" source="MISC">http://www.positronsecurity.com/advisories/2009-000.html</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1914" source="DEBIAN">DSA-1914</ref>
      <ref url="http://trac.osgeo.org/mapserver/ticket/2941" source="CONFIRM">http://trac.osgeo.org/mapserver/ticket/2941</ref>
      <ref url="http://secunia.com/advisories/34603" source="SECUNIA">34603</ref>
      <ref url="http://secunia.com/advisories/34520" source="SECUNIA">34520</ref>
    </refs>
    <vuln_soft>
      <prod vendor="umn" name="mapserver">
        <vers num="4.0" edition="beta1" />
        <vers num="4.0" edition="beta2" />
        <vers num="4.10" edition="beta1" />
        <vers num="4.10" edition="beta2" />
        <vers num="4.10" edition="beta3" />
        <vers num="4.10" edition="rc1" />
        <vers num="4.10.0" />
        <vers num="4.10.1" />
        <vers num="4.10.2" />
        <vers num="4.10.3" />
        <vers num="4.2" edition="beta1" />
        <vers num="4.4.0" edition="beta1" />
        <vers num="4.4.0" edition="beta2" />
        <vers num="4.4.0" edition="beta3" />
        <vers num="4.6.0" edition="beta1" />
        <vers num="4.6.0" edition="beta2" />
        <vers num="4.6.0" edition="beta3" />
        <vers num="4.6.0" edition="rc1" />
        <vers num="4.8" edition="beta1" />
        <vers num="4.8" edition="beta2" />
        <vers num="4.8" edition="beta3" />
        <vers num="4.8" edition="rc1" />
        <vers num="4.8" edition="rc2" />
        <vers num="5.0.0" edition="beta1" />
        <vers num="5.0.0" edition="beta2" />
        <vers num="5.0.0" edition="beta3" />
        <vers num="5.0.0" edition="beta4" />
        <vers num="5.0.0" edition="beta5" />
        <vers num="5.0.0" edition="beta6" />
        <vers num="5.0.0" edition="rc1" />
        <vers num="5.0.0" edition="rc2" />
        <vers num="5.2.0" edition="beta1" />
        <vers num="5.2.0" edition="beta2" />
        <vers num="5.2.0" edition="beta3" />
        <vers num="5.2.0" edition="beta4" />
        <vers num="5.2.0" edition="rc1" />
        <vers num="5.2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0843" published="2009-03-31" name="CVE-2009-0843" modified="2009-10-27" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:N/A:N)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">The msLoadQuery function in mapserv in MapServer 4.x before 4.10.4 and 5.x before 5.2.2 allows remote attackers to determine the existence of arbitrary files via a full pathname in the queryfile parameter, which triggers different error messages depending on whether this pathname exists.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://lists.osgeo.org/pipermail/mapserver-users/2009-March/060600.html" source="MLIST" patch="1">[mapserver-users] 20090326 MapServer 5.2.2 and 4.10.4 released with security fixes</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-April/msg00170.html" source="FEDORA">FEDORA-2009-3383</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-April/msg00147.html" source="FEDORA">FEDORA-2009-3357</ref>
      <ref url="http://www.securitytracker.com/id?1021952" source="SECTRACK">1021952</ref>
      <ref url="http://www.securityfocus.com/bid/34306" source="BID">34306</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/502271/100/0/threaded" source="BUGTRAQ">20090330 Positron Security Advisory #2009-000: Multiple Vulnerabilities in MapServer v5.2.1 and v4.10.3</ref>
      <ref url="http://www.positronsecurity.com/advisories/2009-000.html" source="MISC">http://www.positronsecurity.com/advisories/2009-000.html</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1914" source="DEBIAN">DSA-1914</ref>
      <ref url="http://trac.osgeo.org/mapserver/ticket/2939" source="CONFIRM">http://trac.osgeo.org/mapserver/ticket/2939</ref>
      <ref url="http://secunia.com/advisories/34603" source="SECUNIA">34603</ref>
      <ref url="http://secunia.com/advisories/34520" source="SECUNIA">34520</ref>
    </refs>
    <vuln_soft>
      <prod vendor="umn" name="mapserver">
        <vers num="4.0" edition="beta1" />
        <vers num="4.0" edition="beta2" />
        <vers num="4.10" edition="beta1" />
        <vers num="4.10" edition="beta2" />
        <vers num="4.10" edition="beta3" />
        <vers num="4.10" edition="rc1" />
        <vers num="4.10.0" />
        <vers num="4.10.1" />
        <vers num="4.10.2" />
        <vers num="4.10.3" />
        <vers num="4.2" edition="beta1" />
        <vers num="4.4.0" edition="beta1" />
        <vers num="4.4.0" edition="beta2" />
        <vers num="4.4.0" edition="beta3" />
        <vers num="4.6.0" edition="beta1" />
        <vers num="4.6.0" edition="beta2" />
        <vers num="4.6.0" edition="beta3" />
        <vers num="4.6.0" edition="rc1" />
        <vers num="4.8" edition="beta1" />
        <vers num="4.8" edition="beta2" />
        <vers num="4.8" edition="beta3" />
        <vers num="4.8" edition="rc1" />
        <vers num="4.8" edition="rc2" />
        <vers num="5.0.0" edition="beta1" />
        <vers num="5.0.0" edition="beta2" />
        <vers num="5.0.0" edition="beta3" />
        <vers num="5.0.0" edition="beta4" />
        <vers num="5.0.0" edition="beta5" />
        <vers num="5.0.0" edition="beta6" />
        <vers num="5.0.0" edition="rc1" />
        <vers num="5.0.0" edition="rc2" />
        <vers num="5.2.0" edition="beta1" />
        <vers num="5.2.0" edition="beta2" />
        <vers num="5.2.0" edition="beta3" />
        <vers num="5.2.0" edition="beta4" />
        <vers num="5.2.0" edition="rc1" />
        <vers num="5.2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0844" published="2009-04-08" name="CVE-2009-0844" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:P)" CVSS_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_base_score="5.8">
    <desc>
      <descript source="cve">The get_input_token function in the SPNEGO implementation in MIT Kerberos 5 (aka krb5) 1.5 through 1.6.3 allows remote attackers to cause a denial of service (daemon crash) and possibly obtain sensitive information via a crafted length value that triggers a buffer over-read.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-133A.html" source="CERT">TA09-133A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/662091" source="CERT-VN">VU#662091</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-April/msg00206.html" source="FEDORA">FEDORA-2009-2852</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-April/msg00205.html" source="FEDORA">FEDORA-2009-2834</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/2248" source="VUPEN">ADV-2009-2248</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1297" source="VUPEN">ADV-2009-1297</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1106" source="VUPEN">ADV-2009-1106</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1057" source="VUPEN">ADV-2009-1057</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0976" source="VUPEN">ADV-2009-0976</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0960" source="VUPEN">ADV-2009-0960</ref>
      <ref url="http://www.ubuntu.com/usn/usn-755-1" source="UBUNTU">USN-755-1</ref>
      <ref url="http://www.securitytracker.com/id?1021867" source="SECTRACK">1021867</ref>
      <ref url="http://www.securityfocus.com/bid/34408" source="BID">34408</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/502546/100/0/threaded" source="BUGTRAQ">20090407 rPSA-2009-0058-1 krb5 krb5-server krb5-services krb5-test krb5-workstation</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/502526/100/0/threaded" source="BUGTRAQ">20090407 MITKRB5-SA-2009-001: multiple vulnerabilities in SPNEGO, ASN.1 decoder [CVE-2009-0844 CVE-2009-0845 CVE-2009-0847]</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-0408.html" source="REDHAT">RHSA-2009:0408</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:098" source="MANDRIVA">MDVSA-2009:098</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg21396120" source="CONFIRM">http://www-01.ibm.com/support/docview.wss?uid=swg21396120</ref>
      <ref url="http://wiki.rpath.com/wiki/Advisories:rPSA-2009-0058" source="MISC">http://wiki.rpath.com/wiki/Advisories:rPSA-2009-0058</ref>
      <ref url="http://wiki.rpath.com/Advisories:rPSA-2009-0058" source="CONFIRM">http://wiki.rpath.com/Advisories:rPSA-2009-0058</ref>
      <ref url="http://web.mit.edu/kerberos/advisories/MITKRB5-SA-2009-001.txt" source="CONFIRM">http://web.mit.edu/kerberos/advisories/MITKRB5-SA-2009-001.txt</ref>
      <ref url="http://support.novell.com/docs/Readmes/InfoDocument/patchbuilder/readme_5047181.html" source="MISC">http://support.novell.com/docs/Readmes/InfoDocument/patchbuilder/readme_5047181.html</ref>
      <ref url="http://support.novell.com/docs/Readmes/InfoDocument/patchbuilder/readme_5047180.html" source="MISC">http://support.novell.com/docs/Readmes/InfoDocument/patchbuilder/readme_5047180.html</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2009-142.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2009-142.htm</ref>
      <ref url="http://support.apple.com/kb/HT3549" source="CONFIRM">http://support.apple.com/kb/HT3549</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-256728-1" source="SUNALERT">256728</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200904-09.xml" source="GENTOO">GLSA-200904-09</ref>
      <ref url="http://secunia.com/advisories/35074" source="SECUNIA">35074</ref>
      <ref url="http://secunia.com/advisories/34734" source="SECUNIA">34734</ref>
      <ref url="http://secunia.com/advisories/34640" source="SECUNIA">34640</ref>
      <ref url="http://secunia.com/advisories/34637" source="SECUNIA">34637</ref>
      <ref url="http://secunia.com/advisories/34630" source="SECUNIA">34630</ref>
      <ref url="http://secunia.com/advisories/34628" source="SECUNIA">34628</ref>
      <ref url="http://secunia.com/advisories/34622" source="SECUNIA">34622</ref>
      <ref url="http://secunia.com/advisories/34617" source="SECUNIA">34617</ref>
      <ref url="http://secunia.com/advisories/34594" source="SECUNIA">34594</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9474" source="OVAL">oval:org.mitre.oval:def:9474</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6339" source="OVAL">oval:org.mitre.oval:def:6339</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2009/May/msg00002.html" source="APPLE">APPLE-SA-2009-05-12</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mit" name="kerberos">
        <vers num="5" />
        <vers num="5-1.5" />
        <vers num="5-1.5.1" />
        <vers num="5-1.5.2" />
        <vers num="5-1.5.3" />
        <vers num="5-1.6" />
        <vers num="5-1.6.1" />
        <vers num="5-1.6.2" />
        <vers num="5-1.6.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0845" published="2009-03-27" name="CVE-2009-0845" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The spnego_gss_accept_sec_context function in lib/gssapi/spnego/spnego_mech.c in MIT Kerberos 5 (aka krb5) 1.5 through 1.6.3, when SPNEGO is used, allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via invalid ContextFlags data in the reqFlags field in a negTokenInit token.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-133A.html" source="CERT">TA09-133A</ref>
      <ref url="http://www.kb.cert.org/vuls/id/662091" source="CERT-VN">VU#662091</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-April/msg00206.html" source="FEDORA">FEDORA-2009-2852</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-April/msg00205.html" source="FEDORA">FEDORA-2009-2834</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/49448" source="XF">kerberos-spnego-dos(49448)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/2248" source="VUPEN" adv="1">ADV-2009-2248</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1297" source="VUPEN">ADV-2009-1297</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1106" source="VUPEN">ADV-2009-1106</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1057" source="VUPEN">ADV-2009-1057</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0976" source="VUPEN">ADV-2009-0976</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0847" source="VUPEN" adv="1">ADV-2009-0847</ref>
      <ref url="http://www.ubuntu.com/usn/usn-755-1" source="UBUNTU">USN-755-1</ref>
      <ref url="http://www.securitytracker.com/id?1021867" source="SECTRACK">1021867</ref>
      <ref url="http://www.securityfocus.com/bid/34257" source="BID">34257</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/502546/100/0/threaded" source="BUGTRAQ">20090407 rPSA-2009-0058-1 krb5 krb5-server krb5-services krb5-test krb5-workstation</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/502526/100/0/threaded" source="BUGTRAQ">20090407 MITKRB5-SA-2009-001: multiple vulnerabilities in SPNEGO, ASN.1 decoder [CVE-2009-0844 CVE-2009-0845 CVE-2009-0847]</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-0408.html" source="REDHAT">RHSA-2009:0408</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:082" source="MANDRIVA">MDVSA-2009:082</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg21396120" source="CONFIRM">http://www-01.ibm.com/support/docview.wss?uid=swg21396120</ref>
      <ref url="http://wiki.rpath.com/wiki/Advisories:rPSA-2009-0058" source="MISC">http://wiki.rpath.com/wiki/Advisories:rPSA-2009-0058</ref>
      <ref url="http://wiki.rpath.com/Advisories:rPSA-2009-0058" source="CONFIRM">http://wiki.rpath.com/Advisories:rPSA-2009-0058</ref>
      <ref url="http://web.mit.edu/kerberos/advisories/MITKRB5-SA-2009-001.txt" source="CONFIRM">http://web.mit.edu/kerberos/advisories/MITKRB5-SA-2009-001.txt</ref>
      <ref url="http://support.novell.com/docs/Readmes/InfoDocument/patchbuilder/readme_5047181.html" source="MISC">http://support.novell.com/docs/Readmes/InfoDocument/patchbuilder/readme_5047181.html</ref>
      <ref url="http://support.novell.com/docs/Readmes/InfoDocument/patchbuilder/readme_5047180.html" source="MISC">http://support.novell.com/docs/Readmes/InfoDocument/patchbuilder/readme_5047180.html</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2009-142.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2009-142.htm</ref>
      <ref url="http://support.apple.com/kb/HT3549" source="CONFIRM">http://support.apple.com/kb/HT3549</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-256728-1" source="SUNALERT">256728</ref>
      <ref url="http://src.mit.edu/fisheye/changelog/krb5/?cs=22084" source="CONFIRM" adv="1">http://src.mit.edu/fisheye/changelog/krb5/?cs=22084</ref>
      <ref url="http://src.mit.edu/fisheye/browse/krb5/trunk/src/lib/gssapi/spnego/spnego_mech.c?r1=21875&amp;r2=22084" source="CONFIRM">http://src.mit.edu/fisheye/browse/krb5/trunk/src/lib/gssapi/spnego/spnego_mech.c?r1=21875&amp;r2=22084</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200904-09.xml" source="GENTOO">GLSA-200904-09</ref>
      <ref url="http://secunia.com/advisories/35074" source="SECUNIA" adv="1">35074</ref>
      <ref url="http://secunia.com/advisories/34734" source="SECUNIA">34734</ref>
      <ref url="http://secunia.com/advisories/34640" source="SECUNIA">34640</ref>
      <ref url="http://secunia.com/advisories/34637" source="SECUNIA">34637</ref>
      <ref url="http://secunia.com/advisories/34630" source="SECUNIA">34630</ref>
      <ref url="http://secunia.com/advisories/34628" source="SECUNIA">34628</ref>
      <ref url="http://secunia.com/advisories/34622" source="SECUNIA">34622</ref>
      <ref url="http://secunia.com/advisories/34617" source="SECUNIA">34617</ref>
      <ref url="http://secunia.com/advisories/34594" source="SECUNIA">34594</ref>
      <ref url="http://secunia.com/advisories/34347" source="SECUNIA" adv="1">34347</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6449" source="OVAL">oval:org.mitre.oval:def:6449</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10044" source="OVAL">oval:org.mitre.oval:def:10044</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2009/May/msg00002.html" source="APPLE">APPLE-SA-2009-05-12</ref>
      <ref url="http://krbdev.mit.edu/rt/Ticket/Display.html?user=guest&amp;pass=guest&amp;id=6402" source="CONFIRM">http://krbdev.mit.edu/rt/Ticket/Display.html?user=guest&amp;pass=guest&amp;id=6402</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mit" name="kerberos">
        <vers num="5-1.5" />
        <vers num="5-1.5.1" />
        <vers num="5-1.5.2" />
        <vers num="5-1.5.3" />
        <vers num="5-1.6" />
        <vers num="5-1.6.1" />
        <vers num="5-1.6.2" />
        <vers num="5-1.6.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0846" published="2009-04-08" name="CVE-2009-0846" modified="2011-09-06" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">The asn1_decode_generaltime function in lib/krb5/asn.1/asn1_decode.c in the ASN.1 GeneralizedTime decoder in MIT Kerberos 5 (aka krb5) before 1.6.4 allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via vectors involving an invalid DER encoding that triggers a free of an uninitialized pointer.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-133A.html" source="CERT">TA09-133A</ref>
      <ref url="http://web.mit.edu/kerberos/advisories/MITKRB5-SA-2009-002.txt" source="CONFIRM" patch="1" adv="1">http://web.mit.edu/kerberos/advisories/MITKRB5-SA-2009-002.txt</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-April/msg00206.html" source="FEDORA">FEDORA-2009-2852</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-April/msg00205.html" source="FEDORA">FEDORA-2009-2834</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/2248" source="VUPEN">ADV-2009-2248</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/2084" source="VUPEN">ADV-2009-2084</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1297" source="VUPEN">ADV-2009-1297</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1106" source="VUPEN">ADV-2009-1106</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1057" source="VUPEN">ADV-2009-1057</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0976" source="VUPEN">ADV-2009-0976</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0960" source="VUPEN">ADV-2009-0960</ref>
      <ref url="http://www.vmware.com/security/advisories/VMSA-2009-0008.html" source="CONFIRM">http://www.vmware.com/security/advisories/VMSA-2009-0008.html</ref>
      <ref url="http://www.ubuntu.com/usn/usn-755-1" source="UBUNTU">USN-755-1</ref>
      <ref url="http://www.securitytracker.com/id?1021994" source="SECTRACK">1021994</ref>
      <ref url="http://www.securityfocus.com/bid/34409" source="BID">34409</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/504683/100/0/threaded" source="BUGTRAQ">20090701 VMSA-2009-0008 ESX Service Console update for krb5</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/502546/100/0/threaded" source="BUGTRAQ">20090407 rPSA-2009-0058-1 krb5 krb5-server krb5-services krb5-test krb5-workstation</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/502527/100/0/threaded" source="BUGTRAQ">20090407 MITKRB5-SA-2009-002: ASN.1 decoder frees uninitialized pointer [CVE-2009-0846]</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-0408.html" source="REDHAT">RHSA-2009:0408</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:098" source="MANDRIVA">MDVSA-2009:098</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg21396120" source="CONFIRM">http://www-01.ibm.com/support/docview.wss?uid=swg21396120</ref>
      <ref url="http://wiki.rpath.com/wiki/Advisories:rPSA-2009-0058" source="MISC">http://wiki.rpath.com/wiki/Advisories:rPSA-2009-0058</ref>
      <ref url="http://wiki.rpath.com/Advisories:rPSA-2009-0058" source="CONFIRM">http://wiki.rpath.com/Advisories:rPSA-2009-0058</ref>
      <ref url="http://support.novell.com/docs/Readmes/InfoDocument/patchbuilder/readme_5047181.html" source="MISC">http://support.novell.com/docs/Readmes/InfoDocument/patchbuilder/readme_5047181.html</ref>
      <ref url="http://support.novell.com/docs/Readmes/InfoDocument/patchbuilder/readme_5047180.html" source="MISC">http://support.novell.com/docs/Readmes/InfoDocument/patchbuilder/readme_5047180.html</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2009-142.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2009-142.htm</ref>
      <ref url="http://support.apple.com/kb/HT3549" source="CONFIRM">http://support.apple.com/kb/HT3549</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-256728-1" source="SUNALERT">256728</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200904-09.xml" source="GENTOO">GLSA-200904-09</ref>
      <ref url="http://secunia.com/advisories/35667" source="SECUNIA">35667</ref>
      <ref url="http://secunia.com/advisories/35074" source="SECUNIA">35074</ref>
      <ref url="http://secunia.com/advisories/34734" source="SECUNIA">34734</ref>
      <ref url="http://secunia.com/advisories/34640" source="SECUNIA">34640</ref>
      <ref url="http://secunia.com/advisories/34637" source="SECUNIA">34637</ref>
      <ref url="http://secunia.com/advisories/34630" source="SECUNIA">34630</ref>
      <ref url="http://secunia.com/advisories/34628" source="SECUNIA">34628</ref>
      <ref url="http://secunia.com/advisories/34622" source="SECUNIA">34622</ref>
      <ref url="http://secunia.com/advisories/34617" source="SECUNIA">34617</ref>
      <ref url="http://secunia.com/advisories/34598" source="SECUNIA">34598</ref>
      <ref url="http://secunia.com/advisories/34594" source="SECUNIA">34594</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2009-0410.html" source="REDHAT">RHSA-2009:0410</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2009-0409.html" source="REDHAT">RHSA-2009:0409</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6301" source="OVAL">oval:org.mitre.oval:def:6301</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5483" source="OVAL">oval:org.mitre.oval:def:5483</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10694" source="OVAL">oval:org.mitre.oval:def:10694</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=130497213107107&amp;w=2" source="HP">SSRT100495</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=130497213107107&amp;w=2" source="HP">HPSBOV02682</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=124896429301168&amp;w=2" source="HP">HPSBUX02421</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=124896429301168&amp;w=2" source="HP">HPSBUX02421</ref>
      <ref url="http://lists.vmware.com/pipermail/security-announce/2009/000059.html" source="MLIST">[security-announce] 20090701 VMSA-2009-0008 ESX Service Console update for krb5</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2009/May/msg00002.html" source="APPLE">APPLE-SA-2009-05-12</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mit" name="kerberos">
        <vers num="5" />
        <vers num="5-1.1" />
        <vers num="5-1.2" />
        <vers num="5-1.2.1" />
        <vers num="5-1.2.2" />
        <vers num="5-1.2.3" />
        <vers num="5-1.2.4" />
        <vers num="5-1.2.5" />
        <vers num="5-1.2.6" />
        <vers num="5-1.2.7" />
        <vers num="5-1.2.8" />
        <vers num="5-1.3" edition="alpha1" />
        <vers num="5-1.3.1" />
        <vers num="5-1.3.2" />
        <vers num="5-1.3.3" />
        <vers num="5-1.3.4" />
        <vers num="5-1.3.5" />
        <vers num="5-1.3.6" />
        <vers num="5-1.4" />
        <vers num="5-1.4.1" />
        <vers num="5-1.4.2" />
        <vers num="5-1.4.3" />
        <vers num="5-1.4.4" />
        <vers num="5-1.5" />
        <vers num="5-1.5.1" />
        <vers num="5-1.5.2" />
        <vers num="5-1.5.3" />
        <vers num="5-1.6" />
        <vers num="5-1.6.1" />
        <vers num="5-1.6.2" />
        <vers num="5-1.6.3" />
        <vers num="5_1.0" />
        <vers num="5_1.0.6" />
        <vers num="5_1.1" />
        <vers num="5_1.1.1" />
        <vers num="5_1.2" edition="beta1" />
        <vers num="5_1.2" edition="beta2" />
        <vers num="5_1.3.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0847" published="2009-04-08" name="CVE-2009-0847" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">The asn1buf_imbed function in the ASN.1 decoder in MIT Kerberos 5 (aka krb5) 1.6.3, when PK-INIT is used, allows remote attackers to cause a denial of service (application crash) via a crafted length value that triggers an erroneous malloc call, related to incorrect calculations with pointer arithmetic.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-133A.html" source="CERT">TA09-133A</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-April/msg00206.html" source="FEDORA">FEDORA-2009-2852</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-April/msg00205.html" source="FEDORA">FEDORA-2009-2834</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/2248" source="VUPEN">ADV-2009-2248</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/2084" source="VUPEN">ADV-2009-2084</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1297" source="VUPEN">ADV-2009-1297</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1106" source="VUPEN">ADV-2009-1106</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1057" source="VUPEN">ADV-2009-1057</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0976" source="VUPEN">ADV-2009-0976</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0960" source="VUPEN">ADV-2009-0960</ref>
      <ref url="http://www.ubuntu.com/usn/usn-755-1" source="UBUNTU">USN-755-1</ref>
      <ref url="http://www.securitytracker.com/id?1021993" source="SECTRACK">1021993</ref>
      <ref url="http://www.securityfocus.com/bid/34408" source="BID">34408</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/502546/100/0/threaded" source="BUGTRAQ">20090407 rPSA-2009-0058-1 krb5 krb5-server krb5-services krb5-test krb5-workstation</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/502526/100/0/threaded" source="BUGTRAQ">20090407 MITKRB5-SA-2009-001: multiple vulnerabilities in SPNEGO, ASN.1 decoder [CVE-2009-0844 CVE-2009-0845 CVE-2009-0847]</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:098" source="MANDRIVA">MDVSA-2009:098</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg21396120" source="CONFIRM">http://www-01.ibm.com/support/docview.wss?uid=swg21396120</ref>
      <ref url="http://wiki.rpath.com/wiki/Advisories:rPSA-2009-0058" source="MISC">http://wiki.rpath.com/wiki/Advisories:rPSA-2009-0058</ref>
      <ref url="http://wiki.rpath.com/Advisories:rPSA-2009-0058" source="CONFIRM">http://wiki.rpath.com/Advisories:rPSA-2009-0058</ref>
      <ref url="http://web.mit.edu/kerberos/advisories/MITKRB5-SA-2009-001.txt" source="CONFIRM" adv="1">http://web.mit.edu/kerberos/advisories/MITKRB5-SA-2009-001.txt</ref>
      <ref url="http://support.novell.com/docs/Readmes/InfoDocument/patchbuilder/readme_5047181.html" source="MISC">http://support.novell.com/docs/Readmes/InfoDocument/patchbuilder/readme_5047181.html</ref>
      <ref url="http://support.novell.com/docs/Readmes/InfoDocument/patchbuilder/readme_5047180.html" source="MISC">http://support.novell.com/docs/Readmes/InfoDocument/patchbuilder/readme_5047180.html</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2009-142.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2009-142.htm</ref>
      <ref url="http://support.apple.com/kb/HT3549" source="CONFIRM">http://support.apple.com/kb/HT3549</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-256728-1" source="SUNALERT">256728</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200904-09.xml" source="GENTOO">GLSA-200904-09</ref>
      <ref url="http://secunia.com/advisories/35074" source="SECUNIA">35074</ref>
      <ref url="http://secunia.com/advisories/34734" source="SECUNIA">34734</ref>
      <ref url="http://secunia.com/advisories/34640" source="SECUNIA">34640</ref>
      <ref url="http://secunia.com/advisories/34637" source="SECUNIA">34637</ref>
      <ref url="http://secunia.com/advisories/34628" source="SECUNIA">34628</ref>
      <ref url="http://secunia.com/advisories/34622" source="SECUNIA">34622</ref>
      <ref url="http://secunia.com/advisories/34617" source="SECUNIA">34617</ref>
      <ref url="http://secunia.com/advisories/34594" source="SECUNIA">34594</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6387" source="OVAL">oval:org.mitre.oval:def:6387</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=124896429301168&amp;w=2" source="HP">HPSBUX02421</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=124896429301168&amp;w=2" source="HP">HPSBUX02421</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2009/May/msg00002.html" source="APPLE">APPLE-SA-2009-05-12</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mit" name="kerberos">
        <vers num="5-1.6.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0848" published="2009-03-11" name="CVE-2009-0848" modified="2009-03-21" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="4.4" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.4" CVSS_base_score="4.4">
    <desc>
      <descript source="cve">Untrusted search path vulnerability in GTK2 in OpenSUSE 11.0 and 11.1 allows local users to execute arbitrary code via a Trojan horse GTK module in an unspecified "relative search path."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <local />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/49228" source="XF">opensuse-gtk2-code-execution(49228)</ref>
      <ref url="http://secunia.com/advisories/34259" source="SECUNIA">34259</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-03/msg00001.html" source="SUSE" adv="1">SUSE-SR:2009:006</ref>
    </refs>
    <vuln_soft>
      <prod vendor="opensuse" name="opensuse">
        <vers num="11.0" />
        <vers num="11.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0849" published="2009-03-09" name="CVE-2009-0849" modified="2009-03-10" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Stack-based buffer overflow in the DtbClsLogin function in NovaStor NovaNET 12 allows remote attackers to (1) execute arbitrary code on Linux platforms via a long username field during backup domain authentication, related to libnnlindtb.so; or (2) cause a denial of service (daemon crash) on Windows platforms via a long username field during backup domain authentication, related to nnwindtb.dll.  NOTE: some of these details are obtained from third party information.</descript>
      <descript source="nvd">Per: http://secunia.com/advisories/34024

Successful exploitation allows to crash the application on a Windows system and reportedly allows to execute arbitrary code on a Linux system.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/49074" source="XF">novanet-dtbclslogin-bo(49074)</ref>
      <ref url="http://www.securityfocus.com/bid/33954" source="BID">33954</ref>
      <ref url="http://www.insight-tech.org/index.php?p=NovaNET-12-Remote-Buffer-Oveflow" source="MISC">http://www.insight-tech.org/index.php?p=NovaNET-12-Remote-Buffer-Oveflow</ref>
      <ref url="http://secunia.com/advisories/34024" source="SECUNIA" adv="1">34024</ref>
      <ref url="http://osvdb.org/52302" source="OSVDB">52302</ref>
      <ref url="http://osvdb.org/52301" source="OSVDB">52301</ref>
    </refs>
    <vuln_soft>
      <prod vendor="novastor" name="novanet">
        <vers num="12" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0850" published="2009-03-09" name="CVE-2009-0850" modified="2009-03-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in BitDefender Internet Security 2009 allows user-assisted remote attackers to inject arbitrary web script or HTML via the filename of a virus-infected file, as demonstrated by a filename inside a (1) rar or (2) zip archive file.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2009/0557" source="VUPEN" adv="1">ADV-2009-0557</ref>
      <ref url="http://www.securityfocus.com/bid/33921" source="BID">33921</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/501299/100/0/threaded" source="BUGTRAQ">20090227 Re: BitDefender Internet Security XSS</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/501277/100/0/threaded" source="BUGTRAQ">20090226 BitDefender Internet Security XSS</ref>
      <ref url="http://secunia.com/advisories/34082" source="SECUNIA" adv="1">34082</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bitdefender" name="internet_security">
        <vers num="2009" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0851" published="2009-03-09" name="CVE-2009-0851" modified="2009-06-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in CelerBB 0.0.2, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) viewforum.php and (2) viewtopic.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/34014" source="BID">34014</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/501481/100/0/threaded" source="BUGTRAQ">20090305 CelerBB 0.0.2 Multiple Vulnerabilities</ref>
      <ref url="http://www.milw0rm.com/exploits/8161" source="MILW0RM">8161</ref>
    </refs>
    <vuln_soft>
      <prod vendor="stewart_howe" name="celerbb">
        <vers num="0.0.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0852" published="2009-03-09" name="CVE-2009-0852" modified="2009-03-10" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">showme.php in CelerBB 0.0.2 allows remote attackers to obtain "reserved information" via the user parameter.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/34014" source="BID">34014</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/501481/100/0/threaded" source="BUGTRAQ">20090305 CelerBB 0.0.2 Multiple Vulnerabilities</ref>
      <ref url="http://www.milw0rm.com/exploits/8161" source="MILW0RM">8161</ref>
    </refs>
    <vuln_soft>
      <prod vendor="stewart_howe" name="celerbb">
        <vers num="0.0.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0853" published="2009-03-09" name="CVE-2009-0853" modified="2009-06-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">login.php in CelerBB 0.0.2, when magic_quotes_gpc is disabled, allows remote attackers to bypass authentication and obtain administrative access via special characters in the Username parameter, as demonstrated by an admin'# parameter value.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/34014" source="BID">34014</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/501481/100/0/threaded" source="BUGTRAQ">20090305 CelerBB 0.0.2 Multiple Vulnerabilities</ref>
      <ref url="http://www.milw0rm.com/exploits/8161" source="MILW0RM">8161</ref>
    </refs>
    <vuln_soft>
      <prod vendor="stewart_howe" name="celerbb">
        <vers num="0.0.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0854" published="2009-03-11" name="CVE-2009-0854" modified="2009-03-21" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="6.9" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.4" CVSS_base_score="6.9">
    <desc>
      <descript source="cve">Untrusted search path vulnerability in dash 0.5.4, when used as a login shell, allows local users to execute arbitrary code via a Trojan horse .profile file in the current working directory.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <local />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/49216" source="XF">dash-profile-code-execution(49216)</ref>
      <ref url="http://www.ubuntu.com/usn/USN-732-1" source="UBUNTU">USN-732-1</ref>
      <ref url="http://www.securityfocus.com/bid/34092" source="BID">34092</ref>
      <ref url="http://secunia.com/advisories/34205" source="SECUNIA">34205</ref>
    </refs>
    <vuln_soft>
      <prod vendor="dash" name="dash">
        <vers num="0.5.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0855" published="2009-03-09" name="CVE-2009-0855" modified="2009-04-01" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the administrative console in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.23 on z/OS allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2009/0854" source="VUPEN">ADV-2009-0854</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0607" source="VUPEN" adv="1">ADV-2009-0607</ref>
      <ref url="http://www.securityfocus.com/bid/34259" source="BID">34259</ref>
      <ref url="http://www.securityfocus.com/bid/34001" source="BID">34001</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg1PK82988" source="AIXAPAR">PK82988</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg1PK81212" source="AIXAPAR" adv="1">PK81212</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg1PK77505" source="AIXAPAR" adv="1">PK77505</ref>
      <ref url="http://secunia.com/advisories/34461" source="SECUNIA">34461</ref>
      <ref url="http://secunia.com/advisories/34131" source="SECUNIA" adv="1">34131</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="websphere_application_server">
        <vers num="6.1" />
        <vers num="6.1.0" />
        <vers num="6.1.0.0" />
        <vers num="6.1.0.1" />
        <vers num="6.1.0.10" />
        <vers num="6.1.0.11" />
        <vers num="6.1.0.12" />
        <vers num="6.1.0.13" />
        <vers num="6.1.0.14" />
        <vers num="6.1.0.15" />
        <vers num="6.1.0.16" />
        <vers num="6.1.0.17" />
        <vers num="6.1.0.18" />
        <vers num="6.1.0.19" />
        <vers num="6.1.0.2" />
        <vers num="6.1.0.20" />
        <vers num="6.1.0.21" />
        <vers num="6.1.0.22" />
        <vers num="6.1.0.3" />
        <vers num="6.1.0.4" />
        <vers num="6.1.0.5" />
        <vers num="6.1.0.6" />
        <vers num="6.1.0.7" />
        <vers num="6.1.0.8" />
        <vers num="6.1.0.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0856" published="2009-03-09" name="CVE-2009-0856" modified="2009-06-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in sample applications in IBM WebSphere Application Server (WAS) 6.0.2 before 6.0.2.35, and 6.1 before 6.1.0.23 on z/OS, allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg1PK81212" source="AIXAPAR" patch="1" adv="1">PK81212</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1464" source="VUPEN" adv="1">ADV-2009-1464</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0607" source="VUPEN" adv="1">ADV-2009-0607</ref>
      <ref url="http://www.securityfocus.com/bid/34001" source="BID">34001</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg27006876" source="CONFIRM">http://www-01.ibm.com/support/docview.wss?uid=swg27006876</ref>
      <ref url="http://securitytracker.com/id?1021811" source="SECTRACK">1021811</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="websphere_application_server">
        <vers num="6.1" />
        <vers num="6.1.0.0" />
        <vers num="6.1.0.1" />
        <vers num="6.1.0.10" />
        <vers num="6.1.0.11" />
        <vers num="6.1.0.12" />
        <vers num="6.1.0.13" />
        <vers num="6.1.0.14" />
        <vers num="6.1.0.15" />
        <vers num="6.1.0.16" />
        <vers num="6.1.0.17" />
        <vers num="6.1.0.18" />
        <vers num="6.1.0.19" />
        <vers num="6.1.0.2" />
        <vers num="6.1.0.20" />
        <vers num="6.1.0.21" />
        <vers num="6.1.0.22" />
        <vers num="6.1.0.3" />
        <vers num="6.1.0.4" />
        <vers num="6.1.0.5" />
        <vers num="6.1.0.6" />
        <vers num="6.1.0.7" />
        <vers num="6.1.0.8" />
        <vers num="6.1.0.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0857" published="2009-03-09" name="CVE-2009-0857" modified="2009-06-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in /prm/reports in the Performance Reporting Module (PRM) for Sun Management Center (SunMC) 3.6.1 and 4.0 allows remote attackers to inject arbitrary web script or HTML via the msg parameter.  NOTE: this can be leveraged for access to the SunMC Web Console.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/49076" source="XF" patch="1">sunmc-performancereportingmodule-xss(49076)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0605" source="VUPEN" patch="1" adv="1">ADV-2009-0605</ref>
      <ref url="http://www.securityfocus.com/bid/33999" source="BID" patch="1">33999</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-247046-1" source="SUNALERT" patch="1" adv="1">247046</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-21-125191-04-1" source="CONFIRM" patch="1">http://sunsolve.sun.com/search/document.do?assetkey=1-21-125191-04-1</ref>
      <ref url="http://securitytracker.com/id?1021809" source="SECTRACK">1021809</ref>
      <ref url="http://secunia.com/advisories/34146" source="SECUNIA" adv="1">34146</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="management_center">
        <vers num="3.6.1" />
        <vers num="4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0858" published="2009-03-09" name="CVE-2009-0858" modified="2009-03-10" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:P)" CVSS_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_base_score="5.8">
    <desc>
      <descript source="cve">The response_addname function in response.c in Daniel J. Bernstein djbdns 1.05 and earlier does not constrain offsets in the required manner, which allows remote attackers, with control over a third-party subdomain served by tinydns and axfrdns, to trigger DNS responses containing arbitrary records via crafted zone data for this subdomain.</descript>
    </desc>
    <loss_types>
      <avail />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://securityandthe.net/2009/03/05/security-issue-in-djbdns-confirmed/" source="MISC" patch="1">http://securityandthe.net/2009/03/05/security-issue-in-djbdns-confirmed/</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/49003" source="XF">djbdns-response-packet-spoofing(49003)</ref>
      <ref url="http://www.securityfocus.com/bid/33937" source="BID">33937</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/501479/100/0/threaded" source="BUGTRAQ">20090305 Re: djbdns misformats some long response packets; patch and example attack</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/501340/100/0/threaded" source="BUGTRAQ">20090228 Re: djbdns misformats some long response packets; patch and example attack</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/501294/100/0/threaded" source="BUGTRAQ">20090226 djbdns misformats some long response packets; patch and example attack</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1831" source="DEBIAN">DSA-1831</ref>
      <ref url="http://secunia.com/advisories/35820" source="SECUNIA">35820</ref>
      <ref url="http://marc.info/?l=djbdns&amp;m=123613000920446&amp;w=2" source="MLIST">[dns] 20090304 djbdns&lt;=1.05 lets AXFRed subdomains overwrite domains</ref>
      <ref url="http://marc.info/?l=djbdns&amp;m=123554945710038" source="MLIST">[dns] 20090225 djbdns misformats some long response packets; patch and example</ref>
      <ref url="http://it.slashdot.org/article.pl?sid=09/03/05/2014249" source="MISC">http://it.slashdot.org/article.pl?sid=09/03/05/2014249</ref>
    </refs>
    <vuln_soft>
      <prod vendor="d.j.bernstein" name="djbdns">
        <vers prev="1" num="1.05" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0859" published="2009-03-09" name="CVE-2009-0859" modified="2009-06-12" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:N/I:N/A:C)" CVSS_score="4.7" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="3.4" CVSS_base_score="4.7">
    <desc>
      <descript source="cve">The shm_get_stat function in ipc/shm.c in the shm subsystem in the Linux kernel before 2.6.28.5, when CONFIG_SHMEM is disabled, misinterprets the data type of an inode, which allows local users to cause a denial of service (system hang) via an SHM_INFO shmctl call, as demonstrated by running the ipcs program.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/49229" source="XF">linux-kernel-shmgetstat-dos(49229)</ref>
      <ref url="http://www.ubuntu.com/usn/usn-751-1" source="UBUNTU">USN-751-1</ref>
      <ref url="http://www.securityfocus.com/bid/34020" source="BID">34020</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1800" source="DEBIAN">DSA-1800</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1794" source="DEBIAN">DSA-1794</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1787" source="DEBIAN">DSA-1787</ref>
      <ref url="http://secunia.com/advisories/35394" source="SECUNIA">35394</ref>
      <ref url="http://secunia.com/advisories/35390" source="SECUNIA">35390</ref>
      <ref url="http://secunia.com/advisories/35185" source="SECUNIA">35185</ref>
      <ref url="http://secunia.com/advisories/35121" source="SECUNIA">35121</ref>
      <ref url="http://secunia.com/advisories/35011" source="SECUNIA">35011</ref>
      <ref url="http://secunia.com/advisories/34981" source="SECUNIA">34981</ref>
      <ref url="http://patchwork.kernel.org/patch/6554/" source="CONFIRM">http://patchwork.kernel.org/patch/6554/</ref>
      <ref url="http://openwall.com/lists/oss-security/2009/03/06/1" source="MLIST">[oss-security] 20090306 CVE request: kernel: shm: fix shmctl(SHM_INFO) lockup with !CONFIG_SHMEM</ref>
      <ref url="http://marc.info/?l=linux-kernel&amp;m=123309645625549&amp;w=2" source="MLIST">[linux-kernel] 20090127 [PATCH 1/2] fix shmctl(SHM_INFO) lockup with !CONFIG_SHMEM</ref>
      <ref url="http://marc.info/?l=linux-kernel&amp;m=120428209704324&amp;w=2" source="MLIST">[linux-kernel] 20080229 [BUG] soft lockup detected with ipcs</ref>
      <ref url="http://marc.info/?l=git-commits-head&amp;m=123387479500599&amp;w=2" source="MLIST">[git-commits-head] 20090205 shm: fix shmctl(SHM_INFO) lockup with !CONFIG_SHMEM</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-06/msg00001.html" source="SUSE">SUSE-SA:2009:031</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-06/msg00000.html" source="SUSE">SUSE-SA:2009:030</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-05/msg00002.html" source="SUSE">SUSE-SA:2009:028</ref>
      <ref url="http://kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.28.5" source="CONFIRM">http://kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.28.5</ref>
      <ref url="http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=a68e61e8ff2d46327a37b69056998b47745db6fa" source="CONFIRM">http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=a68e61e8ff2d46327a37b69056998b47745db6fa</ref>
    </refs>
    <vuln_soft>
      <prod vendor="kernel" name="linux">
        <vers num="2.6.0" />
        <vers num="2.6.1" />
        <vers num="2.6.10" />
        <vers num="2.6.11" />
        <vers num="2.6.11.1" />
        <vers num="2.6.11.10" />
        <vers num="2.6.11.12" />
        <vers num="2.6.11.2" />
        <vers num="2.6.11.3" />
        <vers num="2.6.11.4" />
        <vers num="2.6.11.5" />
        <vers num="2.6.11.6" />
        <vers num="2.6.11.7" />
        <vers num="2.6.11.8" />
        <vers num="2.6.11.9" />
        <vers num="2.6.12" />
        <vers num="2.6.12.1" />
        <vers num="2.6.12.2" />
        <vers num="2.6.12.3" />
        <vers num="2.6.12.4" />
        <vers num="2.6.12.5" />
        <vers num="2.6.12.6" />
        <vers num="2.6.13" />
        <vers num="2.6.13.1" />
        <vers num="2.6.13.2" />
        <vers num="2.6.13.3" />
        <vers num="2.6.13.4" />
        <vers num="2.6.13.5" />
        <vers num="2.6.14" />
        <vers num="2.6.14.1" />
        <vers num="2.6.14.2" />
        <vers num="2.6.14.3" />
        <vers num="2.6.14.4" />
        <vers num="2.6.14.5" />
        <vers num="2.6.14.6" />
        <vers num="2.6.14.7" />
        <vers num="2.6.15" />
        <vers num="2.6.15.1" />
        <vers num="2.6.15.2" />
        <vers num="2.6.15.3" />
        <vers num="2.6.15.4" />
        <vers num="2.6.15.5" />
        <vers num="2.6.15.6" />
        <vers num="2.6.15.7" />
        <vers num="2.6.16" />
        <vers num="2.6.16.20" />
        <vers num="2.6.16.21" />
        <vers num="2.6.16.22" />
        <vers num="2.6.16.23" />
        <vers num="2.6.16.24" />
        <vers num="2.6.16.25" />
        <vers num="2.6.16.26" />
        <vers num="2.6.16.27" />
        <vers num="2.6.16.28" />
        <vers num="2.6.16.29" />
        <vers num="2.6.16.30" />
        <vers num="2.6.16.31" />
        <vers num="2.6.16.32" />
        <vers num="2.6.16.33" />
        <vers num="2.6.16.34" />
        <vers num="2.6.16.35" />
        <vers num="2.6.16.36" />
        <vers num="2.6.16.37" />
        <vers num="2.6.16.38" />
        <vers num="2.6.16.39" />
        <vers num="2.6.16.40" />
        <vers num="2.6.16.41" />
        <vers num="2.6.16.42" />
        <vers num="2.6.16.43" />
        <vers num="2.6.16.44" />
        <vers num="2.6.16.45" />
        <vers num="2.6.16.46" />
        <vers num="2.6.16.47" />
        <vers num="2.6.16.48" />
        <vers num="2.6.16.49" />
        <vers num="2.6.16.50" />
        <vers num="2.6.16.51" />
        <vers num="2.6.16.52" />
        <vers num="2.6.16.53" />
        <vers num="2.6.16.54" />
        <vers num="2.6.16.55" />
        <vers num="2.6.16.56" />
        <vers num="2.6.16.57" />
        <vers num="2.6.16.58" />
        <vers num="2.6.16.59" />
        <vers num="2.6.16.60" />
        <vers num="2.6.16.61" />
        <vers num="2.6.16.62" />
        <vers num="2.6.17" />
        <vers num="2.6.17.1" />
        <vers num="2.6.17.10" />
        <vers num="2.6.17.11" />
        <vers num="2.6.17.12" />
        <vers num="2.6.17.13" />
        <vers num="2.6.17.14" />
        <vers num="2.6.17.2" />
        <vers num="2.6.17.3" />
        <vers num="2.6.17.4" />
        <vers num="2.6.17.5" />
        <vers num="2.6.17.6" />
        <vers num="2.6.17.7" />
        <vers num="2.6.17.8" />
        <vers num="2.6.17.9" />
        <vers num="2.6.18" />
        <vers num="2.6.18.1" />
        <vers num="2.6.18.2" />
        <vers num="2.6.18.3" />
        <vers num="2.6.18.4" />
        <vers num="2.6.18.5" />
        <vers num="2.6.18.6" />
        <vers num="2.6.18.7" />
        <vers num="2.6.18.8" />
        <vers num="2.6.19" />
        <vers num="2.6.19.1" />
        <vers num="2.6.19.2" />
        <vers num="2.6.19.3" />
        <vers num="2.6.19.4" />
        <vers num="2.6.19.5" />
        <vers num="2.6.19.6" />
        <vers num="2.6.19.7" />
        <vers num="2.6.2" />
        <vers num="2.6.20" />
        <vers num="2.6.20.1" />
        <vers num="2.6.20.10" />
        <vers num="2.6.20.11" />
        <vers num="2.6.20.12" />
        <vers num="2.6.20.13" />
        <vers num="2.6.20.14" />
        <vers num="2.6.20.15" />
        <vers num="2.6.20.16" />
        <vers num="2.6.20.17" />
        <vers num="2.6.20.18" />
        <vers num="2.6.20.19" />
        <vers num="2.6.20.2" />
        <vers num="2.6.20.20" />
        <vers num="2.6.20.21" />
        <vers num="2.6.20.3" />
        <vers num="2.6.20.4" />
        <vers num="2.6.20.5" />
        <vers num="2.6.20.6" />
        <vers num="2.6.20.7" />
        <vers num="2.6.20.8" />
        <vers num="2.6.20.9" />
        <vers num="2.6.21" />
        <vers num="2.6.21.1" />
        <vers num="2.6.21.2" />
        <vers num="2.6.21.3" />
        <vers num="2.6.21.4" />
        <vers num="2.6.21.5" />
        <vers num="2.6.21.6" />
        <vers num="2.6.21.7" />
        <vers num="2.6.22" />
        <vers num="2.6.22.1" />
        <vers num="2.6.22.10" />
        <vers num="2.6.22.11" />
        <vers num="2.6.22.12" />
        <vers num="2.6.22.13" />
        <vers num="2.6.22.14" />
        <vers num="2.6.22.15" />
        <vers num="2.6.22.16" />
        <vers num="2.6.22.17" />
        <vers num="2.6.22.18" />
        <vers num="2.6.22.19" />
        <vers num="2.6.22.2" />
        <vers num="2.6.22.3" />
        <vers num="2.6.22.4" />
        <vers num="2.6.22.5" />
        <vers num="2.6.22.6" />
        <vers num="2.6.22.7" />
        <vers num="2.6.22.8" />
        <vers num="2.6.22.9" />
        <vers num="2.6.23" />
        <vers num="2.6.23.1" />
        <vers num="2.6.23.10" />
        <vers num="2.6.23.11" />
        <vers num="2.6.23.12" />
        <vers num="2.6.23.13" />
        <vers num="2.6.23.14" />
        <vers num="2.6.23.15" />
        <vers num="2.6.23.16" />
        <vers num="2.6.23.17" />
        <vers num="2.6.23.2" />
        <vers num="2.6.23.3" />
        <vers num="2.6.23.4" />
        <vers num="2.6.23.5" />
        <vers num="2.6.23.6" />
        <vers num="2.6.23.7" />
        <vers num="2.6.23.8" />
        <vers num="2.6.23.9" />
        <vers num="2.6.24" />
        <vers num="2.6.24.1" />
        <vers num="2.6.24.2" />
        <vers num="2.6.24.3" />
        <vers num="2.6.24.4" />
        <vers num="2.6.24.5" />
        <vers num="2.6.24.6" />
        <vers num="2.6.24.7" />
        <vers num="2.6.25" />
        <vers num="2.6.25.1" />
        <vers num="2.6.25.10" />
        <vers num="2.6.25.11" />
        <vers num="2.6.25.12" />
        <vers num="2.6.25.13" />
        <vers num="2.6.25.14" />
        <vers num="2.6.25.15" />
        <vers num="2.6.25.16" />
        <vers num="2.6.25.17" />
        <vers num="2.6.25.18" />
        <vers num="2.6.25.19" />
        <vers num="2.6.25.2" />
        <vers num="2.6.25.20" />
        <vers num="2.6.25.3" />
        <vers num="2.6.25.4" />
        <vers num="2.6.25.5" />
        <vers num="2.6.25.6" />
        <vers num="2.6.25.7" />
        <vers num="2.6.25.8" />
        <vers num="2.6.25.9" />
        <vers num="2.6.26" />
        <vers num="2.6.26.1" />
        <vers num="2.6.26.2" />
        <vers num="2.6.26.3" />
        <vers num="2.6.26.4" />
        <vers num="2.6.26.5" />
        <vers num="2.6.26.6" />
        <vers num="2.6.26.7" />
        <vers num="2.6.26.8" />
        <vers num="2.6.27" />
        <vers num="2.6.27.1" />
        <vers num="2.6.27.10" />
        <vers num="2.6.27.11" />
        <vers num="2.6.27.12" />
        <vers num="2.6.27.13" />
        <vers num="2.6.27.14" />
        <vers num="2.6.27.15" />
        <vers num="2.6.27.16" />
        <vers num="2.6.27.17" />
        <vers num="2.6.27.18" />
        <vers num="2.6.27.19" />
        <vers num="2.6.27.2" />
        <vers num="2.6.27.3" />
        <vers num="2.6.27.4" />
        <vers num="2.6.27.5" />
        <vers num="2.6.27.6" />
        <vers num="2.6.27.7" />
        <vers num="2.6.27.8" />
        <vers num="2.6.27.9" />
        <vers num="2.6.28" />
        <vers num="2.6.28.1" />
        <vers num="2.6.28.2" />
        <vers num="2.6.28.3" />
        <vers prev="1" num="2.6.28.4" />
        <vers num="2.6.3" />
        <vers num="2.6.4" />
        <vers num="2.6.5" />
        <vers num="2.6.6" />
        <vers num="2.6.7" />
        <vers num="2.6.8" />
        <vers num="2.6.8.1" />
        <vers num="2.6.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0860" published="2009-03-10" name="CVE-2009-0860" modified="2009-03-10" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the web user interface in the login application in NetMRI 3.0.1 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, related to error pages.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/33824" source="BID">33824</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/501033/100/0/threaded" source="BUGTRAQ">20090218 DDIVRT-2009-20 NetMRI Login Application Cross-site Scripting Vulnerability</ref>
      <ref url="http://secunia.com/advisories/33963" source="SECUNIA" adv="1">33963</ref>
      <ref url="http://connection.netcordia.com/forums/t/731.aspx" source="CONFIRM" adv="1">http://connection.netcordia.com/forums/t/731.aspx</ref>
    </refs>
    <vuln_soft>
      <prod vendor="netcordia" name="netmri">
        <vers prev="1" num="3.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0861" published="2009-03-10" name="CVE-2009-0861" modified="2009-03-10" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in phpDenora before 1.2.3 allows remote attackers to inject arbitrary web script or HTML via an IRC channel name.  NOTE: some of these details are obtained from third party information.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/33822" source="BID" patch="1">33822</ref>
      <ref url="http://sourceforge.net/project/shownotes.php?release_id=661189" source="CONFIRM" patch="1">http://sourceforge.net/project/shownotes.php?release_id=661189</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/48799" source="XF">phpdenora-ircchannel-xss(48799)</ref>
      <ref url="http://secunia.com/advisories/33960" source="SECUNIA" adv="1">33960</ref>
      <ref url="http://osvdb.org/51981" source="OSVDB">51981</ref>
    </refs>
    <vuln_soft>
      <prod vendor="denorastats" name="phpdenora">
        <vers num="0.9.3" />
        <vers num="0.9.4" />
        <vers num="1.0.0" edition="rc1" />
        <vers num="1.0.0" edition="rc2" />
        <vers num="1.0.0" edition="rc3" />
        <vers num="1.0.1" />
        <vers num="1.1.0" />
        <vers num="1.1.1" />
        <vers num="1.2.0" />
        <vers num="1.2.1" />
        <vers prev="1" num="1.2.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0862" published="2009-03-10" name="CVE-2009-0862" modified="2009-03-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the hook_cntrlr_error_output function in modules/page/hooks/listeners.php in the admincp component in TangoCMS 2.2.x (aka Eagle) before 2.2.4 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.  NOTE: some of these details are obtained from third party information.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://tangocms.org/changelog" source="CONFIRM" patch="1" adv="1">http://tangocms.org/changelog</ref>
      <ref url="http://tangocms.org/article/view/2.2.4-released" source="CONFIRM" patch="1" adv="1">http://tangocms.org/article/view/2.2.4-released</ref>
      <ref url="http://www.securityfocus.com/bid/33833" source="BID">33833</ref>
      <ref url="http://secunia.com/advisories/33967" source="SECUNIA" adv="1">33967</ref>
    </refs>
    <vuln_soft>
      <prod vendor="tangocms" name="tangocms">
        <vers num="1.0.6" />
        <vers num="1.0.8" />
        <vers num="1.0.8.1" />
        <vers num="2.0.0" />
        <vers num="2.0.1" />
        <vers num="2.0.2" />
        <vers num="2.0.3" />
        <vers num="2.0.4" />
        <vers num="2.0.5" />
        <vers num="2.0.6" />
        <vers num="2.1.0" />
        <vers num="2.1.1" />
        <vers num="2.1.2" />
        <vers num="2.2.0" />
        <vers num="2.2.1" />
        <vers num="2.2.2" />
        <vers prev="1" num="2.2.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0863" published="2009-03-10" name="CVE-2009-0863" modified="2009-03-10" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in admin/delete_page.php in S-Cms 1.1 Stable allows remote attackers to execute arbitrary SQL commands via the id parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/48806" source="XF">scms-deletepage-sql-injection(48806)</ref>
      <ref url="http://www.securityfocus.com/bid/33799" source="BID">33799</ref>
      <ref url="http://www.milw0rm.com/exploits/8071" source="MILW0RM">8071</ref>
    </refs>
    <vuln_soft>
      <prod vendor="matteoiammarrone" name="s-cms">
        <vers num="1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0864" published="2009-03-10" name="CVE-2009-0864" modified="2009-03-10" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">S-Cms 1.1 Stable allows remote attackers to bypass authentication and obtain administrative access via an OK value for the login cookie.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/48805" source="XF">scms-cookie-security-bypass(48805)</ref>
      <ref url="http://www.securityfocus.com/bid/33799" source="BID">33799</ref>
      <ref url="http://www.milw0rm.com/exploits/8071" source="MILW0RM">8071</ref>
    </refs>
    <vuln_soft>
      <prod vendor="matteoiammarrone" name="s-cms">
        <vers num="1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0865" published="2009-03-10" name="CVE-2009-0865" modified="2009-03-10" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:C/A:C)" CVSS_score="8.8" CVSS_impact_subscore="9.2" CVSS_exploit_subscore="8.6" CVSS_base_score="8.8">
    <desc>
      <descript source="cve">Directory traversal vulnerability in the SnapShotToFile method in the GeoVision LiveX (aka LiveX_v8200) ActiveX control 8.1.2 and 8.2.0 in LIVEX_~1.OCX allows remote attackers to create or overwrite arbitrary files via a .. (dot dot) in the argument, possibly involving the PlayX and SnapShotX methods.</descript>
    </desc>
    <loss_types>
      <avail />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/48773" source="XF">geovision-livex-activex-file-overwrite(48773)</ref>
      <ref url="http://www.securityfocus.com/bid/33782" source="BID">33782</ref>
      <ref url="http://secunia.com/advisories/33969" source="SECUNIA" adv="1">33969</ref>
      <ref url="http://milw0rm.com/exploits/8059" source="MILW0RM">8059</ref>
    </refs>
    <vuln_soft>
      <prod vendor="geovision" name="livex_activex_control">
        <vers num="8.1.2.0" />
        <vers num="8.2.0.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0866" published="2009-03-10" name="CVE-2009-0866" modified="2009-03-10" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">pHNews Alpha 1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for extra/genbackup.php.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/48801" source="XF">phnews-genbackup-info-disclosure(48801)</ref>
      <ref url="http://www.milw0rm.com/exploits/8073" source="MILW0RM">8073</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phnews" name="phnews">
        <vers num="1" edition="alpha" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0867" published="2009-03-10" name="CVE-2009-0867" modified="2009-03-11" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The HRM-S service in Fujitsu Enhanced Support Facility 3.0 and 3.0.1 allows remote attackers to obtain (1) hardware and (2) software information via unspecified requests in a client connection.</descript>
    </desc>
    <sols>
      <sol source="nvd">Per: http://www.fujitsu.com/global/support/software/security/products-f/esf-200901e.html

For the Patches, please contact a Fujitsu system engineer or your partner(s).</sol>
    </sols>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/48817" source="XF">fujitsu-enhanced-hrms-info-disclosure(48817)</ref>
      <ref url="http://www.securityfocus.com/bid/33831" source="BID">33831</ref>
      <ref url="http://www.fujitsu.com/global/support/software/security/products-f/esf-200901e.html" source="CONFIRM" adv="1">http://www.fujitsu.com/global/support/software/security/products-f/esf-200901e.html</ref>
      <ref url="http://secunia.com/advisories/33974" source="SECUNIA" adv="1">33974</ref>
    </refs>
    <vuln_soft>
      <prod vendor="fujitsu" name="enhanced_support_facility">
        <vers num="3.0" />
        <vers num="3.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0868" published="2009-03-10" name="CVE-2009-0868" modified="2010-09-20" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">CRLF injection vulnerability in the WebLink template in Fujitsu Jasmine2000 Enterprise Edition allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/48818" source="XF">jasmine2000-weblink-response-splitting(48818)</ref>
      <ref url="http://www.securityfocus.com/bid/33832" source="BID">33832</ref>
      <ref url="http://www.fujitsu.com/global/support/software/security/products-f/jasmine-200901e.html" source="CONFIRM" adv="1">http://www.fujitsu.com/global/support/software/security/products-f/jasmine-200901e.html</ref>
      <ref url="http://secunia.com/advisories/33971" source="SECUNIA" adv="1">33971</ref>
    </refs>
    <vuln_soft>
      <prod vendor="fujitsu" name="jasmine2000">
        <vers num="" edition="enterprise" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0869" published="2009-03-10" name="CVE-2009-0869" modified="2009-06-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in the client in IBM Tivoli Storage Manager (TSM) HSM 5.3.2.0 through 5.3.5.0, 5.4.0.0 through 5.4.2.5, and 5.5.0.0 through 5.5.1.4 on Windows allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/34034" source="BID" patch="1">34034</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg21329223" source="CONFIRM" patch="1" adv="1">http://www-01.ibm.com/support/docview.wss?uid=swg21329223</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0638" source="VUPEN" adv="1">ADV-2009-0638</ref>
      <ref url="http://securitytracker.com/id?1021820" source="SECTRACK">1021820</ref>
      <ref url="http://secunia.com/advisories/34189" source="SECUNIA" adv="1">34189</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="tivoli_storage_manager_hsm">
        <vers num="5.3.2.0" />
        <vers num="5.3.5.0" />
        <vers num="5.4.0.0" />
        <vers num="5.4.2.5" />
        <vers num="5.5.0.0" />
        <vers num="5.5.1.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0870" published="2009-03-10" name="CVE-2009-0870" modified="2009-03-26" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:N/I:N/A:C)" CVSS_score="4.7" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="3.4" CVSS_base_score="4.7">
    <desc>
      <descript source="cve">The NFSv4 Server module in the kernel in Sun Solaris 10, and OpenSolaris before snv_111, allow local users to cause a denial of service (infinite loop and system hang) by accessing an hsfs filesystem that is shared through NFSv4, related to the rfs4_op_readdir function.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/34031" source="BID" patch="1">34031</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-252469-1" source="SUNALERT" patch="1" adv="1">252469</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-21-139462-02-1" source="CONFIRM" patch="1">http://sunsolve.sun.com/search/document.do?assetkey=1-21-139462-02-1</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/49133" source="XF">solaris-nfsv4-hsfs-dos(49133)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0765" source="VUPEN">ADV-2009-0765</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0635" source="VUPEN" adv="1">ADV-2009-0635</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2009-090.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2009-090.htm</ref>
      <ref url="http://securitytracker.com/id?1021819" source="SECTRACK">1021819</ref>
      <ref url="http://secunia.com/advisories/34371" source="SECUNIA">34371</ref>
      <ref url="http://secunia.com/advisories/34193" source="SECUNIA" adv="1">34193</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="opensolaris">
        <vers num="snv_01" edition="" />
        <vers num="snv_01" edition=":sparc" />
        <vers num="snv_01" edition=":x86" />
        <vers num="snv_02" edition="" />
        <vers num="snv_02" edition=":sparc" />
        <vers num="snv_02" edition=":x86" />
        <vers num="snv_03" edition="" />
        <vers num="snv_03" edition=":x86" />
        <vers num="snv_03" edition=":sparc" />
        <vers num="snv_04" edition="" />
        <vers num="snv_04" edition=":x86" />
        <vers num="snv_04" edition=":sparc" />
        <vers num="snv_05" edition="" />
        <vers num="snv_05" edition=":sparc" />
        <vers num="snv_05" edition=":x86" />
        <vers num="snv_06" edition="" />
        <vers num="snv_06" edition=":sparc" />
        <vers num="snv_06" edition=":x86" />
        <vers num="snv_07" edition="" />
        <vers num="snv_07" edition=":sparc" />
        <vers num="snv_07" edition=":x86" />
        <vers num="snv_08" edition="" />
        <vers num="snv_08" edition=":x86" />
        <vers num="snv_08" edition=":sparc" />
        <vers num="snv_09" edition="" />
        <vers num="snv_09" edition=":x86" />
        <vers num="snv_09" edition=":sparc" />
        <vers num="snv_10" edition="" />
        <vers num="snv_10" edition=":x86" />
        <vers num="snv_10" edition=":sparc" />
        <vers num="snv_100" edition="" />
        <vers num="snv_100" edition=":sparc" />
        <vers num="snv_100" edition=":x86" />
        <vers num="snv_101" edition="" />
        <vers num="snv_101" edition=":x86" />
        <vers num="snv_101" edition=":sparc" />
        <vers num="snv_102" edition="" />
        <vers num="snv_102" edition=":sparc" />
        <vers num="snv_102" edition=":x86" />
        <vers num="snv_103" edition="" />
        <vers num="snv_103" edition=":x86" />
        <vers num="snv_103" edition=":sparc" />
        <vers num="snv_104" edition="" />
        <vers num="snv_104" edition=":x86" />
        <vers num="snv_104" edition=":sparc" />
        <vers num="snv_105" edition="" />
        <vers num="snv_105" edition=":x86" />
        <vers num="snv_105" edition=":sparc" />
        <vers num="snv_106" edition="" />
        <vers num="snv_106" edition=":sparc" />
        <vers num="snv_106" edition=":x86" />
        <vers num="snv_107" edition="" />
        <vers num="snv_107" edition=":x86" />
        <vers num="snv_107" edition=":sparc" />
        <vers num="snv_108" edition="" />
        <vers num="snv_108" edition=":x86" />
        <vers num="snv_108" edition=":sparc" />
        <vers num="snv_109" edition="" />
        <vers num="snv_109" edition=":x86" />
        <vers num="snv_109" edition=":sparc" />
        <vers num="snv_11" edition="" />
        <vers num="snv_11" edition=":x86" />
        <vers num="snv_11" edition=":sparc" />
        <vers num="snv_110" edition="" />
        <vers num="snv_110" edition=":sparc" />
        <vers num="snv_110" edition=":x86" />
        <vers num="snv_12" edition="" />
        <vers num="snv_12" edition=":x86" />
        <vers num="snv_12" edition=":sparc" />
        <vers num="snv_13" edition="" />
        <vers num="snv_13" edition=":x86" />
        <vers num="snv_13" edition=":sparc" />
        <vers num="snv_14" edition="" />
        <vers num="snv_14" edition=":sparc" />
        <vers num="snv_14" edition=":x86" />
        <vers num="snv_15" edition="" />
        <vers num="snv_15" edition=":x86" />
        <vers num="snv_15" edition=":sparc" />
        <vers num="snv_16" edition="" />
        <vers num="snv_16" edition=":sparc" />
        <vers num="snv_16" edition=":x86" />
        <vers num="snv_17" edition="" />
        <vers num="snv_17" edition=":x86" />
        <vers num="snv_17" edition=":sparc" />
        <vers num="snv_18" edition="" />
        <vers num="snv_18" edition=":x86" />
        <vers num="snv_18" edition=":sparc" />
        <vers num="snv_19" edition="" />
        <vers num="snv_19" edition=":sparc" />
        <vers num="snv_19" edition=":x86" />
        <vers num="snv_20" edition="" />
        <vers num="snv_20" edition=":x86" />
        <vers num="snv_20" edition=":sparc" />
        <vers num="snv_21" edition="" />
        <vers num="snv_21" edition=":sparc" />
        <vers num="snv_21" edition=":x86" />
        <vers num="snv_22" edition="" />
        <vers num="snv_22" edition=":sparc" />
        <vers num="snv_22" edition=":x86" />
        <vers num="snv_23" edition="" />
        <vers num="snv_23" edition=":sparc" />
        <vers num="snv_23" edition=":x86" />
        <vers num="snv_24" edition="" />
        <vers num="snv_24" edition=":sparc" />
        <vers num="snv_24" edition=":x86" />
        <vers num="snv_25" edition="" />
        <vers num="snv_25" edition=":x86" />
        <vers num="snv_25" edition=":sparc" />
        <vers num="snv_26" edition="" />
        <vers num="snv_26" edition=":x86" />
        <vers num="snv_26" edition=":sparc" />
        <vers num="snv_27" edition="" />
        <vers num="snv_27" edition=":sparc" />
        <vers num="snv_27" edition=":x86" />
        <vers num="snv_28" edition="" />
        <vers num="snv_28" edition=":x86" />
        <vers num="snv_28" edition=":sparc" />
        <vers num="snv_29" edition="" />
        <vers num="snv_29" edition=":x86" />
        <vers num="snv_29" edition=":sparc" />
        <vers num="snv_30" edition="" />
        <vers num="snv_30" edition=":sparc" />
        <vers num="snv_30" edition=":x86" />
        <vers num="snv_31" edition="" />
        <vers num="snv_31" edition=":sparc" />
        <vers num="snv_31" edition=":x86" />
        <vers num="snv_32" edition="" />
        <vers num="snv_32" edition=":x86" />
        <vers num="snv_32" edition=":sparc" />
        <vers num="snv_33" edition="" />
        <vers num="snv_33" edition=":x86" />
        <vers num="snv_33" edition=":sparc" />
        <vers num="snv_34" edition="" />
        <vers num="snv_34" edition=":sparc" />
        <vers num="snv_34" edition=":x86" />
        <vers num="snv_35" edition="" />
        <vers num="snv_35" edition=":sparc" />
        <vers num="snv_35" edition=":x86" />
        <vers num="snv_36" edition="" />
        <vers num="snv_36" edition=":x86" />
        <vers num="snv_36" edition=":sparc" />
        <vers num="snv_37" edition="" />
        <vers num="snv_37" edition=":sparc" />
        <vers num="snv_37" edition=":x86" />
        <vers num="snv_38" edition="" />
        <vers num="snv_38" edition=":sparc" />
        <vers num="snv_38" edition=":x86" />
        <vers num="snv_39" edition="" />
        <vers num="snv_39" edition=":sparc" />
        <vers num="snv_39" edition=":x86" />
        <vers num="snv_40" edition="" />
        <vers num="snv_40" edition=":sparc" />
        <vers num="snv_40" edition=":x86" />
        <vers num="snv_41" edition="" />
        <vers num="snv_41" edition=":sparc" />
        <vers num="snv_41" edition=":x86" />
        <vers num="snv_42" edition="" />
        <vers num="snv_42" edition=":x86" />
        <vers num="snv_42" edition=":sparc" />
        <vers num="snv_43" edition="" />
        <vers num="snv_43" edition=":sparc" />
        <vers num="snv_43" edition=":x86" />
        <vers num="snv_44" edition="" />
        <vers num="snv_44" edition=":x86" />
        <vers num="snv_44" edition=":sparc" />
        <vers num="snv_45" edition="" />
        <vers num="snv_45" edition=":x86" />
        <vers num="snv_45" edition=":sparc" />
        <vers num="snv_46" edition="" />
        <vers num="snv_46" edition=":x86" />
        <vers num="snv_46" edition=":sparc" />
        <vers num="snv_47" edition="" />
        <vers num="snv_47" edition=":x86" />
        <vers num="snv_47" edition=":sparc" />
        <vers num="snv_48" edition="" />
        <vers num="snv_48" edition=":sparc" />
        <vers num="snv_48" edition=":x86" />
        <vers num="snv_49" edition="" />
        <vers num="snv_49" edition=":sparc" />
        <vers num="snv_49" edition=":x86" />
        <vers num="snv_50" edition="" />
        <vers num="snv_50" edition=":sparc" />
        <vers num="snv_50" edition=":x86" />
        <vers num="snv_51" edition="" />
        <vers num="snv_51" edition=":sparc" />
        <vers num="snv_51" edition=":x86" />
        <vers num="snv_52" edition="" />
        <vers num="snv_52" edition=":sparc" />
        <vers num="snv_52" edition=":x86" />
        <vers num="snv_53" edition="" />
        <vers num="snv_53" edition=":sparc" />
        <vers num="snv_53" edition=":x86" />
        <vers num="snv_54" edition="" />
        <vers num="snv_54" edition=":x86" />
        <vers num="snv_54" edition=":sparc" />
        <vers num="snv_55" edition="" />
        <vers num="snv_55" edition=":sparc" />
        <vers num="snv_55" edition=":x86" />
        <vers num="snv_56" edition="" />
        <vers num="snv_56" edition=":x86" />
        <vers num="snv_56" edition=":sparc" />
        <vers num="snv_57" edition="" />
        <vers num="snv_57" edition=":x86" />
        <vers num="snv_57" edition=":sparc" />
        <vers num="snv_58" edition="" />
        <vers num="snv_58" edition=":sparc" />
        <vers num="snv_58" edition=":x86" />
        <vers num="snv_59" edition="" />
        <vers num="snv_59" edition=":sparc" />
        <vers num="snv_59" edition=":x86" />
        <vers num="snv_60" edition="" />
        <vers num="snv_60" edition=":x86" />
        <vers num="snv_60" edition=":sparc" />
        <vers num="snv_61" edition="" />
        <vers num="snv_61" edition=":sparc" />
        <vers num="snv_61" edition=":x86" />
        <vers num="snv_62" edition="" />
        <vers num="snv_62" edition=":x86" />
        <vers num="snv_62" edition=":sparc" />
        <vers num="snv_63" edition="" />
        <vers num="snv_63" edition=":x86" />
        <vers num="snv_64" edition="" />
        <vers num="snv_64" edition=":x86" />
        <vers num="snv_65" edition="" />
        <vers num="snv_65" edition=":x86" />
        <vers num="snv_66" edition="" />
        <vers num="snv_66" edition=":x86" />
        <vers num="snv_67" edition="" />
        <vers num="snv_67" edition=":x86" />
        <vers num="snv_68" edition="" />
        <vers num="snv_68" edition=":x86" />
        <vers num="snv_69" edition="" />
        <vers num="snv_69" edition=":x86" />
        <vers num="snv_70" edition="" />
        <vers num="snv_70" edition=":x86" />
        <vers num="snv_71" edition="" />
        <vers num="snv_71" edition=":x86" />
        <vers num="snv_72" edition="" />
        <vers num="snv_72" edition=":x86" />
        <vers num="snv_73" edition="" />
        <vers num="snv_73" edition=":x86" />
        <vers num="snv_73" edition=":sparc" />
        <vers num="snv_74" edition="" />
        <vers num="snv_74" edition=":sparc" />
        <vers num="snv_74" edition=":x86" />
        <vers num="snv_75" edition="" />
        <vers num="snv_75" edition=":sparc" />
        <vers num="snv_75" edition=":x86" />
        <vers num="snv_76" edition="" />
        <vers num="snv_76" edition=":x86" />
        <vers num="snv_76" edition=":sparc" />
        <vers num="snv_77" edition="" />
        <vers num="snv_77" edition=":sparc" />
        <vers num="snv_77" edition=":x86" />
        <vers num="snv_78" edition="" />
        <vers num="snv_78" edition=":sparc" />
        <vers num="snv_78" edition=":x86" />
        <vers num="snv_79" edition="" />
        <vers num="snv_79" edition=":x86" />
        <vers num="snv_79" edition=":sparc" />
        <vers num="snv_80" edition="" />
        <vers num="snv_80" edition=":x86" />
        <vers num="snv_80" edition=":sparc" />
        <vers num="snv_81" edition="" />
        <vers num="snv_81" edition=":x86" />
        <vers num="snv_81" edition=":sparc" />
        <vers num="snv_82" edition="" />
        <vers num="snv_82" edition=":x86" />
        <vers num="snv_82" edition=":sparc" />
        <vers num="snv_83" edition="" />
        <vers num="snv_83" edition=":x86" />
        <vers num="snv_84" edition="" />
        <vers num="snv_84" edition=":x86" />
        <vers num="snv_85" edition="" />
        <vers num="snv_85" edition=":x86" />
        <vers num="snv_86" edition="" />
        <vers num="snv_86" edition=":x86" />
        <vers num="snv_87" edition="" />
        <vers num="snv_87" edition=":x86" />
        <vers num="snv_88" edition="" />
        <vers num="snv_88" edition=":x86" />
        <vers num="snv_89" edition="" />
        <vers num="snv_89" edition=":x86" />
        <vers num="snv_90" edition="" />
        <vers num="snv_90" edition=":x86" />
        <vers num="snv_91" edition="" />
        <vers num="snv_91" edition=":x86" />
        <vers num="snv_92" edition="" />
        <vers num="snv_92" edition=":x86" />
        <vers num="snv_93" edition="" />
        <vers num="snv_93" edition=":sparc" />
        <vers num="snv_93" edition=":x86" />
        <vers num="snv_94" edition="" />
        <vers num="snv_94" edition=":x86" />
        <vers num="snv_94" edition=":sparc" />
        <vers num="snv_95" edition="" />
        <vers num="snv_95" edition=":x86" />
        <vers num="snv_95" edition=":sparc" />
        <vers num="snv_96" edition="" />
        <vers num="snv_96" edition=":sparc" />
        <vers num="snv_96" edition=":x86" />
        <vers num="snv_97" edition="" />
        <vers num="snv_97" edition=":x86" />
        <vers num="snv_97" edition=":sparc" />
        <vers num="snv_98" edition="" />
        <vers num="snv_98" edition=":sparc" />
        <vers num="snv_98" edition=":x86" />
        <vers num="snv_99" edition="" />
        <vers num="snv_99" edition=":sparc" />
        <vers num="snv_99" edition=":x86" />
      </prod>
      <prod vendor="sun" name="solaris">
        <vers num="10.0" edition="" />
        <vers num="10.0" edition=":sparc" />
        <vers num="10.0" edition=":x86" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2009-0871" published="2009-03-11" name="CVE-2009-0871" modified="2009-03-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:S/C:N/I:N/A:P)" CVSS_score="3.5" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="6.8" CVSS_base_score="3.5">
    <desc>
      <descript source="cve">The SIP channel driver in Asterisk Open Source 1.4.22, 1.4.23, and 1.4.23.1; 1.6.0 before 1.6.0.6; 1.6.1 before 1.6.1.0-rc2; and Asterisk Business Edition C.2.3, with the pedantic option enabled, allows remote authenticated users to cause a denial of service (crash) via a SIP INVITE request without any headers, which triggers a NULL pointer dereference in the (1) sip_uri_headers_cmp and (2) sip_uri_params_cmp functions.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/34070" source="BID" patch="1">34070</ref>
      <ref url="http://downloads.digium.com/pub/security/AST-2009-002.html" source="CONFIRM" patch="1" adv="1">http://downloads.digium.com/pub/security/AST-2009-002.html</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0667" source="VUPEN">ADV-2009-0667</ref>
      <ref url="http://www.securitytracker.com/id?1021834" source="SECTRACK">1021834</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/501656/100/0/threaded" source="BUGTRAQ">20090310 AST-2009-002: Remote Crash Vulnerability in SIP channel driver</ref>
      <ref url="http://secunia.com/advisories/34229" source="SECUNIA" adv="1">34229</ref>
      <ref url="http://osvdb.org/52568" source="OSVDB">52568</ref>
      <ref url="http://bugs.digium.com/view.php?id=14417" source="CONFIRM">http://bugs.digium.com/view.php?id=14417</ref>
      <ref url="http://bugs.digium.com/view.php?id=13547" source="CONFIRM">http://bugs.digium.com/view.php?id=13547</ref>
    </refs>
    <vuln_soft>
      <prod vendor="digium" name="asterisk">
        <vers num="1.4.22" />
        <vers num="1.4.23" />
        <vers num="1.4.23.1" />
        <vers num="1.6.0" edition="beta1" />
        <vers num="1.6.0" edition="beta2" />
        <vers num="1.6.0" edition="beta3" />
        <vers num="1.6.0" edition="beta4" />
        <vers num="1.6.0" edition="beta5" />
        <vers num="1.6.0" edition="beta6" />
        <vers num="1.6.0" edition="beta7" />
        <vers num="1.6.0" edition="beta7.1" />
        <vers num="1.6.0" edition="beta8" />
        <vers num="1.6.0" edition="beta9" />
        <vers num="1.6.0" edition="rc4" />
        <vers num="1.6.0" edition="rc5" />
        <vers num="1.6.0" edition="rc6" />
        <vers num="1.6.0.1" />
        <vers num="1.6.0.2" />
        <vers num="1.6.0.3" edition="rc1" />
        <vers num="1.6.0.4" edition="rc1" />
        <vers num="1.6.0.5" />
        <vers num="1.6.1" edition="beta1" />
        <vers num="1.6.1" edition="beta2" />
        <vers num="1.6.1" edition="beta3" />
        <vers num="1.6.1" edition="beta4" />
        <vers num="1.6.1" edition="rc1" />
        <vers num="c.2.3" edition="-" />
        <vers num="c.2.3" edition="-:business" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0872" published="2009-03-11" name="CVE-2009-0872" modified="2009-03-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">The NFS server in Sun Solaris 10, and OpenSolaris before snv_111, does not properly implement the AUTH_NONE (aka sec=none) security mode in combination with other security modes, which allows remote attackers to bypass intended access restrictions and read or modify files, as demonstrated by a combination of the AUTH_NONE and AUTH_SYS security modes.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-253588-1" source="SUNALERT" patch="1" adv="1">253588</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-21-139462-02-1" source="CONFIRM" patch="1">http://sunsolve.sun.com/search/document.do?assetkey=1-21-139462-02-1</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/49170" source="XF">solaris-nfssec-unauthorized-access(49170)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0798" source="VUPEN">ADV-2009-0798</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0658" source="VUPEN" adv="1">ADV-2009-0658</ref>
      <ref url="http://www.securityfocus.com/bid/34063" source="BID">34063</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2009-093.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2009-093.htm</ref>
      <ref url="http://securitytracker.com/id?1021833" source="SECTRACK">1021833</ref>
      <ref url="http://secunia.com/advisories/34429" source="SECUNIA">34429</ref>
      <ref url="http://secunia.com/advisories/34213" source="SECUNIA" adv="1">34213</ref>
      <ref url="http://osvdb.org/52559" source="OSVDB">52559</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="opensolaris">
        <vers num="snv_01" edition="" />
        <vers num="snv_01" edition=":sparc" />
        <vers num="snv_01" edition=":x86" />
        <vers num="snv_02" edition="" />
        <vers num="snv_02" edition=":sparc" />
        <vers num="snv_02" edition=":x86" />
        <vers num="snv_03" edition="" />
        <vers num="snv_03" edition=":x86" />
        <vers num="snv_03" edition=":sparc" />
        <vers num="snv_04" edition="" />
        <vers num="snv_04" edition=":x86" />
        <vers num="snv_04" edition=":sparc" />
        <vers num="snv_05" edition="" />
        <vers num="snv_05" edition=":sparc" />
        <vers num="snv_05" edition=":x86" />
        <vers num="snv_06" edition="" />
        <vers num="snv_06" edition=":sparc" />
        <vers num="snv_06" edition=":x86" />
        <vers num="snv_07" edition="" />
        <vers num="snv_07" edition=":sparc" />
        <vers num="snv_07" edition=":x86" />
        <vers num="snv_08" edition="" />
        <vers num="snv_08" edition=":x86" />
        <vers num="snv_08" edition=":sparc" />
        <vers num="snv_09" edition="" />
        <vers num="snv_09" edition=":x86" />
        <vers num="snv_09" edition=":sparc" />
        <vers num="snv_10" edition="" />
        <vers num="snv_10" edition=":x86" />
        <vers num="snv_10" edition=":sparc" />
        <vers num="snv_100" edition="" />
        <vers num="snv_100" edition=":sparc" />
        <vers num="snv_100" edition=":x86" />
        <vers num="snv_101" edition="" />
        <vers num="snv_101" edition=":x86" />
        <vers num="snv_101" edition=":sparc" />
        <vers num="snv_102" edition="" />
        <vers num="snv_102" edition=":sparc" />
        <vers num="snv_102" edition=":x86" />
        <vers num="snv_103" edition="" />
        <vers num="snv_103" edition=":x86" />
        <vers num="snv_103" edition=":sparc" />
        <vers num="snv_104" edition="" />
        <vers num="snv_104" edition=":x86" />
        <vers num="snv_104" edition=":sparc" />
        <vers num="snv_105" edition="" />
        <vers num="snv_105" edition=":x86" />
        <vers num="snv_105" edition=":sparc" />
        <vers num="snv_106" edition="" />
        <vers num="snv_106" edition=":sparc" />
        <vers num="snv_106" edition=":x86" />
        <vers num="snv_107" edition="" />
        <vers num="snv_107" edition=":x86" />
        <vers num="snv_107" edition=":sparc" />
        <vers num="snv_108" edition="" />
        <vers num="snv_108" edition=":x86" />
        <vers num="snv_108" edition=":sparc" />
        <vers num="snv_109" edition="" />
        <vers num="snv_109" edition=":x86" />
        <vers num="snv_109" edition=":sparc" />
        <vers num="snv_11" edition="" />
        <vers num="snv_11" edition=":x86" />
        <vers num="snv_11" edition=":sparc" />
        <vers prev="1" num="snv_110" edition="" />
        <vers prev="1" num="snv_110" edition=":sparc" />
        <vers prev="1" num="snv_110" edition=":x86" />
        <vers num="snv_12" edition="" />
        <vers num="snv_12" edition=":x86" />
        <vers num="snv_12" edition=":sparc" />
        <vers num="snv_13" edition="" />
        <vers num="snv_13" edition=":x86" />
        <vers num="snv_13" edition=":sparc" />
        <vers num="snv_14" edition="" />
        <vers num="snv_14" edition=":sparc" />
        <vers num="snv_14" edition=":x86" />
        <vers num="snv_15" edition="" />
        <vers num="snv_15" edition=":x86" />
        <vers num="snv_15" edition=":sparc" />
        <vers num="snv_16" edition="" />
        <vers num="snv_16" edition=":sparc" />
        <vers num="snv_16" edition=":x86" />
        <vers num="snv_17" edition="" />
        <vers num="snv_17" edition=":x86" />
        <vers num="snv_17" edition=":sparc" />
        <vers num="snv_18" edition="" />
        <vers num="snv_18" edition=":x86" />
        <vers num="snv_18" edition=":sparc" />
        <vers num="snv_19" edition="" />
        <vers num="snv_19" edition=":sparc" />
        <vers num="snv_19" edition=":x86" />
        <vers num="snv_20" edition="" />
        <vers num="snv_20" edition=":x86" />
        <vers num="snv_20" edition=":sparc" />
        <vers num="snv_21" edition="" />
        <vers num="snv_21" edition=":sparc" />
        <vers num="snv_21" edition=":x86" />
        <vers num="snv_22" edition="" />
        <vers num="snv_22" edition=":sparc" />
        <vers num="snv_22" edition=":x86" />
        <vers num="snv_23" edition="" />
        <vers num="snv_23" edition=":sparc" />
        <vers num="snv_23" edition=":x86" />
        <vers num="snv_24" edition="" />
        <vers num="snv_24" edition=":sparc" />
        <vers num="snv_24" edition=":x86" />
        <vers num="snv_25" edition="" />
        <vers num="snv_25" edition=":x86" />
        <vers num="snv_25" edition=":sparc" />
        <vers num="snv_26" edition="" />
        <vers num="snv_26" edition=":x86" />
        <vers num="snv_26" edition=":sparc" />
        <vers num="snv_27" edition="" />
        <vers num="snv_27" edition=":sparc" />
        <vers num="snv_27" edition=":x86" />
        <vers num="snv_28" edition="" />
        <vers num="snv_28" edition=":x86" />
        <vers num="snv_28" edition=":sparc" />
        <vers num="snv_29" edition="" />
        <vers num="snv_29" edition=":x86" />
        <vers num="snv_29" edition=":sparc" />
        <vers num="snv_30" edition="" />
        <vers num="snv_30" edition=":sparc" />
        <vers num="snv_30" edition=":x86" />
        <vers num="snv_31" edition="" />
        <vers num="snv_31" edition=":sparc" />
        <vers num="snv_31" edition=":x86" />
        <vers num="snv_32" edition="" />
        <vers num="snv_32" edition=":x86" />
        <vers num="snv_32" edition=":sparc" />
        <vers num="snv_33" edition="" />
        <vers num="snv_33" edition=":x86" />
        <vers num="snv_33" edition=":sparc" />
        <vers num="snv_34" edition="" />
        <vers num="snv_34" edition=":sparc" />
        <vers num="snv_34" edition=":x86" />
        <vers num="snv_35" edition="" />
        <vers num="snv_35" edition=":sparc" />
        <vers num="snv_35" edition=":x86" />
        <vers num="snv_36" edition="" />
        <vers num="snv_36" edition=":x86" />
        <vers num="snv_36" edition=":sparc" />
        <vers num="snv_37" edition="" />
        <vers num="snv_37" edition=":sparc" />
        <vers num="snv_37" edition=":x86" />
        <vers num="snv_38" edition="" />
        <vers num="snv_38" edition=":sparc" />
        <vers num="snv_38" edition=":x86" />
        <vers num="snv_39" edition="" />
        <vers num="snv_39" edition=":sparc" />
        <vers num="snv_39" edition=":x86" />
        <vers num="snv_40" edition="" />
        <vers num="snv_40" edition=":sparc" />
        <vers num="snv_40" edition=":x86" />
        <vers num="snv_41" edition="" />
        <vers num="snv_41" edition=":sparc" />
        <vers num="snv_41" edition=":x86" />
        <vers num="snv_42" edition="" />
        <vers num="snv_42" edition=":x86" />
        <vers num="snv_42" edition=":sparc" />
        <vers num="snv_43" edition="" />
        <vers num="snv_43" edition=":sparc" />
        <vers num="snv_43" edition=":x86" />
        <vers num="snv_44" edition="" />
        <vers num="snv_44" edition=":x86" />
        <vers num="snv_44" edition=":sparc" />
        <vers num="snv_45" edition="" />
        <vers num="snv_45" edition=":x86" />
        <vers num="snv_45" edition=":sparc" />
        <vers num="snv_46" edition="" />
        <vers num="snv_46" edition=":x86" />
        <vers num="snv_46" edition=":sparc" />
        <vers num="snv_47" edition="" />
        <vers num="snv_47" edition=":x86" />
        <vers num="snv_47" edition=":sparc" />
        <vers num="snv_48" edition="" />
        <vers num="snv_48" edition=":sparc" />
        <vers num="snv_48" edition=":x86" />
        <vers num="snv_49" edition="" />
        <vers num="snv_49" edition=":sparc" />
        <vers num="snv_49" edition=":x86" />
        <vers num="snv_50" edition="" />
        <vers num="snv_50" edition=":sparc" />
        <vers num="snv_50" edition=":x86" />
        <vers num="snv_51" edition="" />
        <vers num="snv_51" edition=":sparc" />
        <vers num="snv_51" edition=":x86" />
        <vers num="snv_52" edition="" />
        <vers num="snv_52" edition=":sparc" />
        <vers num="snv_52" edition=":x86" />
        <vers num="snv_53" edition="" />
        <vers num="snv_53" edition=":sparc" />
        <vers num="snv_53" edition=":x86" />
        <vers num="snv_54" edition="" />
        <vers num="snv_54" edition=":x86" />
        <vers num="snv_54" edition=":sparc" />
        <vers num="snv_55" edition="" />
        <vers num="snv_55" edition=":sparc" />
        <vers num="snv_55" edition=":x86" />
        <vers num="snv_56" edition="" />
        <vers num="snv_56" edition=":x86" />
        <vers num="snv_56" edition=":sparc" />
        <vers num="snv_57" edition="" />
        <vers num="snv_57" edition=":x86" />
        <vers num="snv_57" edition=":sparc" />
        <vers num="snv_58" edition="" />
        <vers num="snv_58" edition=":sparc" />
        <vers num="snv_58" edition=":x86" />
        <vers num="snv_59" edition="" />
        <vers num="snv_59" edition=":sparc" />
        <vers num="snv_59" edition=":x86" />
        <vers num="snv_60" edition="" />
        <vers num="snv_60" edition=":x86" />
        <vers num="snv_60" edition=":sparc" />
        <vers num="snv_61" edition="" />
        <vers num="snv_61" edition=":sparc" />
        <vers num="snv_61" edition=":x86" />
        <vers num="snv_62" edition="" />
        <vers num="snv_62" edition=":x86" />
        <vers num="snv_62" edition=":sparc" />
        <vers num="snv_63" edition="" />
        <vers num="snv_63" edition=":sparc" />
        <vers num="snv_63" edition=":x86" />
        <vers num="snv_64" edition="" />
        <vers num="snv_64" edition=":x86" />
        <vers num="snv_64" edition=":sparc" />
        <vers num="snv_65" edition="" />
        <vers num="snv_65" edition=":x86" />
        <vers num="snv_65" edition=":sparc" />
        <vers num="snv_66" edition="" />
        <vers num="snv_66" edition=":x86" />
        <vers num="snv_66" edition=":sparc" />
        <vers num="snv_67" edition="" />
        <vers num="snv_67" edition=":sparc" />
        <vers num="snv_67" edition=":x86" />
        <vers num="snv_68" edition="" />
        <vers num="snv_68" edition=":x86" />
        <vers num="snv_68" edition=":sparc" />
        <vers num="snv_69" edition="" />
        <vers num="snv_69" edition=":sparc" />
        <vers num="snv_69" edition=":x86" />
        <vers num="snv_70" edition="" />
        <vers num="snv_70" edition=":sparc" />
        <vers num="snv_70" edition=":x86" />
        <vers num="snv_71" edition="" />
        <vers num="snv_71" edition=":x86" />
        <vers num="snv_71" edition=":sparc" />
        <vers num="snv_72" edition="" />
        <vers num="snv_72" edition=":x86" />
        <vers num="snv_72" edition=":sparc" />
        <vers num="snv_73" edition="" />
        <vers num="snv_73" edition=":x86" />
        <vers num="snv_73" edition=":sparc" />
        <vers num="snv_74" edition="" />
        <vers num="snv_74" edition=":sparc" />
        <vers num="snv_74" edition=":x86" />
        <vers num="snv_75" edition="" />
        <vers num="snv_75" edition=":sparc" />
        <vers num="snv_75" edition=":x86" />
        <vers num="snv_76" edition="" />
        <vers num="snv_76" edition=":x86" />
        <vers num="snv_76" edition=":sparc" />
        <vers num="snv_77" edition="" />
        <vers num="snv_77" edition=":sparc" />
        <vers num="snv_77" edition=":x86" />
        <vers num="snv_78" edition="" />
        <vers num="snv_78" edition=":sparc" />
        <vers num="snv_78" edition=":x86" />
        <vers num="snv_79" edition="" />
        <vers num="snv_79" edition=":x86" />
        <vers num="snv_79" edition=":sparc" />
        <vers num="snv_80" edition="" />
        <vers num="snv_80" edition=":x86" />
        <vers num="snv_80" edition=":sparc" />
        <vers num="snv_81" edition="" />
        <vers num="snv_81" edition=":x86" />
        <vers num="snv_81" edition=":sparc" />
        <vers num="snv_82" edition="" />
        <vers num="snv_82" edition=":x86" />
        <vers num="snv_82" edition=":sparc" />
        <vers num="snv_83" edition="" />
        <vers num="snv_83" edition=":x86" />
        <vers num="snv_83" edition=":sparc" />
        <vers num="snv_84" edition="" />
        <vers num="snv_84" edition=":x86" />
        <vers num="snv_84" edition=":sparc" />
        <vers num="snv_85" edition="" />
        <vers num="snv_85" edition=":x86" />
        <vers num="snv_85" edition=":sparc" />
        <vers num="snv_86" edition="" />
        <vers num="snv_86" edition=":sparc" />
        <vers num="snv_86" edition=":x86" />
        <vers num="snv_87" edition="" />
        <vers num="snv_87" edition=":sparc" />
        <vers num="snv_87" edition=":x86" />
        <vers num="snv_88" edition="" />
        <vers num="snv_88" edition=":x86" />
        <vers num="snv_88" edition=":sparc" />
        <vers num="snv_89" edition="" />
        <vers num="snv_89" edition=":x86" />
        <vers num="snv_89" edition=":sparc" />
        <vers num="snv_90" edition="" />
        <vers num="snv_90" edition=":sparc" />
        <vers num="snv_90" edition=":x86" />
        <vers num="snv_91" edition="" />
        <vers num="snv_91" edition=":sparc" />
        <vers num="snv_91" edition=":x86" />
        <vers num="snv_92" edition="" />
        <vers num="snv_92" edition=":sparc" />
        <vers num="snv_92" edition=":x86" />
        <vers num="snv_93" edition="" />
        <vers num="snv_93" edition=":sparc" />
        <vers num="snv_93" edition=":x86" />
        <vers num="snv_94" edition="" />
        <vers num="snv_94" edition=":x86" />
        <vers num="snv_94" edition=":sparc" />
        <vers num="snv_95" edition="" />
        <vers num="snv_95" edition=":x86" />
        <vers num="snv_95" edition=":sparc" />
        <vers num="snv_96" edition="" />
        <vers num="snv_96" edition=":sparc" />
        <vers num="snv_96" edition=":x86" />
        <vers num="snv_97" edition="" />
        <vers num="snv_97" edition=":x86" />
        <vers num="snv_97" edition=":sparc" />
        <vers num="snv_98" edition="" />
        <vers num="snv_98" edition=":sparc" />
        <vers num="snv_98" edition=":x86" />
        <vers num="snv_99" edition="" />
        <vers num="snv_99" edition=":sparc" />
        <vers num="snv_99" edition=":x86" />
      </prod>
      <prod vendor="sun" name="solaris">
        <vers num="10" edition="" />
        <vers num="10" edition=":x86" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0873" published="2009-03-11" name="CVE-2009-0873" modified="2009-04-02" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">The NFS daemon (aka nfsd) in Sun Solaris 10 and OpenSolaris before snv_106, when NFSv3 is used, does not properly implement combinations of security modes, which allows remote attackers to bypass intended access restrictions and read or modify files, as demonstrated by a combination of the sec=sys and sec=krb5 security modes, related to modes that "override each other."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-250306-1" source="SUNALERT" patch="1" adv="1">250306</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-21-139462-02-1" source="CONFIRM" patch="1" adv="1">http://sunsolve.sun.com/search/document.do?assetkey=1-21-139462-02-1</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/49171" source="XF">solaris-nfsd-unauthorized-access(49171)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0814" source="VUPEN">ADV-2009-0814</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0657" source="VUPEN" adv="1">ADV-2009-0657</ref>
      <ref url="http://www.securityfocus.com/bid/34062" source="BID">34062</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2009-096.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2009-096.htm</ref>
      <ref url="http://securitytracker.com/id?1021832" source="SECTRACK">1021832</ref>
      <ref url="http://secunia.com/advisories/34435" source="SECUNIA">34435</ref>
      <ref url="http://secunia.com/advisories/34225" source="SECUNIA" adv="1">34225</ref>
      <ref url="http://osvdb.org/52560" source="OSVDB">52560</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="opensolaris">
        <vers num="snv_01" edition="" />
        <vers num="snv_01" edition=":sparc" />
        <vers num="snv_01" edition=":x86" />
        <vers num="snv_02" edition="" />
        <vers num="snv_02" edition=":sparc" />
        <vers num="snv_02" edition=":x86" />
        <vers num="snv_03" edition="" />
        <vers num="snv_03" edition=":x86" />
        <vers num="snv_03" edition=":sparc" />
        <vers num="snv_04" edition="" />
        <vers num="snv_04" edition=":x86" />
        <vers num="snv_04" edition=":sparc" />
        <vers num="snv_05" edition="" />
        <vers num="snv_05" edition=":sparc" />
        <vers num="snv_05" edition=":x86" />
        <vers num="snv_06" edition="" />
        <vers num="snv_06" edition=":sparc" />
        <vers num="snv_06" edition=":x86" />
        <vers num="snv_07" edition="" />
        <vers num="snv_07" edition=":sparc" />
        <vers num="snv_07" edition=":x86" />
        <vers num="snv_08" edition="" />
        <vers num="snv_08" edition=":x86" />
        <vers num="snv_08" edition=":sparc" />
        <vers num="snv_09" edition="" />
        <vers num="snv_09" edition=":sparc" />
        <vers num="snv_09" edition=":x86" />
        <vers num="snv_10" edition="" />
        <vers num="snv_10" edition=":x86" />
        <vers num="snv_10" edition=":sparc" />
        <vers num="snv_20" edition="" />
        <vers num="snv_20" edition=":x86" />
        <vers num="snv_20" edition=":sparc" />
        <vers num="snv_21" edition="" />
        <vers num="snv_21" edition=":x86" />
        <vers num="snv_21" edition=":sparc" />
        <vers num="snv_22" edition="" />
        <vers num="snv_22" edition=":sparc" />
        <vers num="snv_22" edition=":x86" />
        <vers num="snv_23" edition="" />
        <vers num="snv_23" edition=":sparc" />
        <vers num="snv_23" edition=":x86" />
        <vers num="snv_24" edition="" />
        <vers num="snv_24" edition=":sparc" />
        <vers num="snv_24" edition=":x86" />
        <vers num="snv_25" edition="" />
        <vers num="snv_25" edition=":sparc" />
        <vers num="snv_25" edition=":x86" />
        <vers num="snv_26" edition="" />
        <vers num="snv_26" edition=":sparc" />
        <vers num="snv_26" edition=":x86" />
        <vers num="snv_27" edition="" />
        <vers num="snv_27" edition=":sparc" />
        <vers num="snv_27" edition=":x86" />
        <vers num="snv_28" edition="" />
        <vers num="snv_28" edition=":sparc" />
        <vers num="snv_28" edition=":x86" />
        <vers num="snv_29" edition="" />
        <vers num="snv_29" edition=":x86" />
        <vers num="snv_29" edition=":sparc" />
        <vers num="snv_30" edition="" />
        <vers num="snv_30" edition=":sparc" />
        <vers num="snv_30" edition=":x86" />
        <vers num="snv_31" edition="" />
        <vers num="snv_31" edition=":sparc" />
        <vers num="snv_31" edition=":x86" />
        <vers num="snv_32" edition="" />
        <vers num="snv_32" edition=":x86" />
        <vers num="snv_32" edition=":sparc" />
        <vers num="snv_33" edition="" />
        <vers num="snv_33" edition=":x86" />
        <vers num="snv_33" edition=":sparc" />
        <vers num="snv_34" edition="" />
        <vers num="snv_34" edition=":sparc" />
        <vers num="snv_34" edition=":x86" />
        <vers num="snv_35" edition="" />
        <vers num="snv_35" edition=":sparc" />
        <vers num="snv_35" edition=":x86" />
        <vers num="snv_36" edition="" />
        <vers num="snv_36" edition=":sparc" />
        <vers num="snv_36" edition=":x86" />
        <vers num="snv_37" edition="" />
        <vers num="snv_37" edition=":sparc" />
        <vers num="snv_37" edition=":x86" />
        <vers num="snv_38" edition="" />
        <vers num="snv_38" edition=":sparc" />
        <vers num="snv_38" edition=":x86" />
        <vers num="snv_39" edition="" />
        <vers num="snv_39" edition=":sparc" />
        <vers num="snv_39" edition=":x86" />
        <vers num="snv_40" edition="" />
        <vers num="snv_40" edition=":x86" />
        <vers num="snv_40" edition=":sparc" />
        <vers num="snv_41" edition="" />
        <vers num="snv_41" edition=":sparc" />
        <vers num="snv_41" edition=":x86" />
        <vers num="snv_42" edition="" />
        <vers num="snv_42" edition=":x86" />
        <vers num="snv_42" edition=":sparc" />
        <vers num="snv_43" edition="" />
        <vers num="snv_43" edition=":sparc" />
        <vers num="snv_43" edition=":x86" />
        <vers num="snv_44" edition="" />
        <vers num="snv_44" edition=":x86" />
        <vers num="snv_44" edition=":sparc" />
        <vers num="snv_45" edition="" />
        <vers num="snv_45" edition=":x86" />
        <vers num="snv_45" edition=":sparc" />
        <vers num="snv_46" edition="" />
        <vers num="snv_46" edition=":sparc" />
        <vers num="snv_46" edition=":x86" />
        <vers num="snv_47" edition="" />
        <vers num="snv_47" edition=":x86" />
        <vers num="snv_47" edition=":sparc" />
        <vers num="snv_48" edition="" />
        <vers num="snv_48" edition=":sparc" />
        <vers num="snv_48" edition=":x86" />
        <vers num="snv_49" edition="" />
        <vers num="snv_49" edition=":sparc" />
        <vers num="snv_49" edition=":x86" />
        <vers num="snv_50" edition="" />
        <vers num="snv_50" edition=":sparc" />
        <vers num="snv_50" edition=":x86" />
        <vers num="snv_51" edition="" />
        <vers num="snv_51" edition=":x86" />
        <vers num="snv_51" edition=":sparc" />
        <vers num="snv_52" edition="" />
        <vers num="snv_52" edition=":x86" />
        <vers num="snv_52" edition=":sparc" />
        <vers num="snv_53" edition="" />
        <vers num="snv_53" edition=":sparc" />
        <vers num="snv_53" edition=":x86" />
        <vers num="snv_54" edition="" />
        <vers num="snv_54" edition=":sparc" />
        <vers num="snv_54" edition=":x86" />
        <vers num="snv_55" edition="" />
        <vers num="snv_55" edition=":sparc" />
        <vers num="snv_55" edition=":x86" />
        <vers num="snv_56" edition="" />
        <vers num="snv_56" edition=":x86" />
        <vers num="snv_56" edition=":sparc" />
        <vers num="snv_57" edition="" />
        <vers num="snv_57" edition=":x86" />
        <vers num="snv_57" edition=":sparc" />
        <vers num="snv_58" edition="" />
        <vers num="snv_58" edition=":sparc" />
        <vers num="snv_58" edition=":x86" />
        <vers num="snv_59" edition="" />
        <vers num="snv_59" edition=":sparc" />
        <vers num="snv_59" edition=":x86" />
        <vers num="snv_60" edition="" />
        <vers num="snv_60" edition=":x86" />
        <vers num="snv_60" edition=":sparc" />
        <vers num="snv_61" edition="" />
        <vers num="snv_61" edition=":sparc" />
        <vers num="snv_61" edition=":x86" />
        <vers num="snv_62" edition="" />
        <vers num="snv_62" edition=":x86" />
        <vers num="snv_62" edition=":sparc" />
        <vers num="snv_63" edition="" />
        <vers num="snv_63" edition=":x86" />
        <vers num="snv_63" edition=":sparc" />
        <vers num="snv_64" edition="" />
        <vers num="snv_64" edition=":x86" />
        <vers num="snv_64" edition=":sparc" />
        <vers num="snv_65" edition="" />
        <vers num="snv_65" edition=":sparc" />
        <vers num="snv_65" edition=":x86" />
        <vers num="snv_66" edition="" />
        <vers num="snv_66" edition=":x86" />
        <vers num="snv_66" edition=":sparc" />
        <vers num="snv_67" edition="" />
        <vers num="snv_67" edition=":sparc" />
        <vers num="snv_67" edition=":x86" />
        <vers num="snv_68" edition="" />
        <vers num="snv_68" edition=":x86" />
        <vers num="snv_68" edition=":sparc" />
        <vers num="snv_69" edition="" />
        <vers num="snv_69" edition=":sparc" />
        <vers num="snv_69" edition=":x86" />
        <vers num="snv_70" edition="" />
        <vers num="snv_70" edition=":sparc" />
        <vers num="snv_70" edition=":x86" />
        <vers num="snv_71" edition="" />
        <vers num="snv_71" edition=":sparc" />
        <vers num="snv_71" edition=":x86" />
        <vers num="snv_72" edition="" />
        <vers num="snv_72" edition=":x86" />
        <vers num="snv_72" edition=":sparc" />
        <vers num="snv_73" edition="" />
        <vers num="snv_73" edition=":x86" />
        <vers num="snv_73" edition=":sparc" />
        <vers num="snv_74" edition="" />
        <vers num="snv_74" edition=":x86" />
        <vers num="snv_74" edition=":sparc" />
        <vers num="snv_75" edition="" />
        <vers num="snv_75" edition=":x86" />
        <vers num="snv_75" edition=":sparc" />
        <vers num="snv_76" edition="" />
        <vers num="snv_76" edition=":sparc" />
        <vers num="snv_76" edition=":x86" />
        <vers num="snv_77" edition="" />
        <vers num="snv_77" edition=":sparc" />
        <vers num="snv_77" edition=":x86" />
        <vers num="snv_78" edition="" />
        <vers num="snv_78" edition=":sparc" />
        <vers num="snv_78" edition=":x86" />
        <vers num="snv_79" edition="" />
        <vers num="snv_79" edition=":x86" />
        <vers num="snv_79" edition=":sparc" />
        <vers num="snv_80" edition="" />
        <vers num="snv_80" edition=":x86" />
        <vers num="snv_80" edition=":sparc" />
        <vers num="snv_81" edition="" />
        <vers num="snv_81" edition=":x86" />
        <vers num="snv_81" edition=":sparc" />
        <vers num="snv_82" edition="" />
        <vers num="snv_82" edition=":x86" />
        <vers num="snv_82" edition=":sparc" />
        <vers num="snv_83" edition="" />
        <vers num="snv_83" edition=":sparc" />
        <vers num="snv_83" edition=":x86" />
        <vers num="snv_84" edition="" />
        <vers num="snv_84" edition=":x86" />
        <vers num="snv_84" edition=":sparc" />
        <vers num="snv_85" edition="" />
        <vers num="snv_85" edition=":sparc" />
        <vers num="snv_85" edition=":x86" />
        <vers num="snv_86" edition="" />
        <vers num="snv_86" edition=":sparc" />
        <vers num="snv_86" edition=":x86" />
        <vers num="snv_87" edition="" />
        <vers num="snv_87" edition=":sparc" />
        <vers num="snv_87" edition=":x86" />
        <vers num="snv_88" edition="" />
        <vers num="snv_88" edition=":x86" />
        <vers num="snv_88" edition=":sparc" />
        <vers num="snv_89" edition="" />
        <vers num="snv_89" edition=":x86" />
        <vers num="snv_89" edition=":sparc" />
        <vers num="snv_90" edition="" />
        <vers num="snv_90" edition=":sparc" />
        <vers num="snv_90" edition=":x86" />
        <vers num="snv_91" edition="" />
        <vers num="snv_91" edition=":x86" />
        <vers num="snv_91" edition=":sparc" />
        <vers num="snv_92" edition="" />
        <vers num="snv_92" edition=":x86" />
        <vers num="snv_92" edition=":sparc" />
        <vers num="snv_93" edition="" />
        <vers num="snv_93" edition=":sparc" />
        <vers num="snv_93" edition=":x86" />
        <vers num="snv_94" edition="" />
        <vers num="snv_94" edition=":x86" />
        <vers num="snv_94" edition=":sparc" />
        <vers num="snv_95" edition="" />
        <vers num="snv_95" edition=":x86" />
        <vers num="snv_95" edition=":sparc" />
        <vers num="snv_96" edition="" />
        <vers num="snv_96" edition=":sparc" />
        <vers num="snv_96" edition=":x86" />
        <vers num="snv_97" edition="" />
        <vers num="snv_97" edition=":x86" />
        <vers num="snv_97" edition=":sparc" />
        <vers num="snv_98" edition="" />
        <vers num="snv_98" edition=":x86" />
        <vers num="snv_98" edition=":sparc" />
        <vers num="snv_99" edition="" />
        <vers num="snv_99" edition=":sparc" />
        <vers num="snv_99" edition=":x86" />
      </prod>
      <prod vendor="sun" name="solaris">
        <vers num="10" />
        <vers num="10.0" edition="" />
        <vers num="10.0" edition=":x86" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0874" published="2009-03-12" name="CVE-2009-0874" modified="2009-04-02" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="4.9" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="3.9" CVSS_base_score="4.9">
    <desc>
      <descript source="cve">Multiple unspecified vulnerabilities in the Doors subsystem in the kernel in Sun Solaris 8 through 10, and OpenSolaris before snv_94, allow local users to cause a denial of service (process hang), or possibly bypass file permissions or gain kernel-context privileges, via vectors including ones related to (1) an argument handling deadlock in a door server and (2) watchpoint problems in the door_call function.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-242486-1" source="SUNALERT" patch="1" adv="1">242486</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-21-117350-61-1" source="CONFIRM" patch="1" adv="1">http://sunsolve.sun.com/search/document.do?assetkey=1-21-117350-61-1</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0766" source="VUPEN">ADV-2009-0766</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0673" source="VUPEN">ADV-2009-0673</ref>
      <ref url="http://www.securitytracker.com/id?1021840" source="SECTRACK">1021840</ref>
      <ref url="http://www.securityfocus.com/bid/34081" source="BID">34081</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2009-095.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2009-095.htm</ref>
      <ref url="http://secunia.com/advisories/34375" source="SECUNIA">34375</ref>
      <ref url="http://secunia.com/advisories/34227" source="SECUNIA" adv="1">34227</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="opensolaris">
        <vers num="snv_01" edition="" />
        <vers num="snv_01" edition=":sparc" />
        <vers num="snv_01" edition=":x86" />
        <vers num="snv_02" edition="" />
        <vers num="snv_02" edition=":sparc" />
        <vers num="snv_02" edition=":x86" />
        <vers num="snv_03" edition="" />
        <vers num="snv_03" edition=":x86" />
        <vers num="snv_03" edition=":sparc" />
        <vers num="snv_04" edition="" />
        <vers num="snv_04" edition=":x86" />
        <vers num="snv_04" edition=":sparc" />
        <vers num="snv_05" edition="" />
        <vers num="snv_05" edition=":sparc" />
        <vers num="snv_05" edition=":x86" />
        <vers num="snv_06" edition="" />
        <vers num="snv_06" edition=":sparc" />
        <vers num="snv_06" edition=":x86" />
        <vers num="snv_07" edition="" />
        <vers num="snv_07" edition=":sparc" />
        <vers num="snv_07" edition=":x86" />
        <vers num="snv_08" edition="" />
        <vers num="snv_08" edition=":x86" />
        <vers num="snv_08" edition=":sparc" />
        <vers num="snv_09" edition="" />
        <vers num="snv_09" edition=":sparc" />
        <vers num="snv_09" edition=":x86" />
        <vers num="snv_10" edition="" />
        <vers num="snv_10" edition=":x86" />
        <vers num="snv_10" edition=":sparc" />
        <vers num="snv_11" edition="" />
        <vers num="snv_11" edition=":x86" />
        <vers num="snv_11" edition=":sparc" />
        <vers num="snv_12" edition="" />
        <vers num="snv_12" edition=":x86" />
        <vers num="snv_12" edition=":sparc" />
        <vers num="snv_13" edition="" />
        <vers num="snv_13" edition=":x86" />
        <vers num="snv_13" edition=":sparc" />
        <vers num="snv_14" edition="" />
        <vers num="snv_14" edition=":x86" />
        <vers num="snv_14" edition=":sparc" />
        <vers num="snv_15" edition="" />
        <vers num="snv_15" edition=":x86" />
        <vers num="snv_15" edition=":sparc" />
        <vers num="snv_16" edition="" />
        <vers num="snv_16" edition=":sparc" />
        <vers num="snv_16" edition=":x86" />
        <vers num="snv_17" edition="" />
        <vers num="snv_17" edition=":x86" />
        <vers num="snv_17" edition=":sparc" />
        <vers num="snv_18" edition="" />
        <vers num="snv_18" edition=":x86" />
        <vers num="snv_18" edition=":sparc" />
        <vers num="snv_19" edition="" />
        <vers num="snv_19" edition=":sparc" />
        <vers num="snv_19" edition=":x86" />
        <vers num="snv_20" edition="" />
        <vers num="snv_20" edition=":x86" />
        <vers num="snv_20" edition=":sparc" />
        <vers num="snv_21" edition="" />
        <vers num="snv_21" edition=":x86" />
        <vers num="snv_21" edition=":sparc" />
        <vers num="snv_22" edition="" />
        <vers num="snv_22" edition=":sparc" />
        <vers num="snv_22" edition=":x86" />
        <vers num="snv_23" edition="" />
        <vers num="snv_23" edition=":sparc" />
        <vers num="snv_23" edition=":x86" />
        <vers num="snv_24" edition="" />
        <vers num="snv_24" edition=":sparc" />
        <vers num="snv_24" edition=":x86" />
        <vers num="snv_25" edition="" />
        <vers num="snv_25" edition=":sparc" />
        <vers num="snv_25" edition=":x86" />
        <vers num="snv_26" edition="" />
        <vers num="snv_26" edition=":sparc" />
        <vers num="snv_26" edition=":x86" />
        <vers num="snv_27" edition="" />
        <vers num="snv_27" edition=":sparc" />
        <vers num="snv_27" edition=":x86" />
        <vers num="snv_28" edition="" />
        <vers num="snv_28" edition=":sparc" />
        <vers num="snv_28" edition=":x86" />
        <vers num="snv_29" edition="" />
        <vers num="snv_29" edition=":x86" />
        <vers num="snv_29" edition=":sparc" />
        <vers num="snv_30" edition="" />
        <vers num="snv_30" edition=":sparc" />
        <vers num="snv_30" edition=":x86" />
        <vers num="snv_31" edition="" />
        <vers num="snv_31" edition=":sparc" />
        <vers num="snv_31" edition=":x86" />
        <vers num="snv_32" edition="" />
        <vers num="snv_32" edition=":x86" />
        <vers num="snv_32" edition=":sparc" />
        <vers num="snv_33" edition="" />
        <vers num="snv_33" edition=":x86" />
        <vers num="snv_33" edition=":sparc" />
        <vers num="snv_34" edition="" />
        <vers num="snv_34" edition=":sparc" />
        <vers num="snv_34" edition=":x86" />
        <vers num="snv_35" edition="" />
        <vers num="snv_35" edition=":sparc" />
        <vers num="snv_35" edition=":x86" />
        <vers num="snv_36" edition="" />
        <vers num="snv_36" edition=":sparc" />
        <vers num="snv_36" edition=":x86" />
        <vers num="snv_37" edition="" />
        <vers num="snv_37" edition=":sparc" />
        <vers num="snv_37" edition=":x86" />
        <vers num="snv_38" edition="" />
        <vers num="snv_38" edition=":sparc" />
        <vers num="snv_38" edition=":x86" />
        <vers num="snv_39" edition="" />
        <vers num="snv_39" edition=":sparc" />
        <vers num="snv_39" edition=":x86" />
        <vers num="snv_40" edition="" />
        <vers num="snv_40" edition=":x86" />
        <vers num="snv_40" edition=":sparc" />
        <vers num="snv_41" edition="" />
        <vers num="snv_41" edition=":sparc" />
        <vers num="snv_41" edition=":x86" />
        <vers num="snv_42" edition="" />
        <vers num="snv_42" edition=":x86" />
        <vers num="snv_42" edition=":sparc" />
        <vers num="snv_43" edition="" />
        <vers num="snv_43" edition=":sparc" />
        <vers num="snv_43" edition=":x86" />
        <vers num="snv_44" edition="" />
        <vers num="snv_44" edition=":x86" />
        <vers num="snv_44" edition=":sparc" />
        <vers num="snv_45" edition="" />
        <vers num="snv_45" edition=":x86" />
        <vers num="snv_45" edition=":sparc" />
        <vers num="snv_46" edition="" />
        <vers num="snv_46" edition=":sparc" />
        <vers num="snv_46" edition=":x86" />
        <vers num="snv_47" edition="" />
        <vers num="snv_47" edition=":x86" />
        <vers num="snv_47" edition=":sparc" />
        <vers num="snv_48" edition="" />
        <vers num="snv_48" edition=":sparc" />
        <vers num="snv_48" edition=":x86" />
        <vers num="snv_49" edition="" />
        <vers num="snv_49" edition=":sparc" />
        <vers num="snv_49" edition=":x86" />
        <vers num="snv_50" edition="" />
        <vers num="snv_50" edition=":sparc" />
        <vers num="snv_50" edition=":x86" />
        <vers num="snv_51" edition="" />
        <vers num="snv_51" edition=":x86" />
        <vers num="snv_51" edition=":sparc" />
        <vers num="snv_52" edition="" />
        <vers num="snv_52" edition=":x86" />
        <vers num="snv_52" edition=":sparc" />
        <vers num="snv_53" edition="" />
        <vers num="snv_53" edition=":sparc" />
        <vers num="snv_53" edition=":x86" />
        <vers num="snv_54" edition="" />
        <vers num="snv_54" edition=":sparc" />
        <vers num="snv_54" edition=":x86" />
        <vers num="snv_55" edition="" />
        <vers num="snv_55" edition=":sparc" />
        <vers num="snv_55" edition=":x86" />
        <vers num="snv_56" edition="" />
        <vers num="snv_56" edition=":x86" />
        <vers num="snv_56" edition=":sparc" />
        <vers num="snv_57" edition="" />
        <vers num="snv_57" edition=":x86" />
        <vers num="snv_57" edition=":sparc" />
        <vers num="snv_58" edition="" />
        <vers num="snv_58" edition=":sparc" />
        <vers num="snv_58" edition=":x86" />
        <vers num="snv_59" edition="" />
        <vers num="snv_59" edition=":sparc" />
        <vers num="snv_59" edition=":x86" />
        <vers num="snv_60" edition="" />
        <vers num="snv_60" edition=":x86" />
        <vers num="snv_60" edition=":sparc" />
        <vers num="snv_61" edition="" />
        <vers num="snv_61" edition=":sparc" />
        <vers num="snv_61" edition=":x86" />
        <vers num="snv_62" edition="" />
        <vers num="snv_62" edition=":x86" />
        <vers num="snv_62" edition=":sparc" />
        <vers num="snv_63" edition="" />
        <vers num="snv_63" edition=":x86" />
        <vers num="snv_63" edition=":sparc" />
        <vers num="snv_64" edition="" />
        <vers num="snv_64" edition=":x86" />
        <vers num="snv_64" edition=":sparc" />
        <vers num="snv_65" edition="" />
        <vers num="snv_65" edition=":sparc" />
        <vers num="snv_65" edition=":x86" />
        <vers num="snv_66" edition="" />
        <vers num="snv_66" edition=":x86" />
        <vers num="snv_66" edition=":sparc" />
        <vers num="snv_67" edition="" />
        <vers num="snv_67" edition=":sparc" />
        <vers num="snv_67" edition=":x86" />
        <vers num="snv_68" edition="" />
        <vers num="snv_68" edition=":x86" />
        <vers num="snv_68" edition=":sparc" />
        <vers num="snv_69" edition="" />
        <vers num="snv_69" edition=":sparc" />
        <vers num="snv_69" edition=":x86" />
        <vers num="snv_70" edition="" />
        <vers num="snv_70" edition=":sparc" />
        <vers num="snv_70" edition=":x86" />
        <vers num="snv_71" edition="" />
        <vers num="snv_71" edition=":sparc" />
        <vers num="snv_71" edition=":x86" />
        <vers num="snv_72" edition="" />
        <vers num="snv_72" edition=":x86" />
        <vers num="snv_72" edition=":sparc" />
        <vers num="snv_73" edition="" />
        <vers num="snv_73" edition=":x86" />
        <vers num="snv_73" edition=":sparc" />
        <vers num="snv_74" edition="" />
        <vers num="snv_74" edition=":x86" />
        <vers num="snv_74" edition=":sparc" />
        <vers num="snv_75" edition="" />
        <vers num="snv_75" edition=":x86" />
        <vers num="snv_75" edition=":sparc" />
        <vers num="snv_76" edition="" />
        <vers num="snv_76" edition=":sparc" />
        <vers num="snv_76" edition=":x86" />
        <vers num="snv_77" edition="" />
        <vers num="snv_77" edition=":sparc" />
        <vers num="snv_77" edition=":x86" />
        <vers num="snv_78" edition="" />
        <vers num="snv_78" edition=":sparc" />
        <vers num="snv_78" edition=":x86" />
        <vers num="snv_79" edition="" />
        <vers num="snv_79" edition=":x86" />
        <vers num="snv_79" edition=":sparc" />
        <vers num="snv_80" edition="" />
        <vers num="snv_80" edition=":x86" />
        <vers num="snv_80" edition=":sparc" />
        <vers num="snv_81" edition="" />
        <vers num="snv_81" edition=":x86" />
        <vers num="snv_81" edition=":sparc" />
        <vers num="snv_82" edition="" />
        <vers num="snv_82" edition=":x86" />
        <vers num="snv_82" edition=":sparc" />
        <vers num="snv_83" edition="" />
        <vers num="snv_83" edition=":sparc" />
        <vers num="snv_83" edition=":x86" />
        <vers num="snv_84" edition="" />
        <vers num="snv_84" edition=":x86" />
        <vers num="snv_84" edition=":sparc" />
        <vers num="snv_85" edition="" />
        <vers num="snv_85" edition=":sparc" />
        <vers num="snv_85" edition=":x86" />
        <vers num="snv_86" edition="" />
        <vers num="snv_86" edition=":sparc" />
        <vers num="snv_86" edition=":x86" />
        <vers num="snv_87" edition="" />
        <vers num="snv_87" edition=":sparc" />
        <vers num="snv_87" edition=":x86" />
        <vers num="snv_88" edition="" />
        <vers num="snv_88" edition=":x86" />
        <vers num="snv_88" edition=":sparc" />
        <vers num="snv_89" edition="" />
        <vers num="snv_89" edition=":x86" />
        <vers num="snv_89" edition=":sparc" />
        <vers num="snv_90" edition="" />
        <vers num="snv_90" edition=":sparc" />
        <vers num="snv_90" edition=":x86" />
        <vers num="snv_91" edition="" />
        <vers num="snv_91" edition=":x86" />
        <vers num="snv_91" edition=":sparc" />
        <vers num="snv_92" edition="" />
        <vers num="snv_92" edition=":x86" />
        <vers num="snv_92" edition=":sparc" />
        <vers prev="1" num="snv_93" edition="" />
        <vers prev="1" num="snv_93" edition=":sparc" />
        <vers prev="1" num="snv_93" edition=":x86" />
      </prod>
      <prod vendor="sun" name="solaris">
        <vers num="10" edition="" />
        <vers num="10" edition=":sparc" />
        <vers num="10" edition=":x86" />
        <vers num="8" edition="" />
        <vers num="8" edition=":sparc" />
        <vers num="8" edition=":x86" />
        <vers num="9" edition="" />
        <vers num="9" edition=":sparc" />
        <vers num="9" edition=":x86" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0875" published="2009-03-12" name="CVE-2009-0875" modified="2009-04-02" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="6.9" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.4" CVSS_base_score="6.9">
    <desc>
      <descript source="cve">Race condition in the Doors subsystem in the kernel in Sun Solaris 8 through 10, and OpenSolaris before snv_94, allows local users to cause a denial of service (process hang), or possibly bypass file permissions or gain kernel-context privileges, via vectors involving the time at which control is transferred from a caller to a door server.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-242486-1" source="SUNALERT" patch="1" adv="1">242486</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-21-117350-61-1" source="CONFIRM" patch="1" adv="1">http://sunsolve.sun.com/search/document.do?assetkey=1-21-117350-61-1</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0766" source="VUPEN">ADV-2009-0766</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0673" source="VUPEN">ADV-2009-0673</ref>
      <ref url="http://www.securitytracker.com/id?1021840" source="SECTRACK">1021840</ref>
      <ref url="http://www.securityfocus.com/bid/34081" source="BID">34081</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2009-095.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2009-095.htm</ref>
      <ref url="http://secunia.com/advisories/34375" source="SECUNIA">34375</ref>
      <ref url="http://secunia.com/advisories/34227" source="SECUNIA" adv="1">34227</ref>
      <ref url="http://osvdb.org/52561" source="OSVDB">52561</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="opensolaris">
        <vers num="snv_01" edition="" />
        <vers num="snv_01" edition=":sparc" />
        <vers num="snv_01" edition=":x86" />
        <vers num="snv_02" edition="" />
        <vers num="snv_02" edition=":sparc" />
        <vers num="snv_02" edition=":x86" />
        <vers num="snv_03" edition="" />
        <vers num="snv_03" edition=":x86" />
        <vers num="snv_03" edition=":sparc" />
        <vers num="snv_04" edition="" />
        <vers num="snv_04" edition=":x86" />
        <vers num="snv_04" edition=":sparc" />
        <vers num="snv_05" edition="" />
        <vers num="snv_05" edition=":sparc" />
        <vers num="snv_05" edition=":x86" />
        <vers num="snv_06" edition="" />
        <vers num="snv_06" edition=":sparc" />
        <vers num="snv_06" edition=":x86" />
        <vers num="snv_07" edition="" />
        <vers num="snv_07" edition=":sparc" />
        <vers num="snv_07" edition=":x86" />
        <vers num="snv_08" edition="" />
        <vers num="snv_08" edition=":x86" />
        <vers num="snv_08" edition=":sparc" />
        <vers num="snv_09" edition="" />
        <vers num="snv_09" edition=":sparc" />
        <vers num="snv_09" edition=":x86" />
        <vers num="snv_10" edition="" />
        <vers num="snv_10" edition=":x86" />
        <vers num="snv_10" edition=":sparc" />
        <vers num="snv_11" edition="" />
        <vers num="snv_11" edition=":x86" />
        <vers num="snv_11" edition=":sparc" />
        <vers num="snv_12" edition="" />
        <vers num="snv_12" edition=":x86" />
        <vers num="snv_12" edition=":sparc" />
        <vers num="snv_13" edition="" />
        <vers num="snv_13" edition=":x86" />
        <vers num="snv_13" edition=":sparc" />
        <vers num="snv_14" edition="" />
        <vers num="snv_14" edition=":x86" />
        <vers num="snv_14" edition=":sparc" />
        <vers num="snv_15" edition="" />
        <vers num="snv_15" edition=":x86" />
        <vers num="snv_15" edition=":sparc" />
        <vers num="snv_16" edition="" />
        <vers num="snv_16" edition=":sparc" />
        <vers num="snv_16" edition=":x86" />
        <vers num="snv_17" edition="" />
        <vers num="snv_17" edition=":x86" />
        <vers num="snv_17" edition=":sparc" />
        <vers num="snv_18" edition="" />
        <vers num="snv_18" edition=":x86" />
        <vers num="snv_18" edition=":sparc" />
        <vers num="snv_19" edition="" />
        <vers num="snv_19" edition=":sparc" />
        <vers num="snv_19" edition=":x86" />
        <vers num="snv_20" edition="" />
        <vers num="snv_20" edition=":x86" />
        <vers num="snv_20" edition=":sparc" />
        <vers num="snv_21" edition="" />
        <vers num="snv_21" edition=":x86" />
        <vers num="snv_21" edition=":sparc" />
        <vers num="snv_22" edition="" />
        <vers num="snv_22" edition=":sparc" />
        <vers num="snv_22" edition=":x86" />
        <vers num="snv_23" edition="" />
        <vers num="snv_23" edition=":sparc" />
        <vers num="snv_23" edition=":x86" />
        <vers num="snv_24" edition="" />
        <vers num="snv_24" edition=":sparc" />
        <vers num="snv_24" edition=":x86" />
        <vers num="snv_25" edition="" />
        <vers num="snv_25" edition=":sparc" />
        <vers num="snv_25" edition=":x86" />
        <vers num="snv_26" edition="" />
        <vers num="snv_26" edition=":sparc" />
        <vers num="snv_26" edition=":x86" />
        <vers num="snv_27" edition="" />
        <vers num="snv_27" edition=":sparc" />
        <vers num="snv_27" edition=":x86" />
        <vers num="snv_28" edition="" />
        <vers num="snv_28" edition=":sparc" />
        <vers num="snv_28" edition=":x86" />
        <vers num="snv_29" edition="" />
        <vers num="snv_29" edition=":x86" />
        <vers num="snv_29" edition=":sparc" />
        <vers num="snv_30" edition="" />
        <vers num="snv_30" edition=":sparc" />
        <vers num="snv_30" edition=":x86" />
        <vers num="snv_31" edition="" />
        <vers num="snv_31" edition=":sparc" />
        <vers num="snv_31" edition=":x86" />
        <vers num="snv_32" edition="" />
        <vers num="snv_32" edition=":x86" />
        <vers num="snv_32" edition=":sparc" />
        <vers num="snv_33" edition="" />
        <vers num="snv_33" edition=":x86" />
        <vers num="snv_33" edition=":sparc" />
        <vers num="snv_34" edition="" />
        <vers num="snv_34" edition=":sparc" />
        <vers num="snv_34" edition=":x86" />
        <vers num="snv_35" edition="" />
        <vers num="snv_35" edition=":sparc" />
        <vers num="snv_35" edition=":x86" />
        <vers num="snv_36" edition="" />
        <vers num="snv_36" edition=":sparc" />
        <vers num="snv_36" edition=":x86" />
        <vers num="snv_37" edition="" />
        <vers num="snv_37" edition=":sparc" />
        <vers num="snv_37" edition=":x86" />
        <vers num="snv_38" edition="" />
        <vers num="snv_38" edition=":sparc" />
        <vers num="snv_38" edition=":x86" />
        <vers num="snv_39" edition="" />
        <vers num="snv_39" edition=":sparc" />
        <vers num="snv_39" edition=":x86" />
        <vers num="snv_40" edition="" />
        <vers num="snv_40" edition=":x86" />
        <vers num="snv_40" edition=":sparc" />
        <vers num="snv_41" edition="" />
        <vers num="snv_41" edition=":sparc" />
        <vers num="snv_41" edition=":x86" />
        <vers num="snv_42" edition="" />
        <vers num="snv_42" edition=":x86" />
        <vers num="snv_42" edition=":sparc" />
        <vers num="snv_43" edition="" />
        <vers num="snv_43" edition=":sparc" />
        <vers num="snv_43" edition=":x86" />
        <vers num="snv_44" edition="" />
        <vers num="snv_44" edition=":x86" />
        <vers num="snv_44" edition=":sparc" />
        <vers num="snv_45" edition="" />
        <vers num="snv_45" edition=":x86" />
        <vers num="snv_45" edition=":sparc" />
        <vers num="snv_46" edition="" />
        <vers num="snv_46" edition=":sparc" />
        <vers num="snv_46" edition=":x86" />
        <vers num="snv_47" edition="" />
        <vers num="snv_47" edition=":x86" />
        <vers num="snv_47" edition=":sparc" />
        <vers num="snv_48" edition="" />
        <vers num="snv_48" edition=":sparc" />
        <vers num="snv_48" edition=":x86" />
        <vers num="snv_49" edition="" />
        <vers num="snv_49" edition=":sparc" />
        <vers num="snv_49" edition=":x86" />
        <vers num="snv_50" edition="" />
        <vers num="snv_50" edition=":sparc" />
        <vers num="snv_50" edition=":x86" />
        <vers num="snv_51" edition="" />
        <vers num="snv_51" edition=":x86" />
        <vers num="snv_51" edition=":sparc" />
        <vers num="snv_52" edition="" />
        <vers num="snv_52" edition=":x86" />
        <vers num="snv_52" edition=":sparc" />
        <vers num="snv_53" edition="" />
        <vers num="snv_53" edition=":sparc" />
        <vers num="snv_53" edition=":x86" />
        <vers num="snv_54" edition="" />
        <vers num="snv_54" edition=":sparc" />
        <vers num="snv_54" edition=":x86" />
        <vers num="snv_55" edition="" />
        <vers num="snv_55" edition=":sparc" />
        <vers num="snv_55" edition=":x86" />
        <vers num="snv_56" edition="" />
        <vers num="snv_56" edition=":x86" />
        <vers num="snv_56" edition=":sparc" />
        <vers num="snv_57" edition="" />
        <vers num="snv_57" edition=":x86" />
        <vers num="snv_57" edition=":sparc" />
        <vers num="snv_58" edition="" />
        <vers num="snv_58" edition=":sparc" />
        <vers num="snv_58" edition=":x86" />
        <vers num="snv_59" edition="" />
        <vers num="snv_59" edition=":sparc" />
        <vers num="snv_59" edition=":x86" />
        <vers num="snv_60" edition="" />
        <vers num="snv_60" edition=":x86" />
        <vers num="snv_60" edition=":sparc" />
        <vers num="snv_61" edition="" />
        <vers num="snv_61" edition=":sparc" />
        <vers num="snv_61" edition=":x86" />
        <vers num="snv_62" edition="" />
        <vers num="snv_62" edition=":x86" />
        <vers num="snv_62" edition=":sparc" />
        <vers num="snv_63" edition="" />
        <vers num="snv_63" edition=":x86" />
        <vers num="snv_63" edition=":sparc" />
        <vers num="snv_64" edition="" />
        <vers num="snv_64" edition=":x86" />
        <vers num="snv_64" edition=":sparc" />
        <vers num="snv_65" edition="" />
        <vers num="snv_65" edition=":sparc" />
        <vers num="snv_65" edition=":x86" />
        <vers num="snv_66" edition="" />
        <vers num="snv_66" edition=":x86" />
        <vers num="snv_66" edition=":sparc" />
        <vers num="snv_67" edition="" />
        <vers num="snv_67" edition=":sparc" />
        <vers num="snv_67" edition=":x86" />
        <vers num="snv_68" edition="" />
        <vers num="snv_68" edition=":x86" />
        <vers num="snv_68" edition=":sparc" />
        <vers num="snv_69" edition="" />
        <vers num="snv_69" edition=":sparc" />
        <vers num="snv_69" edition=":x86" />
        <vers num="snv_70" edition="" />
        <vers num="snv_70" edition=":sparc" />
        <vers num="snv_70" edition=":x86" />
        <vers num="snv_71" edition="" />
        <vers num="snv_71" edition=":sparc" />
        <vers num="snv_71" edition=":x86" />
        <vers num="snv_72" edition="" />
        <vers num="snv_72" edition=":x86" />
        <vers num="snv_72" edition=":sparc" />
        <vers num="snv_73" edition="" />
        <vers num="snv_73" edition=":x86" />
        <vers num="snv_73" edition=":sparc" />
        <vers num="snv_74" edition="" />
        <vers num="snv_74" edition=":x86" />
        <vers num="snv_74" edition=":sparc" />
        <vers num="snv_75" edition="" />
        <vers num="snv_75" edition=":x86" />
        <vers num="snv_75" edition=":sparc" />
        <vers num="snv_76" edition="" />
        <vers num="snv_76" edition=":sparc" />
        <vers num="snv_76" edition=":x86" />
        <vers num="snv_77" edition="" />
        <vers num="snv_77" edition=":sparc" />
        <vers num="snv_77" edition=":x86" />
        <vers num="snv_78" edition="" />
        <vers num="snv_78" edition=":sparc" />
        <vers num="snv_78" edition=":x86" />
        <vers num="snv_79" edition="" />
        <vers num="snv_79" edition=":x86" />
        <vers num="snv_79" edition=":sparc" />
        <vers num="snv_80" edition="" />
        <vers num="snv_80" edition=":x86" />
        <vers num="snv_80" edition=":sparc" />
        <vers num="snv_81" edition="" />
        <vers num="snv_81" edition=":x86" />
        <vers num="snv_81" edition=":sparc" />
        <vers num="snv_82" edition="" />
        <vers num="snv_82" edition=":x86" />
        <vers num="snv_82" edition=":sparc" />
        <vers num="snv_83" edition="" />
        <vers num="snv_83" edition=":sparc" />
        <vers num="snv_83" edition=":x86" />
        <vers num="snv_84" edition="" />
        <vers num="snv_84" edition=":x86" />
        <vers num="snv_84" edition=":sparc" />
        <vers num="snv_85" edition="" />
        <vers num="snv_85" edition=":sparc" />
        <vers num="snv_85" edition=":x86" />
        <vers num="snv_86" edition="" />
        <vers num="snv_86" edition=":sparc" />
        <vers num="snv_86" edition=":x86" />
        <vers num="snv_87" edition="" />
        <vers num="snv_87" edition=":sparc" />
        <vers num="snv_87" edition=":x86" />
        <vers num="snv_88" edition="" />
        <vers num="snv_88" edition=":x86" />
        <vers num="snv_88" edition=":sparc" />
        <vers num="snv_89" edition="" />
        <vers num="snv_89" edition=":x86" />
        <vers num="snv_89" edition=":sparc" />
        <vers num="snv_90" edition="" />
        <vers num="snv_90" edition=":sparc" />
        <vers num="snv_90" edition=":x86" />
        <vers num="snv_91" edition="" />
        <vers num="snv_91" edition=":x86" />
        <vers num="snv_91" edition=":sparc" />
        <vers num="snv_92" edition="" />
        <vers num="snv_92" edition=":x86" />
        <vers num="snv_92" edition=":sparc" />
        <vers prev="1" num="snv_93" edition="" />
        <vers prev="1" num="snv_93" edition=":sparc" />
        <vers prev="1" num="snv_93" edition=":x86" />
      </prod>
      <prod vendor="sun" name="solaris">
        <vers num="10" edition="" />
        <vers num="10" edition=":sparc" />
        <vers num="10" edition=":x86" />
        <vers num="8" edition="" />
        <vers num="8" edition=":sparc" />
        <vers num="8" edition=":x86" />
        <vers num="9" edition="" />
        <vers num="9" edition=":sparc" />
        <vers num="9" edition=":x86" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0876" published="2009-03-12" name="CVE-2009-0876" modified="2009-08-18" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="6.9" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.4" CVSS_base_score="6.9">
    <desc>
      <descript source="cve">Sun xVM VirtualBox 2.0.0, 2.0.2, 2.0.4, 2.0.6r39760, 2.1.0, 2.1.2, and 2.1.4r42893 on Linux allows local users to gain privileges via a hardlink attack, which preserves setuid/setgid bits on Linux, related to DT_RPATH:$ORIGIN.</descript>
    </desc>
    <sols>
      <sol source="nvd">Per: http://sunsolve.sun.com/search/document.do?assetkey=1-66-254568-1

"5. Resolution

This issue is addressed in the following releases:

Linux

    * Sun xVM VirtualBox 2.0.6r43001
    * Sun xVM VirtualBox 2.1.4r43001"</sol>
    </sols>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2009/0674" source="VUPEN" patch="1" adv="1">ADV-2009-0674</ref>
      <ref url="http://www.virtualbox.org/ticket/3444" source="CONFIRM" patch="1" adv="1">http://www.virtualbox.org/ticket/3444</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-254568-1" source="SUNALERT" patch="1" adv="1">254568</ref>
      <ref url="https://bugs.gentoo.org/show_bug.cgi?id=260331" source="CONFIRM">https://bugs.gentoo.org/show_bug.cgi?id=260331</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/49193" source="XF">xvmvirtualbox-unspecified-priv-escalation(49193)</ref>
      <ref url="http://www.securitytracker.com/id?1021841" source="SECTRACK">1021841</ref>
      <ref url="http://www.securityfocus.com/bid/34080" source="BID">34080</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2009/03/17/2" source="MLIST">[oss-security] 20090317 Re: CVE-2009-0876 (VirtualBox) references</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2009/03/15/1" source="MLIST">[oss-security] 20090316 CVE-2009-0876 (VirtualBox) references</ref>
      <ref url="http://secunia.com/advisories/34232" source="SECUNIA" adv="1">34232</ref>
      <ref url="http://osvdb.org/52580" source="OSVDB">52580</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="xvm_virtualbox">
        <vers num="2.0.0" />
        <vers num="2.0.2" />
        <vers num="2.0.4" />
        <vers num="2.0.6r39760" />
        <vers num="2.1.0" />
        <vers num="2.1.2" />
        <vers num="2.1.4r42893" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0877" published="2009-03-12" name="CVE-2009-0877" modified="2009-03-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Sun Java System Communications Express allow remote attackers to inject arbitrary web script or HTML via the (1) Full Name or (2) Subject field.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/34083" source="BID">34083</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/501672/100/0/threaded" source="BUGTRAQ">20090310 Sun Java System Communications Express [HTML Injection]</ref>
      <ref url="http://sosoblood.freehostia.com/SJSC/html_injection.gif" source="MISC">http://sosoblood.freehostia.com/SJSC/html_injection.gif</ref>
      <ref url="http://osvdb.org/52718" source="OSVDB">52718</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="java_system_communications_express">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0878" published="2009-03-12" name="CVE-2009-0878" modified="2009-03-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The read_game_map function in src/terrain_translation.cpp in Wesnoth before r32987 allows remote attackers to cause a denial of service (memory consumption and daemon hang) via a map with a large (1) width or (2) height.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="https://gna.org/bugs/index.php?13031" source="CONFIRM">https://gna.org/bugs/index.php?13031</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/49294" source="XF">wesnoth-readgamemap-dos(49294)</ref>
      <ref url="http://svn.gna.org/viewcvs/wesnoth/trunk/src/terrain_translation.cpp?rev=33078&amp;dir_pagestart=200&amp;view=log" source="CONFIRM">http://svn.gna.org/viewcvs/wesnoth/trunk/src/terrain_translation.cpp?rev=33078&amp;dir_pagestart=200&amp;view=log</ref>
      <ref url="http://svn.gna.org/viewcvs/wesnoth/trunk/src/terrain_translation.cpp?r2=32987&amp;rev=32987&amp;r1=31859&amp;dir_pagestart=200" source="CONFIRM">http://svn.gna.org/viewcvs/wesnoth/trunk/src/terrain_translation.cpp?r2=32987&amp;rev=32987&amp;r1=31859&amp;dir_pagestart=200</ref>
      <ref url="http://packages.debian.org/changelogs/pool/main/w/wesnoth/wesnoth_1.5.12-1/changelog" source="CONFIRM">http://packages.debian.org/changelogs/pool/main/w/wesnoth/wesnoth_1.5.12-1/changelog</ref>
      <ref url="http://packages.debian.org/changelogs/pool/main/w/wesnoth/wesnoth_1.4.7-4/changelog" source="CONFIRM">http://packages.debian.org/changelogs/pool/main/w/wesnoth/wesnoth_1.4.7-4/changelog</ref>
      <ref url="http://launchpad.net/bugs/336396" source="CONFIRM">http://launchpad.net/bugs/336396</ref>
      <ref url="http://launchpad.net/bugs/335089" source="CONFIRM">http://launchpad.net/bugs/335089</ref>
    </refs>
    <vuln_soft>
      <prod vendor="wesnoth" name="wesnoth">
        <vers num="0.2.1" />
        <vers num="0.3" />
        <vers num="0.3.1" />
        <vers num="0.3.2" />
        <vers num="0.3.3" />
        <vers num="0.3.4" />
        <vers num="0.4" />
        <vers num="0.4.1" />
        <vers num="0.4.2" />
        <vers num="0.4.3" />
        <vers num="0.4.4" />
        <vers num="0.4.5" />
        <vers num="0.4.6" />
        <vers num="0.4.7" />
        <vers num="0.4.8" />
        <vers num="0.5" />
        <vers num="0.5.1" />
        <vers num="0.6" />
        <vers num="0.6.1" />
        <vers num="0.6.99.1" />
        <vers num="0.6.99.2" />
        <vers num="0.6.99.3" />
        <vers num="0.6.99.4" />
        <vers num="0.6.99.5" />
        <vers num="0.7" />
        <vers num="0.7.1" />
        <vers num="0.7.10" />
        <vers num="0.7.11" />
        <vers num="0.7.2" />
        <vers num="0.7.3" />
        <vers num="0.7.4" />
        <vers num="0.7.5" />
        <vers num="0.7.6" />
        <vers num="0.7.7" />
        <vers num="0.7.8" />
        <vers num="0.7.9" />
        <vers num="0.8" />
        <vers num="0.8.1" />
        <vers num="0.8.10" />
        <vers num="0.8.11" />
        <vers num="0.8.2" />
        <vers num="0.8.3" />
        <vers num="0.8.4" />
        <vers num="0.8.5" />
        <vers num="0.8.6" />
        <vers num="0.8.7" />
        <vers num="0.8.8" />
        <vers num="0.8.9" />
        <vers num="0.9.0" />
        <vers num="0.9.1" />
        <vers num="0.9.2" />
        <vers num="0.9.3" />
        <vers num="0.9.4" />
        <vers num="0.9.5" />
        <vers num="0.9.6" />
        <vers num="0.9.7" />
        <vers num="1.0" edition="rc" />
        <vers num="1.0rcl" />
        <vers num="1.1" />
        <vers num="1.1.1" />
        <vers num="1.1.10" />
        <vers num="1.1.11" />
        <vers num="1.1.12" />
        <vers num="1.1.13" />
        <vers num="1.1.14" />
        <vers num="1.1.2" />
        <vers num="1.1.3" />
        <vers num="1.1.4" />
        <vers num="1.1.5" />
        <vers num="1.1.6" />
        <vers num="1.1.7" />
        <vers num="1.1.8" />
        <vers num="1.1.9" />
        <vers num="1.2" />
        <vers num="1.2.1" />
        <vers num="1.2.2" />
        <vers num="1.2.3" />
        <vers num="1.2.4" />
        <vers num="1.2.5" />
        <vers num="1.2.6" />
        <vers num="1.2.7" />
        <vers num="1.2.8" />
        <vers num="1.3.1" />
        <vers num="1.3.10" />
        <vers num="1.3.11" />
        <vers num="1.3.12" />
        <vers num="1.3.13" />
        <vers num="1.3.14" />
        <vers num="1.3.15" />
        <vers num="1.3.16" />
        <vers num="1.3.17" />
        <vers num="1.3.18" />
        <vers num="1.3.19" />
        <vers num="1.3.2" />
        <vers num="1.3.3" />
        <vers num="1.3.4" />
        <vers num="1.3.5" />
        <vers num="1.3.6" />
        <vers num="1.3.7" />
        <vers num="1.3.8" />
        <vers num="1.3.9" />
        <vers num="1.4" />
        <vers num="1.4.1" />
        <vers num="1.4.2" />
        <vers num="1.4.3" />
        <vers num="1.4.4" />
        <vers num="1.4.5" />
        <vers num="1.4.6" />
        <vers prev="1" num="1.4.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0879" published="2009-03-12" name="CVE-2009-0879" modified="2009-04-01" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The CIM server in IBM Director before 5.20.3 Service Update 2 on Windows allows remote attackers to cause a denial of service (daemon crash) via a long consumer name, as demonstrated by an M-POST request to a long /CIMListener/ URI.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="https://www14.software.ibm.com/webapp/iwm/web/reg/download.do?source=dmp&amp;S_PKG=director_x_520&amp;S_TACT=sms&amp;lang=en_US&amp;cp=UTF-8" source="MISC" patch="1" adv="1">https://www14.software.ibm.com/webapp/iwm/web/reg/download.do?source=dmp&amp;S_PKG=director_x_520&amp;S_TACT=sms&amp;lang=en_US&amp;cp=UTF-8</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0656" source="VUPEN" patch="1" adv="1">ADV-2009-0656</ref>
      <ref url="https://www.sec-consult.com/files/20090305-1_IBM_director_DoS.txt" source="MISC">https://www.sec-consult.com/files/20090305-1_IBM_director_DoS.txt</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/49285" source="XF">director-cim-consumer-dos(49285)</ref>
      <ref url="http://www.securityfocus.com/bid/34061" source="BID">34061</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/501638/100/0/threaded" source="BUGTRAQ">20090310 SEC Consult SA-20090305-1 :: IBM Director CIM Server Remote Denial of Service Vulnerability</ref>
      <ref url="http://www.milw0rm.com/exploits/8190" source="MILW0RM">8190</ref>
      <ref url="http://securitytracker.com/id?1021825" source="SECTRACK" adv="1">1021825</ref>
      <ref url="http://secunia.com/advisories/34212" source="SECUNIA" adv="1">34212</ref>
      <ref url="http://osvdb.org/52615" source="OSVDB">52615</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="director">
        <vers num="3.1.1" />
        <vers num="4.10" />
        <vers num="4.11" />
        <vers num="4.12" />
        <vers num="4.20" />
        <vers num="4.21" />
        <vers num="4.22" />
        <vers num="5.10.0" />
        <vers num="5.10.1" />
        <vers num="5.10.2" />
        <vers num="5.10.3" />
        <vers num="5.20.0" />
        <vers num="5.20.1" />
        <vers num="5.20.2" />
        <vers prev="1" num="5.20.3" edition="service_update_1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0880" published="2009-03-12" name="CVE-2009-0880" modified="2009-03-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Directory traversal vulnerability in the CIM server in IBM Director before 5.20.3 Service Update 2 on Windows allows remote attackers to load and execute arbitrary local DLL code via a .. (dot dot) in a /CIMListener/ URI in an M-POST request.</descript>
    </desc>
    <sols>
      <sol source="nvd">Per: http://www.securityfocus.com/archive/1/archive/1/501639/100/0/threaded

"The vendor has adressed this vulnerability in service update 2 for IBM
Director agent 5.20.3. Download link:

https://www14.software.ibm.com/webapp/iwm/web/reg/download.do?source=dmp
&amp;S_PKG=director_x_520&amp;S_TACT=sms&lt;=en_US&amp;cp=UTF-8"</sol>
    </sols>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="https://www14.software.ibm.com/webapp/iwm/web/reg/download.do?source=dmp&amp;S_PKG=director_x_520&amp;S_TACT=sms&amp;lang=en_US&amp;cp=UTF-8" source="MISC" patch="1" adv="1">https://www14.software.ibm.com/webapp/iwm/web/reg/download.do?source=dmp&amp;S_PKG=director_x_520&amp;S_TACT=sms&amp;lang=en_US&amp;cp=UTF-8</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0656" source="VUPEN" patch="1" adv="1">ADV-2009-0656</ref>
      <ref url="https://www.sec-consult.com/files/20090305-2_IBM_director_privilege_escalation.txt" source="MISC">https://www.sec-consult.com/files/20090305-2_IBM_director_privilege_escalation.txt</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/49286" source="XF">director-cim-directory-traversal(49286)</ref>
      <ref url="http://www.securityfocus.com/bid/34065" source="BID">34065</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/501639/100/0/threaded" source="BUGTRAQ">20090310 SEC Consult SA-20090305-2 :: IBM Director CIM Server Local Privilege Escalation Vulnerability</ref>
      <ref url="http://secunia.com/advisories/34212" source="SECUNIA" adv="1">34212</ref>
      <ref url="http://osvdb.org/52616" source="OSVDB">52616</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="director">
        <vers num="3.1.1" />
        <vers num="4.10" />
        <vers num="4.11" />
        <vers num="4.12" />
        <vers num="4.20" />
        <vers num="4.21" />
        <vers num="4.22" />
        <vers num="5.10.0" />
        <vers num="5.10.1" />
        <vers num="5.10.2" />
        <vers num="5.10.3" />
        <vers num="5.20.0" />
        <vers num="5.20.1" />
        <vers num="5.20.2" />
        <vers prev="1" num="5.20.3" edition="service_update_1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0881" published="2009-03-12" name="CVE-2009-0881" modified="2009-03-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in ejemplo/paises.php in isiAJAX 1 allows remote attackers to execute arbitrary SQL commands via the id parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/49113" source="XF">isiajax-paises-sql-injection(49113)</ref>
      <ref url="http://www.milw0rm.com/exploits/8167" source="MILW0RM">8167</ref>
    </refs>
    <vuln_soft>
      <prod vendor="josema_enzo" name="isiajax">
        <vers num="1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0882" published="2009-03-12" name="CVE-2009-0882" modified="2009-03-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in nForum 1.5 allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to showtheme.php and the (2) user parameter to userinfo.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/34030" source="BID">34030</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/501560/100/0/threaded" source="BUGTRAQ">20090306 nForum 1.5 Multiple SQL Injection</ref>
    </refs>
    <vuln_soft>
      <prod vendor="roman_bogorodskiy" name="nforum">
        <vers num="1.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0883" published="2009-03-12" name="CVE-2009-0883" modified="2009-03-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">SQL injection vulnerability in Blue Eye CMS 1.0.0 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the BlueEyeCMS_login cookie parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/49104" source="XF">blueeyecms-blueeyecmslogin-sql-injection(49104)</ref>
      <ref url="http://www.securityfocus.com/bid/34022" source="BID">34022</ref>
      <ref url="http://www.milw0rm.com/exploits/8165" source="MILW0RM">8165</ref>
    </refs>
    <vuln_soft>
      <prod vendor="amunak" name="blue_eye_cms">
        <vers prev="1" num="1.0.0" edition="prerc" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0884" published="2009-03-12" name="CVE-2009-0884" modified="2009-03-12" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Buffer overflow in FileZilla Server before 0.9.31 allows remote attackers to cause a denial of service via unspecified vectors related to SSL/TLS packets.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2009/0603" source="VUPEN" patch="1" adv="1">ADV-2009-0603</ref>
      <ref url="http://filezilla-project.org/index.php" source="CONFIRM" patch="1" adv="1">http://filezilla-project.org/index.php</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/49107" source="XF">filezillaserver-ssltls-dos(49107)</ref>
      <ref url="http://www.securitytracker.com/id?1021812" source="SECTRACK" adv="1">1021812</ref>
      <ref url="http://www.securityfocus.com/bid/34006" source="BID">34006</ref>
      <ref url="http://sourceforge.net/project/shownotes.php?release_id=665428" source="CONFIRM">http://sourceforge.net/project/shownotes.php?release_id=665428</ref>
      <ref url="http://secunia.com/advisories/34089" source="SECUNIA" adv="1">34089</ref>
    </refs>
    <vuln_soft>
      <prod vendor="filezilla" name="filezilla_server">
        <vers num="0.8.1" />
        <vers num="0.8.2" />
        <vers num="0.8.3" />
        <vers num="0.8.4" />
        <vers num="0.8.5" />
        <vers num="0.8.6a" />
        <vers num="0.8.7" />
        <vers num="0.8.8" />
        <vers num="0.8.9" />
        <vers num="0.9.0" />
        <vers num="0.9.10" />
        <vers num="0.9.10a" />
        <vers num="0.9.11" />
        <vers num="0.9.12c" />
        <vers num="0.9.13b" />
        <vers num="0.9.14a" />
        <vers num="0.9.15" />
        <vers num="0.9.16c" />
        <vers num="0.9.17" />
        <vers num="0.9.18" />
        <vers num="0.9.19" />
        <vers num="0.9.1b" />
        <vers num="0.9.2" />
        <vers num="0.9.20" />
        <vers num="0.9.21" />
        <vers num="0.9.22" />
        <vers num="0.9.23" />
        <vers num="0.9.24" />
        <vers num="0.9.25" />
        <vers num="0.9.26" />
        <vers num="0.9.27" />
        <vers num="0.9.28" />
        <vers num="0.9.29" />
        <vers num="0.9.3" />
        <vers prev="1" num="0.9.30" />
        <vers num="0.9.4d" />
        <vers num="0.9.4e" />
        <vers num="0.9.5" />
        <vers num="0.9.6" />
        <vers num="0.9.6a" />
        <vers num="0.9.7" />
        <vers num="0.9.8" />
        <vers num="0.9.8a" />
        <vers num="0.9.8b" />
        <vers num="0.9.8c" />
        <vers num="0.9.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0885" published="2009-03-12" name="CVE-2009-0885" modified="2009-04-01" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Multiple heap-based buffer overflows in Media Commands 1.0 allow remote attackers to execute arbitrary code or cause a denial of service (application crash) via a long string in a (1) M3U, (2) M3l, (3) TXT, and (4) LRC playlist file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/49035" source="XF">mediacommands-playlist-bo(49035)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0583" source="VUPEN" adv="1">ADV-2009-0583</ref>
      <ref url="http://www.securityfocus.com/data/vulnerabilities/exploits/33958.rb" source="MISC">http://www.securityfocus.com/data/vulnerabilities/exploits/33958.rb</ref>
      <ref url="http://www.securityfocus.com/data/vulnerabilities/exploits/33958.py" source="MISC">http://www.securityfocus.com/data/vulnerabilities/exploits/33958.py</ref>
      <ref url="http://www.securityfocus.com/data/vulnerabilities/exploits/33958-2.py" source="MISC">http://www.securityfocus.com/data/vulnerabilities/exploits/33958-2.py</ref>
      <ref url="http://www.securityfocus.com/bid/33958" source="BID">33958</ref>
      <ref url="http://www.milw0rm.com/exploits/8135" source="MILW0RM">8135</ref>
      <ref url="http://secunia.com/advisories/34122" source="SECUNIA" adv="1">34122</ref>
      <ref url="http://osvdb.org/52346" source="OSVDB">52346</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mediacommands" name="media_commands">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0886" published="2009-03-12" name="CVE-2009-0886" modified="2009-03-12" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in login.php in OneOrZero Helpdesk 1.6.5.7 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the default_language parameter.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/49114" source="XF">htms-login-file-include(49114)</ref>
      <ref url="http://www.securityfocus.com/bid/34029" source="BID">34029</ref>
      <ref url="http://www.milw0rm.com/exploits/8169" source="MILW0RM">8169</ref>
      <ref url="http://www.milw0rm.com/exploits/8168" source="MILW0RM">8168</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oneorzero" name="oneorzero_helpdesk">
        <vers num="1.4_rc4" />
        <vers num="1.6" />
        <vers num="1.6.3" />
        <vers num="1.6.3.0" />
        <vers num="1.6.4" />
        <vers num="1.6.4.1" />
        <vers num="1.6.4.2" />
        <vers num="1.6.5.3" />
        <vers num="1.6.5.4" />
        <vers prev="1" num="1.6.5.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0887" published="2009-03-12" name="CVE-2009-0887" modified="2009-04-18" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:S/C:C/I:C/A:C)" CVSS_score="6.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="2.7" CVSS_base_score="6.6">
    <desc>
      <descript source="cve">Integer signedness error in the _pam_StrTok function in libpam/pam_misc.c in Linux-PAM (aka pam) 1.0.3 and earlier, when a configuration file contains non-ASCII usernames, might allow remote attackers to cause a denial of service, and might allow remote authenticated users to obtain login access with a different user's non-ASCII username, via a login attempt.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/34010" source="BID" patch="1">34010</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-April/msg00420.html" source="FEDORA">FEDORA-2009-3231</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-April/msg00398.html" source="FEDORA">FEDORA-2009-3204</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/49110" source="XF">linuxpam-pamstrtok-priv-escalation(49110)</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:077" source="MANDRIVA">MDVSA-2009:077</ref>
      <ref url="http://secunia.com/advisories/34733" source="SECUNIA">34733</ref>
      <ref url="http://pam.cvs.sourceforge.net/viewvc/pam/Linux-PAM/libpam/pam_misc.c?view=log" source="CONFIRM">http://pam.cvs.sourceforge.net/viewvc/pam/Linux-PAM/libpam/pam_misc.c?view=log</ref>
      <ref url="http://pam.cvs.sourceforge.net/viewvc/pam/Linux-PAM/libpam/pam_misc.c?r1=1.9&amp;amp;r2=1.10&amp;amp;view=patch" source="CONFIRM">http://pam.cvs.sourceforge.net/viewvc/pam/Linux-PAM/libpam/pam_misc.c?r1=1.9&amp;amp;r2=1.10&amp;amp;view=patch</ref>
      <ref url="http://openwall.com/lists/oss-security/2009/03/05/1" source="MLIST">[oss-security] 20090305 CVE Request -- pam</ref>
    </refs>
    <vuln_soft>
      <prod vendor="kernel" name="linux-pam">
        <vers num="0.99.1.0" />
        <vers num="0.99.10.0" />
        <vers num="0.99.2.0" />
        <vers num="0.99.2.1" />
        <vers num="0.99.3.0" />
        <vers num="0.99.4.0" />
        <vers num="0.99.5.0" />
        <vers num="0.99.6.0" />
        <vers num="0.99.6.1" />
        <vers num="0.99.6.2" />
        <vers num="0.99.6.3" />
        <vers num="0.99.7.0" />
        <vers num="0.99.7.1" />
        <vers num="0.99.8.0" />
        <vers num="0.99.8.1" />
        <vers num="0.99.9.0" />
        <vers num="1.0.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers prev="1" num="1.0.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0888" published="2009-06-11" name="CVE-2009-0888" modified="2009-08-12" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Heap-based buffer overflow in the JBIG2 filter in Adobe Reader 7 and Acrobat 7 before 7.1.3, Adobe Reader 8 and Acrobat 8 before 8.1.6, and Adobe Reader 9 and Acrobat 9 before 9.1.2 might allow remote attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2009-0510, CVE-2009-0511, CVE-2009-0512, and CVE-2009-0889.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-161A.html" source="CERT">TA09-161A</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1547" source="VUPEN" patch="1" adv="1">ADV-2009-1547</ref>
      <ref url="http://www.adobe.com/support/security/bulletins/apsb09-07.html" source="CONFIRM" patch="1" adv="1">http://www.adobe.com/support/security/bulletins/apsb09-07.html</ref>
      <ref url="http://www.securityfocus.com/bid/35274" source="BID">35274</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-1109.html" source="REDHAT">RHSA-2009:1109</ref>
      <ref url="http://securitytracker.com/id?1022361" source="SECTRACK">1022361</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200907-06.xml" source="GENTOO">GLSA-200907-06</ref>
      <ref url="http://secunia.com/advisories/35734" source="SECUNIA">35734</ref>
      <ref url="http://secunia.com/advisories/35496" source="SECUNIA">35496</ref>
      <ref url="http://secunia.com/advisories/34580" source="SECUNIA" adv="1">34580</ref>
    </refs>
    <vuln_soft>
      <prod vendor="adobe" name="acrobat">
        <vers num="7.0" edition="" />
        <vers num="7.0" edition=":standard" />
        <vers num="7.0" edition=":professional" />
        <vers num="7.0.1" edition="" />
        <vers num="7.0.1" edition=":professional" />
        <vers num="7.0.1" edition=":standard" />
        <vers num="7.0.2" edition="" />
        <vers num="7.0.2" edition=":professional" />
        <vers num="7.0.2" edition=":standard" />
        <vers num="7.0.3" edition="" />
        <vers num="7.0.3" edition=":professional" />
        <vers num="7.0.3" edition=":standard" />
        <vers num="7.0.4" edition="" />
        <vers num="7.0.4" edition=":professional" />
        <vers num="7.0.4" edition=":standard" />
        <vers num="7.0.5" edition="" />
        <vers num="7.0.5" edition=":professional" />
        <vers num="7.0.5" edition=":standard" />
        <vers num="7.0.6" edition="" />
        <vers num="7.0.6" edition=":professional" />
        <vers num="7.0.6" edition=":standard" />
        <vers num="7.0.7" edition="" />
        <vers num="7.0.7" edition=":professional" />
        <vers num="7.0.7" edition=":standard" />
        <vers num="7.0.8" edition="" />
        <vers num="7.0.8" edition=":elements" />
        <vers num="7.0.8" edition=":standard" />
        <vers num="7.0.8" edition=":professional" />
        <vers num="7.0.9" edition="" />
        <vers num="7.0.9" edition=":professional" />
        <vers num="7.1" edition="" />
        <vers num="7.1" edition=":standard" />
        <vers num="7.1" edition=":professional" />
        <vers num="7.1.0" />
        <vers num="7.1.1" edition="" />
        <vers num="7.1.1" edition=":standard" />
        <vers num="8.0" edition="" />
        <vers num="8.0" edition=":professional" />
        <vers num="8.0" edition=":standard" />
        <vers num="8.1" edition="" />
        <vers num="8.1" edition=":standard" />
        <vers num="8.1.1" edition="" />
        <vers num="8.1.1" edition=":standard" />
        <vers num="8.1.1" edition=":professional" />
        <vers num="8.1.2" edition="" />
        <vers num="8.1.2" edition=":standard" />
        <vers num="8.1.2" edition=":professional" />
        <vers num="8.1.2" edition="security_update" />
        <vers num="8.1.2" edition="security_update:professional" />
        <vers num="8.1.3" edition="" />
        <vers num="8.1.3" edition=":standard" />
        <vers num="8.1.3" edition=":professional" />
        <vers num="8.1.4" edition="" />
        <vers num="8.1.4" edition=":standard" />
        <vers num="8.1.4" edition=":professional" />
        <vers num="9" />
        <vers num="9.0" edition="" />
        <vers num="9.0" edition=":standard" />
        <vers num="9.0.0" />
        <vers num="9.1" edition="" />
        <vers num="9.1" edition=":standard" />
      </prod>
      <prod vendor="adobe" name="acrobat_reader">
        <vers num="7.0" />
        <vers num="7.0.1" />
        <vers num="7.0.2" />
        <vers num="7.0.3" />
        <vers num="7.0.4" />
        <vers num="7.0.5" />
        <vers num="7.0.6" />
        <vers num="7.0.7" />
        <vers num="7.0.8" />
        <vers num="7.0.9" />
        <vers num="7.1" />
        <vers num="7.1.1" />
        <vers num="8.0" />
        <vers num="8.1" />
        <vers num="8.1.1" />
        <vers num="8.1.2" edition="security_update" />
        <vers num="8.1.3" />
        <vers num="8.1.4" />
        <vers num="8.1.5" />
        <vers num="9" />
        <vers num="9.1" />
        <vers num="9.1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0889" published="2009-06-11" name="CVE-2009-0889" modified="2009-08-12" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Heap-based buffer overflow in the JBIG2 filter in Adobe Reader 7 and Acrobat 7 before 7.1.3, Adobe Reader 8 and Acrobat 8 before 8.1.6, and Adobe Reader 9 and Acrobat 9 before 9.1.2 might allow remote attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2009-0510, CVE-2009-0511, CVE-2009-0512, and CVE-2009-0888.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-161A.html" source="CERT">TA09-161A</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1547" source="VUPEN" patch="1" adv="1">ADV-2009-1547</ref>
      <ref url="http://www.adobe.com/support/security/bulletins/apsb09-07.html" source="CONFIRM" patch="1" adv="1">http://www.adobe.com/support/security/bulletins/apsb09-07.html</ref>
      <ref url="http://www.securityfocus.com/bid/35274" source="BID">35274</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-1109.html" source="REDHAT">RHSA-2009:1109</ref>
      <ref url="http://securitytracker.com/id?1022361" source="SECTRACK">1022361</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200907-06.xml" source="GENTOO">GLSA-200907-06</ref>
      <ref url="http://secunia.com/advisories/35734" source="SECUNIA">35734</ref>
      <ref url="http://secunia.com/advisories/35496" source="SECUNIA">35496</ref>
      <ref url="http://secunia.com/advisories/34580" source="SECUNIA" adv="1">34580</ref>
    </refs>
    <vuln_soft>
      <prod vendor="adobe" name="acrobat">
        <vers num="7.0" edition="" />
        <vers num="7.0" edition=":standard" />
        <vers num="7.0" edition=":professional" />
        <vers num="7.0.1" edition="" />
        <vers num="7.0.1" edition=":professional" />
        <vers num="7.0.1" edition=":standard" />
        <vers num="7.0.2" edition="" />
        <vers num="7.0.2" edition=":professional" />
        <vers num="7.0.2" edition=":standard" />
        <vers num="7.0.3" edition="" />
        <vers num="7.0.3" edition=":professional" />
        <vers num="7.0.3" edition=":standard" />
        <vers num="7.0.4" edition="" />
        <vers num="7.0.4" edition=":professional" />
        <vers num="7.0.4" edition=":standard" />
        <vers num="7.0.5" edition="" />
        <vers num="7.0.5" edition=":professional" />
        <vers num="7.0.5" edition=":standard" />
        <vers num="7.0.6" edition="" />
        <vers num="7.0.6" edition=":professional" />
        <vers num="7.0.6" edition=":standard" />
        <vers num="7.0.7" edition="" />
        <vers num="7.0.7" edition=":professional" />
        <vers num="7.0.7" edition=":standard" />
        <vers num="7.0.8" edition="" />
        <vers num="7.0.8" edition=":elements" />
        <vers num="7.0.8" edition=":standard" />
        <vers num="7.0.8" edition=":professional" />
        <vers num="7.0.9" edition="" />
        <vers num="7.0.9" edition=":professional" />
        <vers num="7.1" edition="" />
        <vers num="7.1" edition=":standard" />
        <vers num="7.1" edition=":professional" />
        <vers num="7.1.0" />
        <vers num="7.1.1" edition="" />
        <vers num="7.1.1" edition=":standard" />
        <vers num="8.0" edition="" />
        <vers num="8.0" edition=":professional" />
        <vers num="8.0" edition=":standard" />
        <vers num="8.1" edition="" />
        <vers num="8.1" edition=":standard" />
        <vers num="8.1.1" edition="" />
        <vers num="8.1.1" edition=":standard" />
        <vers num="8.1.1" edition=":professional" />
        <vers num="8.1.2" edition="" />
        <vers num="8.1.2" edition=":standard" />
        <vers num="8.1.2" edition=":professional" />
        <vers num="8.1.2" edition="security_update" />
        <vers num="8.1.2" edition="security_update:professional" />
        <vers num="8.1.3" edition="" />
        <vers num="8.1.3" edition=":standard" />
        <vers num="8.1.3" edition=":professional" />
        <vers num="8.1.4" edition="" />
        <vers num="8.1.4" edition=":standard" />
        <vers num="8.1.4" edition=":professional" />
        <vers num="9" />
        <vers num="9.0" edition="" />
        <vers num="9.0" edition=":standard" />
        <vers num="9.0.0" />
        <vers num="9.1" edition="" />
        <vers num="9.1" edition=":standard" />
      </prod>
      <prod vendor="adobe" name="acrobat_reader">
        <vers num="7.0" />
        <vers num="7.0.1" />
        <vers num="7.0.2" />
        <vers num="7.0.3" />
        <vers num="7.0.4" />
        <vers num="7.0.5" />
        <vers num="7.0.6" />
        <vers num="7.0.7" />
        <vers num="7.0.8" />
        <vers num="7.0.9" />
        <vers num="7.1" />
        <vers num="7.1.1" />
        <vers num="8.0" />
        <vers num="8.1" />
        <vers num="8.1.1" />
        <vers num="8.1.2" edition="security_update" />
        <vers num="8.1.3" />
        <vers num="8.1.4" />
        <vers num="8.1.5" />
        <vers num="9" />
        <vers num="9.1" />
        <vers num="9.1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0891" published="2009-03-24" name="CVE-2009-0891" modified="2009-03-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:N)" CVSS_score="5.5" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.0" CVSS_base_score="5.5">
    <desc>
      <descript source="cve">The Web Services Security component in IBM WebSphere Application Server 7.0 before Fix Pack 1 (7.0.0.1), 6.1 before Fix Pack 23 (6.1.0.23),and 6.0.2 before Fix Pack 33 (6.0.2.33) does not properly enforce (1) nonce and (2) timestamp expiration values in WS-Security bindings as stored in the com.ibm.wsspi.wssecurity.core custom property, which allows remote authenticated users to conduct session hijacking attacks.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg27014463" source="CONFIRM" patch="1">http://www-01.ibm.com/support/docview.wss?uid=swg27014463</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg27007951" source="CONFIRM" patch="1">http://www-01.ibm.com/support/docview.wss?uid=swg27007951</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg27006876" source="CONFIRM" patch="1">http://www-01.ibm.com/support/docview.wss?uid=swg27006876</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/49391" source="XF">websphere-ws-security-session-hijacking(49391)</ref>
      <ref url="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=PK66676&amp;apar=only" source="AIXAPAR">PK66676</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="websphere_application_server">
        <vers num="6.0.2" edition="" />
        <vers num="6.0.2" edition=":fp17" />
        <vers num="6.0.2.1" />
        <vers num="6.0.2.10" />
        <vers num="6.0.2.11" />
        <vers num="6.0.2.12" />
        <vers num="6.0.2.13" />
        <vers num="6.0.2.14" />
        <vers num="6.0.2.15" />
        <vers num="6.0.2.16" />
        <vers num="6.0.2.17" />
        <vers num="6.0.2.18" />
        <vers num="6.0.2.19" />
        <vers num="6.0.2.2" />
        <vers num="6.0.2.20" />
        <vers num="6.0.2.21" />
        <vers num="6.0.2.22" />
        <vers num="6.0.2.23" />
        <vers num="6.0.2.24" />
        <vers num="6.0.2.25" />
        <vers num="6.0.2.27" />
        <vers num="6.0.2.28" />
        <vers num="6.0.2.29" />
        <vers num="6.0.2.3" />
        <vers num="6.0.2.30" />
        <vers num="6.0.2.31" />
        <vers num="6.0.2.32" />
        <vers num="6.0.2.4" />
        <vers num="6.0.2.5" />
        <vers num="6.0.2.6" />
        <vers num="6.0.2.7" />
        <vers num="6.0.2.8" />
        <vers num="6.0.2.9" />
        <vers num="6.1" />
        <vers num="6.1.0" />
        <vers num="6.1.0.0" />
        <vers num="6.1.0.1" />
        <vers num="6.1.0.10" />
        <vers num="6.1.0.11" />
        <vers num="6.1.0.12" />
        <vers num="6.1.0.13" />
        <vers num="6.1.0.14" />
        <vers num="6.1.0.15" />
        <vers num="6.1.0.16" />
        <vers num="6.1.0.17" />
        <vers num="6.1.0.18" />
        <vers num="6.1.0.19" />
        <vers num="6.1.0.2" />
        <vers num="6.1.0.20" />
        <vers num="6.1.0.21" />
        <vers num="6.1.0.22" />
        <vers num="6.1.0.3" />
        <vers num="6.1.0.4" />
        <vers num="6.1.0.5" />
        <vers num="6.1.0.6" />
        <vers num="6.1.0.7" />
        <vers num="6.1.0.8" />
        <vers num="6.1.0.9" />
        <vers num="7.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0892" published="2009-03-31" name="CVE-2009-0892" modified="2009-04-16" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:N)" CVSS_score="5.5" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.0" CVSS_base_score="5.5">
    <desc>
      <descript source="cve">The administrative console in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.23 and 7.0 before 7.0.0.3 allows attackers to hijack user sessions in "specific scenarios" related to a forced logout.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg27014463" source="CONFIRM" patch="1">http://www-01.ibm.com/support/docview.wss?uid=swg27014463</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg27007951" source="CONFIRM" patch="1">http://www-01.ibm.com/support/docview.wss?uid=swg27007951</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/49499" source="XF">websphere-console-session-hijacking(49499)</ref>
      <ref url="http://www.securityfocus.com/bid/34501" source="BID">34501</ref>
      <ref url="http://secunia.com/advisories/34131" source="SECUNIA" adv="1">34131</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="websphere_application_server">
        <vers num="6.1" />
        <vers num="6.1.0" />
        <vers num="6.1.0.0" />
        <vers num="6.1.0.1" />
        <vers num="6.1.0.10" />
        <vers num="6.1.0.11" />
        <vers num="6.1.0.12" />
        <vers num="6.1.0.13" />
        <vers num="6.1.0.14" />
        <vers num="6.1.0.15" />
        <vers num="6.1.0.16" />
        <vers num="6.1.0.17" />
        <vers num="6.1.0.18" />
        <vers num="6.1.0.19" />
        <vers num="6.1.0.2" />
        <vers num="6.1.0.20" />
        <vers num="6.1.0.21" />
        <vers num="6.1.0.22" />
        <vers num="6.1.0.3" />
        <vers num="6.1.0.4" />
        <vers num="6.1.0.5" />
        <vers num="6.1.0.6" />
        <vers num="6.1.0.7" />
        <vers num="6.1.0.8" />
        <vers num="6.1.0.9" />
        <vers num="7.0" />
        <vers num="7.0.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0893" published="2009-06-02" name="CVE-2009-0893" modified="2009-06-04" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Multiple heap-based buffer overflows in xvidcore/src/decoder.c in the xvidcore library in Xvid before 1.2.2, as used by Windows Media Player and other applications, allow remote attackers to execute arbitrary code by providing a crafted macroblock (aka MBlock) number in a video stream in a crafted movie file that triggers heap memory corruption, related to a "missing resync marker range check" and the (1) decoder_iframe, (2) decoder_pframe, and (3) decoder_bframe functions.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://cvs.xvid.org/cvs/viewvc.cgi/xvidcore/src/decoder.c?r1=1.80&amp;r2=1.81" source="CONFIRM" patch="1">http://cvs.xvid.org/cvs/viewvc.cgi/xvidcore/src/decoder.c?r1=1.80&amp;r2=1.81</ref>
      <ref url="https://www.it-isac.org/postings/cyber/alertdetail.php?id=4634&amp;selyear=2009&amp;menutype=menupublic" source="MISC">https://www.it-isac.org/postings/cyber/alertdetail.php?id=4634&amp;selyear=2009&amp;menutype=menupublic</ref>
      <ref url="http://www.xvid.org/News.64.0.html?&amp;cHash=0170b4e439&amp;tx_ttnews%5BbackPid%5D=64&amp;tx_ttnews%5Btt_news%5D=7" source="CONFIRM">http://www.xvid.org/News.64.0.html?&amp;cHash=0170b4e439&amp;tx_ttnews[backPid]=64&amp;tx_ttnews[tt_news]=7</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1468" source="VUPEN" adv="1">ADV-2009-1468</ref>
      <ref url="http://www.securityfocus.com/bid/35156" source="BID">35156</ref>
      <ref url="http://secunia.com/advisories/35274" source="SECUNIA" adv="1">35274</ref>
      <ref url="http://cvs.xvid.org/cvs/viewvc.cgi/xvidcore/src/decoder.c" source="CONFIRM">http://cvs.xvid.org/cvs/viewvc.cgi/xvidcore/src/decoder.c</ref>
    </refs>
    <vuln_soft>
      <prod vendor="xvid" name="xvid">
        <vers num="1.1.0" />
        <vers num="1.1.1" />
        <vers num="1.1.2" />
        <vers num="1.1.3" />
        <vers num="1.2.0" />
        <vers prev="1" num="1.2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0894" published="2009-06-02" name="CVE-2009-0894" modified="2009-06-04" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Heap-based buffer overflow in the decoder_create function in the initialization functionality in xvidcore/src/decoder.c in Xvid before 1.2.2, as used by Windows Media Player and other applications, allows remote attackers to execute arbitrary code via vectors involving the DirectShow (aka DShow) frontend and improper handling of the XVID_ERR_MEMORY return code during processing of a crafted movie file. NOTE: some of these details are obtained from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://cvs.xvid.org/cvs/viewvc.cgi/xvidcore/src/decoder.c?r1=1.80&amp;r2=1.81" source="CONFIRM" patch="1">http://cvs.xvid.org/cvs/viewvc.cgi/xvidcore/src/decoder.c?r1=1.80&amp;r2=1.81</ref>
      <ref url="http://cvs.xvid.org/cvs/viewvc.cgi/xvidcore/src/decoder.c" source="CONFIRM" patch="1">http://cvs.xvid.org/cvs/viewvc.cgi/xvidcore/src/decoder.c</ref>
      <ref url="https://www.it-isac.org/postings/cyber/alertdetail.php?id=4635&amp;selyear=2009&amp;menutype=menupublic" source="MISC">https://www.it-isac.org/postings/cyber/alertdetail.php?id=4635&amp;selyear=2009&amp;menutype=menupublic</ref>
      <ref url="http://www.xvid.org/News.64.0.html?&amp;cHash=0170b4e439&amp;tx_ttnews%5BbackPid%5D=64&amp;tx_ttnews%5Btt_news%5D=7" source="CONFIRM">http://www.xvid.org/News.64.0.html?&amp;cHash=0170b4e439&amp;tx_ttnews[backPid]=64&amp;tx_ttnews[tt_news]=7</ref>
      <ref url="http://www.securityfocus.com/bid/35158" source="BID">35158</ref>
    </refs>
    <vuln_soft>
      <prod vendor="xvid" name="xvid">
        <vers num="1.1.0" />
        <vers num="1.1.1" />
        <vers num="1.1.2" />
        <vers num="1.1.3" />
        <vers num="1.2.0" />
        <vers prev="1" num="1.2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0895" published="2009-12-03" name="CVE-2009-0895" modified="2009-12-04" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Integer overflow in Novell eDirectory 8.7.3.x before 8.7.3.10 ftf2 and 8.8.x before 8.8.5.2 allows remote attackers to execute arbitrary code via an NDS Verb 0x1 request containing a large integer value that triggers a heap-based buffer overflow.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2009/3379" source="VUPEN" patch="1" adv="1">ADV-2009-3379</ref>
      <ref url="http://www.novell.com/support/viewContent.do?externalId=7004912" source="CONFIRM" patch="1" adv="1">http://www.novell.com/support/viewContent.do?externalId=7004912</ref>
      <ref url="https://bugzilla.novell.com/show_bug.cgi?id=545887" source="MISC">https://bugzilla.novell.com/show_bug.cgi?id=545887</ref>
      <ref url="https://bugzilla.novell.com/show_bug.cgi?id=524344" source="MISC">https://bugzilla.novell.com/show_bug.cgi?id=524344</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/50616" source="XF">application-control-request-overflow(50616)</ref>
      <ref url="http://www.securityfocus.com/bid/37184" source="BID">37184</ref>
      <ref url="http://www.iss.net/threats/356.html" source="ISS">20091124 Novell eDirectory Remote Code Execution</ref>
      <ref url="http://secunia.com/advisories/37554" source="SECUNIA" adv="1">37554</ref>
    </refs>
    <vuln_soft>
      <prod vendor="novell" name="edirectory">
        <vers num="8.7.3" edition="sp10" />
        <vers num="8.7.3" edition="sp10:ftf1" />
        <vers num="8.7.3" edition="sp10_b" />
        <vers num="8.7.3" edition="sp3" />
        <vers num="8.7.3" edition="sp3:ftf1" />
        <vers num="8.7.3" edition="sp4" />
        <vers num="8.7.3" edition="sp4:ftf1" />
        <vers num="8.7.3" edition="sp5" />
        <vers num="8.7.3" edition="sp5:ftf1" />
        <vers num="8.7.3.10" />
        <vers num="8.7.3.8" />
        <vers num="8.7.3.9" />
        <vers num="8.8" edition="sp1" />
        <vers num="8.8" edition="sp2" />
        <vers num="8.8" edition="sp3" />
        <vers num="8.8" edition="sp3:ftf3" />
        <vers num="8.8" edition="sp4" />
        <vers num="8.8.1" />
        <vers num="8.8.2" edition="" />
        <vers num="8.8.2" edition=":ftf1" />
        <vers num="8.8.5" edition="" />
        <vers num="8.8.5" edition=":ftf1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0896" published="2009-06-03" name="CVE-2009-0896" modified="2009-06-03" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in the queue manager in IBM WebSphere MQ 6.x before 6.0.2.7 and 7.x before 7.0.1.0 allows remote attackers to execute arbitrary code via a crafted request.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2009/1463" source="VUPEN" patch="1" adv="1">ADV-2009-1463</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg21386826" source="CONFIRM" patch="1" adv="1">http://www-01.ibm.com/support/docview.wss?uid=swg21386826</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/50641" source="XF">websphere-mq-clientconnection-bo(50641)</ref>
      <ref url="http://www.securityfocus.com/bid/35170" source="BID">35170</ref>
      <ref url="http://securitytracker.com/id?1022311" source="SECTRACK">1022311</ref>
      <ref url="http://secunia.com/advisories/35303" source="SECUNIA" adv="1">35303</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="websphere_mq">
        <vers num="6.0" />
        <vers num="6.0.0.0" />
        <vers num="6.0.1.0" />
        <vers num="6.0.1.1" />
        <vers num="6.0.2.0" />
        <vers num="6.0.2.1" />
        <vers num="6.0.2.2" />
        <vers num="6.0.2.3" />
        <vers num="6.0.2.4" />
        <vers num="6.0.2.5" />
        <vers num="6.0.2.6" />
        <vers num="7.0" />
        <vers num="7.0.0.1" />
        <vers num="7.0.0.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0897" published="2009-05-21" name="CVE-2009-0897" modified="2009-06-04" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:N/A:N)" CVSS_score="4.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.0" CVSS_base_score="4.0">
    <desc>
      <descript source="cve">IBM WebSphere Partner Gateway (WPG) 6.1.0 before 6.1.0.1 and 6.1.1 before 6.1.1.1 allows remote authenticated users to obtain sensitive information via vectors related to the "schema DB2 instance id" and the bcgarchive (aka the archiver script).</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg21366016" source="AIXAPAR" patch="1" adv="1">JR31482</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/50643" source="XF">websphere-pg-bcgarchive-info-disclosure(50643)</ref>
      <ref url="http://www.securityfocus.com/bid/35136" source="BID">35136</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="websphere_partner_gateway">
        <vers num="6.1.0" />
        <vers num="6.1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0898" published="2009-12-10" name="CVE-2009-0898" modified="2009-12-19" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Stack-based buffer overflow in HP OpenView Network Node Manager (OV NNM) 7.01, 7.51, and 7.53 allows remote attackers to execute arbitrary code via a crafted HTTP request.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01950877" source="HP" patch="1" adv="1">HPSBMA02483</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01950877" source="HP" patch="1" adv="1">HPSBMA02483</ref>
      <ref url="http://www.securityfocus.com/bid/37294" source="BID">37294</ref>
      <ref url="http://www.securityfocus.com/bid/37261" source="BID">37261</ref>
      <ref url="http://www.iss.net/threats/357.html" source="ISS">20091209 HP OpenView Network Node Manager Remote Code Execution</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=126046355120442&amp;w=2" source="HP">SSRT090257</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="openview_network_node_manager">
        <vers num="7.0.1" edition="" />
        <vers num="7.0.1" edition=":solaris" />
        <vers num="7.0.1" edition=":hp_ux" />
        <vers num="7.0.1" edition=":windows" />
        <vers num="7.0.1" edition=":linux" />
        <vers num="7.51" edition="-" />
        <vers num="7.51" edition="-:solaris" />
        <vers num="7.51" edition="-:hp-ux" />
        <vers num="7.51" edition="-:linux" />
        <vers num="7.51" edition="-:windows" />
        <vers num="7.53" edition="-" />
        <vers num="7.53" edition="-:solaris" />
        <vers num="7.53" edition="-:windows" />
        <vers num="7.53" edition="-:linux" />
        <vers num="7.53" edition="-:hp-ux" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0899" published="2009-06-03" name="CVE-2009-0899" modified="2009-06-20" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">IBM WebSphere Application Server (WAS) 6.1 through 6.1.0.24 and 7.0 through 7.0.0.4, IBM WebSphere Portal Server 5.1 through 6.0, and IBM Integrated Solutions Console (ISC) 6.0.1 do not properly set the IsSecurityEnabled security flag during migration of WebSphere Member Manager (WMM) to Virtual Member Manager (VMM) and a Federated Repository, which allows attackers to obtain sensitive information from repositories via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg21375859" source="CONFIRM" patch="1" adv="1">http://www-01.ibm.com/support/docview.wss?uid=swg21375859</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/50882" source="XF">websphere-issecurityenabled-info-disclosure(50882)</ref>
      <ref url="http://www.securityfocus.com/bid/35406" source="BID">35406</ref>
      <ref url="http://www-1.ibm.com/support/docview.wss?uid=swg1PK78134" source="AIXAPAR">PK78134</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="integrated_solutions_console">
        <vers num="6.0.1" />
      </prod>
      <prod vendor="ibm" name="websphere_application_server">
        <vers num="6.1.0" />
        <vers num="6.1.0.0" />
        <vers num="6.1.0.1" />
        <vers num="6.1.0.10" />
        <vers num="6.1.0.11" />
        <vers num="6.1.0.12" />
        <vers num="6.1.0.13" />
        <vers num="6.1.0.14" />
        <vers num="6.1.0.15" />
        <vers num="6.1.0.16" />
        <vers num="6.1.0.17" />
        <vers num="6.1.0.18" />
        <vers num="6.1.0.19" />
        <vers num="6.1.0.2" />
        <vers num="6.1.0.20" />
        <vers num="6.1.0.21" />
        <vers num="6.1.0.22" />
        <vers num="6.1.0.23" />
        <vers prev="1" num="6.1.0.24" />
        <vers num="6.1.0.3" />
        <vers num="6.1.0.4" />
        <vers num="6.1.0.5" />
        <vers num="6.1.0.6" />
        <vers num="6.1.0.7" />
        <vers num="6.1.0.8" />
        <vers num="6.1.0.9" />
        <vers num="7.0" />
        <vers num="7.0.0.1" />
        <vers num="7.0.0.3" />
        <vers prev="1" num="7.0.0.4" />
      </prod>
      <prod vendor="ibm" name="websphere_portal">
        <vers num="5.1.0.0" />
        <vers num="5.1.0.1" />
        <vers num="5.1.0.2" />
        <vers num="5.1.0.3" />
        <vers num="5.1.0.4" />
        <vers num="5.1.0.5" />
        <vers num="6.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0900" published="2011-10-30" name="CVE-2009-0900" modified="2011-10-31" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:S/C:P/I:P/A:P)" CVSS_score="4.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="2.7" CVSS_base_score="4.1">
    <desc>
      <descript source="cve">Heap-based buffer overflow in the client in IBM WebSphere MQ 6.0 before 6.0.2.7 and 7.0 before 7.0.1.0 allows local users to gain privileges via crafted SSL information in a Client Channel Definition Table (CCDT) file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/51038" source="XF">websphere-mq-client-ccdt-bo(51038)</ref>
      <ref url="http://www.ibm.com/support/docview.wss?uid=swg1IC59375" source="AIXAPAR">IC59375</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="websphere_mq">
        <vers num="6.0" />
        <vers num="6.0.1.0" />
        <vers num="6.0.1.1" />
        <vers num="6.0.2.0" />
        <vers num="6.0.2.1" />
        <vers num="6.0.2.10" />
        <vers num="6.0.2.2" />
        <vers num="6.0.2.3" />
        <vers num="6.0.2.4" />
        <vers num="6.0.2.5" />
        <vers num="6.0.2.6" />
        <vers num="7.0" />
        <vers num="7.0.0.1" />
        <vers num="7.0.0.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0901" published="2009-07-29" name="CVE-2009-0901" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">The Active Template Library (ATL) in Microsoft Visual Studio .NET 2003 SP1, Visual Studio 2005 SP1 and 2008 Gold, and Visual C++ 2005 SP1 and 2008 Gold and SP1; and Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2; does not prevent VariantClear calls on an uninitialized VARIANT, which allows remote attackers to execute arbitrary code via a malformed stream to an ATL (1) component or (2) control, related to ATL headers and error handling, aka "ATL Uninitialized Object Vulnerability."</descript>
    </desc>
    <impacts>
      <impact source="nvd">Please refer to this link http://www.microsoft.com/technet/security/Bulletin/MS09-035.mspx for mitigating factors and additional information.</impact>
    </impacts>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-286A.html" source="CERT">TA09-286A</ref>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-223A.html" source="CERT">TA09-223A</ref>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-195A.html" source="CERT">TA09-195A</ref>
      <ref url="http://www.securityfocus.com/bid/35832" source="BID" patch="1">35832</ref>
      <ref url="http://www.adobe.com/support/security/bulletins/apsb09-11.html" source="CONFIRM" patch="1">http://www.adobe.com/support/security/bulletins/apsb09-11.html</ref>
      <ref url="http://www.adobe.com/support/security/advisories/apsa09-04.html" source="CONFIRM" patch="1">http://www.adobe.com/support/security/advisories/apsa09-04.html</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/2232" source="VUPEN">ADV-2009-2232</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/2034" source="VUPEN">ADV-2009-2034</ref>
      <ref url="http://www.novell.com/support/viewContent.do?externalId=7004997&amp;sliceId=1" source="CONFIRM">http://www.novell.com/support/viewContent.do?externalId=7004997&amp;sliceId=1</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS09-060.mspx" source="MS">MS09-060</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS09-037.mspx" source="MS">MS09-037</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS09-035.mspx" source="MS" adv="1">MS09-035</ref>
      <ref url="http://www.adobe.com/support/security/bulletins/apsb09-13.html" source="CONFIRM">http://www.adobe.com/support/security/bulletins/apsb09-13.html</ref>
      <ref url="http://www.adobe.com/support/security/bulletins/apsb09-10.html" source="CONFIRM">http://www.adobe.com/support/security/bulletins/apsb09-10.html</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-266108-1" source="SUNALERT">266108</ref>
      <ref url="http://secunia.com/advisories/36746" source="SECUNIA">36746</ref>
      <ref url="http://secunia.com/advisories/36374" source="SECUNIA">36374</ref>
      <ref url="http://secunia.com/advisories/36187" source="SECUNIA">36187</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7581" source="OVAL">oval:org.mitre.oval:def:7581</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6373" source="OVAL">oval:org.mitre.oval:def:6373</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6311" source="OVAL">oval:org.mitre.oval:def:6311</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6289" source="OVAL">oval:org.mitre.oval:def:6289</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=126592505426855&amp;w=2" source="HP">HPSBMA02488</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=126592505426855&amp;w=2" source="HP">HPSBMA02488</ref>
      <ref url="http://blogs.technet.com/srd/archive/2009/08/11/ms09-037-why-we-are-using-cve-s-already-used-in-ms09-035.aspx" source="MISC">http://blogs.technet.com/srd/archive/2009/08/11/ms09-037-why-we-are-using-cve-s-already-used-in-ms09-035.aspx</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="visual_c++">
        <vers num="2005" edition="sp1_redistribution_pkg" />
        <vers num="2008" edition="redistribution_pkg" />
        <vers num="2008" edition="sp1_redistribution_pkg" />
      </prod>
      <prod vendor="microsoft" name="visual_studio">
        <vers num="2005" edition="sp1" />
        <vers num="2005" edition="sp1:64_bit_hosted_visual_c++_tools" />
        <vers num="2008" edition="sp1" />
      </prod>
      <prod vendor="microsoft" name="visual_studio_.net">
        <vers num="2003" edition="sp1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0903" published="2009-06-24" name="CVE-2009-0903" modified="2009-07-11" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.3, and the Feature Pack for Web Services for WAS 6.1 before 6.1.0.25, when a WS-Security policy is established at the operation level, does not properly handle inbound requests that lack a SOAPAction or WS-Addressing Action, which allows remote attackers to bypass intended access restrictions via a crafted request to a JAX-WS application.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www-1.ibm.com/support/docview.wss?uid=swg1PK87767" source="AIXAPAR" patch="1" adv="1">PK87767</ref>
      <ref url="http://www-1.ibm.com/support/docview.wss?uid=swg1PK81944" source="AIXAPAR" patch="1" adv="1">PK81944</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/51293" source="XF">websphere-jaxws-wssecurity-sec-bypass(51293)</ref>
      <ref url="http://www.securityfocus.com/bid/35594" source="BID">35594</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="websphere_application_server">
        <vers num="6.1" />
        <vers num="6.1.0" />
        <vers num="6.1.0.0" />
        <vers num="6.1.0.1" />
        <vers num="6.1.0.10" />
        <vers num="6.1.0.11" />
        <vers num="6.1.0.12" />
        <vers num="6.1.0.13" />
        <vers num="6.1.0.14" />
        <vers num="6.1.0.15" />
        <vers num="6.1.0.16" />
        <vers num="6.1.0.17" />
        <vers num="6.1.0.18" />
        <vers num="6.1.0.19" />
        <vers num="6.1.0.2" />
        <vers num="6.1.0.20" />
        <vers num="6.1.0.21" />
        <vers num="6.1.0.22" />
        <vers num="6.1.0.23" />
        <vers num="6.1.0.24" />
        <vers num="6.1.0.3" />
        <vers num="6.1.0.4" />
        <vers num="6.1.0.5" />
        <vers num="6.1.0.6" />
        <vers num="6.1.0.7" />
        <vers num="6.1.0.8" />
        <vers num="6.1.0.9" />
        <vers num="7.0" />
        <vers num="7.0.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0904" published="2009-07-05" name="CVE-2009-0904" modified="2009-07-22" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">The IBM Stax XMLStreamWriter in the Web Services component in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.25 does not properly process XML encoding, which allows remote attackers to bypass intended access restrictions and possibly modify data via "XML fuzzing attacks" sent through SOAP requests.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/51490" source="XF">websphere-soap-security-bypass(51490)</ref>
      <ref url="http://www.securityfocus.com/bid/35741" source="BID">35741</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg27007951" source="CONFIRM">http://www-01.ibm.com/support/docview.wss?uid=swg27007951</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="websphere_application_server">
        <vers num="6.1" />
        <vers num="6.1.0" />
        <vers num="6.1.0.1" />
        <vers num="6.1.0.10" />
        <vers num="6.1.0.11" />
        <vers num="6.1.0.12" />
        <vers num="6.1.0.13" />
        <vers num="6.1.0.14" />
        <vers num="6.1.0.15" />
        <vers num="6.1.0.16" />
        <vers num="6.1.0.17" />
        <vers num="6.1.0.18" />
        <vers num="6.1.0.19" />
        <vers num="6.1.0.2" />
        <vers num="6.1.0.20" />
        <vers num="6.1.0.21" />
        <vers num="6.1.0.22" />
        <vers num="6.1.0.23" />
        <vers num="6.1.0.3" />
        <vers num="6.1.0.4" />
        <vers num="6.1.0.5" />
        <vers num="6.1.0.6" />
        <vers num="6.1.0.7" />
        <vers num="6.1.0.8" />
        <vers num="6.1.0.9" />
        <vers num="6.1.1" />
        <vers num="6.1.13" />
        <vers num="6.1.14" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2009-0905" published="2011-10-30" name="CVE-2009-0905" modified="2011-10-31" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:S/C:N/I:P/A:N)" CVSS_score="1.7" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.1" CVSS_base_score="1.7">
    <desc>
      <descript source="cve">IBM WebSphere MQ 6.0 before 6.0.2.8 and 7.0 before 7.0.1.0 does not properly handle long group names, which might allow local users to gain privileges by leveraging combinations of group names with the same initial substring.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/51042" source="XF">websphere-mq-group-weak-security(51042)</ref>
      <ref url="http://www.ibm.com/support/docview.wss?uid=swg1IZ37102" source="AIXAPAR">IZ37102</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="websphere_mq">
        <vers num="6.0" />
        <vers num="6.0.1.0" />
        <vers num="6.0.1.1" />
        <vers num="6.0.2.0" />
        <vers num="6.0.2.1" />
        <vers num="6.0.2.2" />
        <vers num="6.0.2.3" />
        <vers num="6.0.2.4" />
        <vers num="6.0.2.5" />
        <vers num="6.0.2.6" />
        <vers num="6.0.2.7" />
        <vers num="7.0" />
        <vers num="7.0.0.1" />
        <vers num="7.0.0.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0906" published="2009-08-13" name="CVE-2009-0906" modified="2009-08-19" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)" CVSS_score="6.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.0" CVSS_base_score="6.5">
    <desc>
      <descript source="cve">The Service Component Architecture (SCA) feature pack for IBM WebSphere Application Server (WAS) SCA 1.0 before 1.0.0.3 allows remote authenticated users to bypass intended authentication.transport access restrictions and obtain unspecified access via unknown vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg27015429" source="CONFIRM" patch="1">http://www-01.ibm.com/support/docview.wss?uid=swg27015429</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/52074" source="XF">was-sca-scaallauthorizedusers-sec-bypass(52074)</ref>
      <ref url="http://secunia.com/advisories/36306" source="SECUNIA" adv="1">36306</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="websphere_application_server">
        <vers num="1.0" />
        <vers num="1.0.0.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" seq="2009-0907" reject="1" published="2009-08-13" name="CVE-2009-0907" modified="2009-08-13">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2009-1899.  Reason: This candidate is a duplicate of CVE-2009-1899.  Notes: All CVE users should reference CVE-2009-1899 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript>
    </desc>
    <refs />
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0908" published="2009-04-06" name="CVE-2009-0908" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">Unspecified vulnerability in the ACE shared folders implementation in the VMware Host Guest File System (HGFS) shared folders feature in VMware ACE 2.5.1 and earlier allows attackers to enable a disabled shared folder.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://seclists.org/fulldisclosure/2009/Apr/0036.html" source="FULLDISC" patch="1">20090403 VMSA-2009-0005 VMware Hosted products, VI Client and patches for ESX and ESXi resolve multiple security issues</ref>
      <ref url="http://lists.vmware.com/pipermail/security-announce/2009/000054.html" source="MLIST" patch="1" adv="1">[security-announce] 20090403 VMSA-2009-0005 VMware Hosted products, VI Client and patches for ESX and ESXi resolve multiple security issues</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0944" source="VUPEN">ADV-2009-0944</ref>
      <ref url="http://www.vmware.com/security/advisories/VMSA-2009-0005.html" source="CONFIRM">http://www.vmware.com/security/advisories/VMSA-2009-0005.html</ref>
      <ref url="http://www.securitytracker.com/id?1021975" source="SECTRACK">1021975</ref>
      <ref url="http://www.securityfocus.com/bid/34373" source="BID">34373</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6399" source="OVAL">oval:org.mitre.oval:def:6399</ref>
    </refs>
    <vuln_soft>
      <prod vendor="vmware" name="ace">
        <vers num="1.0" />
        <vers num="1.0.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.5" />
        <vers num="1.0.6" />
        <vers num="1.0.7" />
        <vers num="2.0" />
        <vers num="2.0.1" />
        <vers num="2.0.2" />
        <vers num="2.0.3" />
        <vers num="2.0.4" />
        <vers num="2.0.5" />
        <vers num="2.5.0" />
        <vers prev="1" num="2.5.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0909" published="2009-04-06" name="CVE-2009-0909" modified="2012-01-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Heap-based buffer overflow in the VNnc Codec in VMware Workstation 6.5.x before 6.5.2 build 156735, VMware Player 2.5.x before 2.5.2 build 156735, VMware ACE 2.5.x before 2.5.2 build 156735, and VMware Server 2.0.x before 2.0.1 build 156745 allows remote attackers to execute arbitrary code via a crafted web page or video file, aka ZDI-CAN-435.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://seclists.org/fulldisclosure/2009/Apr/0036.html" source="FULLDISC" patch="1">20090403 VMSA-2009-0005 VMware Hosted products, VI Client and patches for ESX and ESXi resolve multiple security issues</ref>
      <ref url="http://lists.vmware.com/pipermail/security-announce/2009/000054.html" source="MLIST" patch="1" adv="1">[security-announce] 20090403 VMSA-2009-0005 VMware Hosted products, VI Client and patches for ESX and ESXi resolve multiple security issues</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0944" source="VUPEN">ADV-2009-0944</ref>
      <ref url="http://www.vmware.com/security/advisories/VMSA-2009-0005.html" source="CONFIRM">http://www.vmware.com/security/advisories/VMSA-2009-0005.html</ref>
      <ref url="http://www.securitytracker.com/id?1021974" source="SECTRACK">1021974</ref>
      <ref url="http://www.securityfocus.com/bid/34373" source="BID">34373</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6251" source="OVAL">oval:org.mitre.oval:def:6251</ref>
    </refs>
    <vuln_soft>
      <prod vendor="vmware" name="ace">
        <vers num="2.5.1" />
      </prod>
      <prod vendor="vmware" name="player">
        <vers num="2.5.1" />
      </prod>
      <prod vendor="vmware" name="server">
        <vers num="2.0" />
      </prod>
      <prod vendor="vmware" name="workstation">
        <vers num="6.5.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0910" published="2009-04-06" name="CVE-2009-0910" modified="2012-01-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Heap-based buffer overflow in the VNnc Codec in VMware Workstation 6.5.x before 6.5.2 build 156735, VMware Player 2.5.x before 2.5.2 build 156735, VMware ACE 2.5.x before 2.5.2 build 156735, and VMware Server 2.0.x before 2.0.1 build 156745 allows remote attackers to execute arbitrary code via a crafted web page or video file, aka ZDI-CAN-436.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://seclists.org/fulldisclosure/2009/Apr/0036.html" source="FULLDISC" patch="1">20090403 VMSA-2009-0005 VMware Hosted products, VI Client and patches for ESX and ESXi resolve multiple security issues</ref>
      <ref url="http://lists.vmware.com/pipermail/security-announce/2009/000054.html" source="MLIST" patch="1" adv="1">[security-announce] 20090403 VMSA-2009-0005 VMware Hosted products, VI Client and patches for ESX and ESXi resolve multiple security issues</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0944" source="VUPEN">ADV-2009-0944</ref>
      <ref url="http://www.vmware.com/security/advisories/VMSA-2009-0005.html" source="CONFIRM">http://www.vmware.com/security/advisories/VMSA-2009-0005.html</ref>
      <ref url="http://www.securitytracker.com/id?1021974" source="SECTRACK">1021974</ref>
      <ref url="http://www.securityfocus.com/bid/34373" source="BID">34373</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5786" source="OVAL">oval:org.mitre.oval:def:5786</ref>
    </refs>
    <vuln_soft>
      <prod vendor="vmware" name="ace">
        <vers num="2.5.1" />
      </prod>
      <prod vendor="vmware" name="player">
        <vers num="2.5.1" />
      </prod>
      <prod vendor="vmware" name="server">
        <vers num="2.0" />
      </prod>
      <prod vendor="vmware" name="workstation">
        <vers num="6.5.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0912" published="2009-03-16" name="CVE-2009-0912" modified="2009-03-17" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">perl-MDK-Common 1.1.11 and 1.1.24, 1.2.9 through 1.2.14, and possibly other versions, in Mandriva Linux does not properly handle strings when writing them to configuration files, which allows attackers to gain privileges via "special characters" in unspecified vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/34089" source="BID" patch="1">34089</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/49220" source="XF">perlmdkcommon-unspecified-priv-escalation(49220)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0688" source="VUPEN" adv="1">ADV-2009-0688</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:072" source="MANDRIVA" adv="1">MDVSA-2009:072</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mandriva" name="multi_network_firewall">
        <vers num="2.0" />
      </prod>
      <prod vendor="mandriva" name="linux">
        <vers num="2008.0" edition="-" />
        <vers num="2008.0" edition="-:x86_64" />
        <vers num="2008.1" edition="-" />
        <vers num="2008.1" edition="-:x86_64" />
        <vers num="2009.0" edition="-" />
        <vers num="2009.0" edition="-:x86_64" />
      </prod>
      <prod vendor="mandriva" name="linux_corporate_server">
        <vers num="3.0" edition="-" />
        <vers num="3.0" edition="-:x86_64" />
        <vers num="4.0" edition="-" />
        <vers num="4.0" edition="-:x86_64" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0913" published="2009-03-16" name="CVE-2009-0913" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:N/I:N/A:C)" CVSS_score="4.7" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="3.4" CVSS_base_score="4.7">
    <desc>
      <descript source="cve">Unspecified vulnerability in the keysock kernel module in Solaris 10 and OpenSolaris builds snv_01 through snv_108 allows local users to cause a denial of service (system panic) via unknown vectors related to PF_KEY socket, probably related to setting socket options.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/49247" source="XF">sun-solaris-keysock-dos(49247)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0817" source="VUPEN">ADV-2009-0817</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0717" source="VUPEN">ADV-2009-0717</ref>
      <ref url="http://www.securitytracker.com/id?1021846" source="SECTRACK">1021846</ref>
      <ref url="http://www.securityfocus.com/bid/34118" source="BID">34118</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2009-099.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2009-099.htm</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-253568-1" source="SUNALERT" adv="1">253568</ref>
      <ref url="http://secunia.com/advisories/34456" source="SECUNIA">34456</ref>
      <ref url="http://secunia.com/advisories/34277" source="SECUNIA" adv="1">34277</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6203" source="OVAL">oval:org.mitre.oval:def:6203</ref>
      <ref url="http://osvdb.org/52678" source="OSVDB">52678</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="opensolaris">
        <vers num="snv_01" edition="" />
        <vers num="snv_01" edition=":sparc" />
        <vers num="snv_01" edition=":x86" />
        <vers num="snv_02" edition="" />
        <vers num="snv_02" edition=":sparc" />
        <vers num="snv_02" edition=":x86" />
        <vers num="snv_03" edition="" />
        <vers num="snv_03" edition=":x86" />
        <vers num="snv_03" edition=":sparc" />
        <vers num="snv_04" edition="" />
        <vers num="snv_04" edition=":x86" />
        <vers num="snv_04" edition=":sparc" />
        <vers num="snv_05" edition="" />
        <vers num="snv_05" edition=":sparc" />
        <vers num="snv_05" edition=":x86" />
        <vers num="snv_06" edition="" />
        <vers num="snv_06" edition=":sparc" />
        <vers num="snv_06" edition=":x86" />
        <vers num="snv_07" edition="" />
        <vers num="snv_07" edition=":sparc" />
        <vers num="snv_07" edition=":x86" />
        <vers num="snv_08" edition="" />
        <vers num="snv_08" edition=":x86" />
        <vers num="snv_08" edition=":sparc" />
        <vers num="snv_09" edition="" />
        <vers num="snv_09" edition=":x86" />
        <vers num="snv_09" edition=":sparc" />
        <vers num="snv_10" edition="" />
        <vers num="snv_10" edition=":x86" />
        <vers num="snv_10" edition=":sparc" />
        <vers num="snv_100" edition="" />
        <vers num="snv_100" edition=":sparc" />
        <vers num="snv_100" edition=":x86" />
        <vers num="snv_101" edition="" />
        <vers num="snv_101" edition=":x86" />
        <vers num="snv_101" edition=":sparc" />
        <vers num="snv_102" edition="" />
        <vers num="snv_102" edition=":sparc" />
        <vers num="snv_102" edition=":x86" />
        <vers num="snv_103" edition="" />
        <vers num="snv_103" edition=":x86" />
        <vers num="snv_103" edition=":sparc" />
        <vers num="snv_104" edition="" />
        <vers num="snv_104" edition=":x86" />
        <vers num="snv_104" edition=":sparc" />
        <vers num="snv_105" edition="" />
        <vers num="snv_105" edition=":x86" />
        <vers num="snv_105" edition=":sparc" />
        <vers num="snv_106" edition="" />
        <vers num="snv_106" edition=":sparc" />
        <vers num="snv_106" edition=":x86" />
        <vers num="snv_107" edition="" />
        <vers num="snv_107" edition=":x86" />
        <vers num="snv_107" edition=":sparc" />
        <vers prev="1" num="snv_108" edition="" />
        <vers prev="1" num="snv_108" edition=":x86" />
        <vers prev="1" num="snv_108" edition=":sparc" />
        <vers num="snv_11" edition="" />
        <vers num="snv_11" edition=":x86" />
        <vers num="snv_11" edition=":sparc" />
        <vers num="snv_12" edition="" />
        <vers num="snv_12" edition=":x86" />
        <vers num="snv_12" edition=":sparc" />
        <vers num="snv_13" edition="" />
        <vers num="snv_13" edition=":x86" />
        <vers num="snv_13" edition=":sparc" />
        <vers num="snv_14" edition="" />
        <vers num="snv_14" edition=":sparc" />
        <vers num="snv_14" edition=":x86" />
        <vers num="snv_15" edition="" />
        <vers num="snv_15" edition=":x86" />
        <vers num="snv_15" edition=":sparc" />
        <vers num="snv_16" edition="" />
        <vers num="snv_16" edition=":sparc" />
        <vers num="snv_16" edition=":x86" />
        <vers num="snv_17" edition="" />
        <vers num="snv_17" edition=":x86" />
        <vers num="snv_17" edition=":sparc" />
        <vers num="snv_18" edition="" />
        <vers num="snv_18" edition=":x86" />
        <vers num="snv_18" edition=":sparc" />
        <vers num="snv_19" edition="" />
        <vers num="snv_19" edition=":sparc" />
        <vers num="snv_19" edition=":x86" />
        <vers num="snv_20" edition="" />
        <vers num="snv_20" edition=":x86" />
        <vers num="snv_20" edition=":sparc" />
        <vers num="snv_21" edition="" />
        <vers num="snv_21" edition=":sparc" />
        <vers num="snv_21" edition=":x86" />
        <vers num="snv_22" edition="" />
        <vers num="snv_22" edition=":sparc" />
        <vers num="snv_22" edition=":x86" />
        <vers num="snv_23" edition="" />
        <vers num="snv_23" edition=":sparc" />
        <vers num="snv_23" edition=":x86" />
        <vers num="snv_24" edition="" />
        <vers num="snv_24" edition=":sparc" />
        <vers num="snv_24" edition=":x86" />
        <vers num="snv_25" edition="" />
        <vers num="snv_25" edition=":x86" />
        <vers num="snv_25" edition=":sparc" />
        <vers num="snv_26" edition="" />
        <vers num="snv_26" edition=":x86" />
        <vers num="snv_26" edition=":sparc" />
        <vers num="snv_27" edition="" />
        <vers num="snv_27" edition=":sparc" />
        <vers num="snv_27" edition=":x86" />
        <vers num="snv_28" edition="" />
        <vers num="snv_28" edition=":x86" />
        <vers num="snv_28" edition=":sparc" />
        <vers num="snv_29" edition="" />
        <vers num="snv_29" edition=":x86" />
        <vers num="snv_29" edition=":sparc" />
        <vers num="snv_30" edition="" />
        <vers num="snv_30" edition=":sparc" />
        <vers num="snv_30" edition=":x86" />
        <vers num="snv_31" edition="" />
        <vers num="snv_31" edition=":sparc" />
        <vers num="snv_31" edition=":x86" />
        <vers num="snv_32" edition="" />
        <vers num="snv_32" edition=":x86" />
        <vers num="snv_32" edition=":sparc" />
        <vers num="snv_33" edition="" />
        <vers num="snv_33" edition=":x86" />
        <vers num="snv_33" edition=":sparc" />
        <vers num="snv_34" edition="" />
        <vers num="snv_34" edition=":sparc" />
        <vers num="snv_34" edition=":x86" />
        <vers num="snv_35" edition="" />
        <vers num="snv_35" edition=":sparc" />
        <vers num="snv_35" edition=":x86" />
        <vers num="snv_36" edition="" />
        <vers num="snv_36" edition=":x86" />
        <vers num="snv_36" edition=":sparc" />
        <vers num="snv_37" edition="" />
        <vers num="snv_37" edition=":sparc" />
        <vers num="snv_37" edition=":x86" />
        <vers num="snv_38" edition="" />
        <vers num="snv_38" edition=":sparc" />
        <vers num="snv_38" edition=":x86" />
        <vers num="snv_39" edition="" />
        <vers num="snv_39" edition=":sparc" />
        <vers num="snv_39" edition=":x86" />
        <vers num="snv_40" edition="" />
        <vers num="snv_40" edition=":sparc" />
        <vers num="snv_40" edition=":x86" />
        <vers num="snv_41" edition="" />
        <vers num="snv_41" edition=":sparc" />
        <vers num="snv_41" edition=":x86" />
        <vers num="snv_42" edition="" />
        <vers num="snv_42" edition=":x86" />
        <vers num="snv_42" edition=":sparc" />
        <vers num="snv_43" edition="" />
        <vers num="snv_43" edition=":sparc" />
        <vers num="snv_43" edition=":x86" />
        <vers num="snv_44" edition="" />
        <vers num="snv_44" edition=":x86" />
        <vers num="snv_44" edition=":sparc" />
        <vers num="snv_45" edition="" />
        <vers num="snv_45" edition=":x86" />
        <vers num="snv_45" edition=":sparc" />
        <vers num="snv_46" edition="" />
        <vers num="snv_46" edition=":x86" />
        <vers num="snv_46" edition=":sparc" />
        <vers num="snv_47" edition="" />
        <vers num="snv_47" edition=":x86" />
        <vers num="snv_47" edition=":sparc" />
        <vers num="snv_48" edition="" />
        <vers num="snv_48" edition=":sparc" />
        <vers num="snv_48" edition=":x86" />
        <vers num="snv_49" edition="" />
        <vers num="snv_49" edition=":sparc" />
        <vers num="snv_49" edition=":x86" />
        <vers num="snv_50" edition="" />
        <vers num="snv_50" edition=":sparc" />
        <vers num="snv_50" edition=":x86" />
        <vers num="snv_51" edition="" />
        <vers num="snv_51" edition=":sparc" />
        <vers num="snv_51" edition=":x86" />
        <vers num="snv_52" edition="" />
        <vers num="snv_52" edition=":sparc" />
        <vers num="snv_52" edition=":x86" />
        <vers num="snv_53" edition="" />
        <vers num="snv_53" edition=":sparc" />
        <vers num="snv_53" edition=":x86" />
        <vers num="snv_54" edition="" />
        <vers num="snv_54" edition=":x86" />
        <vers num="snv_54" edition=":sparc" />
        <vers num="snv_55" edition="" />
        <vers num="snv_55" edition=":sparc" />
        <vers num="snv_55" edition=":x86" />
        <vers num="snv_56" edition="" />
        <vers num="snv_56" edition=":x86" />
        <vers num="snv_56" edition=":sparc" />
        <vers num="snv_57" edition="" />
        <vers num="snv_57" edition=":x86" />
        <vers num="snv_57" edition=":sparc" />
        <vers num="snv_58" edition="" />
        <vers num="snv_58" edition=":sparc" />
        <vers num="snv_58" edition=":x86" />
        <vers num="snv_59" edition="" />
        <vers num="snv_59" edition=":sparc" />
        <vers num="snv_59" edition=":x86" />
        <vers num="snv_60" edition="" />
        <vers num="snv_60" edition=":x86" />
        <vers num="snv_60" edition=":sparc" />
        <vers num="snv_61" edition="" />
        <vers num="snv_61" edition=":sparc" />
        <vers num="snv_61" edition=":x86" />
        <vers num="snv_62" edition="" />
        <vers num="snv_62" edition=":x86" />
        <vers num="snv_62" edition=":sparc" />
        <vers num="snv_63" edition="" />
        <vers num="snv_63" edition=":sparc" />
        <vers num="snv_63" edition=":x86" />
        <vers num="snv_64" edition="" />
        <vers num="snv_64" edition=":x86" />
        <vers num="snv_64" edition=":sparc" />
        <vers num="snv_65" edition="" />
        <vers num="snv_65" edition=":x86" />
        <vers num="snv_65" edition=":sparc" />
        <vers num="snv_66" edition="" />
        <vers num="snv_66" edition=":x86" />
        <vers num="snv_66" edition=":sparc" />
        <vers num="snv_67" edition="" />
        <vers num="snv_67" edition=":sparc" />
        <vers num="snv_67" edition=":x86" />
        <vers num="snv_68" edition="" />
        <vers num="snv_68" edition=":x86" />
        <vers num="snv_68" edition=":sparc" />
        <vers num="snv_69" edition="" />
        <vers num="snv_69" edition=":sparc" />
        <vers num="snv_69" edition=":x86" />
        <vers num="snv_70" edition="" />
        <vers num="snv_70" edition=":sparc" />
        <vers num="snv_70" edition=":x86" />
        <vers num="snv_71" edition="" />
        <vers num="snv_71" edition=":x86" />
        <vers num="snv_71" edition=":sparc" />
        <vers num="snv_72" edition="" />
        <vers num="snv_72" edition=":x86" />
        <vers num="snv_72" edition=":sparc" />
        <vers num="snv_73" edition="" />
        <vers num="snv_73" edition=":x86" />
        <vers num="snv_73" edition=":sparc" />
        <vers num="snv_74" edition="" />
        <vers num="snv_74" edition=":sparc" />
        <vers num="snv_74" edition=":x86" />
        <vers num="snv_75" edition="" />
        <vers num="snv_75" edition=":sparc" />
        <vers num="snv_75" edition=":x86" />
        <vers num="snv_76" edition="" />
        <vers num="snv_76" edition=":x86" />
        <vers num="snv_76" edition=":sparc" />
        <vers num="snv_77" edition="" />
        <vers num="snv_77" edition=":sparc" />
        <vers num="snv_77" edition=":x86" />
        <vers num="snv_78" edition="" />
        <vers num="snv_78" edition=":sparc" />
        <vers num="snv_78" edition=":x86" />
        <vers num="snv_79" edition="" />
        <vers num="snv_79" edition=":x86" />
        <vers num="snv_79" edition=":sparc" />
        <vers num="snv_80" edition="" />
        <vers num="snv_80" edition=":x86" />
        <vers num="snv_80" edition=":sparc" />
        <vers num="snv_81" edition="" />
        <vers num="snv_81" edition=":x86" />
        <vers num="snv_81" edition=":sparc" />
        <vers num="snv_82" edition="" />
        <vers num="snv_82" edition=":x86" />
        <vers num="snv_82" edition=":sparc" />
        <vers num="snv_83" edition="" />
        <vers num="snv_83" edition=":x86" />
        <vers num="snv_83" edition=":sparc" />
        <vers num="snv_84" edition="" />
        <vers num="snv_84" edition=":x86" />
        <vers num="snv_84" edition=":sparc" />
        <vers num="snv_85" edition="" />
        <vers num="snv_85" edition=":x86" />
        <vers num="snv_85" edition=":sparc" />
        <vers num="snv_86" edition="" />
        <vers num="snv_86" edition=":sparc" />
        <vers num="snv_86" edition=":x86" />
        <vers num="snv_87" edition="" />
        <vers num="snv_87" edition=":sparc" />
        <vers num="snv_87" edition=":x86" />
        <vers num="snv_88" edition="" />
        <vers num="snv_88" edition=":x86" />
        <vers num="snv_88" edition=":sparc" />
        <vers num="snv_89" edition="" />
        <vers num="snv_89" edition=":x86" />
        <vers num="snv_89" edition=":sparc" />
        <vers num="snv_90" edition="" />
        <vers num="snv_90" edition=":sparc" />
        <vers num="snv_90" edition=":x86" />
        <vers num="snv_91" edition="" />
        <vers num="snv_91" edition=":sparc" />
        <vers num="snv_91" edition=":x86" />
        <vers num="snv_92" edition="" />
        <vers num="snv_92" edition=":sparc" />
        <vers num="snv_92" edition=":x86" />
        <vers num="snv_93" edition="" />
        <vers num="snv_93" edition=":sparc" />
        <vers num="snv_93" edition=":x86" />
        <vers num="snv_94" edition="" />
        <vers num="snv_94" edition=":x86" />
        <vers num="snv_94" edition=":sparc" />
        <vers num="snv_95" edition="" />
        <vers num="snv_95" edition=":x86" />
        <vers num="snv_95" edition=":sparc" />
        <vers num="snv_96" edition="" />
        <vers num="snv_96" edition=":sparc" />
        <vers num="snv_96" edition=":x86" />
        <vers num="snv_97" edition="" />
        <vers num="snv_97" edition=":x86" />
        <vers num="snv_97" edition=":sparc" />
        <vers num="snv_98" edition="" />
        <vers num="snv_98" edition=":sparc" />
        <vers num="snv_98" edition=":x86" />
        <vers num="snv_99" edition="" />
        <vers num="snv_99" edition=":sparc" />
        <vers num="snv_99" edition=":x86" />
      </prod>
      <prod vendor="sun" name="solaris">
        <vers num="10" edition="" />
        <vers num="10" edition=":sparc" />
        <vers num="10" edition=":x86" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0914" published="2009-03-16" name="CVE-2009-0914" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Opera before 9.64 allows remote attackers to execute arbitrary code via a crafted JPEG image that triggers memory corruption.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="https://bugs.gentoo.org/show_bug.cgi?id=261032" source="CONFIRM">https://bugs.gentoo.org/show_bug.cgi?id=261032</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0586" source="VUPEN" adv="1">ADV-2009-0586</ref>
      <ref url="http://www.securityfocus.com/bid/33961" source="BID">33961</ref>
      <ref url="http://www.opera.com/support/kb/view/926/" source="CONFIRM" adv="1">http://www.opera.com/support/kb/view/926/</ref>
      <ref url="http://www.opera.com/docs/changelogs/windows/964/" source="CONFIRM" adv="1">http://www.opera.com/docs/changelogs/windows/964/</ref>
      <ref url="http://www.opera.com/docs/changelogs/solaris/964/" source="CONFIRM">http://www.opera.com/docs/changelogs/solaris/964/</ref>
      <ref url="http://www.opera.com/docs/changelogs/mac/964/" source="CONFIRM">http://www.opera.com/docs/changelogs/mac/964/</ref>
      <ref url="http://www.opera.com/docs/changelogs/linux/964/" source="CONFIRM" adv="1">http://www.opera.com/docs/changelogs/linux/964/</ref>
      <ref url="http://www.opera.com/docs/changelogs/freebsd/964/" source="CONFIRM" adv="1">http://www.opera.com/docs/changelogs/freebsd/964/</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2009/03/07/1" source="MLIST" adv="1">[oss-security] 20090307 CVE Request: Opera &lt;9.64: Execution of arbitrary code</ref>
      <ref url="http://securitytracker.com/id?1021782" source="SECTRACK">1021782</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200903-30.xml" source="GENTOO">GLSA-200903-30</ref>
      <ref url="http://secunia.com/advisories/34418" source="SECUNIA">34418</ref>
      <ref url="http://secunia.com/advisories/34294" source="SECUNIA">34294</ref>
      <ref url="http://secunia.com/advisories/34135" source="SECUNIA" adv="1">34135</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6230" source="OVAL">oval:org.mitre.oval:def:6230</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5955" source="OVAL">oval:org.mitre.oval:def:5955</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-03/msg00004.html" source="SUSE">SUSE-SR:2009:007</ref>
    </refs>
    <vuln_soft>
      <prod vendor="opera" name="opera">
        <vers num="6.01" />
        <vers num="6.02" />
        <vers num="6.03" />
        <vers num="6.04" />
        <vers num="6.05" />
        <vers num="6.06" />
        <vers num="6.1" />
        <vers num="7.0" edition="beta_1" />
        <vers num="7.0" edition="beta_1v2" />
        <vers num="7.0" edition="beta_2" />
        <vers num="7.01" />
        <vers num="7.02" />
        <vers num="7.03" />
        <vers num="7.10" />
        <vers num="7.11" />
        <vers num="7.20" edition="beta7" />
        <vers num="7.21" />
        <vers num="7.22" />
        <vers num="7.23" />
        <vers num="7.30" />
        <vers num="7.50" edition="beta_1" />
        <vers num="7.51" />
        <vers num="7.52" />
        <vers num="7.53" />
        <vers num="7.54" edition="update_1" />
        <vers num="7.54" edition="update_2" />
        <vers num="7.55" />
        <vers num="8.0" edition="beta_1" />
        <vers num="8.0" edition="beta_2" />
        <vers num="8.0" edition="beta_3" />
        <vers num="8.01" />
        <vers num="8.02" />
        <vers num="8.51" />
        <vers num="8.52" />
        <vers num="8.53" />
        <vers num="8.54" />
        <vers num="9.0" edition="beta_1" />
        <vers num="9.0" edition="beta_2" />
        <vers num="9.01" />
        <vers num="9.02" />
        <vers num="9.10" />
        <vers num="9.1tp" />
        <vers num="9.20" edition="beta_1" />
        <vers num="9.21" />
        <vers num="9.22" />
        <vers num="9.23" />
        <vers num="9.24" />
        <vers num="9.25" />
        <vers num="9.26" />
        <vers num="9.27" />
        <vers num="9.50" edition="beta_1" />
        <vers num="9.50" edition="beta_2" />
        <vers num="9.51" />
        <vers num="9.52" />
        <vers num="9.60" edition="beta_1" />
        <vers num="9.61" />
        <vers num="9.62" />
        <vers prev="1" num="9.63" />
      </prod>
      <prod vendor="opera_software" name="opera_web_browser">
        <vers num="3.0" />
        <vers num="3.1" />
        <vers num="3.2.1" />
        <vers num="3.5" />
        <vers num="3.5.1" />
        <vers num="3.6" />
        <vers num="3.6.1" />
        <vers num="3.6.2b" />
        <vers num="3.62" />
        <vers num="4.0" />
        <vers num="4.01" />
        <vers num="4.02" />
        <vers num="4.0b2" />
        <vers num="4.0b3" />
        <vers num="4.0b4" />
        <vers num="4.0b5" />
        <vers num="4.0b6" />
        <vers num="4.0tp" />
        <vers num="5.0" />
        <vers num="5.01" />
        <vers num="5.02" />
        <vers num="5.10" />
        <vers num="5.11" />
        <vers num="5.12" />
        <vers num="6.0b1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0915" published="2009-03-16" name="CVE-2009-0915" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Opera before 9.64 allows remote attackers to conduct cross-domain scripting attacks via unspecified vectors related to plug-ins.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2009/0586" source="VUPEN" adv="1">ADV-2009-0586</ref>
      <ref url="http://www.securityfocus.com/bid/33961" source="BID">33961</ref>
      <ref url="http://www.opera.com/docs/changelogs/windows/964/" source="CONFIRM" adv="1">http://www.opera.com/docs/changelogs/windows/964/</ref>
      <ref url="http://www.opera.com/docs/changelogs/solaris/964/" source="CONFIRM" adv="1">http://www.opera.com/docs/changelogs/solaris/964/</ref>
      <ref url="http://www.opera.com/docs/changelogs/mac/964/" source="CONFIRM" adv="1">http://www.opera.com/docs/changelogs/mac/964/</ref>
      <ref url="http://www.opera.com/docs/changelogs/linux/964/" source="CONFIRM" adv="1">http://www.opera.com/docs/changelogs/linux/964/</ref>
      <ref url="http://www.opera.com/docs/changelogs/freebsd/964/" source="CONFIRM" adv="1">http://www.opera.com/docs/changelogs/freebsd/964/</ref>
      <ref url="http://secunia.com/advisories/34418" source="SECUNIA">34418</ref>
      <ref url="http://secunia.com/advisories/34135" source="SECUNIA" adv="1">34135</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6220" source="OVAL">oval:org.mitre.oval:def:6220</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-03/msg00004.html" source="SUSE">SUSE-SR:2009:007</ref>
    </refs>
    <vuln_soft>
      <prod vendor="opera" name="opera">
        <vers num="6.01" />
        <vers num="6.02" />
        <vers num="6.03" />
        <vers num="6.04" />
        <vers num="6.05" />
        <vers num="6.06" />
        <vers num="6.1" />
        <vers num="7.0" edition="beta_1" />
        <vers num="7.0" edition="beta_1v2" />
        <vers num="7.0" edition="beta_2" />
        <vers num="7.01" />
        <vers num="7.02" />
        <vers num="7.03" />
        <vers num="7.10" />
        <vers num="7.11" />
        <vers num="7.20" edition="beta7" />
        <vers num="7.21" />
        <vers num="7.22" />
        <vers num="7.23" />
        <vers num="7.30" />
        <vers num="7.50" edition="beta_1" />
        <vers num="7.51" />
        <vers num="7.52" />
        <vers num="7.53" />
        <vers num="7.54" edition="update_1" />
        <vers num="7.54" edition="update_2" />
        <vers num="7.55" />
        <vers num="8.0" edition="beta_1" />
        <vers num="8.0" edition="beta_2" />
        <vers num="8.0" edition="beta_3" />
        <vers num="8.01" />
        <vers num="8.02" />
        <vers num="8.51" />
        <vers num="8.52" />
        <vers num="8.53" />
        <vers num="8.54" />
        <vers num="9.0" edition="beta_1" />
        <vers num="9.0" edition="beta_2" />
        <vers num="9.01" />
        <vers num="9.02" />
        <vers num="9.10" />
        <vers num="9.1tp" />
        <vers num="9.20" edition="beta_1" />
        <vers num="9.21" />
        <vers num="9.22" />
        <vers num="9.23" />
        <vers num="9.24" />
        <vers num="9.25" />
        <vers num="9.26" />
        <vers num="9.27" />
        <vers num="9.50" edition="beta_1" />
        <vers num="9.50" edition="beta_2" />
        <vers num="9.51" />
        <vers num="9.52" />
        <vers num="9.60" edition="beta_1" />
        <vers num="9.61" />
        <vers num="9.62" />
        <vers prev="1" num="9.63" />
      </prod>
      <prod vendor="opera_software" name="opera_web_browser">
        <vers num="3.0" />
        <vers num="3.1" />
        <vers num="3.2.1" />
        <vers num="3.5" />
        <vers num="3.5.1" />
        <vers num="3.6" />
        <vers num="3.6.1" />
        <vers num="3.6.2b" />
        <vers num="3.62" />
        <vers num="4.0" />
        <vers num="4.01" />
        <vers num="4.02" />
        <vers num="4.0b2" />
        <vers num="4.0b3" />
        <vers num="4.0b4" />
        <vers num="4.0b5" />
        <vers num="4.0b6" />
        <vers num="4.0tp" />
        <vers num="5.0" />
        <vers num="5.01" />
        <vers num="5.02" />
        <vers num="5.10" />
        <vers num="5.11" />
        <vers num="5.12" />
        <vers num="6.0b1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0916" published="2009-03-16" name="CVE-2009-0916" modified="2009-04-01" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in Opera before 9.64 has unknown impact and attack vectors, related to a "moderately severe issue."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2009/0586" source="VUPEN" adv="1">ADV-2009-0586</ref>
      <ref url="http://www.securityfocus.com/bid/33961" source="BID">33961</ref>
      <ref url="http://www.opera.com/docs/changelogs/windows/964/" source="CONFIRM" adv="1">http://www.opera.com/docs/changelogs/windows/964/</ref>
      <ref url="http://www.opera.com/docs/changelogs/solaris/964/" source="CONFIRM" adv="1">http://www.opera.com/docs/changelogs/solaris/964/</ref>
      <ref url="http://www.opera.com/docs/changelogs/mac/964/" source="CONFIRM" adv="1">http://www.opera.com/docs/changelogs/mac/964/</ref>
      <ref url="http://www.opera.com/docs/changelogs/linux/964/" source="CONFIRM" adv="1">http://www.opera.com/docs/changelogs/linux/964/</ref>
      <ref url="http://www.opera.com/docs/changelogs/freebsd/964/" source="CONFIRM" adv="1">http://www.opera.com/docs/changelogs/freebsd/964/</ref>
      <ref url="http://secunia.com/advisories/34418" source="SECUNIA">34418</ref>
      <ref url="http://secunia.com/advisories/34135" source="SECUNIA" adv="1">34135</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-03/msg00004.html" source="SUSE">SUSE-SR:2009:007</ref>
    </refs>
    <vuln_soft>
      <prod vendor="opera" name="opera">
        <vers num="6.01" />
        <vers num="6.02" />
        <vers num="6.03" />
        <vers num="6.04" />
        <vers num="6.05" />
        <vers num="6.06" />
        <vers num="6.1" />
        <vers num="7.0" edition="beta_1" />
        <vers num="7.0" edition="beta_1v2" />
        <vers num="7.0" edition="beta_2" />
        <vers num="7.01" />
        <vers num="7.02" />
        <vers num="7.03" />
        <vers num="7.10" />
        <vers num="7.11" />
        <vers num="7.20" edition="beta7" />
        <vers num="7.21" />
        <vers num="7.22" />
        <vers num="7.23" />
        <vers num="7.30" />
        <vers num="7.50" edition="beta_1" />
        <vers num="7.51" />
        <vers num="7.52" />
        <vers num="7.53" />
        <vers num="7.54" edition="update_1" />
        <vers num="7.54" edition="update_2" />
        <vers num="7.55" />
        <vers num="8.0" edition="beta_1" />
        <vers num="8.0" edition="beta_2" />
        <vers num="8.0" edition="beta_3" />
        <vers num="8.01" />
        <vers num="8.02" />
        <vers num="8.51" />
        <vers num="8.52" />
        <vers num="8.53" />
        <vers num="8.54" />
        <vers num="9.0" edition="beta_1" />
        <vers num="9.0" edition="beta_2" />
        <vers num="9.01" />
        <vers num="9.02" />
        <vers num="9.10" />
        <vers num="9.1tp" />
        <vers num="9.20" edition="beta_1" />
        <vers num="9.21" />
        <vers num="9.22" />
        <vers num="9.23" />
        <vers num="9.24" />
        <vers num="9.25" />
        <vers num="9.26" />
        <vers num="9.27" />
        <vers num="9.50" edition="beta_1" />
        <vers num="9.50" edition="beta_2" />
        <vers num="9.51" />
        <vers num="9.52" />
        <vers num="9.60" edition="beta_1" />
        <vers num="9.61" />
        <vers num="9.62" />
        <vers prev="1" num="9.63" />
      </prod>
      <prod vendor="opera_software" name="opera_web_browser">
        <vers num="3.0" />
        <vers num="3.1" />
        <vers num="3.2.1" />
        <vers num="3.5" />
        <vers num="3.5.1" />
        <vers num="3.6" />
        <vers num="3.6.1" />
        <vers num="3.6.2b" />
        <vers num="3.62" />
        <vers num="4.0" />
        <vers num="4.01" />
        <vers num="4.02" />
        <vers num="4.0b2" />
        <vers num="4.0b3" />
        <vers num="4.0b4" />
        <vers num="4.0b5" />
        <vers num="4.0b6" />
        <vers num="4.0tp" />
        <vers num="5.0" />
        <vers num="5.01" />
        <vers num="5.02" />
        <vers num="5.10" />
        <vers num="5.11" />
        <vers num="5.12" />
        <vers num="6.0b1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0917" published="2009-03-16" name="CVE-2009-0917" modified="2009-03-25" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in DFLabs PTK 1.0.0 through 1.0.4 allows remote attackers to inject arbitrary web script or HTML by providing a forensic image containing HTML documents, which are rendered in web browsers during inspection by PTK.  NOTE: the vendor states that the product is intended for use in a laboratory with "no contact from / to internet."</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/RGII-7Q4GBJ" source="MISC">http://www.kb.cert.org/vuls/id/RGII-7Q4GBJ</ref>
      <ref url="http://www.kb.cert.org/vuls/id/845747" source="CERT-VN">VU#845747</ref>
      <ref url="http://ptk.dflabs.com/security.html" source="MISC" patch="1" adv="1">http://ptk.dflabs.com/security.html</ref>
      <ref url="http://ptk.dflabs.com/faq.html" source="MISC" patch="1" adv="1">http://ptk.dflabs.com/faq.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/49236" source="XF">ptk-unspecified-xss(49236)</ref>
      <ref url="http://www.securityfocus.com/bid/34111" source="BID">34111</ref>
      <ref url="http://secunia.com/advisories/34257" source="SECUNIA">34257</ref>
    </refs>
    <vuln_soft>
      <prod vendor="dflabs" name="ptk">
        <vers num="1.0.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0918" published="2009-03-16" name="CVE-2009-0918" modified="2009-03-25" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple unspecified vulnerabilities in DFLabs PTK 1.0.0 through 1.0.4 allow remote attackers to execute arbitrary commands in processes launched by PTK's Apache HTTP Server via (1) "external tools" or (2) a crafted forensic image.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/RGII-7Q4GBJ" source="CONFIRM">http://www.kb.cert.org/vuls/id/RGII-7Q4GBJ</ref>
      <ref url="http://www.kb.cert.org/vuls/id/845747" source="CERT-VN">VU#845747</ref>
      <ref url="http://ptk.dflabs.com/security.html" source="CONFIRM" patch="1" adv="1">http://ptk.dflabs.com/security.html</ref>
      <ref url="http://ptk.dflabs.com/faq.html" source="CONFIRM" patch="1" adv="1">http://ptk.dflabs.com/faq.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/49235" source="XF">ptk-unspecified-command-execution(49235)</ref>
      <ref url="http://www.securityfocus.com/bid/34111" source="BID">34111</ref>
    </refs>
    <vuln_soft>
      <prod vendor="dflabs" name="ptk">
        <vers num="1.0.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0919" published="2009-03-16" name="CVE-2009-0919" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">XAMPP installs multiple packages with insecure default passwords, which makes it easier for remote attackers to obtain access via (1) the "lampp" default password for the "nobody" account within the included ProFTPD installation, (2) a blank default password for the "root" account within the included MySQL installation, (3) a blank default password for the "pma" account within the phpMyAdmin installation, and possibly other unspecified passwords.  NOTE: this was originally reported as a problem in DFLabs PTK, but this issue affects any product that is installed within the XAMPP environment, and should not be viewed as a vulnerability within that product. NOTE: DFLabs states that PTK is intended for use in a laboratory with "no contact from / to internet."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://ptk.dflabs.com/security.html" source="MISC" patch="1" adv="1">http://ptk.dflabs.com/security.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/49306" source="XF">ptk-default-password(49306)</ref>
      <ref url="http://www.ibm.com/developerworks/linux/library/l-xampp/" source="MISC">http://www.ibm.com/developerworks/linux/library/l-xampp/</ref>
      <ref url="http://www.debianhelp.co.uk/xampp.htm" source="MISC">http://www.debianhelp.co.uk/xampp.htm</ref>
      <ref url="http://www.apachefriends.org/en/faq-xampp-linux.html" source="CONFIRM">http://www.apachefriends.org/en/faq-xampp-linux.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apachefriends" name="xampp">
        <vers num="0.1" edition="alpha" />
        <vers num="0.1" edition="alpha:solaris" />
        <vers num="0.1" edition="beta" />
        <vers num="0.1" edition="beta:mac_os_x" />
        <vers num="0.2" edition="alpha" />
        <vers num="0.2" edition="alpha:solaris" />
        <vers num="0.2" edition="beta" />
        <vers num="0.2" edition="beta:mac_os_x" />
        <vers num="0.3" edition="-" />
        <vers num="0.3" edition="-:mac_os_x" />
        <vers num="0.3" edition="alpha" />
        <vers num="0.3" edition="alpha:solaris" />
        <vers num="0.4" edition="-" />
        <vers num="0.4" edition="-:mac_os_x" />
        <vers num="0.4" edition="alpha" />
        <vers num="0.4" edition="alpha:solaris" />
        <vers num="0.5" edition="-" />
        <vers num="0.5" edition="-:mac_os_x" />
        <vers num="0.5" edition="beta" />
        <vers num="0.5" edition="beta:solaris" />
        <vers num="0.6" edition="-" />
        <vers num="0.6" edition="-:mac_os_x" />
        <vers num="0.6" edition="beta" />
        <vers num="0.6" edition="beta:solaris" />
        <vers num="0.6.1" edition="-" />
        <vers num="0.6.1" edition="-:mac_os_x" />
        <vers num="0.6.2" edition="-" />
        <vers num="0.6.2" edition="-:mac_os_x" />
        <vers num="0.6.3" edition="-" />
        <vers num="0.6.3" edition="-:mac_os_x" />
        <vers num="0.6a" edition="-" />
        <vers num="0.6a" edition="-:mac_os_x" />
        <vers num="0.7" edition="beta" />
        <vers num="0.7" edition="beta:solaris" />
        <vers num="0.7.0" edition="-" />
        <vers num="0.7.0" edition="-:mac_os_x" />
        <vers num="0.7.1" edition="-" />
        <vers num="0.7.1" edition="-:mac_os_x" />
        <vers num="0.7.2" edition="-" />
        <vers num="0.7.2" edition="-:mac_os_x" />
        <vers num="0.7.3" edition="-" />
        <vers num="0.7.3" edition="-:mac_os_x" />
        <vers num="0.7.4" edition="-" />
        <vers num="0.7.4" edition="-:mac_os_x" />
        <vers num="0.8.1" edition="-" />
        <vers num="0.8.1" edition="-:solaris" />
        <vers num="0.8.2" edition="-" />
        <vers num="0.8.2" edition="-:solaris" />
        <vers num="0.9" edition="-" />
        <vers num="0.9" edition="-:solaris" />
        <vers num="0.9" edition="-:windows" />
        <vers num="1.0" edition="-" />
        <vers num="1.0" edition="-:windows" />
        <vers num="1.0.1" edition="-" />
        <vers num="1.0.1" edition="-:mac_os_x" />
        <vers num="1.1" edition="-" />
        <vers num="1.1" edition="-:windows" />
        <vers num="1.2" edition="-" />
        <vers num="1.2" edition="-:windows" />
        <vers num="1.2" edition="-:linux" />
        <vers num="1.3" edition="-" />
        <vers num="1.3" edition="-:linux" />
        <vers num="1.3" edition="-:windows" />
        <vers num="1.4" edition="-" />
        <vers num="1.4" edition="-:linux" />
        <vers num="1.4" edition="-:windows" />
        <vers num="1.4.10" edition="-" />
        <vers num="1.4.10" edition="-:linux" />
        <vers num="1.4.10" edition="-:windows" />
        <vers num="1.4.11" edition="-" />
        <vers num="1.4.11" edition="-:windows" />
        <vers num="1.4.11" edition="-:linux" />
        <vers num="1.4.12" edition="-" />
        <vers num="1.4.12" edition="-:linux" />
        <vers num="1.4.12" edition="-:windows" />
        <vers num="1.4.13" edition="-" />
        <vers num="1.4.13" edition="-:windows" />
        <vers num="1.4.13" edition="-:linux" />
        <vers num="1.4.14" edition="-" />
        <vers num="1.4.14" edition="-:linux" />
        <vers num="1.4.14" edition="-:windows" />
        <vers num="1.4.15" edition="-" />
        <vers num="1.4.15" edition="-:linux" />
        <vers num="1.4.15" edition="-:windows" />
        <vers num="1.4.16" edition="-" />
        <vers num="1.4.16" edition="-:windows" />
        <vers num="1.4.16" edition="-:linux" />
        <vers num="1.4.2" edition="-" />
        <vers num="1.4.2" edition="-:linux" />
        <vers num="1.4.2" edition="-:windows" />
        <vers num="1.4.3" edition="-" />
        <vers num="1.4.3" edition="-:windows" />
        <vers num="1.4.3" edition="-:linux" />
        <vers num="1.4.4" edition="-" />
        <vers num="1.4.4" edition="-:linux" />
        <vers num="1.4.4" edition="-:windows" />
        <vers num="1.4.5" edition="-" />
        <vers num="1.4.5" edition="-:linux" />
        <vers num="1.4.5" edition="-:windows" />
        <vers num="1.4.6" edition="-" />
        <vers num="1.4.6" edition="-:windows" />
        <vers num="1.4.6" edition="-:linux" />
        <vers num="1.4.7" edition="-" />
        <vers num="1.4.7" edition="-:windows" />
        <vers num="1.4.7" edition="-:linux" />
        <vers num="1.4.8" edition="-" />
        <vers num="1.4.8" edition="-:linux" />
        <vers num="1.4.8" edition="-:windows" />
        <vers num="1.4.9" edition="-" />
        <vers num="1.4.9" edition="-:windows" />
        <vers num="1.4.9" edition="-:linux" />
        <vers num="1.5" edition="-" />
        <vers num="1.5" edition="-:linux" />
        <vers num="1.5.0" edition="-" />
        <vers num="1.5.0" edition="-:windows" />
        <vers num="1.5.1" edition="-" />
        <vers num="1.5.1" edition="-:windows" />
        <vers num="1.5.1" edition="-:linux" />
        <vers num="1.5.2" edition="-" />
        <vers num="1.5.2" edition="-:linux" />
        <vers num="1.5.2" edition="-:windows" />
        <vers num="1.5.3" edition="-" />
        <vers num="1.5.3" edition="-:windows" />
        <vers num="1.5.3" edition="-:linux" />
        <vers num="1.5.4" edition="-" />
        <vers num="1.5.4" edition="-:windows" />
        <vers num="1.5.4" edition="-:linux" />
        <vers num="1.5.4a" edition="-" />
        <vers num="1.5.4a" edition="-:windows" />
        <vers num="1.5.4a" edition="-:linux" />
        <vers num="1.5.5" edition="-" />
        <vers num="1.5.5" edition="-:linux" />
        <vers num="1.5.5" edition="-:windows" />
        <vers num="1.5.5a" edition="-" />
        <vers num="1.5.5a" edition="-:linux" />
        <vers num="1.6" edition="-" />
        <vers num="1.6" edition="-:linux" />
        <vers num="1.6.0" edition="-" />
        <vers num="1.6.0" edition="-:windows" />
        <vers num="1.6.0a" edition="-" />
        <vers num="1.6.0a" edition="-:windows" />
        <vers num="1.6.1" edition="-" />
        <vers num="1.6.1" edition="-:windows" />
        <vers num="1.6.1" edition="-:linux" />
        <vers num="1.6.2" edition="-" />
        <vers num="1.6.2" edition="-:linux" />
        <vers num="1.6.2" edition="-:windows" />
        <vers num="1.6.3" edition="-" />
        <vers num="1.6.3" edition="-:linux" />
        <vers num="1.6.3" edition="-:windows" />
        <vers num="1.6.3a" edition="-" />
        <vers num="1.6.3a" edition="-:windows" />
        <vers num="1.6.3a" edition="-:linux" />
        <vers num="1.6.3b" edition="-" />
        <vers num="1.6.3b" edition="-:linux" />
        <vers num="1.6.4" edition="-" />
        <vers num="1.6.4" edition="-:linux" />
        <vers num="1.6.4" edition="-:windows" />
        <vers num="1.6.5" edition="-" />
        <vers num="1.6.5" edition="-:linux" />
        <vers num="1.6.5" edition="-:windows" />
        <vers num="1.6.5a" edition="-" />
        <vers num="1.6.5a" edition="-:linux" />
        <vers num="1.6.6" edition="-" />
        <vers num="1.6.6" edition="-:linux" />
        <vers num="1.6.6" edition="-:windows" />
        <vers num="1.6.6a" edition="-" />
        <vers num="1.6.6a" edition="-:windows" />
        <vers num="1.6.7" edition="-" />
        <vers num="1.6.7" edition="-:linux" />
        <vers num="1.6.7" edition="-:windows" />
        <vers num="1.6.8" edition="-" />
        <vers num="1.6.8" edition="-:windows" />
        <vers num="1.6.8a" edition="-" />
        <vers num="1.6.8a" edition="-:linux" />
        <vers num="1.7" edition="-" />
        <vers num="1.7" edition="-:windows" />
        <vers num="1.7" edition="-:linux" />
        <vers num="1.7.1" edition="-" />
        <vers num="1.7.1" edition="-:windows" />
        <vers num="1.7.1" edition="-:linux" />
        <vers num="development" edition="-" />
        <vers num="development" edition="-:windows" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0920" published="2009-03-24" name="CVE-2009-0920" modified="2011-09-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Stack-based buffer overflow in OvCgi/Toolbar.exe in HP OpenView Network Node Manager (OV NNM) 7.01, 7.51, and 7.53 allows remote attackers to execute arbitrary code via a long OvOSLocale cookie, a variant of CVE-2008-0067.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/49364" source="XF">hp-ovnnm-ovoslocale-bo(49364)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0819" source="VUPEN" adv="1">ADV-2009-0819</ref>
      <ref url="http://www.securitytracker.com/id?1021883" source="SECTRACK">1021883</ref>
      <ref url="http://www.securityfocus.com/bid/34294" source="BID">34294</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/502054/100/0/threaded" source="BUGTRAQ" adv="1">20090323 CORE-2009-0122: HP OpenView Buffer Overflows</ref>
      <ref url="http://www.coresecurity.com/content/openview-buffer-overflows" source="MISC">http://www.coresecurity.com/content/openview-buffer-overflows</ref>
      <ref url="http://securityreason.com/securityalert/8308" source="SREASON">8308</ref>
      <ref url="http://secunia.com/advisories/34444" source="SECUNIA" adv="1">34444</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=123791084113871&amp;w=2" source="HP">SSRT090008</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=123791084113871&amp;w=2" source="HP">SSRT090008</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="network_node_manager">
        <vers num="7.0.1" />
        <vers num="7.5.1" />
        <vers num="7.5.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0921" published="2009-03-24" name="CVE-2009-0921" modified="2009-10-06" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Multiple heap-based buffer overflows in OvCgi/Toolbar.exe in HP OpenView Network Node Manager (OV NNM) 7.01, 7.51, and 7.53 allow remote attackers to execute arbitrary code via (1) a long OvAcceptLang cookie, which triggers the error in ov.dll and ovwww.dll, or (2) a long Accept-Language HTTP header, which triggers the error in ovwww.dll or libovwww.so.4.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/49363" source="XF">hp-ovnnm-ovacceptlang-acceptlanguage-bo(49363)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0819" source="VUPEN" adv="1">ADV-2009-0819</ref>
      <ref url="http://www.securitytracker.com/id?1021883" source="SECTRACK">1021883</ref>
      <ref url="http://www.securityfocus.com/bid/34135" source="BID">34135</ref>
      <ref url="http://www.securityfocus.com/bid/34134" source="BID">34134</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/502054/100/0/threaded" source="BUGTRAQ">20090323 CORE-2009-0122: HP OpenView Buffer Overflows</ref>
      <ref url="http://www.coresecurity.com/content/openview-buffer-overflows" source="MISC">http://www.coresecurity.com/content/openview-buffer-overflows</ref>
      <ref url="http://secunia.com/advisories/34444" source="SECUNIA">34444</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=123791084113871&amp;w=2" source="HP">SSRT090008</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=123791084113871&amp;w=2" source="HP">SSRT090008</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="network_node_manager">
        <vers num="7.0.1" />
        <vers num="7.5.1" />
        <vers num="7.5.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0922" published="2009-03-17" name="CVE-2009-0922" modified="2010-11-30" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:N/I:N/A:P)" CVSS_score="4.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.0" CVSS_base_score="4.0">
    <desc>
      <descript source="cve">PostgreSQL before 8.3.7, 8.2.13, 8.1.17, 8.0.21, and 7.4.25 allows remote authenticated users to cause a denial of service (stack consumption and crash) by triggering a failure in the conversion of a localized error message to a client-specified encoding, as demonstrated using mismatched encoding conversion requests.</descript>
      <descript source="nvd">Per: https://bugzilla.redhat.com/show_bug.cgi?id=488156

"PostgreSQL allows remote authenticated users to cause a momentary denial
of service (crash due to stack consumption) when there is a failure to
convert a localized error message to the client-specified encoding.
In releases 8.3.6, 8.2.12, 8.1.16. 8.0.20, and 7.4.24, a trivial
misconfiguration is sufficient to provoke a crash.  In older releases
it is necessary to select a locale and client encoding for which
specific messages fail to translate, and so a given installation may or
may not be vulnerable depending on the administrator-determined locale
setting.

Releases 8.3.7, 8.2.13, 8.1.17, 8.0.21, and 7.4.25 are secure against
all known variants of this issue."</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2009/1316" source="VUPEN" patch="1" adv="1">ADV-2009-1316</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0767" source="VUPEN" patch="1" adv="1">ADV-2009-0767</ref>
      <ref url="http://www.securityfocus.com/bid/34090" source="BID" patch="1">34090</ref>
      <ref url="http://www.postgresql.org/about/news.1065" source="CONFIRM" patch="1" adv="1">http://www.postgresql.org/about/news.1065</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-March/msg00843.html" source="FEDORA">FEDORA-2009-2959</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-March/msg00810.html" source="FEDORA">FEDORA-2009-2927</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=488156" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=488156</ref>
      <ref url="http://www.securitytracker.com/id?1021860" source="SECTRACK">1021860</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/503598/100/0/threaded" source="BUGTRAQ">20090519 rPSA-2009-0086-1 postgresql postgresql-contrib postgresql-server</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-1067.html" source="REDHAT">RHSA-2009:1067</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2009/03/11/4" source="MLIST">[oss-security] 20090311 CVE request -- postgresql</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:079" source="MANDRIVA">MDVSA-2009:079</ref>
      <ref url="http://wiki.rpath.com/Advisories:rPSA-2009-0086" source="CONFIRM">http://wiki.rpath.com/Advisories:rPSA-2009-0086</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-77-1020455.1-1" source="SUNALERT">1020455</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-258808-1" source="SUNALERT">258808</ref>
      <ref url="http://secunia.com/advisories/35100" source="SECUNIA" adv="1">35100</ref>
      <ref url="http://secunia.com/advisories/34453" source="SECUNIA" adv="1">34453</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6252" source="OVAL">oval:org.mitre.oval:def:6252</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10874" source="OVAL">oval:org.mitre.oval:def:10874</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-04/msg00010.html" source="SUSE">SUSE-SR:2009:009</ref>
      <ref url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=517405" source="CONFIRM">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=517405</ref>
      <ref url="http://archives.postgresql.org/pgsql-bugs/2009-02/msg00172.php" source="MLIST">[pgsql-bugs] 20090227 BUG #4680: Server crashed if using wrong (mismatch) conversion functions</ref>
      <ref url="http://archives.postgresql.org//pgsql-bugs/2009-02/msg00176.php" source="MLIST">[pgsql-bugs] 20090227 Re: BUG #4680: Server crashed if using wrong (mismatch) conversion functions</ref>
    </refs>
    <vuln_soft>
      <prod vendor="postgresql" name="postgresql">
        <vers num="7.4.24" />
        <vers num="8.0.20" />
        <vers num="8.1.16" />
        <vers num="8.2.12" />
        <vers num="8.3.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0923" published="2009-03-17" name="CVE-2009-0923" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Unspecified vulnerability in Kerberos Incremental Propagation in Solaris 10 and OpenSolaris snv_01 through snv_110 allows remote attackers to cause a denial of service (loss of incremental propagation requests to slave KDC servers) via unknown vectors related to the master Key Distribution Center (KDC) server.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/49276" source="XF">solaris-kerberos-dos(49276)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0875" source="VUPEN">ADV-2009-0875</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0741" source="VUPEN" adv="1">ADV-2009-0741</ref>
      <ref url="http://www.securitytracker.com/id?1021851" source="SECTRACK">1021851</ref>
      <ref url="http://www.securityfocus.com/bid/34139" source="BID">34139</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2009-102.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2009-102.htm</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-249926-1" source="SUNALERT" adv="1">249926</ref>
      <ref url="http://secunia.com/advisories/34487" source="SECUNIA">34487</ref>
      <ref url="http://secunia.com/advisories/34298" source="SECUNIA" adv="1">34298</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6174" source="OVAL">oval:org.mitre.oval:def:6174</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="opensolaris">
        <vers num="snv_01" edition="" />
        <vers num="snv_01" edition=":sparc" />
        <vers num="snv_01" edition=":x86" />
        <vers num="snv_02" edition="" />
        <vers num="snv_02" edition=":sparc" />
        <vers num="snv_02" edition=":x86" />
        <vers num="snv_03" edition="" />
        <vers num="snv_03" edition=":x86" />
        <vers num="snv_03" edition=":sparc" />
        <vers num="snv_04" edition="" />
        <vers num="snv_04" edition=":x86" />
        <vers num="snv_04" edition=":sparc" />
        <vers num="snv_05" edition="" />
        <vers num="snv_05" edition=":sparc" />
        <vers num="snv_05" edition=":x86" />
        <vers num="snv_06" edition="" />
        <vers num="snv_06" edition=":sparc" />
        <vers num="snv_06" edition=":x86" />
        <vers num="snv_07" edition="" />
        <vers num="snv_07" edition=":sparc" />
        <vers num="snv_07" edition=":x86" />
        <vers num="snv_08" edition="" />
        <vers num="snv_08" edition=":x86" />
        <vers num="snv_08" edition=":sparc" />
        <vers num="snv_09" edition="" />
        <vers num="snv_09" edition=":x86" />
        <vers num="snv_09" edition=":sparc" />
        <vers num="snv_10" edition="" />
        <vers num="snv_10" edition=":x86" />
        <vers num="snv_10" edition=":sparc" />
        <vers num="snv_100" edition="" />
        <vers num="snv_100" edition=":sparc" />
        <vers num="snv_100" edition=":x86" />
        <vers num="snv_101" edition="" />
        <vers num="snv_101" edition=":x86" />
        <vers num="snv_101" edition=":sparc" />
        <vers num="snv_102" edition="" />
        <vers num="snv_102" edition=":sparc" />
        <vers num="snv_102" edition=":x86" />
        <vers num="snv_103" edition="" />
        <vers num="snv_103" edition=":x86" />
        <vers num="snv_103" edition=":sparc" />
        <vers num="snv_104" edition="" />
        <vers num="snv_104" edition=":x86" />
        <vers num="snv_104" edition=":sparc" />
        <vers num="snv_105" edition="" />
        <vers num="snv_105" edition=":x86" />
        <vers num="snv_105" edition=":sparc" />
        <vers num="snv_106" edition="" />
        <vers num="snv_106" edition=":sparc" />
        <vers num="snv_106" edition=":x86" />
        <vers num="snv_107" edition="" />
        <vers num="snv_107" edition=":x86" />
        <vers num="snv_107" edition=":sparc" />
        <vers num="snv_108" edition="" />
        <vers num="snv_108" edition=":x86" />
        <vers num="snv_108" edition=":sparc" />
        <vers num="snv_109" edition="" />
        <vers num="snv_109" edition=":x86" />
        <vers num="snv_109" edition=":sparc" />
        <vers num="snv_11" edition="" />
        <vers num="snv_11" edition=":x86" />
        <vers num="snv_11" edition=":sparc" />
        <vers num="snv_110" edition="" />
        <vers num="snv_110" edition=":sparc" />
        <vers num="snv_110" edition=":x86" />
        <vers num="snv_12" edition="" />
        <vers num="snv_12" edition=":x86" />
        <vers num="snv_12" edition=":sparc" />
        <vers num="snv_13" edition="" />
        <vers num="snv_13" edition=":x86" />
        <vers num="snv_13" edition=":sparc" />
        <vers num="snv_14" edition="" />
        <vers num="snv_14" edition=":sparc" />
        <vers num="snv_14" edition=":x86" />
        <vers num="snv_15" edition="" />
        <vers num="snv_15" edition=":x86" />
        <vers num="snv_15" edition=":sparc" />
        <vers num="snv_16" edition="" />
        <vers num="snv_16" edition=":sparc" />
        <vers num="snv_16" edition=":x86" />
        <vers num="snv_17" edition="" />
        <vers num="snv_17" edition=":x86" />
        <vers num="snv_17" edition=":sparc" />
        <vers num="snv_18" edition="" />
        <vers num="snv_18" edition=":x86" />
        <vers num="snv_18" edition=":sparc" />
        <vers num="snv_19" edition="" />
        <vers num="snv_19" edition=":sparc" />
        <vers num="snv_19" edition=":x86" />
        <vers num="snv_20" edition="" />
        <vers num="snv_20" edition=":x86" />
        <vers num="snv_20" edition=":sparc" />
        <vers num="snv_21" edition="" />
        <vers num="snv_21" edition=":sparc" />
        <vers num="snv_21" edition=":x86" />
        <vers num="snv_22" edition="" />
        <vers num="snv_22" edition=":sparc" />
        <vers num="snv_22" edition=":x86" />
        <vers num="snv_23" edition="" />
        <vers num="snv_23" edition=":sparc" />
        <vers num="snv_23" edition=":x86" />
        <vers num="snv_24" edition="" />
        <vers num="snv_24" edition=":sparc" />
        <vers num="snv_24" edition=":x86" />
        <vers num="snv_25" edition="" />
        <vers num="snv_25" edition=":x86" />
        <vers num="snv_25" edition=":sparc" />
        <vers num="snv_26" edition="" />
        <vers num="snv_26" edition=":x86" />
        <vers num="snv_26" edition=":sparc" />
        <vers num="snv_27" edition="" />
        <vers num="snv_27" edition=":sparc" />
        <vers num="snv_27" edition=":x86" />
        <vers num="snv_28" edition="" />
        <vers num="snv_28" edition=":x86" />
        <vers num="snv_28" edition=":sparc" />
        <vers num="snv_29" edition="" />
        <vers num="snv_29" edition=":x86" />
        <vers num="snv_29" edition=":sparc" />
        <vers num="snv_30" edition="" />
        <vers num="snv_30" edition=":sparc" />
        <vers num="snv_30" edition=":x86" />
        <vers num="snv_31" edition="" />
        <vers num="snv_31" edition=":sparc" />
        <vers num="snv_31" edition=":x86" />
        <vers num="snv_32" edition="" />
        <vers num="snv_32" edition=":x86" />
        <vers num="snv_32" edition=":sparc" />
        <vers num="snv_33" edition="" />
        <vers num="snv_33" edition=":x86" />
        <vers num="snv_33" edition=":sparc" />
        <vers num="snv_34" edition="" />
        <vers num="snv_34" edition=":sparc" />
        <vers num="snv_34" edition=":x86" />
        <vers num="snv_35" edition="" />
        <vers num="snv_35" edition=":sparc" />
        <vers num="snv_35" edition=":x86" />
        <vers num="snv_36" edition="" />
        <vers num="snv_36" edition=":x86" />
        <vers num="snv_36" edition=":sparc" />
        <vers num="snv_37" edition="" />
        <vers num="snv_37" edition=":sparc" />
        <vers num="snv_37" edition=":x86" />
        <vers num="snv_38" edition="" />
        <vers num="snv_38" edition=":sparc" />
        <vers num="snv_38" edition=":x86" />
        <vers num="snv_39" edition="" />
        <vers num="snv_39" edition=":sparc" />
        <vers num="snv_39" edition=":x86" />
        <vers num="snv_40" edition="" />
        <vers num="snv_40" edition=":sparc" />
        <vers num="snv_40" edition=":x86" />
        <vers num="snv_41" edition="" />
        <vers num="snv_41" edition=":sparc" />
        <vers num="snv_41" edition=":x86" />
        <vers num="snv_42" edition="" />
        <vers num="snv_42" edition=":x86" />
        <vers num="snv_42" edition=":sparc" />
        <vers num="snv_43" edition="" />
        <vers num="snv_43" edition=":sparc" />
        <vers num="snv_43" edition=":x86" />
        <vers num="snv_44" edition="" />
        <vers num="snv_44" edition=":x86" />
        <vers num="snv_44" edition=":sparc" />
        <vers num="snv_45" edition="" />
        <vers num="snv_45" edition=":x86" />
        <vers num="snv_45" edition=":sparc" />
        <vers num="snv_46" edition="" />
        <vers num="snv_46" edition=":x86" />
        <vers num="snv_46" edition=":sparc" />
        <vers num="snv_47" edition="" />
        <vers num="snv_47" edition=":x86" />
        <vers num="snv_47" edition=":sparc" />
        <vers num="snv_48" edition="" />
        <vers num="snv_48" edition=":sparc" />
        <vers num="snv_48" edition=":x86" />
        <vers num="snv_49" edition="" />
        <vers num="snv_49" edition=":sparc" />
        <vers num="snv_49" edition=":x86" />
        <vers num="snv_50" edition="" />
        <vers num="snv_50" edition=":sparc" />
        <vers num="snv_50" edition=":x86" />
        <vers num="snv_51" edition="" />
        <vers num="snv_51" edition=":sparc" />
        <vers num="snv_51" edition=":x86" />
        <vers num="snv_52" edition="" />
        <vers num="snv_52" edition=":sparc" />
        <vers num="snv_52" edition=":x86" />
        <vers num="snv_53" edition="" />
        <vers num="snv_53" edition=":sparc" />
        <vers num="snv_53" edition=":x86" />
        <vers num="snv_54" edition="" />
        <vers num="snv_54" edition=":x86" />
        <vers num="snv_54" edition=":sparc" />
        <vers num="snv_55" edition="" />
        <vers num="snv_55" edition=":sparc" />
        <vers num="snv_55" edition=":x86" />
        <vers num="snv_56" edition="" />
        <vers num="snv_56" edition=":x86" />
        <vers num="snv_56" edition=":sparc" />
        <vers num="snv_57" edition="" />
        <vers num="snv_57" edition=":x86" />
        <vers num="snv_57" edition=":sparc" />
        <vers num="snv_58" edition="" />
        <vers num="snv_58" edition=":sparc" />
        <vers num="snv_58" edition=":x86" />
        <vers num="snv_59" edition="" />
        <vers num="snv_59" edition=":sparc" />
        <vers num="snv_59" edition=":x86" />
        <vers num="snv_60" edition="" />
        <vers num="snv_60" edition=":x86" />
        <vers num="snv_60" edition=":sparc" />
        <vers num="snv_61" edition="" />
        <vers num="snv_61" edition=":sparc" />
        <vers num="snv_61" edition=":x86" />
        <vers num="snv_62" edition="" />
        <vers num="snv_62" edition=":x86" />
        <vers num="snv_62" edition=":sparc" />
        <vers num="snv_63" edition="" />
        <vers num="snv_63" edition=":sparc" />
        <vers num="snv_63" edition=":x86" />
        <vers num="snv_64" edition="" />
        <vers num="snv_64" edition=":x86" />
        <vers num="snv_64" edition=":sparc" />
        <vers num="snv_65" edition="" />
        <vers num="snv_65" edition=":x86" />
        <vers num="snv_65" edition=":sparc" />
        <vers num="snv_66" edition="" />
        <vers num="snv_66" edition=":x86" />
        <vers num="snv_66" edition=":sparc" />
        <vers num="snv_67" edition="" />
        <vers num="snv_67" edition=":sparc" />
        <vers num="snv_67" edition=":x86" />
        <vers num="snv_68" edition="" />
        <vers num="snv_68" edition=":x86" />
        <vers num="snv_68" edition=":sparc" />
        <vers num="snv_69" edition="" />
        <vers num="snv_69" edition=":sparc" />
        <vers num="snv_69" edition=":x86" />
        <vers num="snv_70" edition="" />
        <vers num="snv_70" edition=":sparc" />
        <vers num="snv_70" edition=":x86" />
        <vers num="snv_71" edition="" />
        <vers num="snv_71" edition=":x86" />
        <vers num="snv_71" edition=":sparc" />
        <vers num="snv_72" edition="" />
        <vers num="snv_72" edition=":x86" />
        <vers num="snv_72" edition=":sparc" />
        <vers num="snv_73" edition="" />
        <vers num="snv_73" edition=":x86" />
        <vers num="snv_73" edition=":sparc" />
        <vers num="snv_74" edition="" />
        <vers num="snv_74" edition=":sparc" />
        <vers num="snv_74" edition=":x86" />
        <vers num="snv_75" edition="" />
        <vers num="snv_75" edition=":sparc" />
        <vers num="snv_75" edition=":x86" />
        <vers num="snv_76" edition="" />
        <vers num="snv_76" edition=":x86" />
        <vers num="snv_76" edition=":sparc" />
        <vers num="snv_77" edition="" />
        <vers num="snv_77" edition=":sparc" />
        <vers num="snv_77" edition=":x86" />
        <vers num="snv_78" edition="" />
        <vers num="snv_78" edition=":sparc" />
        <vers num="snv_78" edition=":x86" />
        <vers num="snv_79" edition="" />
        <vers num="snv_79" edition=":x86" />
        <vers num="snv_79" edition=":sparc" />
        <vers num="snv_80" edition="" />
        <vers num="snv_80" edition=":x86" />
        <vers num="snv_80" edition=":sparc" />
        <vers num="snv_81" edition="" />
        <vers num="snv_81" edition=":x86" />
        <vers num="snv_81" edition=":sparc" />
        <vers num="snv_82" edition="" />
        <vers num="snv_82" edition=":x86" />
        <vers num="snv_82" edition=":sparc" />
        <vers num="snv_83" edition="" />
        <vers num="snv_83" edition=":x86" />
        <vers num="snv_83" edition=":sparc" />
        <vers num="snv_84" edition="" />
        <vers num="snv_84" edition=":x86" />
        <vers num="snv_84" edition=":sparc" />
        <vers num="snv_85" edition="" />
        <vers num="snv_85" edition=":x86" />
        <vers num="snv_85" edition=":sparc" />
        <vers num="snv_86" edition="" />
        <vers num="snv_86" edition=":sparc" />
        <vers num="snv_86" edition=":x86" />
        <vers num="snv_87" edition="" />
        <vers num="snv_87" edition=":sparc" />
        <vers num="snv_87" edition=":x86" />
        <vers num="snv_88" edition="" />
        <vers num="snv_88" edition=":x86" />
        <vers num="snv_88" edition=":sparc" />
        <vers num="snv_89" edition="" />
        <vers num="snv_89" edition=":x86" />
        <vers num="snv_89" edition=":sparc" />
        <vers num="snv_90" edition="" />
        <vers num="snv_90" edition=":sparc" />
        <vers num="snv_90" edition=":x86" />
        <vers num="snv_91" edition="" />
        <vers num="snv_91" edition=":sparc" />
        <vers num="snv_91" edition=":x86" />
        <vers num="snv_92" edition="" />
        <vers num="snv_92" edition=":sparc" />
        <vers num="snv_92" edition=":x86" />
        <vers num="snv_93" edition="" />
        <vers num="snv_93" edition=":sparc" />
        <vers num="snv_93" edition=":x86" />
        <vers num="snv_94" edition="" />
        <vers num="snv_94" edition=":x86" />
        <vers num="snv_94" edition=":sparc" />
        <vers num="snv_95" edition="" />
        <vers num="snv_95" edition=":x86" />
        <vers num="snv_95" edition=":sparc" />
        <vers num="snv_96" edition="" />
        <vers num="snv_96" edition=":sparc" />
        <vers num="snv_96" edition=":x86" />
        <vers num="snv_97" edition="" />
        <vers num="snv_97" edition=":x86" />
        <vers num="snv_97" edition=":sparc" />
        <vers num="snv_98" edition="" />
        <vers num="snv_98" edition=":sparc" />
        <vers num="snv_98" edition=":x86" />
        <vers num="snv_99" edition="" />
        <vers num="snv_99" edition=":sparc" />
        <vers num="snv_99" edition=":x86" />
      </prod>
      <prod vendor="sun" name="solaris">
        <vers num="10.0" edition="" />
        <vers num="10.0" edition=":sparc" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0924" published="2009-03-17" name="CVE-2009-0924" modified="2009-04-02" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:N/I:N/A:C)" CVSS_score="4.7" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="3.4" CVSS_base_score="4.7">
    <desc>
      <descript source="cve">Unspecified vulnerability in Sun OpenSolaris snv_39 through snv_45, when running in 64-bit mode on x86 architectures, allows local users to cause a denial of service (hang of UFS filesystem write) via unknown vectors related to the (1) ufs_getpage and (2) ufs_putapage routines, aka CR 6442712.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/49281" source="XF">solaris-ufs-filesystem-64bit-dos(49281)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0876" source="VUPEN">ADV-2009-0876</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0742" source="VUPEN" adv="1">ADV-2009-0742</ref>
      <ref url="http://www.securitytracker.com/id?1021850" source="SECTRACK">1021850</ref>
      <ref url="http://www.securityfocus.com/bid/34137" source="BID">34137</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2009-103.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2009-103.htm</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-254628-1" source="SUNALERT" adv="1">254628</ref>
      <ref url="http://secunia.com/advisories/34331" source="SECUNIA">34331</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="opensolaris">
        <vers num="snv_39" edition="" />
        <vers num="snv_39" edition=":x86" />
        <vers num="snv_40" edition="" />
        <vers num="snv_40" edition=":x86" />
        <vers num="snv_41" edition="" />
        <vers num="snv_41" edition=":x86" />
        <vers num="snv_42" edition="" />
        <vers num="snv_42" edition=":x86" />
        <vers num="snv_43" edition="" />
        <vers num="snv_43" edition=":x86" />
        <vers num="snv_44" edition="" />
        <vers num="snv_44" edition=":x86" />
        <vers num="snv_45" edition="" />
        <vers num="snv_45" edition=":x86" />
        <vers num="snv_47" edition="" />
        <vers num="snv_47" edition=":sparc" />
        <vers num="snv_48" edition="" />
        <vers num="snv_48" edition=":sparc" />
        <vers num="snv_49" edition="" />
        <vers num="snv_49" edition=":sparc" />
        <vers num="snv_50" edition="" />
        <vers num="snv_50" edition=":sparc" />
        <vers num="snv_51" edition="" />
        <vers num="snv_51" edition=":sparc" />
        <vers num="snv_52" edition="" />
        <vers num="snv_52" edition=":sparc" />
        <vers num="snv_53" edition="" />
        <vers num="snv_53" edition=":sparc" />
        <vers num="snv_54" edition="" />
        <vers num="snv_54" edition=":sparc" />
        <vers num="snv_55" edition="" />
        <vers num="snv_55" edition=":sparc" />
        <vers num="snv_56" edition="" />
        <vers num="snv_56" edition=":sparc" />
        <vers num="snv_57" edition="" />
        <vers num="snv_57" edition=":sparc" />
        <vers num="snv_58" edition="" />
        <vers num="snv_58" edition=":sparc" />
        <vers num="snv_59" edition="" />
        <vers num="snv_59" edition=":sparc" />
        <vers num="snv_60" edition="" />
        <vers num="snv_60" edition=":sparc" />
        <vers num="snv_61" edition="" />
        <vers num="snv_61" edition=":sparc" />
        <vers num="snv_62" edition="" />
        <vers num="snv_62" edition=":sparc" />
        <vers num="snv_63" edition="" />
        <vers num="snv_63" edition=":sparc" />
        <vers num="snv_64" edition="" />
        <vers num="snv_64" edition=":sparc" />
        <vers num="snv_65" edition="" />
        <vers num="snv_65" edition=":sparc" />
        <vers num="snv_66" edition="" />
        <vers num="snv_66" edition=":sparc" />
        <vers num="snv_67" edition="" />
        <vers num="snv_67" edition=":sparc" />
        <vers num="snv_68" edition="" />
        <vers num="snv_68" edition=":sparc" />
        <vers num="snv_69" edition="" />
        <vers num="snv_69" edition=":sparc" />
        <vers num="snv_70" edition="" />
        <vers num="snv_70" edition=":sparc" />
        <vers num="snv_71" edition="" />
        <vers num="snv_71" edition=":sparc" />
        <vers num="snv_72" edition="" />
        <vers num="snv_72" edition=":sparc" />
        <vers num="snv_73" edition="" />
        <vers num="snv_73" edition=":sparc" />
        <vers num="snv_74" edition="" />
        <vers num="snv_74" edition=":sparc" />
        <vers num="snv_75" edition="" />
        <vers num="snv_75" edition=":sparc" />
        <vers num="snv_76" edition="" />
        <vers num="snv_76" edition=":sparc" />
        <vers num="snv_77" edition="" />
        <vers num="snv_77" edition=":sparc" />
        <vers num="snv_78" edition="" />
        <vers num="snv_78" edition=":sparc" />
        <vers num="snv_79" edition="" />
        <vers num="snv_79" edition=":sparc" />
        <vers num="snv_80" edition="" />
        <vers num="snv_80" edition=":sparc" />
        <vers num="snv_81" edition="" />
        <vers num="snv_81" edition=":sparc" />
        <vers num="snv_82" edition="" />
        <vers num="snv_82" edition=":sparc" />
        <vers num="snv_83" edition="" />
        <vers num="snv_83" edition=":sparc" />
        <vers num="snv_84" edition="" />
        <vers num="snv_84" edition=":sparc" />
        <vers num="snv_85" edition="" />
        <vers num="snv_85" edition=":sparc" />
        <vers num="snv_86" edition="" />
        <vers num="snv_86" edition=":x86" />
        <vers num="snv_87" edition="" />
        <vers num="snv_87" edition=":x86" />
        <vers num="snv_88" edition="" />
        <vers num="snv_88" edition=":x86" />
        <vers num="snv_89" edition="" />
        <vers num="snv_89" edition=":x86" />
        <vers num="snv_91" edition="" />
        <vers num="snv_91" edition=":x86" />
      </prod>
      <prod vendor="sun" name="solaris">
        <vers num="10.0" edition="" />
        <vers num="10.0" edition=":sparc" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0925" published="2009-03-17" name="CVE-2009-0925" modified="2009-04-02" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:N/I:N/A:C)" CVSS_score="4.7" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="3.4" CVSS_base_score="4.7">
    <desc>
      <descript source="cve">Unspecified vulnerability in Sun Solaris 10 on SPARC sun4v systems, and OpenSolaris snv_47 through snv_85, allows local users to cause a denial of service (hang of UFS filesystem write) via unknown vectors related to the (1) ufs_getpage and (2) ufs_putapage routines, aka CR 6425723.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/49282" source="XF">solaris-ufs-filesystem-sun4vdos(49282)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0876" source="VUPEN">ADV-2009-0876</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0742" source="VUPEN" adv="1">ADV-2009-0742</ref>
      <ref url="http://www.securitytracker.com/id?1021850" source="SECTRACK">1021850</ref>
      <ref url="http://www.securityfocus.com/bid/34137" source="BID">34137</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2009-103.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2009-103.htm</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-254628-1" source="SUNALERT" adv="1">254628</ref>
      <ref url="http://secunia.com/advisories/34331" source="SECUNIA">34331</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0926" published="2009-03-17" name="CVE-2009-0926" modified="2009-04-02" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="4.9" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="3.9" CVSS_base_score="4.9">
    <desc>
      <descript source="cve">Unspecified vulnerability in the UFS filesystem functionality in Sun OpenSolaris snv_86 through snv_91, when running in 32-bit mode on x86 systems, allows local users to cause a denial of service (panic) via unknown vectors related to the (1) ufs_getpage and (2) ufs_putapage routines, aka CR 6679732.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/49283" source="XF">solaris-ufs-filesystem-32bit-dos(49283)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0876" source="VUPEN">ADV-2009-0876</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0742" source="VUPEN">ADV-2009-0742</ref>
      <ref url="http://www.securitytracker.com/id?1021850" source="SECTRACK">1021850</ref>
      <ref url="http://www.securityfocus.com/bid/34137" source="BID">34137</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2009-103.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2009-103.htm</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-254628-1" source="SUNALERT" adv="1">254628</ref>
      <ref url="http://secunia.com/advisories/34331" source="SECUNIA">34331</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="opensolaris">
        <vers num="build_snv_39" edition="" />
        <vers num="build_snv_39" edition=":x86" />
        <vers num="snv_40" edition="" />
        <vers num="snv_40" edition=":x86" />
        <vers num="snv_41" edition="" />
        <vers num="snv_41" edition=":x86" />
        <vers num="snv_42" edition="" />
        <vers num="snv_42" edition=":x86" />
        <vers num="snv_43" edition="" />
        <vers num="snv_43" edition=":x86" />
        <vers num="snv_44" edition="" />
        <vers num="snv_44" edition=":x86" />
        <vers num="snv_47" edition="" />
        <vers num="snv_47" edition=":sparc" />
        <vers num="snv_48" edition="" />
        <vers num="snv_48" edition=":sparc" />
        <vers num="snv_49" edition="" />
        <vers num="snv_49" edition=":sparc" />
        <vers num="snv_50" edition="" />
        <vers num="snv_50" edition=":sparc" />
        <vers num="snv_51" edition="" />
        <vers num="snv_51" edition=":sparc" />
        <vers num="snv_52" edition="" />
        <vers num="snv_52" edition=":sparc" />
        <vers num="snv_53" edition="" />
        <vers num="snv_53" edition=":sparc" />
        <vers num="snv_54" edition="" />
        <vers num="snv_54" edition=":sparc" />
        <vers num="snv_55" edition="" />
        <vers num="snv_55" edition=":sparc" />
        <vers num="snv_56" edition="" />
        <vers num="snv_56" edition=":sparc" />
        <vers num="snv_57" edition="" />
        <vers num="snv_57" edition=":sparc" />
        <vers num="snv_58" edition="" />
        <vers num="snv_58" edition=":sparc" />
        <vers num="snv_59" edition="" />
        <vers num="snv_59" edition=":sparc" />
        <vers num="snv_60" edition="" />
        <vers num="snv_60" edition=":sparc" />
        <vers num="snv_61" edition="" />
        <vers num="snv_61" edition=":sparc" />
        <vers num="snv_62" edition="" />
        <vers num="snv_62" edition=":sparc" />
        <vers num="snv_63" edition="" />
        <vers num="snv_63" edition=":sparc" />
        <vers num="snv_64" edition="" />
        <vers num="snv_64" edition=":sparc" />
        <vers num="snv_65" edition="" />
        <vers num="snv_65" edition=":sparc" />
        <vers num="snv_66" edition="" />
        <vers num="snv_66" edition=":sparc" />
        <vers num="snv_67" edition="" />
        <vers num="snv_67" edition=":sparc" />
        <vers num="snv_68" edition="" />
        <vers num="snv_68" edition=":sparc" />
        <vers num="snv_69" edition="" />
        <vers num="snv_69" edition=":sparc" />
        <vers num="snv_70" edition="" />
        <vers num="snv_70" edition=":sparc" />
        <vers num="snv_71" edition="" />
        <vers num="snv_71" edition=":sparc" />
        <vers num="snv_72" edition="" />
        <vers num="snv_72" edition=":sparc" />
        <vers num="snv_73" edition="" />
        <vers num="snv_73" edition=":sparc" />
        <vers num="snv_74" edition="" />
        <vers num="snv_74" edition=":sparc" />
        <vers num="snv_75" edition="" />
        <vers num="snv_75" edition=":sparc" />
        <vers num="snv_76" edition="" />
        <vers num="snv_76" edition=":sparc" />
        <vers num="snv_77" edition="" />
        <vers num="snv_77" edition=":sparc" />
        <vers num="snv_78" edition="" />
        <vers num="snv_78" edition=":sparc" />
        <vers num="snv_79" edition="" />
        <vers num="snv_79" edition=":sparc" />
        <vers num="snv_80" edition="" />
        <vers num="snv_80" edition=":sparc" />
        <vers num="snv_81" edition="" />
        <vers num="snv_81" edition=":sparc" />
        <vers num="snv_82" edition="" />
        <vers num="snv_82" edition=":sparc" />
        <vers num="snv_83" edition="" />
        <vers num="snv_83" edition=":sparc" />
        <vers num="snv_84" edition="" />
        <vers num="snv_84" edition=":sparc" />
        <vers num="snv_85" edition="" />
        <vers num="snv_85" edition=":sparc" />
        <vers num="snv_86" edition="" />
        <vers num="snv_86" edition=":x86" />
        <vers num="snv_88" edition="" />
        <vers num="snv_88" edition=":x86" />
        <vers num="snv_89" edition="" />
        <vers num="snv_89" edition=":x86" />
        <vers num="snv_90" edition="" />
        <vers num="snv_90" edition=":x86" />
        <vers num="snv_91" edition="" />
        <vers num="snv_91" edition=":x86" />
      </prod>
      <prod vendor="sun" name="solaris">
        <vers num="10" edition="" />
        <vers num="10" edition=":sparc" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0927" published="2009-03-19" name="CVE-2009-0927" modified="2009-04-28" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Stack-based buffer overflow in Adobe Reader and Adobe Acrobat 9 before 9.1, 8 before 8.1.3 , and 7 before 7.1.1 allows remote attackers to execute arbitrary code via a crafted argument to the getIcon method of a Collab object, a different vulnerability than CVE-2009-0658.</descript>
    </desc>
    <sols>
      <sol source="nvd">Per vendor advisory in the 'details' section it states:

"The Adobe Reader and Acrobat 9.1 and 7.1.1 updates resolve an input validation issue in a JavaScript method that could potentially lead to remote code execution. This issue has already been resolved in Adobe Reader 8.1.3 and Acrobat 8.1.3. (CVE-2009-0927)"

http://www.adobe.com/support/security/bulletins/apsb09-04.html




</sol>
    </sols>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.adobe.com/support/security/bulletins/apsb09-04.html" source="CONFIRM" patch="1" adv="1">http://www.adobe.com/support/security/bulletins/apsb09-04.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/49312" source="XF">adobe-unspecified-javascript-code-execution(49312)</ref>
      <ref url="http://www.zerodayinitiative.com/advisories/ZDI-09-014" source="MISC">http://www.zerodayinitiative.com/advisories/ZDI-09-014</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1019" source="VUPEN">ADV-2009-1019</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0770" source="VUPEN">ADV-2009-0770</ref>
      <ref url="http://www.securitytracker.com/id?1021861" source="SECTRACK">1021861</ref>
      <ref url="http://www.securityfocus.com/bid/34169" source="BID">34169</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/502116/100/0/threaded" source="BUGTRAQ">20090324 ZDI-09-014: Adobe Acrobat getIcon() Stack Overflow Vulnerability</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-256788-1" source="SUNALERT">256788</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200904-17.xml" source="GENTOO">GLSA-200904-17</ref>
      <ref url="http://secunia.com/advisories/34790" source="SECUNIA">34790</ref>
      <ref url="http://secunia.com/advisories/34706" source="SECUNIA">34706</ref>
      <ref url="http://secunia.com/advisories/34490" source="SECUNIA">34490</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-04/msg00010.html" source="SUSE">SUSE-SR:2009:009</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-03/msg00005.html" source="SUSE">SUSE-SA:2009:014</ref>
    </refs>
    <vuln_soft>
      <prod vendor="adobe" name="acrobat">
        <vers num="7.0" />
        <vers num="7.0.1" />
        <vers num="7.0.2" />
        <vers num="7.0.3" />
        <vers num="7.0.5" />
        <vers num="7.0.7" />
        <vers num="7.0.8" />
        <vers num="7.0.9" />
        <vers prev="1" num="7.1.0" />
        <vers num="8.0" />
        <vers num="8.1" />
        <vers num="8.1.1" />
        <vers prev="1" num="8.1.2" />
        <vers prev="1" num="9.0" />
      </prod>
      <prod vendor="adobe" name="reader">
        <vers num="7.0.1" />
        <vers num="7.0.2" />
        <vers num="7.0.3" />
        <vers num="7.0.5" />
        <vers num="7.0.7" />
        <vers num="7.0.8" />
        <vers num="7.0.9" />
        <vers prev="1" num="7.1.0" />
        <vers num="8.1.1" />
        <vers prev="1" num="8.1.2" />
        <vers prev="1" num="9.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0928" published="2009-03-24" name="CVE-2009-0928" modified="2010-10-25" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Heap-based buffer overflow in Adobe Acrobat Reader and Acrobat Professional 7.1.0, 8.1.3, 9.0.0, and other versions allows remote attackers to execute arbitrary code via a PDF file containing a JBIG2 stream with a size inconsistency related to an unspecified table.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2009/1019" source="VUPEN" adv="1">ADV-2009-1019</ref>
      <ref url="http://www.securitytracker.com/id?1021892" source="SECTRACK">1021892</ref>
      <ref url="http://www.securityfocus.com/bid/34229" source="BID">34229</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-0376.html" source="REDHAT">RHSA-2009:0376</ref>
      <ref url="http://www.adobe.com/support/security/bulletins/apsb09-04.html" source="CONFIRM" adv="1">http://www.adobe.com/support/security/bulletins/apsb09-04.html</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-256788-1" source="SUNALERT">256788</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200904-17.xml" source="GENTOO">GLSA-200904-17</ref>
      <ref url="http://secunia.com/advisories/34790" source="SECUNIA" adv="1">34790</ref>
      <ref url="http://secunia.com/advisories/34706" source="SECUNIA" adv="1">34706</ref>
      <ref url="http://secunia.com/advisories/34490" source="SECUNIA" adv="1">34490</ref>
      <ref url="http://secunia.com/advisories/34392" source="SECUNIA" adv="1">34392</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-04/msg00010.html" source="SUSE">SUSE-SR:2009:009</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-03/msg00005.html" source="SUSE">SUSE-SA:2009:014</ref>
      <ref url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=776" source="IDEFENSE">20090324 Adobe Reader and Acrobat JBIG2 Encoded Stream Heap Overflow Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="adobe" name="acrobat">
        <vers num="3.0" />
        <vers num="3.1" />
        <vers num="4.0" />
        <vers num="4.0.5" />
        <vers num="4.0.5a" />
        <vers num="4.0.5c" />
        <vers num="5.0" />
        <vers num="5.0.10" />
        <vers num="5.0.5" />
        <vers num="5.0.6" />
        <vers num="6.0" />
        <vers num="6.0.1" />
        <vers num="6.0.2" />
        <vers num="6.0.3" />
        <vers num="6.0.4" />
        <vers num="6.0.5" />
        <vers num="6.0.6" />
        <vers num="7.0" />
        <vers num="7.0.1" />
        <vers num="7.0.2" />
        <vers num="7.0.3" />
        <vers num="7.0.4" />
        <vers num="7.0.5" />
        <vers num="7.0.6" />
        <vers num="7.0.7" />
        <vers num="7.0.8" />
        <vers num="7.0.9" />
        <vers num="7.1.0" />
        <vers num="7.1.1" />
        <vers num="7.1.2" />
        <vers num="7.1.3" />
        <vers num="7.1.4" />
        <vers num="8.0.0" />
        <vers num="8.1" />
        <vers num="8.1.1" />
        <vers num="8.1.2" />
        <vers num="8.1.3" />
        <vers num="8.1.4" />
        <vers num="8.1.5" />
        <vers num="8.1.6" />
        <vers num="8.1.7" />
        <vers num="8.2" />
        <vers num="8.2.1" />
        <vers num="8.2.2" />
        <vers num="8.2.3" />
        <vers num="8.2.4" />
        <vers prev="1" num="9.0" />
      </prod>
      <prod vendor="adobe" name="acrobat_reader">
        <vers num="3.0" />
        <vers num="3.01" />
        <vers num="3.02" />
        <vers num="4.0" />
        <vers num="4.0.5" />
        <vers num="4.0.5a" />
        <vers num="4.0.5c" />
        <vers num="4.5" />
        <vers num="5.0" />
        <vers num="5.0.10" />
        <vers num="5.0.11" />
        <vers num="5.0.5" />
        <vers num="5.0.6" />
        <vers num="5.0.7" />
        <vers num="5.0.9" />
        <vers num="5.1" />
        <vers num="6.0" />
        <vers num="6.0.1" />
        <vers num="6.0.2" />
        <vers num="6.0.3" />
        <vers num="6.0.4" />
        <vers num="6.0.5" />
        <vers num="6.0.6" />
        <vers num="7.0" />
        <vers num="7.0.1" />
        <vers num="7.0.2" />
        <vers num="7.0.3" />
        <vers num="7.0.4" />
        <vers num="7.0.5" />
        <vers num="7.0.6" />
        <vers num="7.0.7" />
        <vers num="7.0.8" />
        <vers num="7.0.9" />
        <vers num="7.1.0" />
        <vers num="7.1.1" />
        <vers num="7.1.2" />
        <vers num="7.1.3" />
        <vers num="7.1.4" />
        <vers num="8.0" />
        <vers num="8.1" />
        <vers num="8.1.1" />
        <vers num="8.1.2" />
        <vers num="8.1.4" />
        <vers num="8.1.5" />
        <vers num="8.1.6" />
        <vers num="8.1.7" />
        <vers num="8.2" />
        <vers num="8.2.1" />
        <vers num="8.2.2" />
        <vers num="8.2.3" />
        <vers num="8.2.4" />
        <vers prev="1" num="9.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0929" published="2009-03-17" name="CVE-2009-0929" modified="2009-04-01" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in the media manager in Nucleus CMS before 3.40 allows remote attackers to read arbitrary files via unknown vectors.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/49142" source="XF">nucleuscms-mediamanager-directory-traversal(49142)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0637" source="VUPEN">ADV-2009-0637</ref>
      <ref url="http://www.securityfocus.com/bid/34040" source="BID">34040</ref>
      <ref url="http://www.nucleuscms.org/index.php/item/index.php/item/3051" source="CONFIRM" adv="1">http://www.nucleuscms.org/index.php/item/index.php/item/3051</ref>
      <ref url="http://secunia.com/advisories/34180" source="SECUNIA" adv="1">34180</ref>
    </refs>
    <vuln_soft>
      <prod vendor="nucleus_group" name="nucleus_cms">
        <vers num="3.0" />
        <vers num="3.01" />
        <vers num="3.0_1" />
        <vers num="3.0_rc" />
        <vers num="3.1" />
        <vers num="3.2" />
        <vers num="3.21" />
        <vers num="3.22" />
        <vers num="3.23" />
        <vers prev="1" num="3.40" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0930" published="2009-03-17" name="CVE-2009-0930" modified="2009-04-16" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Horde IMP before 4.2.2 and 4.3.3 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors to (1) smime.php, (2) pgp.php, and (3) message.php.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/33492" source="BID">33492</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1770" source="DEBIAN">DSA-1770</ref>
      <ref url="http://secunia.com/advisories/34703" source="SECUNIA">34703</ref>
      <ref url="http://secunia.com/advisories/34418" source="SECUNIA">34418</ref>
      <ref url="http://secunia.com/advisories/33719" source="SECUNIA" adv="1">33719</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-03/msg00004.html" source="SUSE">SUSE-SR:2009:007</ref>
      <ref url="http://lists.horde.org/archives/announce/2009/000485.html" source="MLIST">[announce] 20090127 IMP 4.3.3 (final)</ref>
      <ref url="http://lists.horde.org/archives/announce/2009/000484.html" source="MLIST">[announce] 20090127 IMP 4.2.2 (final)</ref>
      <ref url="http://cvs.horde.org/co.php/imp/docs/CHANGES?r=1.699.2.375" source="CONFIRM">http://cvs.horde.org/co.php/imp/docs/CHANGES?r=1.699.2.375</ref>
      <ref url="http://cvs.horde.org/co.php/imp/docs/CHANGES?r=1.699.2.301.2.3" source="CONFIRM">http://cvs.horde.org/co.php/imp/docs/CHANGES?r=1.699.2.301.2.3</ref>
    </refs>
    <vuln_soft>
      <prod vendor="debian" name="horde_imp">
        <vers num="4.0" />
        <vers prev="1" num="4.0.2" />
        <vers prev="1" num="4.0.3" />
        <vers prev="1" num="4.0.4" />
        <vers prev="1" num="4.1.4" />
        <vers prev="1" num="4.1.5" />
        <vers prev="1" num="4.2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0931" published="2009-03-17" name="CVE-2009-0931" modified="2009-03-18" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the tag cloud search script (horde/services/portal/cloud_search.php) in Horde before 3.2.4 and 3.3.3, and Horde Groupware before 1.1.5, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/33491" source="BID" patch="1">33491</ref>
      <ref url="http://secunia.com/advisories/33695" source="SECUNIA" adv="1">33695</ref>
      <ref url="http://lists.horde.org/archives/announce/2009/000486.html" source="MLIST" adv="1">[announce] 20090127 Horde Groupware 1.1.5 (final)</ref>
      <ref url="http://lists.horde.org/archives/announce/2009/000483.html" source="MLIST" adv="1">[announce] 20090127 Horde 3.2.4 (final)</ref>
      <ref url="http://lists.horde.org/archives/announce/2009/000482.html" source="MLIST" adv="1">[announce] 20090127 Horde 3.3.3 (final)</ref>
      <ref url="http://cvs.horde.org/co.php/horde/docs/CHANGES?r=1.515.2.503" source="CONFIRM">http://cvs.horde.org/co.php/horde/docs/CHANGES?r=1.515.2.503</ref>
      <ref url="http://cvs.horde.org/co.php/horde/docs/CHANGES?r=1.515.2.413.2.5" source="CONFIRM">http://cvs.horde.org/co.php/horde/docs/CHANGES?r=1.515.2.413.2.5</ref>
      <ref url="http://cvs.horde.org/co.php/groupware/docs/groupware/CHANGES?r=1.28.2.5" source="CONFIRM" adv="1">http://cvs.horde.org/co.php/groupware/docs/groupware/CHANGES?r=1.28.2.5</ref>
    </refs>
    <vuln_soft>
      <prod vendor="debian" name="horde">
        <vers num="3.2.2" />
        <vers num="3.2.3" />
        <vers num="3.3" />
        <vers prev="1" num="3.3.1" />
        <vers prev="1" num="3.3.2" />
      </prod>
      <prod vendor="debian" name="horde_groupware">
        <vers prev="1" num="1.1.1" />
        <vers prev="1" num="1.1.2" />
        <vers prev="1" num="1.1.3" />
        <vers prev="1" num="1.1.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0932" published="2009-03-17" name="CVE-2009-0932" modified="2011-09-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">Directory traversal vulnerability in framework/Image/Image.php in Horde before 3.2.4 and 3.3.3 and Horde Groupware before 1.1.5 allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the Horde_Image driver name.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/33491" source="BID">33491</ref>
      <ref url="http://securityreason.com/securityalert/8077" source="SREASON">8077</ref>
      <ref url="http://secunia.com/advisories/34609" source="SECUNIA">34609</ref>
      <ref url="http://secunia.com/advisories/34418" source="SECUNIA">34418</ref>
      <ref url="http://secunia.com/advisories/33695" source="SECUNIA" adv="1">33695</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-03/msg00004.html" source="SUSE">SUSE-SR:2009:007</ref>
      <ref url="http://lists.horde.org/archives/announce/2009/000486.html" source="MLIST" adv="1">[announce] 20090127 Horde Groupware 1.1.5 (final)</ref>
      <ref url="http://lists.horde.org/archives/announce/2009/000483.html" source="MLIST" adv="1">[announce] 20090127 Horde 3.2.4 (final)</ref>
      <ref url="http://lists.horde.org/archives/announce/2009/000482.html" source="MLIST" adv="1">[announce] 20090127 Horde 3.3.3 (final)</ref>
      <ref url="http://cvs.horde.org/co.php/horde/docs/CHANGES?r=1.515.2.503" source="CONFIRM" adv="1">http://cvs.horde.org/co.php/horde/docs/CHANGES?r=1.515.2.503</ref>
      <ref url="http://cvs.horde.org/co.php/horde/docs/CHANGES?r=1.515.2.413.2.5" source="CONFIRM" adv="1">http://cvs.horde.org/co.php/horde/docs/CHANGES?r=1.515.2.413.2.5</ref>
      <ref url="http://cvs.horde.org/co.php/groupware/docs/groupware/CHANGES?r=1.28.2.5" source="CONFIRM" adv="1">http://cvs.horde.org/co.php/groupware/docs/groupware/CHANGES?r=1.28.2.5</ref>
    </refs>
    <vuln_soft>
      <prod vendor="debian" name="horde">
        <vers num="3.2" />
        <vers num="3.2.2" />
        <vers num="3.2.3" />
        <vers num="3.3" />
        <vers num="3.3.1" />
        <vers num="3.3.2" />
      </prod>
      <prod vendor="debian" name="horde_groupware">
        <vers num="1.1.1" />
        <vers num="1.1.2" />
        <vers num="1.1.3" />
        <vers num="1.1.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0933" published="2009-03-17" name="CVE-2009-0933" modified="2009-03-19" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the administrative interface in Dotclear before 2.1.5 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2009/0636" source="VUPEN" patch="1" adv="1">ADV-2009-0636</ref>
      <ref url="http://dotclear.org/blog/post/2009/02/05/Dotclear-2.1.5" source="CONFIRM" patch="1" adv="1">http://dotclear.org/blog/post/2009/02/05/Dotclear-2.1.5</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/49138" source="XF">dotclear-admin-interface-xss(49138)</ref>
      <ref url="http://www.securityfocus.com/bid/34036" source="BID">34036</ref>
      <ref url="http://secunia.com/advisories/34181" source="SECUNIA" adv="1">34181</ref>
    </refs>
    <vuln_soft>
      <prod vendor="dotclear" name="dotclear">
        <vers num="1.2.1" />
        <vers num="1.2.2" />
        <vers num="1.2.3" />
        <vers num="1.2.4" />
        <vers num="1.2.5" />
        <vers num="1.2.6" />
        <vers num="1.2.7" />
        <vers num="1.2.8" />
        <vers num="2.0" edition="beta_2" />
        <vers num="2.0" edition="beta_3" />
        <vers num="2.0" edition="beta_4" />
        <vers num="2.0" edition="beta_5.2" />
        <vers num="2.0" edition="beta_5.4" />
        <vers num="2.0" edition="beta_6" />
        <vers num="2.0" edition="beta_7" />
        <vers num="2.0" edition="rc1" />
        <vers num="2.0" edition="rc2" />
        <vers num="2.0.1" />
        <vers num="2.0.2" />
        <vers num="2.1" />
        <vers num="2.1.1" />
        <vers num="2.1.3" />
        <vers prev="1" num="2.1.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0934" published="2009-03-17" name="CVE-2009-0934" modified="2009-06-08" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in ejabberd before 2.0.4 allows remote attackers to inject arbitrary web script or HTML via unknown vectors related to links and MUC logs.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-March/msg00735.html" source="FEDORA">FEDORA-2009-2746</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-March/msg00675.html" source="FEDORA">FEDORA-2009-2747</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/49289" source="XF">ejabberd-chatroom-xss(49289)</ref>
      <ref url="http://www.securityfocus.com/bid/34133" source="BID">34133</ref>
      <ref url="http://www.process-one.net/en/ejabberd/release_notes/release_note_ejabberd_204" source="CONFIRM" adv="1">http://www.process-one.net/en/ejabberd/release_notes/release_note_ejabberd_204</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2009/03/16/1" source="MLIST">[oss-security] 20090316 CVE request: XSS in MUC logs of ejabberd</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1774" source="DEBIAN">DSA-1774</ref>
      <ref url="http://secunia.com/advisories/34781" source="SECUNIA">34781</ref>
      <ref url="http://secunia.com/advisories/34354" source="SECUNIA">34354</ref>
      <ref url="http://secunia.com/advisories/34340" source="SECUNIA" adv="1">34340</ref>
      <ref url="http://osvdb.org/52714" source="OSVDB">52714</ref>
    </refs>
    <vuln_soft>
      <prod vendor="process-one" name="ejabberd">
        <vers num="0.9" />
        <vers num="0.9.1" />
        <vers num="0.9.8" />
        <vers num="1.0.0" />
        <vers num="1.1.0" />
        <vers num="1.1.1" />
        <vers num="1.1.1.0" />
        <vers num="1.1.1.1" />
        <vers num="1.1.14" />
        <vers num="1.1.2" />
        <vers num="1.1.3" />
        <vers num="2.0.0" edition="beta1" />
        <vers num="2.0.0" edition="rc1" />
        <vers num="2.0.1_2" />
        <vers num="2.0.2" />
        <vers prev="1" num="2.0.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0935" published="2009-03-17" name="CVE-2009-0935" modified="2009-04-01" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:N/I:N/A:C)" CVSS_score="4.7" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="3.4" CVSS_base_score="4.7">
    <desc>
      <descript source="cve">The inotify_read function in the Linux kernel 2.6.27 to 2.6.27.13, 2.6.28 to 2.6.28.2, and 2.6.29-rc3 allows local users to cause a denial of service (OOPS) via a read with an invalid address to an inotify instance, which causes the device's event list mutex to be unlocked twice and prevents proper synchronization of a data structure for the inotify instance.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/33624" source="BID" patch="1">33624</ref>
      <ref url="http://marc.info/?l=linux-kernel&amp;m=123337123501681&amp;w=2" source="MLIST" patch="1">[linux-kernel] 20090131 [patch 03/43] inotify: clean up inotify_read and fix locking</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=488935" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=488935</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/49331" source="XF">linux-kernel-inotify-read-dos(49331)</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2009/03/19/2" source="MLIST">[oss-security] 20090319 Re: CVE request: kernel: inotify local DoS</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2009/03/18/5" source="MLIST">[oss-security] 20090318 Re: CVE request: kernel: inotify local DoS</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2009/03/06/2" source="MLIST">[oss-security] 20090306 CVE request: kernel: inotify local DoS</ref>
      <ref url="http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.28.3" source="CONFIRM">http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.28.3</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="kernel">
        <vers num="2.6" />
        <vers num="2.6.0" />
        <vers num="2.6.1" />
        <vers num="2.6.10" />
        <vers num="2.6.11" />
        <vers num="2.6.11.1" />
        <vers num="2.6.11.10" />
        <vers num="2.6.11.11" />
        <vers num="2.6.11.12" />
        <vers num="2.6.11.2" />
        <vers num="2.6.11.3" />
        <vers num="2.6.11.4" />
        <vers num="2.6.11.5" />
        <vers num="2.6.11.6" />
        <vers num="2.6.11.7" />
        <vers num="2.6.11.8" />
        <vers num="2.6.11.9" />
        <vers num="2.6.12" />
        <vers num="2.6.12.1" />
        <vers num="2.6.12.2" />
        <vers num="2.6.12.3" />
        <vers num="2.6.12.4" />
        <vers num="2.6.12.5" />
        <vers num="2.6.12.6" />
        <vers num="2.6.13" />
        <vers num="2.6.13.1" />
        <vers num="2.6.13.5" />
        <vers num="2.6.14" />
        <vers num="2.6.14.1" />
        <vers num="2.6.14.2" />
        <vers num="2.6.14.3" />
        <vers num="2.6.14.4" />
        <vers num="2.6.14.5" />
        <vers num="2.6.14.6" />
        <vers num="2.6.14.7" />
        <vers num="2.6.15" />
        <vers num="2.6.15.1" />
        <vers num="2.6.15.2" />
        <vers num="2.6.15.3" />
        <vers num="2.6.15.4" />
        <vers num="2.6.15.5" />
        <vers num="2.6.15.6" />
        <vers num="2.6.15.7" />
        <vers num="2.6.16" />
        <vers num="2.6.16.1" />
        <vers num="2.6.16.10" />
        <vers num="2.6.16.11" />
        <vers num="2.6.16.12" />
        <vers num="2.6.16.13" />
        <vers num="2.6.16.14" />
        <vers num="2.6.16.15" />
        <vers num="2.6.16.16" />
        <vers num="2.6.16.17" />
        <vers num="2.6.16.18" />
        <vers num="2.6.16.19" />
        <vers num="2.6.16.2" />
        <vers num="2.6.16.20" />
        <vers num="2.6.16.21" />
        <vers num="2.6.16.22" />
        <vers num="2.6.16.23" />
        <vers num="2.6.16.24" />
        <vers num="2.6.16.25" />
        <vers num="2.6.16.26" />
        <vers num="2.6.16.27" />
        <vers num="2.6.16.28" />
        <vers num="2.6.16.29" />
        <vers num="2.6.16.3" />
        <vers num="2.6.16.30" />
        <vers num="2.6.16.31" />
        <vers num="2.6.16.32" />
        <vers num="2.6.16.33" />
        <vers num="2.6.16.34" />
        <vers num="2.6.16.35" />
        <vers num="2.6.16.36" />
        <vers num="2.6.16.37" />
        <vers num="2.6.16.38" />
        <vers num="2.6.16.39" />
        <vers num="2.6.16.4" />
        <vers num="2.6.16.40" />
        <vers num="2.6.16.41" />
        <vers num="2.6.16.42" />
        <vers num="2.6.16.43" />
        <vers num="2.6.16.44" />
        <vers num="2.6.16.45" />
        <vers num="2.6.16.46" />
        <vers num="2.6.16.47" />
        <vers num="2.6.16.48" />
        <vers num="2.6.16.49" />
        <vers num="2.6.16.5" />
        <vers num="2.6.16.50" />
        <vers num="2.6.16.51" />
        <vers num="2.6.16.52" />
        <vers num="2.6.16.53" />
        <vers num="2.6.16.54" />
        <vers num="2.6.16.55" />
        <vers num="2.6.16.56" />
        <vers num="2.6.16.57" />
        <vers num="2.6.16.58" />
        <vers num="2.6.16.59" />
        <vers num="2.6.16.6" />
        <vers num="2.6.16.60" />
        <vers num="2.6.16.61" />
        <vers num="2.6.16.62" />
        <vers num="2.6.16.7" />
        <vers num="2.6.16.8" />
        <vers num="2.6.16.9" />
        <vers num="2.6.17" />
        <vers num="2.6.17.1" />
        <vers num="2.6.17.10" />
        <vers num="2.6.17.11" />
        <vers num="2.6.17.12" />
        <vers num="2.6.17.13" />
        <vers num="2.6.17.14" />
        <vers num="2.6.17.3" />
        <vers num="2.6.17.5" />
        <vers num="2.6.17.6" />
        <vers num="2.6.17.8" />
        <vers num="2.6.17.9" />
        <vers num="2.6.18" />
        <vers num="2.6.18.1" />
        <vers num="2.6.18.3" />
        <vers num="2.6.18.5" />
        <vers num="2.6.18.6" />
        <vers num="2.6.18.7" />
        <vers num="2.6.18.8" />
        <vers num="2.6.19" />
        <vers num="2.6.19.1" />
        <vers num="2.6.19.3" />
        <vers num="2.6.19.4" />
        <vers num="2.6.19.5" />
        <vers num="2.6.19.6" />
        <vers num="2.6.19.7" />
        <vers num="2.6.2" />
        <vers num="2.6.2.27.13" />
        <vers num="2.6.20" />
        <vers num="2.6.20.1" />
        <vers num="2.6.20.10" />
        <vers num="2.6.20.11" />
        <vers num="2.6.20.12" />
        <vers num="2.6.20.13" />
        <vers num="2.6.20.14" />
        <vers num="2.6.20.15" />
        <vers num="2.6.20.16" />
        <vers num="2.6.20.17" />
        <vers num="2.6.20.18" />
        <vers num="2.6.20.19" />
        <vers num="2.6.20.21" />
        <vers num="2.6.20.3" />
        <vers num="2.6.20.5" />
        <vers num="2.6.20.7" />
        <vers num="2.6.20.8" />
        <vers num="2.6.20.9" />
        <vers num="2.6.21" />
        <vers num="2.6.21.1" />
        <vers num="2.6.21.2" />
        <vers num="2.6.21.4" />
        <vers num="2.6.21.5" />
        <vers num="2.6.21.6" />
        <vers num="2.6.21.7" />
        <vers num="2.6.22" />
        <vers num="2.6.22.1" />
        <vers num="2.6.22.10" />
        <vers num="2.6.22.11" />
        <vers num="2.6.22.12" />
        <vers num="2.6.22.13" />
        <vers num="2.6.22.14" />
        <vers num="2.6.22.15" />
        <vers num="2.6.22.16" />
        <vers num="2.6.22.17" />
        <vers num="2.6.22.18" />
        <vers num="2.6.22.19" />
        <vers num="2.6.22.2" />
        <vers num="2.6.22.3" />
        <vers num="2.6.22.4" />
        <vers num="2.6.22.5" />
        <vers num="2.6.22.6" />
        <vers num="2.6.22.7" />
        <vers num="2.6.22.8" />
        <vers num="2.6.22.9" />
        <vers num="2.6.23" />
        <vers num="2.6.23.1" />
        <vers num="2.6.23.10" />
        <vers num="2.6.23.11" />
        <vers num="2.6.23.12" />
        <vers num="2.6.23.13" />
        <vers num="2.6.23.14" />
        <vers num="2.6.23.15" />
        <vers num="2.6.23.17" />
        <vers num="2.6.23.2" />
        <vers num="2.6.23.3" />
        <vers num="2.6.23.4" />
        <vers num="2.6.23.5" />
        <vers num="2.6.23.6" />
        <vers num="2.6.23.7" />
        <vers num="2.6.23.8" />
        <vers num="2.6.23.9" />
        <vers num="2.6.24" />
        <vers num="2.6.24.1" />
        <vers num="2.6.24.2" />
        <vers num="2.6.24.3" />
        <vers num="2.6.24.4" />
        <vers num="2.6.24.5" />
        <vers num="2.6.24.6" />
        <vers num="2.6.24.7" />
        <vers num="2.6.25" />
        <vers num="2.6.25.1" />
        <vers num="2.6.25.10" />
        <vers num="2.6.25.11" />
        <vers num="2.6.25.12" />
        <vers num="2.6.25.13" />
        <vers num="2.6.25.14" />
        <vers num="2.6.25.15" />
        <vers num="2.6.25.16" />
        <vers num="2.6.25.17" />
        <vers num="2.6.25.18" />
        <vers num="2.6.25.19" />
        <vers num="2.6.25.2" />
        <vers num="2.6.25.20" />
        <vers num="2.6.25.3" />
        <vers num="2.6.25.4" />
        <vers num="2.6.25.5" />
        <vers num="2.6.25.6" />
        <vers num="2.6.25.7" />
        <vers num="2.6.25.8" />
        <vers num="2.6.25.9" />
        <vers num="2.6.26" />
        <vers num="2.6.26.1" />
        <vers num="2.6.26.2" />
        <vers num="2.6.26.3" />
        <vers num="2.6.26.4" />
        <vers num="2.6.26.5" />
        <vers num="2.6.26.6" />
        <vers num="2.6.26.7" />
        <vers num="2.6.26.8" />
        <vers num="2.6.27" />
        <vers num="2.6.27.1" />
        <vers num="2.6.27.10" />
        <vers num="2.6.27.11" />
        <vers num="2.6.27.12" />
        <vers num="2.6.27.14" />
        <vers num="2.6.27.15" />
        <vers num="2.6.27.16" />
        <vers num="2.6.27.17" />
        <vers num="2.6.27.18" />
        <vers num="2.6.27.19" />
        <vers num="2.6.27.2" />
        <vers num="2.6.27.20" />
        <vers num="2.6.27.3" />
        <vers num="2.6.27.4" />
        <vers num="2.6.27.5" />
        <vers num="2.6.27.6" />
        <vers num="2.6.27.7" />
        <vers num="2.6.27.8" />
        <vers num="2.6.27.9" />
        <vers num="2.6.28" />
        <vers num="2.6.28.1" />
        <vers num="2.6.28.2" />
        <vers num="2.6.28.3" />
        <vers num="2.6.28.4" />
        <vers num="2.6.28.5" />
        <vers num="2.6.28.6" />
        <vers num="2.6.28.7" />
        <vers num="2.6.28.8" />
        <vers num="2.6.3" />
        <vers num="2.6.4" />
        <vers num="2.6.5" />
        <vers num="2.6.6" />
        <vers num="2.6.7" />
        <vers num="2.6.8" />
        <vers num="2.6.8.1" />
        <vers num="2.6.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0936" published="2009-03-17" name="CVE-2009-0936" modified="2009-04-18" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in Tor before 0.2.0.34 allows attackers to cause a denial of service (infinite loop) via "corrupt votes."</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://archives.seul.org/or/announce/Feb-2009/msg00000.html" source="MLIST" patch="1">[or-announce] 20090209 Tor 0.2.0.34 is released (security fixes)</ref>
      <ref url="http://www.securityfocus.com/bid/33713" source="BID">33713</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200904-11.xml" source="GENTOO">GLSA-200904-11</ref>
      <ref url="http://secunia.com/advisories/34583" source="SECUNIA">34583</ref>
      <ref url="http://secunia.com/advisories/33880" source="SECUNIA" adv="1">33880</ref>
    </refs>
    <vuln_soft>
      <prod vendor="tor" name="tor">
        <vers num="0.2.0.1" edition="alpha" />
        <vers num="0.2.0.10" edition="alpha" />
        <vers num="0.2.0.11" edition="alpha" />
        <vers num="0.2.0.12" edition="alpha" />
        <vers num="0.2.0.13" edition="alpha" />
        <vers num="0.2.0.14" edition="alpha" />
        <vers num="0.2.0.15" edition="alpha" />
        <vers num="0.2.0.16" edition="alpha" />
        <vers num="0.2.0.17" edition="alpha" />
        <vers num="0.2.0.18" edition="alpha" />
        <vers num="0.2.0.19" edition="alpha" />
        <vers num="0.2.0.2" edition="alpha" />
        <vers num="0.2.0.20" edition="alpha" />
        <vers num="0.2.0.21" edition="alpha" />
        <vers num="0.2.0.22" edition="alpha" />
        <vers num="0.2.0.23" edition="alpha" />
        <vers num="0.2.0.24" edition="alpha" />
        <vers num="0.2.0.25" edition="alpha" />
        <vers num="0.2.0.26" edition="alpha" />
        <vers num="0.2.0.27" edition="alpha" />
        <vers num="0.2.0.28" edition="alpha" />
        <vers num="0.2.0.29" edition="alpha" />
        <vers num="0.2.0.3" edition="alpha" />
        <vers num="0.2.0.30" edition="alpha" />
        <vers num="0.2.0.31" edition="alpha" />
        <vers num="0.2.0.32" edition="alpha" />
        <vers prev="1" num="0.2.0.33" />
        <vers num="0.2.0.4" edition="alpha" />
        <vers num="0.2.0.5" edition="alpha" />
        <vers num="0.2.0.6" edition="alpha" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0937" published="2009-03-17" name="CVE-2009-0937" modified="2009-04-18" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in Tor before 0.2.0.34 allows directory mirrors to cause a denial of service via unknown vectors.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://archives.seul.org/or/announce/Feb-2009/msg00000.html" source="MLIST" patch="1">[or-announce] 20090209 Tor 0.2.0.34 is released (security fixes)</ref>
      <ref url="http://www.securityfocus.com/bid/33713" source="BID">33713</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200904-11.xml" source="GENTOO">GLSA-200904-11</ref>
      <ref url="http://secunia.com/advisories/34583" source="SECUNIA">34583</ref>
      <ref url="http://secunia.com/advisories/33880" source="SECUNIA" adv="1">33880</ref>
    </refs>
    <vuln_soft>
      <prod vendor="tor" name="tor">
        <vers num="0.2.0.1" edition="alpha" />
        <vers num="0.2.0.10" edition="alpha" />
        <vers num="0.2.0.11" edition="alpha" />
        <vers num="0.2.0.12" edition="alpha" />
        <vers num="0.2.0.13" edition="alpha" />
        <vers num="0.2.0.14" edition="alpha" />
        <vers num="0.2.0.15" edition="alpha" />
        <vers num="0.2.0.16" edition="alpha" />
        <vers num="0.2.0.17" edition="alpha" />
        <vers num="0.2.0.18" edition="alpha" />
        <vers num="0.2.0.19" edition="alpha" />
        <vers num="0.2.0.2" edition="alpha" />
        <vers num="0.2.0.20" edition="alpha" />
        <vers num="0.2.0.21" edition="alpha" />
        <vers num="0.2.0.22" edition="alpha" />
        <vers num="0.2.0.23" edition="alpha" />
        <vers num="0.2.0.24" edition="alpha" />
        <vers num="0.2.0.25" edition="alpha" />
        <vers num="0.2.0.26" edition="alpha" />
        <vers num="0.2.0.27" edition="alpha" />
        <vers num="0.2.0.28" edition="alpha" />
        <vers num="0.2.0.29" edition="alpha" />
        <vers num="0.2.0.3" edition="alpha" />
        <vers num="0.2.0.30" edition="alpha" />
        <vers num="0.2.0.31" edition="alpha" />
        <vers num="0.2.0.32" edition="alpha" />
        <vers prev="1" num="0.2.0.33" />
        <vers num="0.2.0.4" edition="alpha" />
        <vers num="0.2.0.5" edition="alpha" />
        <vers num="0.2.0.6" edition="alpha" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0938" published="2009-03-17" name="CVE-2009-0938" modified="2009-04-18" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in Tor before 0.2.0.34 allows directory mirrors to cause a denial of service (exit node crash) via "malformed input."</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://archives.seul.org/or/announce/Feb-2009/msg00000.html" source="MLIST" patch="1">[or-announce] 20090209 Tor 0.2.0.34 is released (security fixes)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/49323" source="XF">tor-mirrors-dos(49323)</ref>
      <ref url="http://www.securityfocus.com/bid/33713" source="BID">33713</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200904-11.xml" source="GENTOO">GLSA-200904-11</ref>
      <ref url="http://secunia.com/advisories/34583" source="SECUNIA">34583</ref>
      <ref url="http://secunia.com/advisories/33880" source="SECUNIA" adv="1">33880</ref>
    </refs>
    <vuln_soft>
      <prod vendor="tor" name="tor">
        <vers num="0.2.0.1" edition="alpha" />
        <vers num="0.2.0.10" edition="alpha" />
        <vers num="0.2.0.11" edition="alpha" />
        <vers num="0.2.0.12" edition="alpha" />
        <vers num="0.2.0.13" edition="alpha" />
        <vers num="0.2.0.14" edition="alpha" />
        <vers num="0.2.0.15" edition="alpha" />
        <vers num="0.2.0.16" edition="alpha" />
        <vers num="0.2.0.17" edition="alpha" />
        <vers num="0.2.0.18" edition="alpha" />
        <vers num="0.2.0.19" edition="alpha" />
        <vers num="0.2.0.2" edition="alpha" />
        <vers num="0.2.0.20" edition="alpha" />
        <vers num="0.2.0.21" edition="alpha" />
        <vers num="0.2.0.22" edition="alpha" />
        <vers num="0.2.0.23" edition="alpha" />
        <vers num="0.2.0.24" edition="alpha" />
        <vers num="0.2.0.25" edition="alpha" />
        <vers num="0.2.0.26" edition="alpha" />
        <vers num="0.2.0.27" edition="alpha" />
        <vers num="0.2.0.28" edition="alpha" />
        <vers num="0.2.0.29" edition="alpha" />
        <vers num="0.2.0.3" edition="alpha" />
        <vers num="0.2.0.30" edition="alpha" />
        <vers num="0.2.0.31" edition="alpha" />
        <vers num="0.2.0.32" edition="alpha" />
        <vers prev="1" num="0.2.0.33" />
        <vers num="0.2.0.4" edition="alpha" />
        <vers num="0.2.0.5" edition="alpha" />
        <vers num="0.2.0.6" edition="alpha" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0939" published="2009-03-17" name="CVE-2009-0939" modified="2009-04-18" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Tor before 0.2.0.34 treats incomplete IPv4 addresses as valid, which has unknown impact and attack vectors related to "Spec conformance," as demonstrated using 192.168.0.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/33713" source="BID">33713</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200904-11.xml" source="GENTOO">GLSA-200904-11</ref>
      <ref url="http://secunia.com/advisories/34583" source="SECUNIA">34583</ref>
      <ref url="http://secunia.com/advisories/33880" source="SECUNIA" adv="1">33880</ref>
      <ref url="http://archives.seul.org/or/announce/Feb-2009/msg00000.html" source="MLIST">[or-announce] 20090209 Tor 0.2.0.34 is released (security fixes)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="tor" name="tor">
        <vers num="0.2.0.1" edition="alpha" />
        <vers num="0.2.0.10" edition="alpha" />
        <vers num="0.2.0.11" edition="alpha" />
        <vers num="0.2.0.12" edition="alpha" />
        <vers num="0.2.0.13" edition="alpha" />
        <vers num="0.2.0.14" edition="alpha" />
        <vers num="0.2.0.15" edition="alpha" />
        <vers num="0.2.0.16" edition="alpha" />
        <vers num="0.2.0.17" edition="alpha" />
        <vers num="0.2.0.18" edition="alpha" />
        <vers num="0.2.0.19" edition="alpha" />
        <vers num="0.2.0.2" edition="alpha" />
        <vers num="0.2.0.20" edition="alpha" />
        <vers num="0.2.0.21" edition="alpha" />
        <vers num="0.2.0.22" edition="alpha" />
        <vers num="0.2.0.23" edition="alpha" />
        <vers num="0.2.0.24" edition="alpha" />
        <vers num="0.2.0.25" edition="alpha" />
        <vers num="0.2.0.26" edition="alpha" />
        <vers num="0.2.0.27" edition="alpha" />
        <vers num="0.2.0.28" edition="alpha" />
        <vers num="0.2.0.29" edition="alpha" />
        <vers num="0.2.0.3" edition="alpha" />
        <vers num="0.2.0.30" edition="alpha" />
        <vers num="0.2.0.31" edition="alpha" />
        <vers num="0.2.0.32" edition="alpha" />
        <vers prev="1" num="0.2.0.33" />
        <vers num="0.2.0.4" edition="alpha" />
        <vers num="0.2.0.5" edition="alpha" />
        <vers num="0.2.0.6" edition="alpha" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0940" published="2009-03-18" name="CVE-2009-0940" modified="2009-10-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">Multiple cross-site request forgery (CSRF) vulnerabilities in the HP Embedded Web Server (EWS) on HP LaserJet Printers, Edgeline Printers, and Digital Senders allow remote attackers to hijack the intranet connectivity of arbitrary users for requests that (1) print documents via unknown vectors, (2) modify the network configuration via a NetIPChange request to hp/device/config_result_YesNo.html/config, or (3) change the password via the Password and ConfirmPassword parameters to hp/device/set_config_password.html/config.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2009/0754" source="VUPEN">ADV-2009-0754</ref>
      <ref url="http://www.securityfocus.com/bid/34143" source="BID">34143</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/501884/100/0/threaded" source="BUGTRAQ">20090316 HP Laserjet multiple models web management CSRF vulnerability &amp; insecure default configuration</ref>
      <ref url="http://www.louhinetworks.fi/advisory/HP_20090317.txt" source="MISC">http://www.louhinetworks.fi/advisory/HP_20090317.txt</ref>
      <ref url="http://osvdb.org/52849" source="OSVDB">52849</ref>
      <ref url="http://osvdb.org/52848" source="OSVDB">52848</ref>
      <ref url="http://osvdb.org/52847" source="OSVDB">52847</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01684566" source="HP" adv="1">HPSN-2009-001</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="8100c_digital_sender">
        <vers num="-" />
      </prod>
      <prod vendor="hp" name="9100c_digital_sender">
        <vers num="-" />
      </prod>
      <prod vendor="hp" name="9200c_digital_sender">
        <vers num="-" />
      </prod>
      <prod vendor="hp" name="9250c_digital_sender">
        <vers num="-" />
      </prod>
      <prod vendor="hp" name="color_laserjet">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="color_laserjet_1500">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="color_laserjet_2500">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="color_laserjet_2500l">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="color_laserjet_2500lse">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="color_laserjet_2500n">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="color_laserjet_2500tn">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="color_laserjet_2605dtn">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="color_laserjet_4370mfp">
        <vers num="20081211_46.211.2" />
      </prod>
      <prod vendor="hp" name="color_laserjet_4600">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="color_laserjet_4600dn">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="color_laserjet_4600dtn">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="color_laserjet_4600hdn">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="color_laserjet_4650">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="color_laserjet_4700">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="color_laserjet_4730_mfp">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="color_laserjet_5500">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="color_laserjet_5550">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="color_laserjet_8500">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="color_laserjet_8550">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="color_laserjet_9500">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="color_laserjet_9500_mfp">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="color_laserjet_9500mfp">
        <vers num="20070719_05.011.2" />
      </prod>
      <prod vendor="hp" name="color_mfp_cm8050">
        <vers num="-" edition="-" />
        <vers num="-" edition="-:edgeline" />
      </prod>
      <prod vendor="hp" name="color_mfp_cm8060">
        <vers num="-" edition="-" />
        <vers num="-" edition="-:edgeline" />
      </prod>
      <prod vendor="hp" name="digital_senders">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="edgeline_printers">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="laserjet_1000">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="laserjet_1005">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="laserjet_1010">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="laserjet_1012">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="laserjet_1015">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="laserjet_1018">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="laserjet_1018s">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="laserjet_1020">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="laserjet_1020_plus">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="laserjet_1022">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="laserjet_1022n">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="laserjet_1022nw">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="laserjet_1100">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="laserjet_1150">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="laserjet_1160">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="laserjet_1200">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="laserjet_1300">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="laserjet_1320">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="laserjet_2">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="laserjet_2000">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="laserjet_2100">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="laserjet_2200">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="laserjet_2200dtn">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="laserjet_2300">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="laserjet_2300dn">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="laserjet_2400">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="laserjet_2410">
        <vers num="20070410_08.112.3" />
      </prod>
      <prod vendor="hp" name="laserjet_2420">
        <vers num="20070410_08.112.3" />
      </prod>
      <prod vendor="hp" name="laserjet_2430">
        <vers num="20070410_08.112.3" />
      </prod>
      <prod vendor="hp" name="laserjet_2500">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="laserjet_2500c">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="laserjet_2600c">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="laserjet_2600n">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="laserjet_3000">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="laserjet_3700">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="laserjet_4">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="laserjet_4/4m">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="laserjet_4000">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="laserjet_4000n">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="laserjet_4050">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="laserjet_4100">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="laserjet_4100_mfp">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="laserjet_4100mfp">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="laserjet_4200">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="laserjet_4200dtn">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="laserjet_4200ln">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="laserjet_4240">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="laserjet_4240n">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="laserjet_4250">
        <vers num="20080319_08.015.0" />
      </prod>
      <prod vendor="hp" name="laserjet_4300">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="laserjet_4345_mfp">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="laserjet_4345mfp">
        <vers num="20081211_09.131.1" />
      </prod>
      <prod vendor="hp" name="laserjet_4350">
        <vers num="20080319_08.015.0" />
      </prod>
      <prod vendor="hp" name="laserjet_4350dtn">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="laserjet_4650dn">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="laserjet_4_plus/m_plus">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="laserjet_4l/ml">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="laserjet_4m_plus">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="laserjet_4p/mp">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="laserjet_4si">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="laserjet_4v/mv">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="laserjet_5">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="laserjet_5/m/n">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="laserjet_5000">
        <vers num="r.25.15" />
        <vers num="r.25.47" />
      </prod>
      <prod vendor="hp" name="laserjet_500_plus">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="laserjet_5100">
        <vers num="v.29.12" />
      </prod>
      <prod vendor="hp" name="laserjet_5100dtn">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="laserjet_5200">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="laserjet_5l">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="laserjet_5m">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="laserjet_5p/mp">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="laserjet_5si">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="laserjet_8000">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="laserjet_8100">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="laserjet_8150">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="laserjet_8150dn">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="laserjet_9000">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="laserjet_9000_mfp">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="laserjet_9000mfp">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="laserjet_9040">
        <vers num="20080204_08.110.0" />
      </prod>
      <prod vendor="hp" name="laserjet_9040mfp">
        <vers num="20080204_08.110.0" />
      </prod>
      <prod vendor="hp" name="laserjet_9050">
        <vers num="20080204_08.110.0" />
      </prod>
      <prod vendor="hp" name="laserjet_9050_mfp">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="laserjet_9050mfp">
        <vers num="20080204_08.110.0" />
      </prod>
      <prod vendor="hp" name="laserjet_9055">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="laserjet_9065">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="laserjet_9500">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="laserjet_9500mfp">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="laserjet_ii">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="laserjet_iid">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="laserjet_iii">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="laserjet_iiid">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="laserjet_iiip">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="laserjet_iiisi">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="laserjet_iip">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="laserjet_iip_plus">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="laserjet_m1522n_mfp">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="laserjet_m3027_mfp">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="laserjet_m3035_mfp">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="laserjet_m4345_mfp">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="laserjet_m5025_mfp">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="laserjet_m5035_mfp">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="laserjet_p1000">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="laserjet_p1005">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="laserjet_p1006">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="laserjet_p1007">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="laserjet_p1008">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="laserjet_p1009">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="laserjet_p1500">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="laserjet_p1505">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="laserjet_p1505n">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="laserjet_p2000">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="laserjet_p2010">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="laserjet_p2015">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="laserjet_p2030">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="laserjet_p2050">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="laserjet_p3000">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="laserjet_p3005">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="laserjet_p4010">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="laserjet_p4014">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="laserjet_p4015">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="laserjet_p4500">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="laserjet_p4510">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0941" published="2009-03-18" name="CVE-2009-0941" modified="2009-10-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)" CVSS_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_base_score="7.6">
    <desc>
      <descript source="cve">The HP Embedded Web Server (EWS) on HP LaserJet Printers, Edgeline Printers, and Digital Senders has no management password by default, which makes it easier for remote attackers to obtain access.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2009/0754" source="VUPEN">ADV-2009-0754</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/501884/100/0/threaded" source="BUGTRAQ">20090316 HP Laserjet multiple models web management CSRF vulnerability &amp; insecure default configuration</ref>
      <ref url="http://www.louhinetworks.fi/advisory/HP_20090317.txt" source="MISC">http://www.louhinetworks.fi/advisory/HP_20090317.txt</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01684566" source="HP" adv="1">HPSN-2009-001</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="8100c_digital_sender">
        <vers num="-" />
      </prod>
      <prod vendor="hp" name="9100c_digital_sender">
        <vers num="-" />
      </prod>
      <prod vendor="hp" name="9200c_digital_sender">
        <vers num="-" />
      </prod>
      <prod vendor="hp" name="9250c_digital_sender">
        <vers num="-" />
      </prod>
      <prod vendor="hp" name="color_laserjet">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="color_laserjet_1500">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="color_laserjet_2500">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="color_laserjet_2500l">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="color_laserjet_2500lse">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="color_laserjet_2500n">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="color_laserjet_2500tn">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="color_laserjet_2605dtn">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="color_laserjet_4370mfp">
        <vers num="20081211_46.211.2" />
      </prod>
      <prod vendor="hp" name="color_laserjet_4600">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="color_laserjet_4600dn">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="color_laserjet_4600dtn">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="color_laserjet_4600hdn">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="color_laserjet_4650">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="color_laserjet_4700">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="color_laserjet_4730_mfp">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="color_laserjet_5500">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="color_laserjet_5550">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="color_laserjet_8500">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="color_laserjet_8550">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="color_laserjet_9500">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="color_laserjet_9500_mfp">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="color_laserjet_9500mfp">
        <vers num="20070719_05.011.2" />
      </prod>
      <prod vendor="hp" name="color_mfp_cm8050">
        <vers num="-" edition="-" />
        <vers num="-" edition="-:edgeline" />
      </prod>
      <prod vendor="hp" name="color_mfp_cm8060">
        <vers num="-" edition="-" />
        <vers num="-" edition="-:edgeline" />
      </prod>
      <prod vendor="hp" name="digital_senders">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="edgeline_printers">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="laserjet_1000">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="laserjet_1005">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="laserjet_1010">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="laserjet_1012">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="laserjet_1015">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="laserjet_1018">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="laserjet_1018s">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="laserjet_1020">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="laserjet_1020_plus">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="laserjet_1022">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="laserjet_1022n">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="laserjet_1022nw">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="laserjet_1100">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="laserjet_1150">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="laserjet_1160">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="laserjet_1200">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="laserjet_1300">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="laserjet_1320">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="laserjet_2">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="laserjet_2000">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="laserjet_2100">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="laserjet_2200">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="laserjet_2200dtn">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="laserjet_2300">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="laserjet_2300dn">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="laserjet_2400">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="laserjet_2410">
        <vers num="20070410_08.112.3" />
      </prod>
      <prod vendor="hp" name="laserjet_2420">
        <vers num="20070410_08.112.3" />
      </prod>
      <prod vendor="hp" name="laserjet_2430">
        <vers num="20070410_08.112.3" />
      </prod>
      <prod vendor="hp" name="laserjet_2500">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="laserjet_2500c">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="laserjet_2600c">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="laserjet_2600n">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="laserjet_3000">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="laserjet_3700">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="laserjet_4">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="laserjet_4/4m">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="laserjet_4000">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="laserjet_4000n">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="laserjet_4050">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="laserjet_4100">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="laserjet_4100_mfp">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="laserjet_4100mfp">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="laserjet_4200">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="laserjet_4200dtn">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="laserjet_4200ln">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="laserjet_4240">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="laserjet_4240n">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="laserjet_4250">
        <vers num="20080319_08.015.0" />
      </prod>
      <prod vendor="hp" name="laserjet_4300">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="laserjet_4345_mfp">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="laserjet_4345mfp">
        <vers num="20081211_09.131.1" />
      </prod>
      <prod vendor="hp" name="laserjet_4350">
        <vers num="20080319_08.015.0" />
      </prod>
      <prod vendor="hp" name="laserjet_4350dtn">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="laserjet_4650dn">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="laserjet_4_plus/m_plus">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="laserjet_4l/ml">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="laserjet_4m_plus">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="laserjet_4p/mp">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="laserjet_4si">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="laserjet_4v/mv">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="laserjet_5">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="laserjet_5/m/n">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="laserjet_5000">
        <vers num="r.25.15" />
        <vers num="r.25.47" />
      </prod>
      <prod vendor="hp" name="laserjet_500_plus">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="laserjet_5100">
        <vers num="v.29.12" />
      </prod>
      <prod vendor="hp" name="laserjet_5100dtn">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="laserjet_5200">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="laserjet_5l">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="laserjet_5m">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="laserjet_5p/mp">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="laserjet_5si">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="laserjet_8000">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="laserjet_8100">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="laserjet_8150">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="laserjet_8150dn">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="laserjet_9000">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="laserjet_9000_mfp">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="laserjet_9000mfp">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="laserjet_9040">
        <vers num="20080204_08.110.0" />
      </prod>
      <prod vendor="hp" name="laserjet_9040mfp">
        <vers num="20080204_08.110.0" />
      </prod>
      <prod vendor="hp" name="laserjet_9050">
        <vers num="20080204_08.110.0" />
      </prod>
      <prod vendor="hp" name="laserjet_9050_mfp">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="laserjet_9050mfp">
        <vers num="20080204_08.110.0" />
      </prod>
      <prod vendor="hp" name="laserjet_9055">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="laserjet_9065">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="laserjet_9500">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="laserjet_9500mfp">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="laserjet_ii">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="laserjet_iid">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="laserjet_iii">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="laserjet_iiid">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="laserjet_iiip">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="laserjet_iiisi">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="laserjet_iip">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="laserjet_iip_plus">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="laserjet_m1522n_mfp">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="laserjet_m3027_mfp">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="laserjet_m3035_mfp">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="laserjet_m4345_mfp">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="laserjet_m5025_mfp">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="laserjet_m5035_mfp">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="laserjet_p1000">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="laserjet_p1005">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="laserjet_p1006">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="laserjet_p1007">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="laserjet_p1008">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="laserjet_p1009">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="laserjet_p1500">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="laserjet_p1505">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="laserjet_p1505n">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="laserjet_p2000">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="laserjet_p2010">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="laserjet_p2015">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="laserjet_p2030">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="laserjet_p2050">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="laserjet_p3000">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="laserjet_p3005">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="laserjet_p4010">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="laserjet_p4014">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="laserjet_p4015">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="laserjet_p4500">
        <vers num="" />
      </prod>
      <prod vendor="hp" name="laserjet_p4510">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0942" published="2009-05-13" name="CVE-2009-0942" modified="2009-05-16" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Help Viewer in Apple Mac OS X 10.4.11 and 10.5 before 10.5.7 does not verify that certain Cascading Style Sheets (CSS) are located in a registered help book, which allows remote attackers to execute arbitrary code via a help: URL that triggers invocation of AppleScript files.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-133A.html" source="CERT">TA09-133A</ref>
      <ref url="http://support.apple.com/kb/HT3549" source="CONFIRM" patch="1" adv="1">http://support.apple.com/kb/HT3549</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2009/May/msg00002.html" source="APPLE" patch="1" adv="1">APPLE-SA-2009-05-12</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/50485" source="XF">macos-helpviewer-css-code-execution(50485)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1297" source="VUPEN">ADV-2009-1297</ref>
      <ref url="http://www.securitytracker.com/id?1022216" source="SECTRACK">1022216</ref>
      <ref url="http://www.securityfocus.com/bid/34926" source="BID">34926</ref>
      <ref url="http://secunia.com/advisories/35074" source="SECUNIA">35074</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.4.11" />
        <vers num="10.5.0" />
        <vers num="10.5.1" />
        <vers num="10.5.2" />
        <vers num="10.5.3" />
        <vers num="10.5.4" />
        <vers num="10.5.5" />
        <vers num="10.5.6" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.4.11" />
        <vers num="10.5.0" />
        <vers num="10.5.1" />
        <vers num="10.5.2" />
        <vers num="10.5.3" />
        <vers num="10.5.4" />
        <vers num="10.5.5" />
        <vers num="10.5.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0943" published="2009-05-13" name="CVE-2009-0943" modified="2009-05-16" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Help Viewer in Apple Mac OS X 10.4.11 and 10.5 before 10.5.7 does not verify that HTML pathnames are located in a registered help book, which allows remote attackers to execute arbitrary code via a help: URL that triggers invocation of AppleScript files.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-133A.html" source="CERT">TA09-133A</ref>
      <ref url="http://support.apple.com/kb/HT3549" source="CONFIRM" patch="1" adv="1">http://support.apple.com/kb/HT3549</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2009/May/msg00002.html" source="APPLE" patch="1" adv="1">APPLE-SA-2009-05-12</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/50486" source="XF">macos-helpviewer-html-code-execution(50486)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1297" source="VUPEN">ADV-2009-1297</ref>
      <ref url="http://www.securitytracker.com/id?1022216" source="SECTRACK">1022216</ref>
      <ref url="http://www.securityfocus.com/bid/34926" source="BID">34926</ref>
      <ref url="http://secunia.com/advisories/35074" source="SECUNIA">35074</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.4.11" />
        <vers num="10.5.0" />
        <vers num="10.5.1" />
        <vers num="10.5.2" />
        <vers num="10.5.3" />
        <vers num="10.5.4" />
        <vers num="10.5.5" />
        <vers num="10.5.6" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.4.11" />
        <vers num="10.5.0" />
        <vers num="10.5.1" />
        <vers num="10.5.2" />
        <vers num="10.5.3" />
        <vers num="10.5.4" />
        <vers num="10.5.5" />
        <vers num="10.5.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0944" published="2009-05-13" name="CVE-2009-0944" modified="2009-05-16" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">The Microsoft Office Spotlight Importer in Spotlight in Apple Mac OS X 10.4.11 and 10.5 before 10.5.7 does not properly validate Microsoft Office files, which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a file that triggers memory corruption.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-133A.html" source="CERT">TA09-133A</ref>
      <ref url="http://support.apple.com/kb/HT3549" source="CONFIRM" patch="1" adv="1">http://support.apple.com/kb/HT3549</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2009/May/msg00002.html" source="APPLE" patch="1" adv="1">APPLE-SA-2009-05-12</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1297" source="VUPEN">ADV-2009-1297</ref>
      <ref url="http://www.securitytracker.com/id?1022215" source="SECTRACK">1022215</ref>
      <ref url="http://www.securityfocus.com/bid/34939" source="BID">34939</ref>
      <ref url="http://www.securityfocus.com/bid/34926" source="BID">34926</ref>
      <ref url="http://secunia.com/advisories/35074" source="SECUNIA">35074</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.4.11" />
        <vers num="10.5.0" />
        <vers num="10.5.1" />
        <vers num="10.5.2" />
        <vers num="10.5.3" />
        <vers num="10.5.4" />
        <vers num="10.5.5" />
        <vers num="10.5.6" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.4.11" />
        <vers num="10.5.0" />
        <vers num="10.5.1" />
        <vers num="10.5.2" />
        <vers num="10.5.3" />
        <vers num="10.5.4" />
        <vers num="10.5.5" />
        <vers num="10.5.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0945" published="2009-05-13" name="CVE-2009-0945" modified="2011-02-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Array index error in the insertItemBefore method in WebKit, as used in Apple Safari before 3.2.3 and 4 Public Beta, iPhone OS 1.0 through 2.2.1, iPhone OS for iPod touch 1.1 through 2.2.1, Google Chrome Stable before 1.0.154.65, and possibly other products allows remote attackers to execute arbitrary code via a document with a SVGPathList data structure containing a negative index in the (1) SVGTransformList, (2) SVGStringList, (3) SVGNumberList, (4) SVGPathSegList, (5) SVGPointList, or (6) SVGLengthList SVGList object, which triggers memory corruption.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-133A.html" source="CERT">TA09-133A</ref>
      <ref url="http://support.apple.com/kb/HT3549" source="CONFIRM" patch="1" adv="1">http://support.apple.com/kb/HT3549</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2009/May/msg00002.html" source="APPLE" patch="1" adv="1">APPLE-SA-2009-05-12</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2009/May/msg00001.html" source="APPLE" patch="1" adv="1">APPLE-SA-2009-05-12</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2009/May/msg00000.html" source="APPLE" patch="1" adv="1">APPLE-SA-2009-05-12</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-July/msg01196.html" source="FEDORA">FEDORA-2009-8049</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-July/msg01177.html" source="FEDORA">FEDORA-2009-8039</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-July/msg00303.html" source="FEDORA">FEDORA-2009-6166</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/50477" source="XF">safari-webkit-svglist-bo(50477)</ref>
      <ref url="http://www.zerodayinitiative.com/advisories/ZDI-09-022" source="MISC">http://www.zerodayinitiative.com/advisories/ZDI-09-022</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0212" source="VUPEN">ADV-2011-0212</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1621" source="VUPEN">ADV-2009-1621</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1321" source="VUPEN">ADV-2009-1321</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1298" source="VUPEN">ADV-2009-1298</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1297" source="VUPEN">ADV-2009-1297</ref>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-823-1" source="UBUNTU">USN-823-1</ref>
      <ref url="http://www.ubuntu.com/usn/USN-857-1" source="UBUNTU">USN-857-1</ref>
      <ref url="http://www.ubuntu.com/usn/USN-836-1" source="UBUNTU">USN-836-1</ref>
      <ref url="http://www.ubuntu.com/usn/USN-822-1" source="UBUNTU">USN-822-1</ref>
      <ref url="http://www.securitytracker.com/id?1022207" source="SECTRACK">1022207</ref>
      <ref url="http://www.securityfocus.com/bid/34924" source="BID">34924</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/503594/100/0/threaded" source="BUGTRAQ">20090519 ZDI-09-022: Apple Safari Malformed SVGList Parsing Code Execution Vulnerability</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-1130.html" source="REDHAT">RHSA-2009:1130</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1950" source="DEBIAN">DSA-1950</ref>
      <ref url="http://support.apple.com/kb/HT3639" source="CONFIRM">http://support.apple.com/kb/HT3639</ref>
      <ref url="http://support.apple.com/kb/HT3550" source="CONFIRM">http://support.apple.com/kb/HT3550</ref>
      <ref url="http://secunia.com/advisories/43068" source="SECUNIA">43068</ref>
      <ref url="http://secunia.com/advisories/37746" source="SECUNIA">37746</ref>
      <ref url="http://secunia.com/advisories/36790" source="SECUNIA">36790</ref>
      <ref url="http://secunia.com/advisories/36461" source="SECUNIA">36461</ref>
      <ref url="http://secunia.com/advisories/36062" source="SECUNIA">36062</ref>
      <ref url="http://secunia.com/advisories/35805" source="SECUNIA">35805</ref>
      <ref url="http://secunia.com/advisories/35576" source="SECUNIA">35576</ref>
      <ref url="http://secunia.com/advisories/35095" source="SECUNIA">35095</ref>
      <ref url="http://secunia.com/advisories/35074" source="SECUNIA">35074</ref>
      <ref url="http://secunia.com/advisories/35056" source="SECUNIA">35056</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11584" source="OVAL">oval:org.mitre.oval:def:11584</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.html" source="SUSE">SUSE-SR:2011:002</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2009/Jun/msg00005.html" source="APPLE">APPLE-SA-2009-06-17-1</ref>
      <ref url="http://googlechromereleases.blogspot.com/2009/05/stable-update-bug-fix.html" source="CONFIRM">http://googlechromereleases.blogspot.com/2009/05/stable-update-bug-fix.html</ref>
      <ref url="http://code.google.com/p/chromium/issues/detail?id=9019" source="CONFIRM">http://code.google.com/p/chromium/issues/detail?id=9019</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="safari">
        <vers num="0.8" />
        <vers num="0.9" />
        <vers num="1.0" edition="beta" />
        <vers num="1.0" edition="beta2" />
        <vers num="1.0.0" />
        <vers num="1.0.0b1" />
        <vers num="1.0.0b2" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" edition="85.8" />
        <vers num="1.0.3" edition="85.8.1" />
        <vers num="1.1" />
        <vers num="1.1.0" />
        <vers num="1.1.1" />
        <vers num="1.2" />
        <vers num="1.2.0" />
        <vers num="1.2.1" />
        <vers num="1.2.2" />
        <vers num="1.2.3" />
        <vers num="1.2.4" />
        <vers num="1.2.5" />
        <vers num="1.3" />
        <vers num="1.3.0" />
        <vers num="1.3.1" />
        <vers num="1.3.2" edition="312.5" />
        <vers num="1.3.2" edition="312.6" />
        <vers num="2" />
        <vers num="2.0" />
        <vers num="2.0.0" />
        <vers num="2.0.1" />
        <vers num="2.0.2" />
        <vers num="2.0.3" edition="417.8" />
        <vers num="2.0.3" edition="417.9" />
        <vers num="2.0.3" edition="417.9.2" />
        <vers num="2.0.4" />
        <vers num="3" />
        <vers num="3.0" />
        <vers num="3.0.0" />
        <vers num="3.0.1" />
        <vers num="3.0.2" />
        <vers num="3.0.3" />
        <vers num="3.0.4" />
        <vers num="3.1" />
        <vers num="3.1.0" />
        <vers num="3.1.1" />
        <vers num="3.1.2" />
        <vers num="3.2" />
        <vers num="3.2.0" />
        <vers num="3.2.1" />
        <vers prev="1" num="3.2.2" />
        <vers num="4.0" edition="beta" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0946" published="2009-04-16" name="CVE-2009-0946" modified="2010-11-18" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Multiple integer overflows in FreeType 2.3.9 and earlier allow remote attackers to execute arbitrary code via vectors related to large values in certain inputs in (1) smooth/ftsmooth.c, (2) sfnt/ttcmap.c, and (3) cff/cffload.c.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-133A.html" source="CERT">TA09-133A</ref>
      <ref url="http://git.savannah.gnu.org/cgit/freetype/freetype2.git/tree/ChangeLog" source="CONFIRM" patch="1">http://git.savannah.gnu.org/cgit/freetype/freetype2.git/tree/ChangeLog</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=491384" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=491384</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1621" source="VUPEN">ADV-2009-1621</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1522" source="VUPEN">ADV-2009-1522</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1297" source="VUPEN">ADV-2009-1297</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1058" source="VUPEN">ADV-2009-1058</ref>
      <ref url="http://www.ubuntu.com/usn/USN-767-1" source="UBUNTU">USN-767-1</ref>
      <ref url="http://www.securityfocus.com/bid/34550" source="BID">34550</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-1062.html" source="REDHAT">RHSA-2009:1062</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-1061.html" source="REDHAT">RHSA-2009:1061</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-0329.html" source="REDHAT">RHSA-2009:0329</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:243" source="MANDRIVA">MDVSA-2009:243</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1784" source="DEBIAN">DSA-1784</ref>
      <ref url="http://support.apple.com/kb/HT4435" source="CONFIRM">http://support.apple.com/kb/HT4435</ref>
      <ref url="http://support.apple.com/kb/HT3639" source="CONFIRM">http://support.apple.com/kb/HT3639</ref>
      <ref url="http://support.apple.com/kb/HT3613" source="CONFIRM">http://support.apple.com/kb/HT3613</ref>
      <ref url="http://support.apple.com/kb/HT3549" source="CONFIRM">http://support.apple.com/kb/HT3549</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-270268-1" source="SUNALERT">270268</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200905-05.xml" source="GENTOO">GLSA-200905-05</ref>
      <ref url="http://secunia.com/advisories/35379" source="SECUNIA">35379</ref>
      <ref url="http://secunia.com/advisories/35210" source="SECUNIA">35210</ref>
      <ref url="http://secunia.com/advisories/35204" source="SECUNIA">35204</ref>
      <ref url="http://secunia.com/advisories/35200" source="SECUNIA">35200</ref>
      <ref url="http://secunia.com/advisories/35198" source="SECUNIA">35198</ref>
      <ref url="http://secunia.com/advisories/35074" source="SECUNIA">35074</ref>
      <ref url="http://secunia.com/advisories/35065" source="SECUNIA">35065</ref>
      <ref url="http://secunia.com/advisories/34967" source="SECUNIA">34967</ref>
      <ref url="http://secunia.com/advisories/34913" source="SECUNIA">34913</ref>
      <ref url="http://secunia.com/advisories/34723" source="SECUNIA" adv="1">34723</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10149" source="OVAL">oval:org.mitre.oval:def:10149</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-05/msg00000.html" source="SUSE">SUSE-SR:2009:010</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Nov/msg00000.html" source="APPLE">APPLE-SA-2010-11-10-1</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2009/May/msg00002.html" source="APPLE">APPLE-SA-2009-05-12</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2009/Jun/msg00005.html" source="APPLE">APPLE-SA-2009-06-17-1</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2009/jun/msg00002.html" source="APPLE">APPLE-SA-2009-06-08-1</ref>
      <ref url="http://git.savannah.gnu.org/cgit/freetype/freetype2.git/commit/?id=a18788b14db60ae3673f932249cd02d33a227c4e" source="CONFIRM">http://git.savannah.gnu.org/cgit/freetype/freetype2.git/commit/?id=a18788b14db60ae3673f932249cd02d33a227c4e</ref>
      <ref url="http://git.savannah.gnu.org/cgit/freetype/freetype2.git/commit/?id=79972af4f0485a11dcb19551356c45245749fc5b" source="CONFIRM">http://git.savannah.gnu.org/cgit/freetype/freetype2.git/commit/?id=79972af4f0485a11dcb19551356c45245749fc5b</ref>
      <ref url="http://git.savannah.gnu.org/cgit/freetype/freetype2.git/commit/?id=0545ec1ca36b27cb928128870a83e5f668980bc5" source="CONFIRM">http://git.savannah.gnu.org/cgit/freetype/freetype2.git/commit/?id=0545ec1ca36b27cb928128870a83e5f668980bc5</ref>
    </refs>
    <vuln_soft>
      <prod vendor="freetype" name="freetype">
        <vers num="1.3.1" />
        <vers num="2.0.6" />
        <vers num="2.0.9" />
        <vers num="2.1" />
        <vers num="2.1.10" />
        <vers num="2.1.3" />
        <vers num="2.1.4" />
        <vers num="2.1.5" />
        <vers num="2.1.6" />
        <vers num="2.1.7" />
        <vers num="2.1.8" />
        <vers num="2.1.8_rc1" />
        <vers num="2.1.9" />
        <vers num="2.2" />
        <vers num="2.2.1" />
        <vers num="2.2.10" />
        <vers num="2.3.3" />
        <vers num="2.3.4" />
        <vers num="2.3.5" />
        <vers prev="1" num="2.3.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0949" published="2009-06-09" name="CVE-2009-0949" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The ippReadIO function in cups/ipp.c in cupsd in CUPS before 1.3.10 does not properly initialize memory for IPP request packets, which allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a scheduler request with two consecutive IPP_TAG_UNSUPPORTED tags.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2009/dsa-1811" source="DEBIAN" patch="1">DSA-1811</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=500972" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=500972</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/50926" source="XF">apple-cups-ipptag-dos(50926)</ref>
      <ref url="http://www.ubuntu.com/usn/USN-780-1" source="UBUNTU">USN-780-1</ref>
      <ref url="http://www.securityfocus.com/bid/35169" source="BID">35169</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/504032/100/0/threaded" source="BUGTRAQ">20090602 CORE-2009-0420 - Apple CUPS IPP_TAG_UNSUPPORTED Handling null pointer Vulnerability</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-1083.html" source="REDHAT">RHSA-2009:1083</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-1082.html" source="REDHAT">RHSA-2009:1082</ref>
      <ref url="http://www.coresecurity.com/content/AppleCUPS-null-pointer-vulnerability" source="MISC">http://www.coresecurity.com/content/AppleCUPS-null-pointer-vulnerability</ref>
      <ref url="http://support.apple.com/kb/HT3865" source="CONFIRM">http://support.apple.com/kb/HT3865</ref>
      <ref url="http://securitytracker.com/id?1022321" source="SECTRACK">1022321</ref>
      <ref url="http://secunia.com/advisories/36701" source="SECUNIA">36701</ref>
      <ref url="http://secunia.com/advisories/35685" source="SECUNIA">35685</ref>
      <ref url="http://secunia.com/advisories/35342" source="SECUNIA" adv="1">35342</ref>
      <ref url="http://secunia.com/advisories/35340" source="SECUNIA" adv="1">35340</ref>
      <ref url="http://secunia.com/advisories/35328" source="SECUNIA" adv="1">35328</ref>
      <ref url="http://secunia.com/advisories/35322" source="SECUNIA" adv="1">35322</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9631" source="OVAL">oval:org.mitre.oval:def:9631</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-07/msg00002.html" source="SUSE">SUSE-SR:2009:012</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2009/Sep/msg00004.html" source="APPLE">APPLE-SA-2009-09-10-2</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="cups">
        <vers num="1.1" />
        <vers num="1.1.1" />
        <vers num="1.1.10" />
        <vers num="1.1.10-1" />
        <vers num="1.1.11" />
        <vers num="1.1.12" />
        <vers num="1.1.13" />
        <vers num="1.1.14" />
        <vers num="1.1.15" />
        <vers num="1.1.16" />
        <vers num="1.1.17" />
        <vers num="1.1.18" />
        <vers num="1.1.19" edition="rc1" />
        <vers num="1.1.19" edition="rc2" />
        <vers num="1.1.19" edition="rc3" />
        <vers num="1.1.19" edition="rc4" />
        <vers num="1.1.19" edition="rc5" />
        <vers num="1.1.2" />
        <vers num="1.1.20" edition="rc1" />
        <vers num="1.1.20" edition="rc2" />
        <vers num="1.1.20" edition="rc3" />
        <vers num="1.1.20" edition="rc4" />
        <vers num="1.1.20" edition="rc5" />
        <vers num="1.1.20" edition="rc6" />
        <vers num="1.1.21" edition="rc1" />
        <vers num="1.1.21" edition="rc2" />
        <vers num="1.1.22" edition="rc1" />
        <vers num="1.1.22" edition="rc2" />
        <vers num="1.1.23" edition="rc1" />
        <vers num="1.1.3" />
        <vers num="1.1.4" />
        <vers num="1.1.5" />
        <vers num="1.1.5-1" />
        <vers num="1.1.5-2" />
        <vers num="1.1.6" />
        <vers num="1.1.6-1" />
        <vers num="1.1.6-2" />
        <vers num="1.1.6-3" />
        <vers num="1.1.7" />
        <vers num="1.1.8" />
        <vers num="1.1.9" />
        <vers num="1.1.9-1" />
        <vers num="1.2" edition="b1" />
        <vers num="1.2" edition="b2" />
        <vers num="1.2" edition="rc1" />
        <vers num="1.2" edition="rc2" />
        <vers num="1.2" edition="rc3" />
        <vers num="1.2.0" />
        <vers num="1.2.1" />
        <vers num="1.2.10" />
        <vers num="1.2.11" />
        <vers num="1.2.12" />
        <vers num="1.2.2" />
        <vers num="1.2.3" />
        <vers num="1.2.4" />
        <vers num="1.2.5" />
        <vers num="1.2.6" />
        <vers num="1.2.7" />
        <vers num="1.2.8" />
        <vers num="1.2.9" />
        <vers num="1.3" edition="b1" />
        <vers num="1.3" edition="rc1" />
        <vers num="1.3" edition="rc2" />
        <vers num="1.3.0" />
        <vers num="1.3.1" />
        <vers num="1.3.2" />
        <vers num="1.3.3" />
        <vers num="1.3.4" />
        <vers num="1.3.5" />
        <vers num="1.3.6" />
        <vers num="1.3.7" />
        <vers num="1.3.8" />
        <vers prev="1" num="1.3.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0950" published="2009-06-02" name="CVE-2009-0950" modified="2009-08-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Stack-based buffer overflow in Apple iTunes before 8.2 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via an itms: URL with a long URL component after a colon.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2009/1470" source="VUPEN" patch="1" adv="1">ADV-2009-1470</ref>
      <ref url="http://www.securityfocus.com/bid/35157" source="BID" patch="1">35157</ref>
      <ref url="http://support.apple.com/kb/HT3592" source="CONFIRM" patch="1" adv="1">http://support.apple.com/kb/HT3592</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2009/Jun/msg00001.html" source="APPLE" patch="1" adv="1">APPLE-SA-2009-06-01-2</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/50899" source="XF">itunes-itms-bo(50899)</ref>
      <ref url="http://www.securitytracker.com/id?1022313" source="SECTRACK">1022313</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/504043/100/0/threaded" source="BUGTRAQ">20090602 Re: TPTI-09-03: Apple iTunes Multiple Protocol Handler Buffer Overflow Vulnerabilities</ref>
      <ref url="http://www.milw0rm.com/exploits/8934" source="MILW0RM">8934</ref>
      <ref url="http://www.milw0rm.com/exploits/8861" source="MILW0RM">8861</ref>
      <ref url="http://static.dataspill.org/releases/itunes/itms_overflow.rb" source="MISC">http://static.dataspill.org/releases/itunes/itms_overflow.rb</ref>
      <ref url="http://secunia.com/advisories/35314" source="SECUNIA" adv="1">35314</ref>
      <ref url="http://redpig.dataspill.org/2009/05/drive-by-attack-for-itunes-811.html" source="MISC">http://redpig.dataspill.org/2009/05/drive-by-attack-for-itunes-811.html</ref>
      <ref url="http://osvdb.org/54833" source="OSVDB">54833</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="itunes">
        <vers num="1.0" edition="" />
        <vers num="1.0" edition=":windows" />
        <vers num="1.0" edition="-" />
        <vers num="1.0" edition="-:windows" />
        <vers num="1.0" edition="-:mac" />
        <vers num="1.1" />
        <vers num="1.1.1" edition="" />
        <vers num="1.1.1" edition=":windows" />
        <vers num="1.1.1" edition="-" />
        <vers num="1.1.1" edition="-:mac" />
        <vers num="1.1.1" edition="-:windows" />
        <vers num="1.1.2" edition="" />
        <vers num="1.1.2" edition=":windows" />
        <vers num="1.1.2" edition="-" />
        <vers num="1.1.2" edition="-:windows" />
        <vers num="1.1.2" edition="-:mac" />
        <vers num="2.0" edition="" />
        <vers num="2.0" edition=":windows" />
        <vers num="2.0" edition="-" />
        <vers num="2.0" edition="-:mac" />
        <vers num="2.0" edition="-:windows" />
        <vers num="2.0.1" edition="" />
        <vers num="2.0.1" edition=":windows" />
        <vers num="2.0.1" edition="-" />
        <vers num="2.0.1" edition="-:windows" />
        <vers num="2.0.1" edition="-:mac" />
        <vers num="2.0.2" edition="" />
        <vers num="2.0.2" edition=":windows" />
        <vers num="2.0.2" edition="-" />
        <vers num="2.0.2" edition="-:windows" />
        <vers num="2.0.2" edition="-:mac" />
        <vers num="2.0.3" edition="" />
        <vers num="2.0.3" edition=":windows" />
        <vers num="2.0.3" edition="-" />
        <vers num="2.0.3" edition="-:mac" />
        <vers num="2.0.3" edition="-:windows" />
        <vers num="2.0.4" edition="" />
        <vers num="2.0.4" edition=":windows" />
        <vers num="2.0.4" edition="-" />
        <vers num="2.0.4" edition="-:windows" />
        <vers num="2.0.4" edition="-:mac" />
        <vers num="3.0" edition="" />
        <vers num="3.0" edition=":windows" />
        <vers num="3.0.1" edition="" />
        <vers num="3.0.1" edition=":windows" />
        <vers num="4.0" edition="" />
        <vers num="4.0" edition=":windows" />
        <vers num="4.0.0" edition="-" />
        <vers num="4.0.0" edition="-:windows" />
        <vers num="4.0.0" edition="-:mac" />
        <vers num="4.0.1" edition="" />
        <vers num="4.0.1" edition=":windows" />
        <vers num="4.0.1" edition="-" />
        <vers num="4.0.1" edition="-:mac" />
        <vers num="4.0.1" edition="-:windows" />
        <vers num="4.1" edition="" />
        <vers num="4.1" edition=":windows" />
        <vers num="4.1.0" edition="-" />
        <vers num="4.1.0" edition="-:windows" />
        <vers num="4.1.0" edition="-:mac" />
        <vers num="4.2" edition="" />
        <vers num="4.2" edition=":windows" />
        <vers num="4.2.0" edition="-" />
        <vers num="4.2.0" edition="-:windows" />
        <vers num="4.2.0" edition="-:mac" />
        <vers num="4.2.72" edition="" />
        <vers num="4.2.72" edition=":windows" />
        <vers num="4.5" edition="" />
        <vers num="4.5" edition=":windows" />
        <vers num="4.5.0" edition="-" />
        <vers num="4.5.0" edition="-:mac" />
        <vers num="4.5.0" edition="-:windows" />
        <vers num="4.6" edition="" />
        <vers num="4.6" edition=":windows" />
        <vers num="4.6.0" edition="-" />
        <vers num="4.6.0" edition="-:mac" />
        <vers num="4.6.0" edition="-:windows" />
        <vers num="4.7" edition="" />
        <vers num="4.7" edition=":windows" />
        <vers num="4.7.0" edition="-" />
        <vers num="4.7.0" edition="-:mac" />
        <vers num="4.7.0" edition="-:windows" />
        <vers num="4.7.1" edition="" />
        <vers num="4.7.1" edition=":windows" />
        <vers num="4.7.1" edition="-" />
        <vers num="4.7.1" edition="-:windows" />
        <vers num="4.7.1" edition="-:mac" />
        <vers num="4.7.1.30" edition="" />
        <vers num="4.7.1.30" edition=":windows" />
        <vers num="4.7.2" />
        <vers num="4.8" edition="" />
        <vers num="4.8" edition=":windows" />
        <vers num="4.8.0" edition="-" />
        <vers num="4.8.0" edition="-:mac" />
        <vers num="4.8.0" edition="-:windows" />
        <vers num="4.9" edition="" />
        <vers num="4.9" edition=":windows" />
        <vers num="4.9.0" edition="-" />
        <vers num="4.9.0" edition="-:mac" />
        <vers num="4.9.0" edition="-:windows" />
        <vers num="5.0" edition="" />
        <vers num="5.0" edition=":windows" />
        <vers num="5.0.0" edition="-" />
        <vers num="5.0.0" edition="-:mac" />
        <vers num="5.0.0" edition="-:windows" />
        <vers num="5.0.1" edition="" />
        <vers num="5.0.1" edition=":windows" />
        <vers num="5.0.1" edition="-" />
        <vers num="5.0.1" edition="-:mac" />
        <vers num="5.0.1" edition="-:windows" />
        <vers num="6.0" edition="" />
        <vers num="6.0" edition=":windows" />
        <vers num="6.0.0" edition="-" />
        <vers num="6.0.0" edition="-:windows" />
        <vers num="6.0.0" edition="-:mac" />
        <vers num="6.0.1" edition="" />
        <vers num="6.0.1" edition=":windows" />
        <vers num="6.0.1" edition="-" />
        <vers num="6.0.1" edition="-:mac" />
        <vers num="6.0.1" edition="-:windows" />
        <vers num="6.0.2" edition="" />
        <vers num="6.0.2" edition=":windows" />
        <vers num="6.0.2" edition="-" />
        <vers num="6.0.2" edition="-:windows" />
        <vers num="6.0.2" edition="-:mac" />
        <vers num="6.0.3" edition="" />
        <vers num="6.0.3" edition=":windows" />
        <vers num="6.0.3" edition="-" />
        <vers num="6.0.3" edition="-:mac" />
        <vers num="6.0.3" edition="-:windows" />
        <vers num="6.0.4" edition="" />
        <vers num="6.0.4" edition=":windows" />
        <vers num="6.0.4" edition="-" />
        <vers num="6.0.4" edition="-:windows" />
        <vers num="6.0.4" edition="-:mac" />
        <vers num="6.0.4.2" edition="" />
        <vers num="6.0.4.2" edition=":windows" />
        <vers num="6.0.5" edition="" />
        <vers num="6.0.5" edition=":windows" />
        <vers num="6.0.5" edition="-" />
        <vers num="6.0.5" edition="-:mac" />
        <vers num="6.0.5" edition="-:windows" />
        <vers num="7.0.0" edition="-" />
        <vers num="7.0.0" edition="-:mac" />
        <vers num="7.0.0" edition="-:windows" />
        <vers num="7.0.1" edition="-" />
        <vers num="7.0.1" edition="-:mac" />
        <vers num="7.0.1" edition="-:windows" />
        <vers num="7.0.2" edition="" />
        <vers num="7.0.2" edition=":windows" />
        <vers num="7.0.2" edition="-" />
        <vers num="7.0.2" edition="-:windows" />
        <vers num="7.0.2" edition="-:mac" />
        <vers num="7.1.0" edition="-" />
        <vers num="7.1.0" edition="-:windows" />
        <vers num="7.1.0" edition="-:mac" />
        <vers num="7.1.1" edition="-" />
        <vers num="7.1.1" edition="-:windows" />
        <vers num="7.1.1" edition="-:mac" />
        <vers num="7.2.0" edition="-" />
        <vers num="7.2.0" edition="-:windows" />
        <vers num="7.2.0" edition="-:mac" />
        <vers num="7.3.0" edition="-" />
        <vers num="7.3.0" edition="-:windows" />
        <vers num="7.3.0" edition="-:mac" />
        <vers num="7.3.1" edition="-" />
        <vers num="7.3.1" edition="-:windows" />
        <vers num="7.3.1" edition="-:mac" />
        <vers num="7.3.2" edition="" />
        <vers num="7.3.2" edition=":windows" />
        <vers num="7.3.2" edition="-" />
        <vers num="7.3.2" edition="-:mac" />
        <vers num="7.3.2" edition="-:windows" />
        <vers num="7.4" edition="" />
        <vers num="7.4" edition=":windows" />
        <vers num="7.4.0" edition="-" />
        <vers num="7.4.0" edition="-:windows" />
        <vers num="7.4.0" edition="-:mac" />
        <vers num="7.4.1" edition="" />
        <vers num="7.4.1" edition=":windows" />
        <vers num="7.4.1" edition="-" />
        <vers num="7.4.1" edition="-:mac" />
        <vers num="7.4.1" edition="-:windows" />
        <vers num="7.4.2" edition="" />
        <vers num="7.4.2" edition=":windows" />
        <vers num="7.4.2" edition="-" />
        <vers num="7.4.2" edition="-:windows" />
        <vers num="7.4.2" edition="-:mac" />
        <vers num="7.4.3" edition="" />
        <vers num="7.4.3" edition=":windows" />
        <vers num="7.5" edition="" />
        <vers num="7.5" edition=":windows" />
        <vers num="7.5.0" edition="-" />
        <vers num="7.5.0" edition="-:windows" />
        <vers num="7.5.0" edition="-:mac" />
        <vers num="7.6" edition="" />
        <vers num="7.6" edition=":windows" />
        <vers num="7.6.0" edition="-" />
        <vers num="7.6.0" edition="-:windows" />
        <vers num="7.6.0" edition="-:mac" />
        <vers num="7.6.1" edition="" />
        <vers num="7.6.1" edition=":windows" />
        <vers num="7.6.1" edition="-" />
        <vers num="7.6.1" edition="-:windows" />
        <vers num="7.6.1" edition="-:mac" />
        <vers num="7.6.2" edition="" />
        <vers num="7.6.2" edition=":windows" />
        <vers num="7.6.2" edition="-" />
        <vers num="7.6.2" edition="-:mac" />
        <vers num="7.6.2" edition="-:windows" />
        <vers num="7.7" edition="" />
        <vers num="7.7" edition=":windows" />
        <vers num="7.7.0" edition="-" />
        <vers num="7.7.0" edition="-:windows" />
        <vers num="7.7.0" edition="-:mac" />
        <vers num="7.7.1" edition="" />
        <vers num="7.7.1" edition=":windows" />
        <vers num="7.7.1" edition="-" />
        <vers num="7.7.1" edition="-:mac" />
        <vers num="7.7.1" edition="-:windows" />
        <vers num="8.0" edition="-" />
        <vers num="8.0" edition="-:windows" />
        <vers num="8.0" edition="-:mac" />
        <vers num="8.0.0" edition="-" />
        <vers num="8.0.0" edition="-:mac" />
        <vers num="8.0.0" edition="-:windows" />
        <vers num="8.0.1" edition="-" />
        <vers num="8.0.1" edition="-:mac" />
        <vers num="8.0.1" edition="-:windows" />
        <vers num="8.0.2" edition="-" />
        <vers num="8.0.2" edition="-:windows" />
        <vers num="8.0.2" edition="-:mac" />
        <vers num="8.1" edition="-" />
        <vers num="8.1" edition="-:mac" />
        <vers num="8.1" edition="-:windows" />
        <vers prev="1" num="8.1.1" edition="-" />
        <vers prev="1" num="8.1.1" edition="-:mac" />
        <vers prev="1" num="8.1.1" edition="-:windows" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0951" published="2009-06-02" name="CVE-2009-0951" modified="2009-06-09" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Heap-based buffer overflow in Apple QuickTime before 7.6.2 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted FLC compression file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2009/1469" source="VUPEN" patch="1" adv="1">ADV-2009-1469</ref>
      <ref url="http://support.apple.com/kb/HT3591" source="CONFIRM" patch="1">http://support.apple.com/kb/HT3591</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/50887" source="XF">quicktime-flc-bo(50887)</ref>
      <ref url="http://www.securitytracker.com/id?1022314" source="SECTRACK">1022314</ref>
      <ref url="http://www.securityfocus.com/bid/35161" source="BID">35161</ref>
      <ref url="http://secunia.com/advisories/35091" source="SECUNIA" adv="1">35091</ref>
      <ref url="http://osvdb.org/54878" source="OSVDB">54878</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2009/Jun/msg00000.html" source="APPLE" adv="1">APPLE-SA-2009-06-01-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="quicktime">
        <vers num="3" />
        <vers num="4.1.2" edition="-" />
        <vers num="4.1.2" edition="-:windows" />
        <vers num="4.1.2" edition="-:mac" />
        <vers num="5.0" />
        <vers num="5.0.1" edition="-" />
        <vers num="5.0.1" edition="-:windows" />
        <vers num="5.0.1" edition="-:mac" />
        <vers num="5.0.2" edition="-" />
        <vers num="5.0.2" edition="-:windows" />
        <vers num="5.0.2" edition="-:mac" />
        <vers num="6.0" edition="-" />
        <vers num="6.0" edition="-:windows" />
        <vers num="6.0.0" edition="-" />
        <vers num="6.0.0" edition="-:windows" />
        <vers num="6.0.0" edition="-:mac" />
        <vers num="6.0.1" edition="-" />
        <vers num="6.0.1" edition="-:windows" />
        <vers num="6.0.1" edition="-:mac" />
        <vers num="6.0.2" edition="-" />
        <vers num="6.0.2" edition="-:windows" />
        <vers num="6.0.2" edition="-:mac" />
        <vers num="6.1" />
        <vers num="6.1.0" edition="-" />
        <vers num="6.1.0" edition="-:mac" />
        <vers num="6.1.0" edition="-:windows" />
        <vers num="6.1.1" edition="-" />
        <vers num="6.1.1" edition="-:windows" />
        <vers num="6.1.1" edition="-:mac" />
        <vers num="6.2.0" edition="-" />
        <vers num="6.2.0" edition="-:windows" />
        <vers num="6.2.0" edition="-:mac" />
        <vers num="6.3.0" edition="-" />
        <vers num="6.3.0" edition="-:mac" />
        <vers num="6.3.0" edition="-:windows" />
        <vers num="6.4.0" edition="-" />
        <vers num="6.4.0" edition="-:mac" />
        <vers num="6.4.0" edition="-:windows" />
        <vers num="6.5" />
        <vers num="6.5.0" edition="-" />
        <vers num="6.5.0" edition="-:windows" />
        <vers num="6.5.0" edition="-:mac" />
        <vers num="6.5.1" edition="-" />
        <vers num="6.5.1" edition="-:mac" />
        <vers num="6.5.1" edition="-:windows" />
        <vers num="6.5.2" edition="-" />
        <vers num="6.5.2" edition="-:mac" />
        <vers num="6.5.2" edition="-:windows" />
        <vers num="7.0" edition="" />
        <vers num="7.0" edition=":windows" />
        <vers num="7.0" edition="-" />
        <vers num="7.0" edition="-:windows" />
        <vers num="7.0.0" edition="-" />
        <vers num="7.0.0" edition="-:windows" />
        <vers num="7.0.0" edition="-:mac" />
        <vers num="7.0.1" edition="" />
        <vers num="7.0.1" edition=":windows" />
        <vers num="7.0.1" edition="-" />
        <vers num="7.0.1" edition="-:mac" />
        <vers num="7.0.1" edition="-:windows" />
        <vers num="7.0.2" edition="" />
        <vers num="7.0.2" edition=":windows" />
        <vers num="7.0.2" edition="-" />
        <vers num="7.0.2" edition="-:windows" />
        <vers num="7.0.2" edition="-:mac" />
        <vers num="7.0.3" edition="-" />
        <vers num="7.0.3" edition="-:windows" />
        <vers num="7.0.3" edition="-:mac" />
        <vers num="7.0.4" edition="-" />
        <vers num="7.0.4" edition="-:windows" />
        <vers num="7.0.4" edition="-:mac" />
        <vers num="7.0.8" />
        <vers num="7.1" />
        <vers num="7.1.0" edition="-" />
        <vers num="7.1.0" edition="-:windows" />
        <vers num="7.1.0" edition="-:mac" />
        <vers num="7.1.1" edition="-" />
        <vers num="7.1.1" edition="-:mac" />
        <vers num="7.1.1" edition="-:windows" />
        <vers num="7.1.2" edition="-" />
        <vers num="7.1.2" edition="-:windows" />
        <vers num="7.1.2" edition="-:mac" />
        <vers num="7.1.3" edition="-" />
        <vers num="7.1.3" edition="-:mac" />
        <vers num="7.1.3" edition="-:windows" />
        <vers num="7.1.4" edition="-" />
        <vers num="7.1.4" edition="-:windows" />
        <vers num="7.1.4" edition="-:mac" />
        <vers num="7.1.5" edition="-" />
        <vers num="7.1.5" edition="-:windows" />
        <vers num="7.1.5" edition="-:mac" />
        <vers num="7.1.6" edition="-" />
        <vers num="7.1.6" edition="-:mac" />
        <vers num="7.1.6" edition="-:windows" />
        <vers num="7.2" edition="" />
        <vers num="7.2" edition=":vista" />
        <vers num="7.2.0" edition="-" />
        <vers num="7.2.0" edition="-:windows" />
        <vers num="7.2.0" edition="-:mac" />
        <vers num="7.2.1" edition="-" />
        <vers num="7.2.1" edition="-:mac" />
        <vers num="7.2.1" edition="-:windows" />
        <vers num="7.3" />
        <vers num="7.3.0" edition="-" />
        <vers num="7.3.0" edition="-:windows" />
        <vers num="7.3.0" edition="-:mac" />
        <vers num="7.3.1" edition="-" />
        <vers num="7.3.1" edition="-:windows" />
        <vers num="7.3.1" edition="-:mac" />
        <vers num="7.3.1.70" />
        <vers num="7.4" />
        <vers num="7.4.0" edition="-" />
        <vers num="7.4.0" edition="-:mac" />
        <vers num="7.4.0" edition="-:windows" />
        <vers num="7.4.1" edition="-" />
        <vers num="7.4.1" edition="-:mac" />
        <vers num="7.4.1" edition="-:windows" />
        <vers num="7.4.4" />
        <vers num="7.4.5" edition="-" />
        <vers num="7.4.5" edition="-:windows" />
        <vers num="7.4.5" edition="-:mac" />
        <vers num="7.5" />
        <vers num="7.5.0" edition="-" />
        <vers num="7.5.0" edition="-:windows" />
        <vers num="7.5.0" edition="-:mac" />
        <vers num="7.5.5" edition="-" />
        <vers num="7.5.5" edition="-:windows" />
        <vers num="7.5.5" edition="-:mac" />
        <vers num="7.6.0" />
        <vers prev="1" num="7.6.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0952" published="2009-06-02" name="CVE-2009-0952" modified="2009-06-09" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Buffer overflow in Apple QuickTime before 7.6.2 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted compressed PSD image.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2009/1469" source="VUPEN" patch="1" adv="1">ADV-2009-1469</ref>
      <ref url="http://support.apple.com/kb/HT3591" source="CONFIRM" patch="1" adv="1">http://support.apple.com/kb/HT3591</ref>
      <ref url="http://www.securitytracker.com/id?1022314" source="SECTRACK">1022314</ref>
      <ref url="http://www.securityfocus.com/bid/35168" source="BID">35168</ref>
      <ref url="http://secunia.com/advisories/35091" source="SECUNIA" adv="1">35091</ref>
      <ref url="http://osvdb.org/54877" source="OSVDB">54877</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2009/Jun/msg00000.html" source="APPLE" adv="1">APPLE-SA-2009-06-01-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="quicktime">
        <vers num="3" />
        <vers num="4.1.2" edition="-" />
        <vers num="4.1.2" edition="-:windows" />
        <vers num="4.1.2" edition="-:mac" />
        <vers num="5.0" />
        <vers num="5.0.1" edition="-" />
        <vers num="5.0.1" edition="-:windows" />
        <vers num="5.0.1" edition="-:mac" />
        <vers num="5.0.2" edition="-" />
        <vers num="5.0.2" edition="-:windows" />
        <vers num="5.0.2" edition="-:mac" />
        <vers num="6.0" edition="-" />
        <vers num="6.0" edition="-:windows" />
        <vers num="6.0.0" edition="-" />
        <vers num="6.0.0" edition="-:windows" />
        <vers num="6.0.0" edition="-:mac" />
        <vers num="6.0.1" edition="-" />
        <vers num="6.0.1" edition="-:windows" />
        <vers num="6.0.1" edition="-:mac" />
        <vers num="6.0.2" edition="-" />
        <vers num="6.0.2" edition="-:windows" />
        <vers num="6.0.2" edition="-:mac" />
        <vers num="6.1" />
        <vers num="6.1.0" edition="-" />
        <vers num="6.1.0" edition="-:mac" />
        <vers num="6.1.0" edition="-:windows" />
        <vers num="6.1.1" edition="-" />
        <vers num="6.1.1" edition="-:windows" />
        <vers num="6.1.1" edition="-:mac" />
        <vers num="6.2.0" edition="-" />
        <vers num="6.2.0" edition="-:windows" />
        <vers num="6.2.0" edition="-:mac" />
        <vers num="6.3.0" edition="-" />
        <vers num="6.3.0" edition="-:mac" />
        <vers num="6.3.0" edition="-:windows" />
        <vers num="6.4.0" edition="-" />
        <vers num="6.4.0" edition="-:mac" />
        <vers num="6.4.0" edition="-:windows" />
        <vers num="6.5" />
        <vers num="6.5.0" edition="-" />
        <vers num="6.5.0" edition="-:windows" />
        <vers num="6.5.0" edition="-:mac" />
        <vers num="6.5.1" edition="-" />
        <vers num="6.5.1" edition="-:mac" />
        <vers num="6.5.1" edition="-:windows" />
        <vers num="6.5.2" edition="-" />
        <vers num="6.5.2" edition="-:mac" />
        <vers num="6.5.2" edition="-:windows" />
        <vers num="7.0" edition="" />
        <vers num="7.0" edition=":windows" />
        <vers num="7.0" edition="-" />
        <vers num="7.0" edition="-:windows" />
        <vers num="7.0.0" edition="-" />
        <vers num="7.0.0" edition="-:windows" />
        <vers num="7.0.0" edition="-:mac" />
        <vers num="7.0.1" edition="" />
        <vers num="7.0.1" edition=":windows" />
        <vers num="7.0.1" edition="-" />
        <vers num="7.0.1" edition="-:mac" />
        <vers num="7.0.1" edition="-:windows" />
        <vers num="7.0.2" edition="" />
        <vers num="7.0.2" edition=":windows" />
        <vers num="7.0.2" edition="-" />
        <vers num="7.0.2" edition="-:windows" />
        <vers num="7.0.2" edition="-:mac" />
        <vers num="7.0.3" edition="-" />
        <vers num="7.0.3" edition="-:windows" />
        <vers num="7.0.3" edition="-:mac" />
        <vers num="7.0.4" edition="-" />
        <vers num="7.0.4" edition="-:windows" />
        <vers num="7.0.4" edition="-:mac" />
        <vers num="7.0.8" />
        <vers num="7.1" />
        <vers num="7.1.0" edition="-" />
        <vers num="7.1.0" edition="-:windows" />
        <vers num="7.1.0" edition="-:mac" />
        <vers num="7.1.1" edition="-" />
        <vers num="7.1.1" edition="-:mac" />
        <vers num="7.1.1" edition="-:windows" />
        <vers num="7.1.2" edition="-" />
        <vers num="7.1.2" edition="-:windows" />
        <vers num="7.1.2" edition="-:mac" />
        <vers num="7.1.3" edition="-" />
        <vers num="7.1.3" edition="-:mac" />
        <vers num="7.1.3" edition="-:windows" />
        <vers num="7.1.4" edition="-" />
        <vers num="7.1.4" edition="-:windows" />
        <vers num="7.1.4" edition="-:mac" />
        <vers num="7.1.5" edition="-" />
        <vers num="7.1.5" edition="-:windows" />
        <vers num="7.1.5" edition="-:mac" />
        <vers num="7.1.6" edition="-" />
        <vers num="7.1.6" edition="-:mac" />
        <vers num="7.1.6" edition="-:windows" />
        <vers num="7.2" edition="" />
        <vers num="7.2" edition=":vista" />
        <vers num="7.2.0" edition="-" />
        <vers num="7.2.0" edition="-:windows" />
        <vers num="7.2.0" edition="-:mac" />
        <vers num="7.2.1" edition="-" />
        <vers num="7.2.1" edition="-:mac" />
        <vers num="7.2.1" edition="-:windows" />
        <vers num="7.3" />
        <vers num="7.3.0" edition="-" />
        <vers num="7.3.0" edition="-:windows" />
        <vers num="7.3.0" edition="-:mac" />
        <vers num="7.3.1" edition="-" />
        <vers num="7.3.1" edition="-:windows" />
        <vers num="7.3.1" edition="-:mac" />
        <vers num="7.3.1.70" />
        <vers num="7.4" />
        <vers num="7.4.0" edition="-" />
        <vers num="7.4.0" edition="-:mac" />
        <vers num="7.4.0" edition="-:windows" />
        <vers num="7.4.1" edition="-" />
        <vers num="7.4.1" edition="-:mac" />
        <vers num="7.4.1" edition="-:windows" />
        <vers num="7.4.4" />
        <vers num="7.4.5" edition="-" />
        <vers num="7.4.5" edition="-:windows" />
        <vers num="7.4.5" edition="-:mac" />
        <vers num="7.5" />
        <vers num="7.5.0" edition="-" />
        <vers num="7.5.0" edition="-:windows" />
        <vers num="7.5.0" edition="-:mac" />
        <vers num="7.5.5" edition="-" />
        <vers num="7.5.5" edition="-:windows" />
        <vers num="7.5.5" edition="-:mac" />
        <vers num="7.6.0" />
        <vers prev="1" num="7.6.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0953" published="2009-06-02" name="CVE-2009-0953" modified="2009-06-09" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Heap-based buffer overflow in Apple QuickTime before 7.6.2 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted PICT image.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2009/1469" source="VUPEN" patch="1" adv="1">ADV-2009-1469</ref>
      <ref url="http://support.apple.com/kb/HT3591" source="CONFIRM" patch="1" adv="1">http://support.apple.com/kb/HT3591</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/50890" source="XF">quicktime-pictfile-bo(50890)</ref>
      <ref url="http://www.securitytracker.com/id?1022314" source="SECTRACK">1022314</ref>
      <ref url="http://www.securityfocus.com/bid/35164" source="BID">35164</ref>
      <ref url="http://secunia.com/advisories/35091" source="SECUNIA" adv="1">35091</ref>
      <ref url="http://osvdb.org/54876" source="OSVDB">54876</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2009/Jun/msg00000.html" source="APPLE" adv="1">APPLE-SA-2009-06-01-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="quicktime">
        <vers num="3" />
        <vers num="4.1.2" edition="-" />
        <vers num="4.1.2" edition="-:windows" />
        <vers num="4.1.2" edition="-:mac" />
        <vers num="5.0" />
        <vers num="5.0.1" edition="-" />
        <vers num="5.0.1" edition="-:windows" />
        <vers num="5.0.1" edition="-:mac" />
        <vers num="5.0.2" edition="-" />
        <vers num="5.0.2" edition="-:windows" />
        <vers num="5.0.2" edition="-:mac" />
        <vers num="6.0" edition="-" />
        <vers num="6.0" edition="-:windows" />
        <vers num="6.0.0" edition="-" />
        <vers num="6.0.0" edition="-:windows" />
        <vers num="6.0.0" edition="-:mac" />
        <vers num="6.0.1" edition="-" />
        <vers num="6.0.1" edition="-:windows" />
        <vers num="6.0.1" edition="-:mac" />
        <vers num="6.0.2" edition="-" />
        <vers num="6.0.2" edition="-:windows" />
        <vers num="6.0.2" edition="-:mac" />
        <vers num="6.1" />
        <vers num="6.1.0" edition="-" />
        <vers num="6.1.0" edition="-:mac" />
        <vers num="6.1.0" edition="-:windows" />
        <vers num="6.1.1" edition="-" />
        <vers num="6.1.1" edition="-:windows" />
        <vers num="6.1.1" edition="-:mac" />
        <vers num="6.2.0" edition="-" />
        <vers num="6.2.0" edition="-:windows" />
        <vers num="6.2.0" edition="-:mac" />
        <vers num="6.3.0" edition="-" />
        <vers num="6.3.0" edition="-:mac" />
        <vers num="6.3.0" edition="-:windows" />
        <vers num="6.4.0" edition="-" />
        <vers num="6.4.0" edition="-:mac" />
        <vers num="6.4.0" edition="-:windows" />
        <vers num="6.5" />
        <vers num="6.5.0" edition="-" />
        <vers num="6.5.0" edition="-:windows" />
        <vers num="6.5.0" edition="-:mac" />
        <vers num="6.5.1" edition="-" />
        <vers num="6.5.1" edition="-:mac" />
        <vers num="6.5.1" edition="-:windows" />
        <vers num="6.5.2" edition="-" />
        <vers num="6.5.2" edition="-:mac" />
        <vers num="6.5.2" edition="-:windows" />
        <vers num="7.0" edition="" />
        <vers num="7.0" edition=":windows" />
        <vers num="7.0" edition="-" />
        <vers num="7.0" edition="-:windows" />
        <vers num="7.0.0" edition="-" />
        <vers num="7.0.0" edition="-:windows" />
        <vers num="7.0.0" edition="-:mac" />
        <vers num="7.0.1" edition="" />
        <vers num="7.0.1" edition=":windows" />
        <vers num="7.0.1" edition="-" />
        <vers num="7.0.1" edition="-:mac" />
        <vers num="7.0.1" edition="-:windows" />
        <vers num="7.0.2" edition="" />
        <vers num="7.0.2" edition=":windows" />
        <vers num="7.0.2" edition="-" />
        <vers num="7.0.2" edition="-:windows" />
        <vers num="7.0.2" edition="-:mac" />
        <vers num="7.0.3" edition="-" />
        <vers num="7.0.3" edition="-:windows" />
        <vers num="7.0.3" edition="-:mac" />
        <vers num="7.0.4" edition="-" />
        <vers num="7.0.4" edition="-:windows" />
        <vers num="7.0.4" edition="-:mac" />
        <vers num="7.0.8" />
        <vers num="7.1" />
        <vers num="7.1.0" edition="-" />
        <vers num="7.1.0" edition="-:windows" />
        <vers num="7.1.0" edition="-:mac" />
        <vers num="7.1.1" edition="-" />
        <vers num="7.1.1" edition="-:mac" />
        <vers num="7.1.1" edition="-:windows" />
        <vers num="7.1.2" edition="-" />
        <vers num="7.1.2" edition="-:windows" />
        <vers num="7.1.2" edition="-:mac" />
        <vers num="7.1.3" edition="-" />
        <vers num="7.1.3" edition="-:mac" />
        <vers num="7.1.3" edition="-:windows" />
        <vers num="7.1.4" edition="-" />
        <vers num="7.1.4" edition="-:windows" />
        <vers num="7.1.4" edition="-:mac" />
        <vers num="7.1.5" edition="-" />
        <vers num="7.1.5" edition="-:windows" />
        <vers num="7.1.5" edition="-:mac" />
        <vers num="7.1.6" edition="-" />
        <vers num="7.1.6" edition="-:mac" />
        <vers num="7.1.6" edition="-:windows" />
        <vers num="7.2" edition="" />
        <vers num="7.2" edition=":vista" />
        <vers num="7.2.0" edition="-" />
        <vers num="7.2.0" edition="-:windows" />
        <vers num="7.2.0" edition="-:mac" />
        <vers num="7.2.1" edition="-" />
        <vers num="7.2.1" edition="-:mac" />
        <vers num="7.2.1" edition="-:windows" />
        <vers num="7.3" />
        <vers num="7.3.0" edition="-" />
        <vers num="7.3.0" edition="-:windows" />
        <vers num="7.3.0" edition="-:mac" />
        <vers num="7.3.1" edition="-" />
        <vers num="7.3.1" edition="-:windows" />
        <vers num="7.3.1" edition="-:mac" />
        <vers num="7.3.1.70" />
        <vers num="7.4" />
        <vers num="7.4.0" edition="-" />
        <vers num="7.4.0" edition="-:mac" />
        <vers num="7.4.0" edition="-:windows" />
        <vers num="7.4.1" edition="-" />
        <vers num="7.4.1" edition="-:mac" />
        <vers num="7.4.1" edition="-:windows" />
        <vers num="7.4.4" />
        <vers num="7.4.5" edition="-" />
        <vers num="7.4.5" edition="-:windows" />
        <vers num="7.4.5" edition="-:mac" />
        <vers num="7.5" />
        <vers num="7.5.0" edition="-" />
        <vers num="7.5.0" edition="-:windows" />
        <vers num="7.5.0" edition="-:mac" />
        <vers num="7.5.5" edition="-" />
        <vers num="7.5.5" edition="-:windows" />
        <vers num="7.5.5" edition="-:mac" />
        <vers num="7.6.0" />
        <vers prev="1" num="7.6.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0954" published="2009-06-02" name="CVE-2009-0954" modified="2009-06-09" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Heap-based buffer overflow in Apple QuickTime before 7.6.2 on Windows allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a movie file containing crafted Clipping Region (CRGN) atom types.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2009/1469" source="VUPEN" patch="1" adv="1">ADV-2009-1469</ref>
      <ref url="http://www.securityfocus.com/bid/35167" source="BID" patch="1">35167</ref>
      <ref url="http://support.apple.com/kb/HT3591" source="CONFIRM" patch="1" adv="1">http://support.apple.com/kb/HT3591</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2009/Jun/msg00000.html" source="APPLE" patch="1" adv="1">APPLE-SA-2009-06-01-1</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/50892" source="XF">quicktime-crgn-bo(50892)</ref>
      <ref url="http://www.securitytracker.com/id?1022314" source="SECTRACK">1022314</ref>
      <ref url="http://secunia.com/advisories/35091" source="SECUNIA" adv="1">35091</ref>
      <ref url="http://osvdb.org/54875" source="OSVDB">54875</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="quicktime">
        <vers num="3" />
        <vers num="4.1.2" edition="-" />
        <vers num="4.1.2" edition="-:windows" />
        <vers num="5.0" />
        <vers num="5.0.1" edition="-" />
        <vers num="5.0.1" edition="-:windows" />
        <vers num="5.0.2" edition="-" />
        <vers num="5.0.2" edition="-:windows" />
        <vers num="6.0" edition="-" />
        <vers num="6.0" edition="-:windows" />
        <vers num="6.0.0" edition="-" />
        <vers num="6.0.0" edition="-:windows" />
        <vers num="6.0.1" edition="-" />
        <vers num="6.0.1" edition="-:windows" />
        <vers num="6.0.2" edition="-" />
        <vers num="6.0.2" edition="-:windows" />
        <vers num="6.1" />
        <vers num="6.1.0" edition="-" />
        <vers num="6.1.0" edition="-:windows" />
        <vers num="6.1.1" edition="-" />
        <vers num="6.1.1" edition="-:windows" />
        <vers num="6.2.0" edition="-" />
        <vers num="6.2.0" edition="-:windows" />
        <vers num="6.3.0" edition="-" />
        <vers num="6.3.0" edition="-:windows" />
        <vers num="6.4.0" edition="-" />
        <vers num="6.4.0" edition="-:windows" />
        <vers num="6.5" />
        <vers num="6.5.0" edition="-" />
        <vers num="6.5.0" edition="-:windows" />
        <vers num="6.5.1" edition="-" />
        <vers num="6.5.1" edition="-:windows" />
        <vers num="6.5.2" edition="-" />
        <vers num="6.5.2" edition="-:windows" />
        <vers num="7.0" edition="" />
        <vers num="7.0" edition=":windows" />
        <vers num="7.0" edition="-" />
        <vers num="7.0" edition="-:windows" />
        <vers num="7.0.0" edition="-" />
        <vers num="7.0.0" edition="-:windows" />
        <vers num="7.0.1" edition="" />
        <vers num="7.0.1" edition=":windows" />
        <vers num="7.0.1" edition="-" />
        <vers num="7.0.1" edition="-:windows" />
        <vers num="7.0.2" edition="" />
        <vers num="7.0.2" edition=":windows" />
        <vers num="7.0.2" edition="-" />
        <vers num="7.0.2" edition="-:windows" />
        <vers num="7.0.3" edition="-" />
        <vers num="7.0.3" edition="-:windows" />
        <vers num="7.0.4" edition="-" />
        <vers num="7.0.4" edition="-:windows" />
        <vers num="7.0.8" />
        <vers num="7.1" />
        <vers num="7.1.0" edition="-" />
        <vers num="7.1.0" edition="-:windows" />
        <vers num="7.1.1" edition="-" />
        <vers num="7.1.1" edition="-:windows" />
        <vers num="7.1.2" edition="-" />
        <vers num="7.1.2" edition="-:windows" />
        <vers num="7.1.3" edition="-" />
        <vers num="7.1.3" edition="-:windows" />
        <vers num="7.1.4" edition="-" />
        <vers num="7.1.4" edition="-:windows" />
        <vers num="7.1.5" edition="-" />
        <vers num="7.1.5" edition="-:windows" />
        <vers num="7.1.6" edition="-" />
        <vers num="7.1.6" edition="-:windows" />
        <vers num="7.2" />
        <vers num="7.2.0" edition="-" />
        <vers num="7.2.0" edition="-:windows" />
        <vers num="7.2.1" edition="-" />
        <vers num="7.2.1" edition="-:windows" />
        <vers num="7.3" />
        <vers num="7.3.0" edition="-" />
        <vers num="7.3.0" edition="-:windows" />
        <vers num="7.3.1" edition="-" />
        <vers num="7.3.1" edition="-:windows" />
        <vers num="7.3.1.70" />
        <vers num="7.4" />
        <vers num="7.4.0" edition="-" />
        <vers num="7.4.0" edition="-:windows" />
        <vers num="7.4.1" edition="-" />
        <vers num="7.4.1" edition="-:windows" />
        <vers num="7.4.4" />
        <vers num="7.4.5" edition="-" />
        <vers num="7.4.5" edition="-:windows" />
        <vers num="7.5" />
        <vers num="7.5.0" edition="-" />
        <vers num="7.5.0" edition="-:windows" />
        <vers num="7.5.5" edition="-" />
        <vers num="7.5.5" edition="-:windows" />
        <vers num="7.6.0" />
        <vers prev="1" num="7.6.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0955" published="2009-06-02" name="CVE-2009-0955" modified="2009-06-09" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Apple QuickTime before 7.6.2 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via crafted image description atoms in an Apple video file, related to a "sign extension issue."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2009/1469" source="VUPEN" patch="1" adv="1">ADV-2009-1469</ref>
      <ref url="http://www.securityfocus.com/bid/35166" source="BID" patch="1">35166</ref>
      <ref url="http://support.apple.com/kb/HT3591" source="CONFIRM" patch="1" adv="1">http://support.apple.com/kb/HT3591</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/50895" source="XF">quicktime-image-description-code-exec(50895)</ref>
      <ref url="http://www.securitytracker.com/id?1022314" source="SECTRACK">1022314</ref>
      <ref url="http://secunia.com/advisories/35091" source="SECUNIA" adv="1">35091</ref>
      <ref url="http://osvdb.org/54874" source="OSVDB">54874</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2009/Jun/msg00000.html" source="APPLE" adv="1">APPLE-SA-2009-06-01-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="quicktime">
        <vers num="3" />
        <vers num="4.1.2" edition="-" />
        <vers num="4.1.2" edition="-:windows" />
        <vers num="4.1.2" edition="-:mac" />
        <vers num="5.0" />
        <vers num="5.0.1" edition="-" />
        <vers num="5.0.1" edition="-:windows" />
        <vers num="5.0.1" edition="-:mac" />
        <vers num="5.0.2" edition="-" />
        <vers num="5.0.2" edition="-:windows" />
        <vers num="5.0.2" edition="-:mac" />
        <vers num="6.0" edition="-" />
        <vers num="6.0" edition="-:windows" />
        <vers num="6.0.0" edition="-" />
        <vers num="6.0.0" edition="-:windows" />
        <vers num="6.0.0" edition="-:mac" />
        <vers num="6.0.1" edition="-" />
        <vers num="6.0.1" edition="-:windows" />
        <vers num="6.0.1" edition="-:mac" />
        <vers num="6.0.2" edition="-" />
        <vers num="6.0.2" edition="-:windows" />
        <vers num="6.0.2" edition="-:mac" />
        <vers num="6.1" />
        <vers num="6.1.0" edition="-" />
        <vers num="6.1.0" edition="-:mac" />
        <vers num="6.1.0" edition="-:windows" />
        <vers num="6.1.1" edition="-" />
        <vers num="6.1.1" edition="-:windows" />
        <vers num="6.1.1" edition="-:mac" />
        <vers num="6.2.0" edition="-" />
        <vers num="6.2.0" edition="-:windows" />
        <vers num="6.2.0" edition="-:mac" />
        <vers num="6.3.0" edition="-" />
        <vers num="6.3.0" edition="-:mac" />
        <vers num="6.3.0" edition="-:windows" />
        <vers num="6.4.0" edition="-" />
        <vers num="6.4.0" edition="-:mac" />
        <vers num="6.4.0" edition="-:windows" />
        <vers num="6.5" />
        <vers num="6.5.0" edition="-" />
        <vers num="6.5.0" edition="-:windows" />
        <vers num="6.5.0" edition="-:mac" />
        <vers num="6.5.1" edition="-" />
        <vers num="6.5.1" edition="-:mac" />
        <vers num="6.5.1" edition="-:windows" />
        <vers num="6.5.2" edition="-" />
        <vers num="6.5.2" edition="-:mac" />
        <vers num="6.5.2" edition="-:windows" />
        <vers num="7.0" edition="" />
        <vers num="7.0" edition=":windows" />
        <vers num="7.0" edition="-" />
        <vers num="7.0" edition="-:windows" />
        <vers num="7.0.0" edition="-" />
        <vers num="7.0.0" edition="-:windows" />
        <vers num="7.0.0" edition="-:mac" />
        <vers num="7.0.1" edition="" />
        <vers num="7.0.1" edition=":windows" />
        <vers num="7.0.1" edition="-" />
        <vers num="7.0.1" edition="-:mac" />
        <vers num="7.0.1" edition="-:windows" />
        <vers num="7.0.2" edition="" />
        <vers num="7.0.2" edition=":windows" />
        <vers num="7.0.2" edition="-" />
        <vers num="7.0.2" edition="-:windows" />
        <vers num="7.0.2" edition="-:mac" />
        <vers num="7.0.3" edition="-" />
        <vers num="7.0.3" edition="-:windows" />
        <vers num="7.0.3" edition="-:mac" />
        <vers num="7.0.4" edition="-" />
        <vers num="7.0.4" edition="-:windows" />
        <vers num="7.0.4" edition="-:mac" />
        <vers num="7.0.8" />
        <vers num="7.1" />
        <vers num="7.1.0" edition="-" />
        <vers num="7.1.0" edition="-:windows" />
        <vers num="7.1.0" edition="-:mac" />
        <vers num="7.1.1" edition="-" />
        <vers num="7.1.1" edition="-:mac" />
        <vers num="7.1.1" edition="-:windows" />
        <vers num="7.1.2" edition="-" />
        <vers num="7.1.2" edition="-:windows" />
        <vers num="7.1.2" edition="-:mac" />
        <vers num="7.1.3" edition="-" />
        <vers num="7.1.3" edition="-:mac" />
        <vers num="7.1.3" edition="-:windows" />
        <vers num="7.1.4" edition="-" />
        <vers num="7.1.4" edition="-:windows" />
        <vers num="7.1.4" edition="-:mac" />
        <vers num="7.1.5" edition="-" />
        <vers num="7.1.5" edition="-:windows" />
        <vers num="7.1.5" edition="-:mac" />
        <vers num="7.1.6" edition="-" />
        <vers num="7.1.6" edition="-:mac" />
        <vers num="7.1.6" edition="-:windows" />
        <vers num="7.2" edition="" />
        <vers num="7.2" edition=":vista" />
        <vers num="7.2.0" edition="-" />
        <vers num="7.2.0" edition="-:windows" />
        <vers num="7.2.0" edition="-:mac" />
        <vers num="7.2.1" edition="-" />
        <vers num="7.2.1" edition="-:mac" />
        <vers num="7.2.1" edition="-:windows" />
        <vers num="7.3" />
        <vers num="7.3.0" edition="-" />
        <vers num="7.3.0" edition="-:windows" />
        <vers num="7.3.0" edition="-:mac" />
        <vers num="7.3.1" edition="-" />
        <vers num="7.3.1" edition="-:windows" />
        <vers num="7.3.1" edition="-:mac" />
        <vers num="7.3.1.70" />
        <vers num="7.4" />
        <vers num="7.4.0" edition="-" />
        <vers num="7.4.0" edition="-:mac" />
        <vers num="7.4.0" edition="-:windows" />
        <vers num="7.4.1" edition="-" />
        <vers num="7.4.1" edition="-:mac" />
        <vers num="7.4.1" edition="-:windows" />
        <vers num="7.4.4" />
        <vers num="7.4.5" edition="-" />
        <vers num="7.4.5" edition="-:windows" />
        <vers num="7.4.5" edition="-:mac" />
        <vers num="7.5.0" edition="-" />
        <vers num="7.5.0" edition="-:windows" />
        <vers num="7.5.0" edition="-:mac" />
        <vers num="7.5.5" edition="-" />
        <vers num="7.5.5" edition="-:windows" />
        <vers num="7.5.5" edition="-:mac" />
        <vers num="7.6.0" edition="-" />
        <vers num="7.6.0" edition="-:windows" />
        <vers num="7.6.0" edition="-:mac" />
        <vers prev="1" num="7.6.1" edition="-" />
        <vers prev="1" num="7.6.1" edition="-:windows" />
        <vers prev="1" num="7.6.1" edition="-:mac" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0956" published="2009-06-02" name="CVE-2009-0956" modified="2009-06-09" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Apple QuickTime before 7.6.2 does not properly initialize memory before use in handling movie files, which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a movie containing a user data atom of size zero.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2009/1469" source="VUPEN" patch="1" adv="1">ADV-2009-1469</ref>
      <ref url="http://www.securityfocus.com/bid/35162" source="BID" patch="1">35162</ref>
      <ref url="http://support.apple.com/kb/HT3591" source="CONFIRM" patch="1" adv="1">http://support.apple.com/kb/HT3591</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2009/Jun/msg00000.html" source="APPLE" patch="1" adv="1">APPLE-SA-2009-06-01-1</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/50896" source="XF">quicktime-userdata-code-execution(50896)</ref>
      <ref url="http://www.securitytracker.com/id?1022314" source="SECTRACK">1022314</ref>
      <ref url="http://secunia.com/advisories/35091" source="SECUNIA" adv="1">35091</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="quicktime">
        <vers num="3" />
        <vers num="4.1.2" edition="-" />
        <vers num="4.1.2" edition="-:windows" />
        <vers num="4.1.2" edition="-:mac" />
        <vers num="5.0" />
        <vers num="5.0.1" edition="-" />
        <vers num="5.0.1" edition="-:windows" />
        <vers num="5.0.1" edition="-:mac" />
        <vers num="5.0.2" edition="-" />
        <vers num="5.0.2" edition="-:windows" />
        <vers num="5.0.2" edition="-:mac" />
        <vers num="6.0" edition="-" />
        <vers num="6.0" edition="-:windows" />
        <vers num="6.0.0" edition="-" />
        <vers num="6.0.0" edition="-:windows" />
        <vers num="6.0.0" edition="-:mac" />
        <vers num="6.0.1" edition="-" />
        <vers num="6.0.1" edition="-:windows" />
        <vers num="6.0.1" edition="-:mac" />
        <vers num="6.0.2" edition="-" />
        <vers num="6.0.2" edition="-:windows" />
        <vers num="6.0.2" edition="-:mac" />
        <vers num="6.1" />
        <vers num="6.1.0" edition="-" />
        <vers num="6.1.0" edition="-:mac" />
        <vers num="6.1.0" edition="-:windows" />
        <vers num="6.1.1" edition="-" />
        <vers num="6.1.1" edition="-:windows" />
        <vers num="6.1.1" edition="-:mac" />
        <vers num="6.2.0" edition="-" />
        <vers num="6.2.0" edition="-:windows" />
        <vers num="6.2.0" edition="-:mac" />
        <vers num="6.3.0" edition="-" />
        <vers num="6.3.0" edition="-:mac" />
        <vers num="6.3.0" edition="-:windows" />
        <vers num="6.4.0" edition="-" />
        <vers num="6.4.0" edition="-:mac" />
        <vers num="6.4.0" edition="-:windows" />
        <vers num="6.5" />
        <vers num="6.5.0" edition="-" />
        <vers num="6.5.0" edition="-:windows" />
        <vers num="6.5.0" edition="-:mac" />
        <vers num="6.5.1" edition="-" />
        <vers num="6.5.1" edition="-:mac" />
        <vers num="6.5.1" edition="-:windows" />
        <vers num="6.5.2" edition="-" />
        <vers num="6.5.2" edition="-:mac" />
        <vers num="6.5.2" edition="-:windows" />
        <vers num="7.0" edition="" />
        <vers num="7.0" edition=":windows" />
        <vers num="7.0" edition="-" />
        <vers num="7.0" edition="-:windows" />
        <vers num="7.0.0" edition="-" />
        <vers num="7.0.0" edition="-:windows" />
        <vers num="7.0.0" edition="-:mac" />
        <vers num="7.0.1" edition="" />
        <vers num="7.0.1" edition=":windows" />
        <vers num="7.0.1" edition="-" />
        <vers num="7.0.1" edition="-:mac" />
        <vers num="7.0.1" edition="-:windows" />
        <vers num="7.0.2" edition="" />
        <vers num="7.0.2" edition=":windows" />
        <vers num="7.0.2" edition="-" />
        <vers num="7.0.2" edition="-:windows" />
        <vers num="7.0.2" edition="-:mac" />
        <vers num="7.0.3" edition="-" />
        <vers num="7.0.3" edition="-:windows" />
        <vers num="7.0.3" edition="-:mac" />
        <vers num="7.0.4" edition="-" />
        <vers num="7.0.4" edition="-:windows" />
        <vers num="7.0.4" edition="-:mac" />
        <vers num="7.0.8" />
        <vers num="7.1" />
        <vers num="7.1.0" edition="-" />
        <vers num="7.1.0" edition="-:windows" />
        <vers num="7.1.0" edition="-:mac" />
        <vers num="7.1.1" edition="-" />
        <vers num="7.1.1" edition="-:mac" />
        <vers num="7.1.1" edition="-:windows" />
        <vers num="7.1.2" edition="-" />
        <vers num="7.1.2" edition="-:windows" />
        <vers num="7.1.2" edition="-:mac" />
        <vers num="7.1.3" edition="-" />
        <vers num="7.1.3" edition="-:mac" />
        <vers num="7.1.3" edition="-:windows" />
        <vers num="7.1.4" edition="-" />
        <vers num="7.1.4" edition="-:windows" />
        <vers num="7.1.4" edition="-:mac" />
        <vers num="7.1.5" edition="-" />
        <vers num="7.1.5" edition="-:windows" />
        <vers num="7.1.5" edition="-:mac" />
        <vers num="7.1.6" edition="-" />
        <vers num="7.1.6" edition="-:mac" />
        <vers num="7.1.6" edition="-:windows" />
        <vers num="7.2" edition="" />
        <vers num="7.2" edition=":vista" />
        <vers num="7.2.0" edition="-" />
        <vers num="7.2.0" edition="-:windows" />
        <vers num="7.2.0" edition="-:mac" />
        <vers num="7.2.1" edition="-" />
        <vers num="7.2.1" edition="-:mac" />
        <vers num="7.2.1" edition="-:windows" />
        <vers num="7.3" />
        <vers num="7.3.0" edition="-" />
        <vers num="7.3.0" edition="-:windows" />
        <vers num="7.3.0" edition="-:mac" />
        <vers num="7.3.1" edition="-" />
        <vers num="7.3.1" edition="-:windows" />
        <vers num="7.3.1" edition="-:mac" />
        <vers num="7.3.1.70" />
        <vers num="7.4" />
        <vers num="7.4.0" edition="-" />
        <vers num="7.4.0" edition="-:mac" />
        <vers num="7.4.0" edition="-:windows" />
        <vers num="7.4.1" edition="-" />
        <vers num="7.4.1" edition="-:mac" />
        <vers num="7.4.1" edition="-:windows" />
        <vers num="7.4.4" />
        <vers num="7.4.5" edition="-" />
        <vers num="7.4.5" edition="-:windows" />
        <vers num="7.4.5" edition="-:mac" />
        <vers num="7.5" />
        <vers num="7.5.0" edition="-" />
        <vers num="7.5.0" edition="-:windows" />
        <vers num="7.5.0" edition="-:mac" />
        <vers num="7.5.5" edition="-" />
        <vers num="7.5.5" edition="-:windows" />
        <vers num="7.5.5" edition="-:mac" />
        <vers num="7.6.0" />
        <vers prev="1" num="7.6.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0957" published="2009-06-02" name="CVE-2009-0957" modified="2009-06-09" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Heap-based buffer overflow in Apple QuickTime before 7.6.2 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted JP2 image.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2009/1469" source="VUPEN" patch="1" adv="1">ADV-2009-1469</ref>
      <ref url="http://www.securityfocus.com/bid/35165" source="BID" patch="1">35165</ref>
      <ref url="http://support.apple.com/kb/HT3591" source="CONFIRM" patch="1" adv="1">http://support.apple.com/kb/HT3591</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2009/Jun/msg00000.html" source="APPLE" patch="1" adv="1">APPLE-SA-2009-06-01-1</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/50898" source="XF">quicktime-jp2-bo(50898)</ref>
      <ref url="http://www.securitytracker.com/id?1022314" source="SECTRACK">1022314</ref>
      <ref url="http://secunia.com/advisories/35091" source="SECUNIA" adv="1">35091</ref>
      <ref url="http://osvdb.org/54873" source="OSVDB">54873</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="quicktime">
        <vers num="3" />
        <vers num="4.1.2" edition="-" />
        <vers num="4.1.2" edition="-:windows" />
        <vers num="4.1.2" edition="-:mac" />
        <vers num="5.0" />
        <vers num="5.0.1" edition="-" />
        <vers num="5.0.1" edition="-:windows" />
        <vers num="5.0.1" edition="-:mac" />
        <vers num="5.0.2" edition="-" />
        <vers num="5.0.2" edition="-:windows" />
        <vers num="5.0.2" edition="-:mac" />
        <vers num="6.0" edition="-" />
        <vers num="6.0" edition="-:windows" />
        <vers num="6.0.0" edition="-" />
        <vers num="6.0.0" edition="-:windows" />
        <vers num="6.0.0" edition="-:mac" />
        <vers num="6.0.1" edition="-" />
        <vers num="6.0.1" edition="-:windows" />
        <vers num="6.0.1" edition="-:mac" />
        <vers num="6.0.2" edition="-" />
        <vers num="6.0.2" edition="-:windows" />
        <vers num="6.0.2" edition="-:mac" />
        <vers num="6.1" />
        <vers num="6.1.0" edition="-" />
        <vers num="6.1.0" edition="-:mac" />
        <vers num="6.1.0" edition="-:windows" />
        <vers num="6.1.1" edition="-" />
        <vers num="6.1.1" edition="-:windows" />
        <vers num="6.1.1" edition="-:mac" />
        <vers num="6.2.0" edition="-" />
        <vers num="6.2.0" edition="-:windows" />
        <vers num="6.2.0" edition="-:mac" />
        <vers num="6.3.0" edition="-" />
        <vers num="6.3.0" edition="-:mac" />
        <vers num="6.3.0" edition="-:windows" />
        <vers num="6.4.0" edition="-" />
        <vers num="6.4.0" edition="-:mac" />
        <vers num="6.4.0" edition="-:windows" />
        <vers num="6.5" />
        <vers num="6.5.0" edition="-" />
        <vers num="6.5.0" edition="-:windows" />
        <vers num="6.5.0" edition="-:mac" />
        <vers num="6.5.1" edition="-" />
        <vers num="6.5.1" edition="-:mac" />
        <vers num="6.5.1" edition="-:windows" />
        <vers num="6.5.2" edition="-" />
        <vers num="6.5.2" edition="-:mac" />
        <vers num="6.5.2" edition="-:windows" />
        <vers num="7.0" edition="" />
        <vers num="7.0" edition=":windows" />
        <vers num="7.0" edition="-" />
        <vers num="7.0" edition="-:windows" />
        <vers num="7.0.0" edition="-" />
        <vers num="7.0.0" edition="-:windows" />
        <vers num="7.0.0" edition="-:mac" />
        <vers num="7.0.1" edition="" />
        <vers num="7.0.1" edition=":windows" />
        <vers num="7.0.1" edition="-" />
        <vers num="7.0.1" edition="-:mac" />
        <vers num="7.0.1" edition="-:windows" />
        <vers num="7.0.2" edition="" />
        <vers num="7.0.2" edition=":windows" />
        <vers num="7.0.2" edition="-" />
        <vers num="7.0.2" edition="-:windows" />
        <vers num="7.0.2" edition="-:mac" />
        <vers num="7.0.3" edition="-" />
        <vers num="7.0.3" edition="-:windows" />
        <vers num="7.0.3" edition="-:mac" />
        <vers num="7.0.4" edition="-" />
        <vers num="7.0.4" edition="-:windows" />
        <vers num="7.0.4" edition="-:mac" />
        <vers num="7.0.8" />
        <vers num="7.1" />
        <vers num="7.1.0" edition="-" />
        <vers num="7.1.0" edition="-:windows" />
        <vers num="7.1.0" edition="-:mac" />
        <vers num="7.1.1" edition="-" />
        <vers num="7.1.1" edition="-:mac" />
        <vers num="7.1.1" edition="-:windows" />
        <vers num="7.1.2" edition="-" />
        <vers num="7.1.2" edition="-:windows" />
        <vers num="7.1.2" edition="-:mac" />
        <vers num="7.1.3" edition="-" />
        <vers num="7.1.3" edition="-:mac" />
        <vers num="7.1.3" edition="-:windows" />
        <vers num="7.1.4" edition="-" />
        <vers num="7.1.4" edition="-:windows" />
        <vers num="7.1.4" edition="-:mac" />
        <vers num="7.1.5" edition="-" />
        <vers num="7.1.5" edition="-:windows" />
        <vers num="7.1.5" edition="-:mac" />
        <vers num="7.1.6" edition="-" />
        <vers num="7.1.6" edition="-:mac" />
        <vers num="7.1.6" edition="-:windows" />
        <vers num="7.2" edition="" />
        <vers num="7.2" edition=":vista" />
        <vers num="7.2.0" edition="-" />
        <vers num="7.2.0" edition="-:windows" />
        <vers num="7.2.0" edition="-:mac" />
        <vers num="7.2.1" edition="-" />
        <vers num="7.2.1" edition="-:mac" />
        <vers num="7.2.1" edition="-:windows" />
        <vers num="7.3" />
        <vers num="7.3.0" edition="-" />
        <vers num="7.3.0" edition="-:windows" />
        <vers num="7.3.0" edition="-:mac" />
        <vers num="7.3.1" edition="-" />
        <vers num="7.3.1" edition="-:windows" />
        <vers num="7.3.1" edition="-:mac" />
        <vers num="7.3.1.70" />
        <vers num="7.4" />
        <vers num="7.4.0" edition="-" />
        <vers num="7.4.0" edition="-:mac" />
        <vers num="7.4.0" edition="-:windows" />
        <vers num="7.4.1" edition="-" />
        <vers num="7.4.1" edition="-:mac" />
        <vers num="7.4.1" edition="-:windows" />
        <vers num="7.4.4" />
        <vers num="7.4.5" edition="-" />
        <vers num="7.4.5" edition="-:windows" />
        <vers num="7.4.5" edition="-:mac" />
        <vers num="7.5" />
        <vers num="7.5.0" edition="-" />
        <vers num="7.5.0" edition="-:windows" />
        <vers num="7.5.0" edition="-:mac" />
        <vers num="7.5.5" edition="-" />
        <vers num="7.5.5" edition="-:windows" />
        <vers num="7.5.5" edition="-:mac" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0958" published="2009-06-19" name="CVE-2009-0958" modified="2009-06-24" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:N/A:N)" CVSS_score="7.1" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="8.6" CVSS_base_score="7.1">
    <desc>
      <descript source="cve">Apple iPhone OS 1.0 through 2.2.1 and iPhone OS for iPod touch 1.1 through 2.2.1 stores an exception for a hostname when the user accepts an untrusted Exchange server certificate, which causes it to be accepted without prompting in future usage and allows remote Exchange servers to obtain sensitive information such as credentials.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://support.apple.com/kb/HT3639" source="CONFIRM" patch="1" adv="1">http://support.apple.com/kb/HT3639</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/51208" source="XF">iphone-ipod-certificate-info-disclosure(51208)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1621" source="VUPEN">ADV-2009-1621</ref>
      <ref url="http://www.securityfocus.com/bid/35447" source="BID">35447</ref>
      <ref url="http://www.securityfocus.com/bid/35414" source="BID">35414</ref>
      <ref url="http://osvdb.org/55236" source="OSVDB">55236</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2009/Jun/msg00005.html" source="APPLE" adv="1">APPLE-SA-2009-06-17-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="iphone_os">
        <vers num="1.0.0" edition="-" />
        <vers num="1.0.0" edition="-:iphone" />
        <vers num="1.0.1" edition="-" />
        <vers num="1.0.1" edition="-:iphone" />
        <vers num="1.0.2" edition="-" />
        <vers num="1.0.2" edition="-:iphone" />
        <vers num="1.1.0" edition="-" />
        <vers num="1.1.0" edition="-:ipodtouch" />
        <vers num="1.1.0" edition="-:iphone" />
        <vers num="1.1.1" edition="-" />
        <vers num="1.1.1" edition="-:ipodtouch" />
        <vers num="1.1.1" edition="-:iphone" />
        <vers num="1.1.2" edition="-" />
        <vers num="1.1.2" edition="-:ipodtouch" />
        <vers num="1.1.2" edition="-:iphone" />
        <vers num="1.1.3" edition="-" />
        <vers num="1.1.3" edition="-:iphone" />
        <vers num="1.1.3" edition="-:ipodtouch" />
        <vers num="1.1.4" edition="-" />
        <vers num="1.1.4" edition="-:ipodtouch" />
        <vers num="1.1.4" edition="-:iphone" />
        <vers num="1.1.5" edition="-" />
        <vers num="1.1.5" edition="-:iphone" />
        <vers num="1.1.5" edition="-:ipodtouch" />
        <vers num="2.0.0" edition="-" />
        <vers num="2.0.0" edition="-:ipodtouch" />
        <vers num="2.0.0" edition="-:iphone" />
        <vers num="2.0.1" edition="-" />
        <vers num="2.0.1" edition="-:ipodtouch" />
        <vers num="2.0.1" edition="-:iphone" />
        <vers num="2.0.2" edition="-" />
        <vers num="2.0.2" edition="-:iphone" />
        <vers num="2.1" edition="-" />
        <vers num="2.1" edition="-:ipodtouch" />
        <vers num="2.1" edition="-:iphone" />
        <vers num="2.2" edition="-" />
        <vers num="2.2" edition="-:ipodtouch" />
        <vers num="2.2" edition="-:iphone" />
        <vers num="2.2.1" edition="-" />
        <vers num="2.2.1" edition="-:iphone" />
        <vers num="2.2.1" edition="-:ipodtouch" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0959" published="2009-06-19" name="CVE-2009-0959" modified="2009-06-24" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:C)" CVSS_score="7.1" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="8.6" CVSS_base_score="7.1">
    <desc>
      <descript source="cve">The MPEG-4 video codec in Apple iPhone OS 1.0 through 2.2.1 and iPhone OS for iPod touch 1.1 through 2.2.1 allows remote attackers to cause a denial of service (device reset) via a crafted MPEG-4 video file that triggers an "input validation issue."</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://support.apple.com/kb/HT3639" source="CONFIRM" patch="1" adv="1">http://support.apple.com/kb/HT3639</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/51211" source="XF">ipod-iphone-mpeg4-dos(51211)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1621" source="VUPEN">ADV-2009-1621</ref>
      <ref url="http://www.securityfocus.com/bid/35433" source="BID">35433</ref>
      <ref url="http://www.securityfocus.com/bid/35414" source="BID">35414</ref>
      <ref url="http://osvdb.org/55237" source="OSVDB">55237</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2009/Jun/msg00005.html" source="APPLE" adv="1">APPLE-SA-2009-06-17-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="iphone_os">
        <vers num="1.0.0" edition="-" />
        <vers num="1.0.0" edition="-:iphone" />
        <vers num="1.0.1" edition="-" />
        <vers num="1.0.1" edition="-:iphone" />
        <vers num="1.0.2" edition="-" />
        <vers num="1.0.2" edition="-:iphone" />
        <vers num="1.1.0" edition="-" />
        <vers num="1.1.0" edition="-:ipodtouch" />
        <vers num="1.1.0" edition="-:iphone" />
        <vers num="1.1.1" edition="-" />
        <vers num="1.1.1" edition="-:ipodtouch" />
        <vers num="1.1.1" edition="-:iphone" />
        <vers num="1.1.2" edition="-" />
        <vers num="1.1.2" edition="-:ipodtouch" />
        <vers num="1.1.2" edition="-:iphone" />
        <vers num="1.1.3" edition="-" />
        <vers num="1.1.3" edition="-:iphone" />
        <vers num="1.1.3" edition="-:ipodtouch" />
        <vers num="1.1.4" edition="-" />
        <vers num="1.1.4" edition="-:ipodtouch" />
        <vers num="1.1.4" edition="-:iphone" />
        <vers num="1.1.5" edition="-" />
        <vers num="1.1.5" edition="-:iphone" />
        <vers num="1.1.5" edition="-:ipodtouch" />
        <vers num="2.0.0" edition="-" />
        <vers num="2.0.0" edition="-:ipodtouch" />
        <vers num="2.0.0" edition="-:iphone" />
        <vers num="2.0.1" edition="-" />
        <vers num="2.0.1" edition="-:ipodtouch" />
        <vers num="2.0.1" edition="-:iphone" />
        <vers num="2.0.2" edition="-" />
        <vers num="2.0.2" edition="-:iphone" />
        <vers num="2.1" edition="-" />
        <vers num="2.1" edition="-:ipodtouch" />
        <vers num="2.1" edition="-:iphone" />
        <vers num="2.2" edition="-" />
        <vers num="2.2" edition="-:ipodtouch" />
        <vers num="2.2" edition="-:iphone" />
        <vers num="2.2.1" edition="-" />
        <vers num="2.2.1" edition="-:iphone" />
        <vers num="2.2.1" edition="-:ipodtouch" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0960" published="2009-06-19" name="CVE-2009-0960" modified="2009-06-24" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:N/A:N)" CVSS_score="7.1" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="8.6" CVSS_base_score="7.1">
    <desc>
      <descript source="cve">The Mail component in Apple iPhone OS 1.0 through 2.2.1 and iPhone OS for iPod touch 1.1 through 2.2.1 does not provide an option to disable remote image loading in HTML email, which allows remote attackers to determine the device address and when an e-mail is read via an HTML email containing an image URL.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://support.apple.com/kb/HT3639" source="CONFIRM" patch="1" adv="1">http://support.apple.com/kb/HT3639</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2009/Jun/msg00005.html" source="APPLE" patch="1" adv="1">APPLE-SA-2009-06-17-1</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/51209" source="XF">iphone-ipod-mail-weak-security(51209)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1621" source="VUPEN" adv="1">ADV-2009-1621</ref>
      <ref url="http://www.securityfocus.com/bid/35434" source="BID">35434</ref>
      <ref url="http://www.securityfocus.com/bid/35414" source="BID">35414</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="iphone_os">
        <vers num="1.0.0" edition="-" />
        <vers num="1.0.0" edition="-:iphone" />
        <vers num="1.0.1" edition="-" />
        <vers num="1.0.1" edition="-:iphone" />
        <vers num="1.0.2" edition="-" />
        <vers num="1.0.2" edition="-:iphone" />
        <vers num="1.1.0" edition="-" />
        <vers num="1.1.0" edition="-:ipodtouch" />
        <vers num="1.1.0" edition="-:iphone" />
        <vers num="1.1.1" edition="-" />
        <vers num="1.1.1" edition="-:ipodtouch" />
        <vers num="1.1.1" edition="-:iphone" />
        <vers num="1.1.2" edition="-" />
        <vers num="1.1.2" edition="-:ipodtouch" />
        <vers num="1.1.2" edition="-:iphone" />
        <vers num="1.1.3" edition="-" />
        <vers num="1.1.3" edition="-:iphone" />
        <vers num="1.1.3" edition="-:ipodtouch" />
        <vers num="1.1.4" edition="-" />
        <vers num="1.1.4" edition="-:ipodtouch" />
        <vers num="1.1.4" edition="-:iphone" />
        <vers num="1.1.5" edition="-" />
        <vers num="1.1.5" edition="-:iphone" />
        <vers num="1.1.5" edition="-:ipodtouch" />
        <vers num="2.0.0" edition="-" />
        <vers num="2.0.0" edition="-:ipodtouch" />
        <vers num="2.0.0" edition="-:iphone" />
        <vers num="2.0.1" edition="-" />
        <vers num="2.0.1" edition="-:ipodtouch" />
        <vers num="2.0.1" edition="-:iphone" />
        <vers num="2.0.2" edition="-" />
        <vers num="2.0.2" edition="-:iphone" />
        <vers num="2.1" edition="-" />
        <vers num="2.1" edition="-:ipodtouch" />
        <vers num="2.1" edition="-:iphone" />
        <vers num="2.2" edition="-" />
        <vers num="2.2" edition="-:ipodtouch" />
        <vers num="2.2" edition="-:iphone" />
        <vers num="2.2.1" edition="-" />
        <vers num="2.2.1" edition="-:iphone" />
        <vers num="2.2.1" edition="-:ipodtouch" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0961" published="2009-06-19" name="CVE-2009-0961" modified="2009-06-24" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The Mail component in Apple iPhone OS 1.0 through 2.2.1 and iPhone OS for iPod touch 1.1 through 2.2.1 dismisses the call approval dialog when another alert appears, which might allow remote attackers to force the iPhone to place a call without user approval by causing an application to trigger an alert.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://support.apple.com/kb/HT3639" source="CONFIRM" patch="1" adv="1">http://support.apple.com/kb/HT3639</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/51210" source="XF">iphone-ipod-mail-security-bypass(51210)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1621" source="VUPEN">ADV-2009-1621</ref>
      <ref url="http://www.securityfocus.com/bid/35414" source="BID">35414</ref>
      <ref url="http://osvdb.org/55238" source="OSVDB">55238</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2009/Jun/msg00005.html" source="APPLE" adv="1">APPLE-SA-2009-06-17-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="iphone_os">
        <vers num="1.0.0" edition="-" />
        <vers num="1.0.0" edition="-:iphone" />
        <vers num="1.0.1" edition="-" />
        <vers num="1.0.1" edition="-:iphone" />
        <vers num="1.0.2" edition="-" />
        <vers num="1.0.2" edition="-:iphone" />
        <vers num="1.1.0" edition="-" />
        <vers num="1.1.0" edition="-:ipodtouch" />
        <vers num="1.1.0" edition="-:iphone" />
        <vers num="1.1.1" edition="-" />
        <vers num="1.1.1" edition="-:ipodtouch" />
        <vers num="1.1.1" edition="-:iphone" />
        <vers num="1.1.2" edition="-" />
        <vers num="1.1.2" edition="-:ipodtouch" />
        <vers num="1.1.2" edition="-:iphone" />
        <vers num="1.1.3" edition="-" />
        <vers num="1.1.3" edition="-:iphone" />
        <vers num="1.1.3" edition="-:ipodtouch" />
        <vers num="1.1.4" edition="-" />
        <vers num="1.1.4" edition="-:ipodtouch" />
        <vers num="1.1.4" edition="-:iphone" />
        <vers num="1.1.5" edition="-" />
        <vers num="1.1.5" edition="-:iphone" />
        <vers num="1.1.5" edition="-:ipodtouch" />
        <vers num="2.0.0" edition="-" />
        <vers num="2.0.0" edition="-:ipodtouch" />
        <vers num="2.0.0" edition="-:iphone" />
        <vers num="2.0.1" edition="-" />
        <vers num="2.0.1" edition="-:ipodtouch" />
        <vers num="2.0.1" edition="-:iphone" />
        <vers num="2.0.2" edition="-" />
        <vers num="2.0.2" edition="-:iphone" />
        <vers num="2.1" edition="-" />
        <vers num="2.1" edition="-:ipodtouch" />
        <vers num="2.1" edition="-:iphone" />
        <vers num="2.2" edition="-" />
        <vers num="2.2" edition="-:ipodtouch" />
        <vers num="2.2" edition="-:iphone" />
        <vers num="2.2.1" edition="-" />
        <vers num="2.2.1" edition="-:iphone" />
        <vers num="2.2.1" edition="-:ipodtouch" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0962" published="2009-03-18" name="CVE-2009-0962" modified="2009-03-19" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Unspecified vulnerability in Futomi's CGI Cafe MP Form Mail CGI eCommerce 1.3.0 and earlier, and CGI Professional 3.2.2 and earlier, allows remote attackers to gain administrative privileges via unknown attack vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/49180" source="XF">mpformmailcgi-pro-unspecified-sec-bypass(49180)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/49179" source="XF">mpformmailcgi-ecom-unspecified-sec-bypass(49179)</ref>
      <ref url="http://www.securityfocus.com/bid/34071" source="BID">34071</ref>
      <ref url="http://www.futomi.com/library/info/2009/20090310.html" source="CONFIRM" adv="1">http://www.futomi.com/library/info/2009/20090310.html</ref>
      <ref url="http://secunia.com/advisories/34197" source="SECUNIA" adv="1">34197</ref>
      <ref url="http://osvdb.org/52527" source="OSVDB">52527</ref>
      <ref url="http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-000014.html" source="JVNDB">JVNDB-2009-000014</ref>
      <ref url="http://jvn.jp/en/jp/JVN84899898/index.html" source="JVN">JVN#84899898</ref>
    </refs>
    <vuln_soft>
      <prod vendor="futomi" name="mp_form_mail_cgi">
        <vers prev="1" num="1.3.0" edition="-" />
        <vers prev="1" num="1.3.0" edition="-:ecommerce" />
        <vers prev="1" num="3.2.2" edition="-" />
        <vers prev="1" num="3.2.2" edition="-:pro" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0963" published="2009-03-19" name="CVE-2009-0963" modified="2009-04-01" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in PHPRunner 4.2, and possibly earlier, allow remote attackers to execute arbitrary SQL commands via the SearchField parameter to (1) UserView_list.php, (2) orders_list.php, (3) users_list.php, and (4) Administrator_list.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/49278" source="XF">phprunner-searchfield-sql-injection(49278)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0750" source="VUPEN">ADV-2009-0750</ref>
      <ref url="http://www.securityfocus.com/bid/34146" source="BID">34146</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/501894/100/0/threaded" source="BUGTRAQ">20090317 PHPRunner SQL Injection</ref>
      <ref url="http://www.milw0rm.com/exploits/8226" source="MILW0RM">8226</ref>
      <ref url="http://www.bugreport.ir/index_63.htm" source="MISC">http://www.bugreport.ir/index_63.htm</ref>
      <ref url="http://secunia.com/advisories/34330" source="SECUNIA" adv="1">34330</ref>
      <ref url="http://osvdb.org/52801" source="OSVDB">52801</ref>
      <ref url="http://osvdb.org/52800" source="OSVDB">52800</ref>
      <ref url="http://osvdb.org/52799" source="OSVDB">52799</ref>
      <ref url="http://osvdb.org/52798" source="OSVDB">52798</ref>
    </refs>
    <vuln_soft>
      <prod vendor="xlinesoft" name="phprunner">
        <vers num="3.1" />
        <vers prev="1" num="4.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0964" published="2009-03-19" name="CVE-2009-0964" modified="2009-04-01" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">UserView_list.php in PHPRunner 4.2, and possibly earlier, stores passwords in cleartext in the database, which allows attackers to gain privileges.  NOTE: this can be leveraged with a separate SQL injection vulnerability to obtain passwords remotely without authentication.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/49279" source="XF">phprunner-userview-information-disclosure(49279)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0750" source="VUPEN">ADV-2009-0750</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/501894/100/0/threaded" source="BUGTRAQ">20090317 PHPRunner SQL Injection</ref>
      <ref url="http://www.milw0rm.com/exploits/8226" source="MILW0RM">8226</ref>
      <ref url="http://www.bugreport.ir/index_63.htm" source="MISC">http://www.bugreport.ir/index_63.htm</ref>
      <ref url="http://osvdb.org/52804" source="OSVDB">52804</ref>
    </refs>
    <vuln_soft>
      <prod vendor="xlinesoft" name="phprunner">
        <vers num="3.1" />
        <vers prev="1" num="4.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0965" published="2009-03-19" name="CVE-2009-0965" modified="2009-04-01" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in functions/browse.php in Ganesha Digital Library (GDL) 4.0 and 4.2 allows remote attackers to execute arbitrary SQL commands via the node parameter in a browse action to gdl.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/49292" source="XF">gdl-node-sql-injection(49292)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0751" source="VUPEN">ADV-2009-0751</ref>
      <ref url="http://www.securityfocus.com/bid/34144" source="BID">34144</ref>
      <ref url="http://www.milw0rm.com/exploits/8228" source="MILW0RM">8228</ref>
      <ref url="http://osvdb.org/52803" source="OSVDB">52803</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ismail_fahmi" name="ganesha_digital_library">
        <vers num="4.0" />
        <vers num="4.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0966" published="2009-03-19" name="CVE-2009-0966" modified="2009-04-01" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in cross.php in YABSoft Mega File Hosting 1.2 allows remote attackers to execute arbitrary PHP code via a URL in the url parameter.  NOTE: this can also be leveraged to include and execute arbitrary local files via .. (dot dot) sequences.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/49302" source="XF">megafile-cross-file-include(49302)</ref>
      <ref url="http://www.securityfocus.com/bid/34157" source="BID">34157</ref>
      <ref url="http://www.milw0rm.com/exploits/8230" source="MILW0RM">8230</ref>
      <ref url="http://secunia.com/advisories/34325" source="SECUNIA" adv="1">34325</ref>
      <ref url="http://osvdb.org/52789" source="OSVDB">52789</ref>
    </refs>
    <vuln_soft>
      <prod vendor="yabsoft" name="mega_file_hosting_script">
        <vers num="1.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0967" published="2009-03-19" name="CVE-2009-0967" modified="2010-04-27" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:N/I:N/A:P)" CVSS_score="4.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.0" CVSS_base_score="4.0">
    <desc>
      <descript source="cve">The FTP server in Serv-U 7.0.0.1 through 7.4.0.1 allows remote authenticated users to cause a denial of service (service hang) via a large number of SMNT commands without an argument.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/49260" source="XF">servuftp-smnt-dos(49260)</ref>
      <ref url="http://www.securityfocus.com/bid/34127" source="BID">34127</ref>
      <ref url="http://www.milw0rm.com/exploits/8212" source="MILW0RM">8212</ref>
    </refs>
    <vuln_soft>
      <prod vendor="serv-u" name="serv-u">
        <vers num="7.0.0.1" />
        <vers num="7.0.0.2" />
        <vers num="7.0.0.3" />
        <vers num="7.0.0.4" />
        <vers num="7.1.0.0" />
        <vers num="7.1.0.1" />
        <vers num="7.1.0.2" />
        <vers num="7.2.0.0" />
        <vers num="7.2.0.1" />
        <vers num="7.3.0.0" />
        <vers num="7.3.0.1" />
        <vers num="7.3.0.2" />
        <vers num="7.4.0.0" />
        <vers num="7.4.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0968" published="2009-03-19" name="CVE-2009-0968" modified="2009-04-01" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in fmoblog.php in the fMoblog plugin 2.1 for WordPress allows remote attackers to execute arbitrary SQL commands via the id parameter to index.php.  NOTE: some of these details are obtained from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/49296" source="XF">fmoblog-index-sql-injection(49296)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0752" source="VUPEN" adv="1">ADV-2009-0752</ref>
      <ref url="http://www.securityfocus.com/bid/34147" source="BID">34147</ref>
      <ref url="http://www.milw0rm.com/exploits/8229" source="MILW0RM">8229</ref>
      <ref url="http://secunia.com/advisories/34341" source="SECUNIA" adv="1">34341</ref>
      <ref url="http://osvdb.org/52836" source="OSVDB">52836</ref>
    </refs>
    <vuln_soft>
      <prod vendor="fahlstad" name="fmoblog_plugin">
        <vers num="2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0969" published="2009-03-19" name="CVE-2009-0969" modified="2011-03-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site request forgery (CSRF) vulnerability in account/settings/account/index.php in phpFoX 1.6.21 allows remote attackers to hijack the authentication of administrators for requests that change the email address via the act[update] action.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/49288" source="XF">phpfox-unspecified-csrf(49288)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/49288" source="XF">phpfox-email-account-csrf(49288)</ref>
      <ref url="http://secunia.com/advisories/34333" source="SECUNIA" adv="1">34333</ref>
      <ref url="http://packetstormsecurity.org/0903-exploits/phpfox1621-xsrf.txt" source="MISC">http://packetstormsecurity.org/0903-exploits/phpfox1621-xsrf.txt</ref>
      <ref url="http://osvdb.org/52770" source="OSVDB">52770</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpfox" name="phpfox">
        <vers num="1.6.2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0970" published="2009-03-19" name="CVE-2009-0970" modified="2009-03-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in includes/class_image.php in PHP Pro Bid 6.05, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the fileExtension parameter.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/49290" source="XF">phpprobid-classimage-file-include(49290)</ref>
      <ref url="http://www.securityfocus.com/bid/34145" source="BID">34145</ref>
      <ref url="http://www.osvdb.org/52750" source="OSVDB">52750</ref>
      <ref url="http://secunia.com/advisories/34278" source="SECUNIA" adv="1">34278</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpprobid" name="php_pro_bid">
        <vers num="6.05" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0971" published="2009-03-19" name="CVE-2009-0971" modified="2009-04-01" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in futomi's CGI Cafe Access Analyzer CGI Standard Version 3.8.1 and earlier allows remote attackers to inject arbitrary web script or HTML via unknown vectors.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.futomi.com/library/info/2009/20090316.html" source="CONFIRM" patch="1" adv="1">http://www.futomi.com/library/info/2009/20090316.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/49264" source="XF">cgicafe-unspecified-xss(49264)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0737" source="VUPEN" adv="1">ADV-2009-0737</ref>
      <ref url="http://www.securityfocus.com/bid/34123" source="BID">34123</ref>
      <ref url="http://secunia.com/advisories/34271" source="SECUNIA" adv="1">34271</ref>
      <ref url="http://osvdb.org/52802" source="OSVDB">52802</ref>
      <ref url="http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-000015.html" source="JVNDB">JVNDB-2009-000015</ref>
      <ref url="http://jvn.jp/en/jp/JVN23558374/index.html" source="JVN">JVN#23558374</ref>
    </refs>
    <vuln_soft>
      <prod vendor="futomi" name="access_analyzer_cgi">
        <vers num="1.1" edition="" />
        <vers num="1.1" edition=":std" />
        <vers num="1.2" edition="" />
        <vers num="1.2" edition=":std" />
        <vers num="1.3" edition="" />
        <vers num="1.3" edition=":std" />
        <vers num="1.4" edition="" />
        <vers num="1.4" edition=":std" />
        <vers num="2.0" edition="" />
        <vers num="2.0" edition=":std" />
        <vers num="2.1" edition="" />
        <vers num="2.1" edition=":std" />
        <vers num="2.2" edition="" />
        <vers num="2.2" edition=":std" />
        <vers num="2.3" edition="" />
        <vers num="2.3" edition=":std" />
        <vers num="2.4" edition="" />
        <vers num="2.4" edition=":std" />
        <vers num="3.0" edition="" />
        <vers num="3.0" edition=":std" />
        <vers num="3.1" edition="" />
        <vers num="3.1" edition=":std" />
        <vers num="3.2" edition="" />
        <vers num="3.2" edition=":std" />
        <vers num="3.3" edition="" />
        <vers num="3.3" edition=":std" />
        <vers num="3.4" edition="" />
        <vers num="3.4" edition=":std" />
        <vers num="3.5" edition="" />
        <vers num="3.5" edition=":std" />
        <vers num="3.6" edition="" />
        <vers num="3.6" edition=":std" />
        <vers num="3.7" edition="" />
        <vers num="3.7" edition=":std" />
        <vers num="3.8" edition="" />
        <vers num="3.8" edition=":std" />
        <vers prev="1" num="3.8.1" edition="" />
        <vers prev="1" num="3.8.1" edition=":std" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0972" published="2009-04-15" name="CVE-2009-0972" modified="2011-02-04" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)" CVSS_score="6.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.0" CVSS_base_score="6.5">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Workspace Manager component in Oracle Database 11.1.0.6, 11.1.0.7, 10.2.0.3, 10.2.0.4, 10.1.0.5, 9.2.0.8, and 9.2.0.8DV allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-105A.html" source="CERT">TA09-105A</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuapr2009.html" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuapr2009.html</ref>
      <ref url="http://www.securitytracker.com/id?1022052" source="SECTRACK">1022052</ref>
      <ref url="http://www.securityfocus.com/bid/34461" source="BID">34461</ref>
      <ref url="http://secunia.com/advisories/34693" source="SECUNIA">34693</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="database_10g">
        <vers num="10.1.0.5" />
        <vers num="10.2.0.3" />
        <vers num="10.2.0.4" />
      </prod>
      <prod vendor="oracle" name="database_11g">
        <vers num="11.1.0.6" />
        <vers num="11.1.0.7" />
      </prod>
      <prod vendor="oracle" name="database_9i">
        <vers num="9.2.0.8" />
        <vers num="9.2.0.8dv" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0973" published="2009-04-15" name="CVE-2009-0973" modified="2011-02-04" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Cluster Ready Services component in Oracle Database 10.1.0.5 allows remote attackers to affect availability via unknown vectors.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-105A.html" source="CERT">TA09-105A</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuapr2009.html" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuapr2009.html</ref>
      <ref url="http://www.securitytracker.com/id?1022052" source="SECTRACK">1022052</ref>
      <ref url="http://www.securityfocus.com/bid/34461" source="BID">34461</ref>
      <ref url="http://secunia.com/advisories/34693" source="SECUNIA">34693</ref>
      <ref url="http://osvdb.org/53736" source="OSVDB">53736</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="database_10g">
        <vers num="10.1.0.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0974" published="2009-04-15" name="CVE-2009-0974" modified="2011-02-04" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Portal component in Oracle Application Server 10.1.2.3 and 10.1.4.2 allows remote attackers to affect integrity via unknown vectors.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-105A.html" source="CERT">TA09-105A</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuapr2009.html" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuapr2009.html</ref>
      <ref url="http://www.securitytracker.com/id?1022055" source="SECTRACK">1022055</ref>
      <ref url="http://www.securityfocus.com/bid/34461" source="BID">34461</ref>
      <ref url="http://secunia.com/advisories/34693" source="SECUNIA">34693</ref>
      <ref url="http://osvdb.org/53751" source="OSVDB">53751</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="application_server_10g">
        <vers num="10.1.2.3" />
        <vers num="10.1.4.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0975" published="2009-04-15" name="CVE-2009-0975" modified="2011-02-04" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:N)" CVSS_score="5.5" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.0" CVSS_base_score="5.5">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Workspace Manager component in Oracle Database 10.2.0.4 and 11.1.0.6 allows remote authenticated users to affect confidentiality and integrity via unknown vectors.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-105A.html" source="CERT">TA09-105A</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuapr2009.html" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuapr2009.html</ref>
      <ref url="http://www.securitytracker.com/id?1022052" source="SECTRACK">1022052</ref>
      <ref url="http://www.securityfocus.com/bid/34461" source="BID">34461</ref>
      <ref url="http://secunia.com/advisories/34693" source="SECUNIA">34693</ref>
      <ref url="http://osvdb.org/53732" source="OSVDB">53732</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="database_10g">
        <vers num="10.2.0.4" />
      </prod>
      <prod vendor="oracle" name="database_11g">
        <vers num="11.1.0.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0976" published="2009-04-15" name="CVE-2009-0976" modified="2011-02-04" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:N)" CVSS_score="5.5" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.0" CVSS_base_score="5.5">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Workspace Manager component in Oracle Database 10.2.0.4 and 11.1.0.6 allows remote authenticated users to affect confidentiality and integrity, related to LTADM.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-105A.html" source="CERT">TA09-105A</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuapr2009.html" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuapr2009.html</ref>
      <ref url="http://www.securitytracker.com/id?1022052" source="SECTRACK">1022052</ref>
      <ref url="http://www.securityfocus.com/bid/34461" source="BID">34461</ref>
      <ref url="http://secunia.com/advisories/34693" source="SECUNIA">34693</ref>
      <ref url="http://osvdb.org/53733" source="OSVDB">53733</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="database_10g">
        <vers num="10.2.0.4" />
      </prod>
      <prod vendor="oracle" name="database_11g">
        <vers num="11.1.0.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0977" published="2009-04-15" name="CVE-2009-0977" modified="2011-02-04" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:N)" CVSS_score="5.5" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.0" CVSS_base_score="5.5">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Advanced Queuing component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.0.5, and 10.2.0.3 allows remote authenticated users to affect confidentiality and integrity, related to DBMS_AQIN.  NOTE: the previous information was obtained from the April 2009 CPU.  Oracle has not commented on reliable researcher claims that this issue is SQL injection in the GRANT_TYPE_ACCESS procedure in the DBMS_AQADM_SYS package.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-105A.html" source="CERT">TA09-105A</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuapr2009.html" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuapr2009.html</ref>
      <ref url="http://www.securitytracker.com/id?1022052" source="SECTRACK">1022052</ref>
      <ref url="http://www.securityfocus.com/bid/34461" source="BID">34461</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/502727/100/0/threaded" source="BUGTRAQ">20090416 SQL Injection in package DBMS_AQADM_SYS</ref>
      <ref url="http://www.red-database-security.com/advisory/oracle_sql_injection_dbms_aqadm_sys.html" source="MISC">http://www.red-database-security.com/advisory/oracle_sql_injection_dbms_aqadm_sys.html</ref>
      <ref url="http://secunia.com/advisories/34693" source="SECUNIA">34693</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="database_10g">
        <vers num="10.1.0.5" />
        <vers num="10.2.0.3" />
      </prod>
      <prod vendor="oracle" name="database_9i">
        <vers num="9.2.0.8" />
        <vers num="9.2.0.8dv" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0978" published="2009-04-15" name="CVE-2009-0978" modified="2011-02-04" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:N)" CVSS_score="5.5" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.0" CVSS_base_score="5.5">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Workspace Manager component in Oracle Database 10.2.0.4 and 11.1.0.6 allows remote authenticated users to affect confidentiality and integrity via unknown vectors.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-105A.html" source="CERT">TA09-105A</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuapr2009.html" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuapr2009.html</ref>
      <ref url="http://www.securitytracker.com/id?1022052" source="SECTRACK">1022052</ref>
      <ref url="http://www.securityfocus.com/bid/34461" source="BID">34461</ref>
      <ref url="http://secunia.com/advisories/34693" source="SECUNIA">34693</ref>
      <ref url="http://osvdb.org/53734" source="OSVDB">53734</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="database_10g">
        <vers num="10.2.0.4" />
      </prod>
      <prod vendor="oracle" name="database_11g">
        <vers num="11.1.0.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0979" published="2009-04-15" name="CVE-2009-0979" modified="2011-02-04" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:C/I:C/A:C)" CVSS_score="9.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.0" CVSS_base_score="9.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Resource Manager component in Oracle Database 9.2.0.8 and 9.2.0.8DV allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-105A.html" source="CERT">TA09-105A</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuapr2009.html" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuapr2009.html</ref>
      <ref url="http://www.securitytracker.com/id?1022052" source="SECTRACK">1022052</ref>
      <ref url="http://www.securityfocus.com/bid/34461" source="BID">34461</ref>
      <ref url="http://secunia.com/advisories/34693" source="SECUNIA">34693</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="database_9i">
        <vers num="9.2.0.8" />
        <vers num="9.2.0.8dv" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0980" published="2009-04-15" name="CVE-2009-0980" modified="2011-02-04" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:N/I:P/A:P)" CVSS_score="5.5" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.0" CVSS_base_score="5.5">
    <desc>
      <descript source="cve">Unspecified vulnerability in the SQLX Functions component in Oracle Database 10.2.0.3 and 11.1.0.6 allows remote authenticated users to affect integrity and availability, related to AGGXQIMP.</descript>
    </desc>
    <loss_types>
      <avail />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-105A.html" source="CERT">TA09-105A</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuapr2009.html" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuapr2009.html</ref>
      <ref url="http://www.securitytracker.com/id?1022052" source="SECTRACK">1022052</ref>
      <ref url="http://www.securityfocus.com/bid/34461" source="BID">34461</ref>
      <ref url="http://secunia.com/advisories/34693" source="SECUNIA">34693</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="database_10g">
        <vers num="10.2.0.3" />
      </prod>
      <prod vendor="oracle" name="database_11g">
        <vers num="11.1.0.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0981" published="2009-04-15" name="CVE-2009-0981" modified="2011-02-04" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:N/A:N)" CVSS_score="4.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.0" CVSS_base_score="4.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Application Express component in Oracle Database 11.1.0.7 allows remote authenticated users to affect confidentiality, related to APEX.  NOTE: the previous information was obtained from the April 2009 CPU.  Oracle has not commented on reliable researcher claims that this issue allows remote authenticated users to obtain APEX password hashes from the WWV_FLOW_USERS table via a SELECT statement.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-105A.html" source="CERT">TA09-105A</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuapr2009.html" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuapr2009.html</ref>
      <ref url="http://www.securitytracker.com/id?1022052" source="SECTRACK">1022052</ref>
      <ref url="http://www.securityfocus.com/bid/34461" source="BID">34461</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/502724/100/0/threaded" source="BUGTRAQ">20090416 Unprivileged DB users can see APEX password hashes</ref>
      <ref url="http://www.red-database-security.com/advisory/apex_password_hashes.html" source="MISC">http://www.red-database-security.com/advisory/apex_password_hashes.html</ref>
      <ref url="http://www.milw0rm.com/exploits/8456" source="MILW0RM">8456</ref>
      <ref url="http://secunia.com/advisories/34693" source="SECUNIA">34693</ref>
      <ref url="http://osvdb.org/53738" source="OSVDB">53738</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="database_11g">
        <vers num="11.1.0.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0982" published="2009-04-15" name="CVE-2009-0982" modified="2011-02-04" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:N/I:P/A:N)" CVSS_score="4.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.0" CVSS_base_score="4.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Enterprise and JD Edwards EnterpriseOne 8.49.19 allows remote authenticated users to affect integrity via unknown vectors.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-105A.html" source="CERT">TA09-105A</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuapr2009.html" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuapr2009.html</ref>
      <ref url="http://www.securitytracker.com/id?1022057" source="SECTRACK">1022057</ref>
      <ref url="http://www.securityfocus.com/bid/34461" source="BID">34461</ref>
      <ref url="http://secunia.com/advisories/34693" source="SECUNIA">34693</ref>
      <ref url="http://osvdb.org/53759" source="OSVDB">53759</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="jd_edwards_enterpriseone">
        <vers num="8.49.19" />
      </prod>
      <prod vendor="oracle" name="peoplesoft_enterprise">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0983" published="2009-04-15" name="CVE-2009-0983" modified="2011-02-04" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Portal component in Oracle Application Server 10.1.2.3 and 10.1.4.2 allows remote attackers to affect integrity via unknown vectors, a different vulnerability than CVE-2009-0974.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-105A.html" source="CERT">TA09-105A</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuapr2009.html" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuapr2009.html</ref>
      <ref url="http://www.securitytracker.com/id?1022055" source="SECTRACK">1022055</ref>
      <ref url="http://www.securityfocus.com/bid/34461" source="BID">34461</ref>
      <ref url="http://secunia.com/advisories/34693" source="SECUNIA">34693</ref>
      <ref url="http://osvdb.org/53752" source="OSVDB">53752</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="application_server_10g">
        <vers num="10.1.2.3" />
        <vers num="10.1.4.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0984" published="2009-04-15" name="CVE-2009-0984" modified="2011-02-04" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:N)" CVSS_score="5.5" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.0" CVSS_base_score="5.5">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Database Vault component in Oracle Database 9.2.0.8DV, 10.2.0.4, and 11.1.0.6 allows remote authenticated users to affect confidentiality and integrity, related to DBMS_SYS_SQL.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-105A.html" source="CERT">TA09-105A</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuapr2009.html" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuapr2009.html</ref>
      <ref url="http://www.securitytracker.com/id?1022052" source="SECTRACK">1022052</ref>
      <ref url="http://www.securityfocus.com/bid/34461" source="BID">34461</ref>
      <ref url="http://secunia.com/advisories/34693" source="SECUNIA">34693</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="database_10g">
        <vers num="10.2.0.4" />
      </prod>
      <prod vendor="oracle" name="database_11g">
        <vers num="11.1.0.6" />
      </prod>
      <prod vendor="oracle" name="database_9i">
        <vers num="9.2.0.8dv" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0985" published="2009-04-15" name="CVE-2009-0985" modified="2011-02-04" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:S/C:C/I:C/A:C)" CVSS_score="7.1" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.1">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Core RDBMS component in Oracle Database 10.1.0.5, 10.2.0.4, and 11.1.0.6 allows remote authenticated users with the IMP_FULL_DATABASE role to affect confidentiality, integrity, and availability.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-105A.html" source="CERT">TA09-105A</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuapr2009.html" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuapr2009.html</ref>
      <ref url="http://www.securitytracker.com/id?1022052" source="SECTRACK">1022052</ref>
      <ref url="http://www.securityfocus.com/bid/34461" source="BID">34461</ref>
      <ref url="http://secunia.com/advisories/34693" source="SECUNIA">34693</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="database_10g">
        <vers num="10.1.0.5" />
        <vers num="10.2.0.4" />
      </prod>
      <prod vendor="oracle" name="database_11g">
        <vers num="11.1.0.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0986" published="2009-04-15" name="CVE-2009-0986" modified="2011-02-04" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:M/C:P/I:P/A:P)" CVSS_score="5.4" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="5.5" CVSS_base_score="5.4">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Workspace Manager component in Oracle Database 10.2.0.4 and 11.1.0.6 allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-105A.html" source="CERT">TA09-105A</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuapr2009.html" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuapr2009.html</ref>
      <ref url="http://www.securitytracker.com/id?1022052" source="SECTRACK">1022052</ref>
      <ref url="http://www.securityfocus.com/bid/34461" source="BID">34461</ref>
      <ref url="http://secunia.com/advisories/34693" source="SECUNIA">34693</ref>
      <ref url="http://osvdb.org/53735" source="OSVDB">53735</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="database_10g">
        <vers num="10.2.0.4" />
      </prod>
      <prod vendor="oracle" name="database_11g">
        <vers num="11.1.0.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0987" published="2009-07-14" name="CVE-2009-0987" modified="2009-08-12" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:N)" CVSS_score="5.5" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.0" CVSS_base_score="5.5">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Upgrade component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.0.5, and 10.2.0.3 allows remote authenticated users to affect confidentiality and integrity via unknown vectors.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujul2009.html" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujul2009.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/51746" source="XF">oracle-database-upgrade-unspecified(51746)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1900" source="VUPEN">ADV-2009-1900</ref>
      <ref url="http://www.securitytracker.com/id?1022560" source="SECTRACK">1022560</ref>
      <ref url="http://www.securityfocus.com/bid/35679" source="BID">35679</ref>
      <ref url="http://secunia.com/advisories/35776" source="SECUNIA">35776</ref>
      <ref url="http://osvdb.org/55889" source="OSVDB">55889</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="database_server">
        <vers num="10.1.0.5" />
        <vers num="10.2.0.3" />
        <vers num="9.2.0.8" />
        <vers num="9.2.0.8dv" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2009-0988" published="2009-04-15" name="CVE-2009-0988" modified="2011-02-04" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:S/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Password Policy component in Oracle Database 11.1.0.6 allows remote authenticated users to affect confidentiality via unknown vectors.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-105A.html" source="CERT">TA09-105A</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuapr2009.html" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuapr2009.html</ref>
      <ref url="http://www.securitytracker.com/id?1022052" source="SECTRACK">1022052</ref>
      <ref url="http://www.securityfocus.com/bid/34461" source="BID">34461</ref>
      <ref url="http://secunia.com/advisories/34693" source="SECUNIA">34693</ref>
      <ref url="http://osvdb.org/53740" source="OSVDB">53740</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="database_11g">
        <vers num="11.1.0.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0989" published="2009-04-15" name="CVE-2009-0989" modified="2011-02-04" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:N)" CVSS_score="5.5" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.0" CVSS_base_score="5.5">
    <desc>
      <descript source="cve">Unspecified vulnerability in the BI Publisher component in Oracle Application Server 5.6.2, 10.1.3.2.1, and 10.1.3.3.3 allows remote authenticated users to affect confidentiality and integrity via unknown vectors.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-105A.html" source="CERT">TA09-105A</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuapr2009.html" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuapr2009.html</ref>
      <ref url="http://www.securitytracker.com/id?1022055" source="SECTRACK">1022055</ref>
      <ref url="http://www.securityfocus.com/bid/34461" source="BID">34461</ref>
      <ref url="http://secunia.com/advisories/34693" source="SECUNIA">34693</ref>
      <ref url="http://osvdb.org/53742" source="OSVDB">53742</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="application_server">
        <vers num="5.6.2" />
      </prod>
      <prod vendor="oracle" name="application_server_10g">
        <vers num="10.1.3.2.1" />
        <vers num="10.1.3.3.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0990" published="2009-04-15" name="CVE-2009-0990" modified="2011-02-04" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:N)" CVSS_score="5.5" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.0" CVSS_base_score="5.5">
    <desc>
      <descript source="cve">Unspecified vulnerability in the BI Publisher component in Oracle Application Server 5.6.2, 10.1.3.2.1, and 10.1.3.3.3 allows remote authenticated users to affect confidentiality and integrity via unknown vectors.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-105A.html" source="CERT">TA09-105A</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuapr2009.html" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuapr2009.html</ref>
      <ref url="http://www.securitytracker.com/id?1022055" source="SECTRACK">1022055</ref>
      <ref url="http://www.securityfocus.com/bid/34461" source="BID">34461</ref>
      <ref url="http://secunia.com/advisories/34693" source="SECUNIA">34693</ref>
      <ref url="http://osvdb.org/53743" source="OSVDB">53743</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="application_server">
        <vers num="5.6.2" />
      </prod>
      <prod vendor="oracle" name="application_server_10g">
        <vers num="10.1.3.2.1" />
        <vers num="10.1.3.3.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0991" published="2009-04-15" name="CVE-2009-0991" modified="2011-02-04" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Listener component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.0.5, 10.2.0.4, and 11.1.0.7 allows remote attackers to affect availability via unknown vectors.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-105A.html" source="CERT">TA09-105A</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuapr2009.html" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuapr2009.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/50026" source="XF">oracledatabase-tnslistener-dos(50026)</ref>
      <ref url="http://www.securitytracker.com/id?1022052" source="SECTRACK">1022052</ref>
      <ref url="http://www.securityfocus.com/bid/34461" source="BID">34461</ref>
      <ref url="http://secunia.com/advisories/34693" source="SECUNIA">34693</ref>
      <ref url="http://osvdb.org/53737" source="OSVDB">53737</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="database_10g">
        <vers num="10.1.0.5" />
        <vers num="10.2.0.4" />
      </prod>
      <prod vendor="oracle" name="database_11g">
        <vers num="11.1.0.7" />
      </prod>
      <prod vendor="oracle" name="database_9i">
        <vers num="9.2.0.8" />
        <vers num="9.2.0.8dv" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0992" published="2009-04-15" name="CVE-2009-0992" modified="2011-02-04" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:N)" CVSS_score="5.5" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.0" CVSS_base_score="5.5">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Advanced Queuing component in Oracle Database 10.1.0.5, 10.2.0.4, and 11.1.0.7 allows remote authenticated users to affect confidentiality and integrity, related to DBMS_AQIN. NOTE: the previous information was obtained from the April 2009 CPU. Oracle has not commented on reliable researcher claims that this issue is SQL injection in the DEQ_EXEJOB procedure.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-105A.html" source="CERT">TA09-105A</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuapr2009.html" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuapr2009.html</ref>
      <ref url="http://www.securitytracker.com/id?1022052" source="SECTRACK">1022052</ref>
      <ref url="http://www.securityfocus.com/bid/34461" source="BID">34461</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/502723/100/0/threaded" source="BUGTRAQ">20090416 SQL Injection in package DBMS_AQIN</ref>
      <ref url="http://www.red-database-security.com/advisory/oracle_sql_injection_dbms_aqin.html" source="MISC">http://www.red-database-security.com/advisory/oracle_sql_injection_dbms_aqin.html</ref>
      <ref url="http://secunia.com/advisories/34693" source="SECUNIA">34693</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="database_10g">
        <vers num="10.1.0.5" />
        <vers num="10.2.0.4" />
      </prod>
      <prod vendor="oracle" name="database_11g">
        <vers num="11.1.0.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-0993" published="2009-04-15" name="CVE-2009-0993" modified="2011-02-04" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Unspecified vulnerability in the OPMN component in Oracle Application Server 10.1.2.3 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.  NOTE: the previous information was obtained from the April 2009 CPU.  Oracle has not commented on reliable researcher claims that this issue is a format string vulnerability that allows remote attackers to execute arbitrary code via format string specifiers in an HTTP POST URI, which are not properly handled when logging to opmn/logs/opmn.log.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-105A.html" source="CERT">TA09-105A</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuapr2009.html" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuapr2009.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/50030" source="XF">oracle-appserver-opmn-unspecified(50030)</ref>
      <ref url="http://www.zerodayinitiative.com/advisories/ZDI-09-017" source="MISC">http://www.zerodayinitiative.com/advisories/ZDI-09-017</ref>
      <ref url="http://www.securitytracker.com/id?1022055" source="SECTRACK">1022055</ref>
      <ref url="http://www.securityfocus.com/bid/34461" source="BID">34461</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/502683/100/0/threaded" source="BUGTRAQ">20090414 ZDI-09-017: Oracle Applications Server 10g Format String Vulnerability</ref>
      <ref url="http://secunia.com/advisories/34693" source="SECUNIA">34693</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="application_server_10g">
        <vers num="10.1.2.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0994" published="2009-04-15" name="CVE-2009-0994" modified="2011-02-04" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:N/A:N)" CVSS_score="4.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.0" CVSS_base_score="4.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the BI Publisher component in Oracle Application Server 5.6.2, 10.1.3.2.1, 10.1.3.3.3, and 10.1.3.4 allows remote authenticated users to affect confidentiality via unknown vectors.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-105A.html" source="CERT">TA09-105A</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuapr2009.html" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuapr2009.html</ref>
      <ref url="http://www.securitytracker.com/id?1022055" source="SECTRACK">1022055</ref>
      <ref url="http://www.securityfocus.com/bid/34461" source="BID">34461</ref>
      <ref url="http://secunia.com/advisories/34693" source="SECUNIA">34693</ref>
      <ref url="http://osvdb.org/53744" source="OSVDB">53744</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="application_server">
        <vers num="5.6.2" />
      </prod>
      <prod vendor="oracle" name="application_server_10g">
        <vers num="10.1.3.2.1" />
        <vers num="10.1.3.3.3" />
        <vers num="10.1.3.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0995" published="2009-04-15" name="CVE-2009-0995" modified="2011-02-04" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Oracle Applications Framework component in Oracle E-Business Suite 12.0.6 and 11i10CU2 allows remote attackers to affect integrity via unknown vectors.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-105A.html" source="CERT">TA09-105A</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuapr2009.html" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuapr2009.html</ref>
      <ref url="http://www.securitytracker.com/id?1022056" source="SECTRACK">1022056</ref>
      <ref url="http://www.securityfocus.com/bid/34461" source="BID">34461</ref>
      <ref url="http://secunia.com/advisories/34693" source="SECUNIA">34693</ref>
      <ref url="http://osvdb.org/53754" source="OSVDB">53754</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="e-business_suite">
        <vers num="11i10cu2" />
      </prod>
      <prod vendor="oracle" name="e-business_suite_12">
        <vers num="12.0.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0996" published="2009-04-15" name="CVE-2009-0996" modified="2011-02-04" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:N/A:N)" CVSS_score="4.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.0" CVSS_base_score="4.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the BI Publisher component in Oracle Application Server 10.1.3.2.1, 10.1.3.3.3, and 10.1.3.4 allows remote authenticated users to affect confidentiality via unknown vectors.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-105A.html" source="CERT">TA09-105A</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuapr2009.html" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuapr2009.html</ref>
      <ref url="http://www.securitytracker.com/id?1022055" source="SECTRACK">1022055</ref>
      <ref url="http://www.securityfocus.com/bid/34461" source="BID">34461</ref>
      <ref url="http://secunia.com/advisories/34693" source="SECUNIA">34693</ref>
      <ref url="http://osvdb.org/53745" source="OSVDB">53745</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="application_server_10g">
        <vers num="10.1.3.2.1" />
        <vers num="10.1.3.3.3" />
        <vers num="10.1.3.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0997" published="2009-04-15" name="CVE-2009-0997" modified="2011-02-04" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:N/A:N)" CVSS_score="4.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.0" CVSS_base_score="4.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Database Vault component in Oracle Database 11.1.0.6 allows remote authenticated users to affect confidentiality, related to DBMS_SYS_SQL.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-105A.html" source="CERT">TA09-105A</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuapr2009.html" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuapr2009.html</ref>
      <ref url="http://www.securitytracker.com/id?1022052" source="SECTRACK">1022052</ref>
      <ref url="http://www.securityfocus.com/bid/34461" source="BID">34461</ref>
      <ref url="http://secunia.com/advisories/34693" source="SECUNIA">34693</ref>
      <ref url="http://osvdb.org/53739" source="OSVDB">53739</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="database_server">
        <vers num="11.1.0.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0998" published="2009-04-15" name="CVE-2009-0998" modified="2011-02-04" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:N)" CVSS_score="5.5" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.0" CVSS_base_score="5.5">
    <desc>
      <descript source="cve">Unspecified vulnerability in the PeopleSoft Enterprise HRMS - eBenefits component in Oracle PeopleSoft Enterprise and JD Edwards EnterpriseOne 8.9.18 and 9.0.8 allows remote authenticated users to affect confidentiality and integrity via unknown vectors.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-105A.html" source="CERT">TA09-105A</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuapr2009.html" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuapr2009.html</ref>
      <ref url="http://www.securityfocus.com/bid/34461" source="BID">34461</ref>
      <ref url="http://secunia.com/advisories/34693" source="SECUNIA">34693</ref>
      <ref url="http://osvdb.org/53758" source="OSVDB">53758</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="jd_edwards_enterpriseone">
        <vers num="8.9.18" />
        <vers num="9.0.8" />
      </prod>
      <prod vendor="oracle" name="peoplesoft_enterprise">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-0999" published="2009-04-15" name="CVE-2009-0999" modified="2011-02-04" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Oracle Application Object Library component in Oracle E-Business Suite 12.0.6 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-105A.html" source="CERT">TA09-105A</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuapr2009.html" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuapr2009.html</ref>
      <ref url="http://www.securitytracker.com/id?1022056" source="SECTRACK">1022056</ref>
      <ref url="http://www.securityfocus.com/bid/34461" source="BID">34461</ref>
      <ref url="http://secunia.com/advisories/34693" source="SECUNIA">34693</ref>
      <ref url="http://osvdb.org/53753" source="OSVDB">53753</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="e-business_suite">
        <vers num="12.0.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1000" published="2009-04-15" name="CVE-2009-1000" modified="2011-02-04" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The Oracle Applications Framework component in Oracle E-Business Suite 12.0.6 and 11i10CU2 uses default passwords for unspecified "FND Applications Users (not DB users)," which has unknown impact and attack vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-105A.html" source="CERT">TA09-105A</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuapr2009.html" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuapr2009.html</ref>
      <ref url="http://www.securitytracker.com/id?1022056" source="SECTRACK">1022056</ref>
      <ref url="http://www.securityfocus.com/bid/34461" source="BID">34461</ref>
      <ref url="http://secunia.com/advisories/34693" source="SECUNIA">34693</ref>
      <ref url="http://osvdb.org/53755" source="OSVDB">53755</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="e-business_suite">
        <vers num="11i10cu2" />
        <vers num="12.0.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1001" published="2009-04-15" name="CVE-2009-1001" modified="2011-02-04" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:N)" CVSS_score="5.5" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.0" CVSS_base_score="5.5">
    <desc>
      <descript source="cve">Unspecified vulnerability in Oracle BEA WebLogic Portal 8.1 Gold through SP6 allows remote authenticated users to gain privileges via unknown vectors.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-105A.html" source="CERT">TA09-105A</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuapr2009.html" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuapr2009.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/50053" source="XF">oracle-weblogic-wls-priv-escalation(50053)</ref>
      <ref url="http://www.securitytracker.com/id?1022059" source="SECTRACK">1022059</ref>
      <ref url="http://www.securityfocus.com/bid/34461" source="BID">34461</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/wls-security/1001.html" source="CONFIRM">http://www.oracle.com/technology/deploy/security/wls-security/1001.html</ref>
      <ref url="http://osvdb.org/53767" source="OSVDB">53767</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="bea_product_suite">
        <vers num="8.1" edition="sp6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1002" published="2009-04-15" name="CVE-2009-1002" modified="2011-02-04" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)" CVSS_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_base_score="5.8">
    <desc>
      <descript source="cve">Unspecified vulnerability in Oracle BEA WebLogic Server 10.3, 10.0 Gold through MP1, 9.2 Gold through MP3, 9.1, 9.0, 8.1 Gold through SP6, and 7.0 Gold through SP7 allows remote attackers to gain privileges via unknown vectors.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-105A.html" source="CERT">TA09-105A</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuapr2009.html" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuapr2009.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/50052" source="XF">oracle-weblogic-wls-priv-escalation2(50052)</ref>
      <ref url="http://www.securitytracker.com/id?1022059" source="SECTRACK">1022059</ref>
      <ref url="http://www.securityfocus.com/bid/34461" source="BID">34461</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/wls-security/1002.html" source="CONFIRM">http://www.oracle.com/technology/deploy/security/wls-security/1002.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="bea_product_suite">
        <vers num="10.0" edition="mp1" />
        <vers num="10.3" />
        <vers num="7.0" edition="sp7" />
        <vers num="8.1" edition="sp6" />
        <vers num="9.0" />
        <vers num="9.1" />
        <vers num="9.2" edition="mp3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1003" published="2009-04-15" name="CVE-2009-1003" modified="2011-02-04" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the WebLogic Server component in BEA Product Suite 10.3, 10.0 MP1, 9.2 MP3, 9.1, and 9.0 allows remote attackers to affect integrity via unknown vectors related to "access to source code of web pages."</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-105A.html" source="CERT">TA09-105A</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuapr2009.html" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuapr2009.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/50054" source="XF">oracle-weblogic-wls-read-source(50054)</ref>
      <ref url="http://www.securitytracker.com/id?1022059" source="SECTRACK">1022059</ref>
      <ref url="http://www.securityfocus.com/bid/34461" source="BID">34461</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/wls-security/1003.html" source="CONFIRM">http://www.oracle.com/technology/deploy/security/wls-security/1003.html</ref>
      <ref url="http://osvdb.org/53762" source="OSVDB">53762</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="bea_product_suite">
        <vers num="10.0" edition="mp1" />
        <vers num="10.3" />
        <vers num="9.0" />
        <vers num="9.1" />
        <vers num="9.2" edition="mp3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1004" published="2009-04-15" name="CVE-2009-1004" modified="2011-02-04" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:N)" CVSS_score="4.0" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="4.9" CVSS_base_score="4.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the WebLogic Server component in BEA Product Suite 10.3 allows remote attackers to affect confidentiality and integrity via unknown vectors.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-105A.html" source="CERT">TA09-105A</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuapr2009.html" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuapr2009.html</ref>
      <ref url="http://www.securitytracker.com/id?1022059" source="SECTRACK">1022059</ref>
      <ref url="http://www.securityfocus.com/bid/34461" source="BID">34461</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="bea_product_suite">
        <vers num="10.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1005" published="2009-04-15" name="CVE-2009-1005" modified="2011-02-04" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:S/C:P/I:P/A:P)" CVSS_score="4.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="2.7" CVSS_base_score="4.1">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Oracle Data Service Integrator (AquaLogic Data Services Platform) component in BEA Product Suite 10.3.0, 3.2, 3.0.1, and 3.0 allows local users to affect confidentiality, integrity, and availability via unknown vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-105A.html" source="CERT">TA09-105A</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuapr2009.html" source="CONFIRM" patch="1">http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuapr2009.html</ref>
      <ref url="http://www.securitytracker.com/id?1022059" source="SECTRACK">1022059</ref>
      <ref url="http://www.securityfocus.com/bid/34461" source="BID">34461</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/wls-security/1005.html" source="CONFIRM">http://www.oracle.com/technology/deploy/security/wls-security/1005.html</ref>
      <ref url="http://osvdb.org/53760" source="OSVDB">53760</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="bea_product_suite">
        <vers num="10.3.0" />
        <vers num="3.0" />
        <vers num="3.0.1" />
        <vers num="3.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1006" published="2009-04-15" name="CVE-2009-1006" modified="2011-02-04" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the JRockit component in BEA Product Suite R27.6.2 and earlier, with SDK/JRE 1.4.2, JRE/JDK 5, and JRE/JDK 6, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-105A.html" source="CERT">TA09-105A</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuapr2009.html" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuapr2009.html</ref>
      <ref url="http://www.securitytracker.com/id?1022059" source="SECTRACK">1022059</ref>
      <ref url="http://www.securityfocus.com/bid/34461" source="BID">34461</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="jrockit">
        <vers num="r26.0" />
        <vers num="r26.1" />
        <vers num="r26.2" />
        <vers num="r26.3" />
        <vers num="r26.4" />
        <vers num="r27.1" />
        <vers num="r27.2" />
        <vers num="r27.3" />
        <vers num="r27.3.1" />
        <vers num="r27.4" />
        <vers num="r27.5" />
        <vers num="r27.6" />
        <vers num="r27.6.0" />
        <vers num="r27.6.1" />
        <vers prev="1" num="r27.6.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1007" published="2009-10-22" name="CVE-2009-1007" modified="2009-10-27" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)" CVSS_score="6.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.0" CVSS_base_score="6.5">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Data Mining component in Oracle Database 10.2.0.4 allows remote authenticated users to affect confidentiality, integrity, and availability, related to SYS.DMP_SYS.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-294A.html" source="CERT">TA09-294A</ref>
      <ref url="http://www.securitytracker.com/id?1023057" source="SECTRACK">1023057</ref>
      <ref url="http://www.securityfocus.com/bid/36750" source="BID">36750</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuoct2009.html" source="CONFIRM" adv="1">http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuoct2009.html</ref>
      <ref url="http://secunia.com/advisories/37027" source="SECUNIA">37027</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="database_server">
        <vers num="10.2.0.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1008" published="2009-04-15" name="CVE-2009-1008" modified="2011-02-04" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="4.4" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.4" CVSS_base_score="4.4">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Outside In Technology component in Oracle Application Server 8.2.2 and 8.3.0 allows local users to affect confidentiality, integrity, and availability, related to HTML.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-105A.html" source="CERT">TA09-105A</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuapr2009.html" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuapr2009.html</ref>
      <ref url="http://www.securitytracker.com/id?1022055" source="SECTRACK">1022055</ref>
      <ref url="http://www.securityfocus.com/bid/34461" source="BID">34461</ref>
      <ref url="http://secunia.com/advisories/34693" source="SECUNIA">34693</ref>
      <ref url="http://osvdb.org/53747" source="OSVDB">53747</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="application_server">
        <vers num="8.2.2" />
        <vers num="8.3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1009" published="2009-04-15" name="CVE-2009-1009" modified="2011-02-04" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="4.4" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.4" CVSS_base_score="4.4">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Outside In Technology component in Oracle Application Server 8.1.9 allows local users to affect confidentiality, integrity, and availability, related to HTML.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-105A.html" source="CERT">TA09-105A</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuapr2009.html" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuapr2009.html</ref>
      <ref url="http://www.securitytracker.com/id?1022055" source="SECTRACK">1022055</ref>
      <ref url="http://www.securityfocus.com/bid/34461" source="BID">34461</ref>
      <ref url="http://secunia.com/advisories/34693" source="SECUNIA">34693</ref>
      <ref url="http://osvdb.org/53748" source="OSVDB">53748</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="application_server">
        <vers num="8.1.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1010" published="2009-04-15" name="CVE-2009-1010" modified="2011-02-04" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="4.4" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.4" CVSS_base_score="4.4">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Outside In Technology component in Oracle Application Server 8.2.2 and 8.3.0 allows local users to affect confidentiality, integrity, and availability, related to HTML.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-105A.html" source="CERT">TA09-105A</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuapr2009.html" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuapr2009.html</ref>
      <ref url="http://www.securitytracker.com/id?1022055" source="SECTRACK">1022055</ref>
      <ref url="http://www.securityfocus.com/bid/34461" source="BID">34461</ref>
      <ref url="http://secunia.com/advisories/34693" source="SECUNIA">34693</ref>
      <ref url="http://osvdb.org/53749" source="OSVDB">53749</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="application_server">
        <vers num="8.2.2" />
        <vers num="8.3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1011" published="2009-04-15" name="CVE-2009-1011" modified="2011-02-04" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="4.4" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.4" CVSS_base_score="4.4">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Outside In Technology component in Oracle Application Server 8.2.2 and 8.3.0 allows local users to affect confidentiality, integrity, and availability, related to HTML.  NOTE: the previous information was obtained from the April 2009 CPU.  Oracle has not commented on reliable researcher claims that this issue is for multiple integer overflows in a function that parses an optional data stream within a Microsoft Office file, leading to a heap-based buffer overflow.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-105A.html" source="CERT">TA09-105A</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuapr2009.html" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuapr2009.html</ref>
      <ref url="http://www.securitytracker.com/id?1022055" source="SECTRACK">1022055</ref>
      <ref url="http://www.securityfocus.com/bid/34461" source="BID">34461</ref>
      <ref url="http://secunia.com/advisories/34693" source="SECUNIA">34693</ref>
      <ref url="http://osvdb.org/53750" source="OSVDB">53750</ref>
      <ref url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=798" source="IDEFENSE">20090515 Multiple Vendor Outside In Multiple Integer Overflow Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="application_server">
        <vers num="8.2.2" />
        <vers num="8.3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1012" published="2009-04-15" name="CVE-2009-1012" modified="2011-02-04" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the plug-ins for Apache and IIS web servers in Oracle BEA WebLogic Server 7.0 Gold through SP7, 8.1 Gold through SP6, 9.0, 9.1, 9.2 Gold through MP3, 10.0 Gold through MP1, and 10.3 allows remote attackers to affect confidentiality, integrity, and availability.  NOTE: the previous information was obtained from the April 2009 CPU.  Oracle has not commented on claims from a reliable researcher that this is an integer overflow in an unspecified plug-in that parses HTTP requests, which leads to a heap-based buffer overflow.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-105A.html" source="CERT">TA09-105A</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuapr2009.html" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuapr2009.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/64935" source="XF">oracle-bea-http-bo(64935)</ref>
      <ref url="http://www.securitytracker.com/id?1022059" source="SECTRACK">1022059</ref>
      <ref url="http://www.securityfocus.com/bid/34461" source="BID">34461</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/wls-security/1012.html" source="CONFIRM">http://www.oracle.com/technology/deploy/security/wls-security/1012.html</ref>
      <ref url="http://secunia.com/secunia_research/2009-22/" source="MISC">http://secunia.com/secunia_research/2009-22/</ref>
      <ref url="http://osvdb.org/53765" source="OSVDB">53765</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="bea_product_suite">
        <vers num="10.0" edition="mp1" />
        <vers num="10.3" />
        <vers num="7.0" edition="sp7" />
        <vers num="8.1" edition="sp6" />
        <vers num="9.0" />
        <vers num="9.1" />
        <vers num="9.2" edition="mp3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1013" published="2009-04-15" name="CVE-2009-1013" modified="2011-02-04" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Enterprise and JD Edwards EnterpriseOne 8.49.19 allows remote attackers to affect confidentiality and integrity via unknown vectors.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-105A.html" source="CERT">TA09-105A</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuapr2009.html" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuapr2009.html</ref>
      <ref url="http://www.securitytracker.com/id?1022057" source="SECTRACK">1022057</ref>
      <ref url="http://www.securityfocus.com/bid/34461" source="BID">34461</ref>
      <ref url="http://secunia.com/advisories/34693" source="SECUNIA">34693</ref>
      <ref url="http://osvdb.org/53756" source="OSVDB">53756</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="jd_edwards_enterpriseone">
        <vers num="8.49.19" />
      </prod>
      <prod vendor="oracle" name="peoplesoft_enterprise">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1014" published="2009-04-15" name="CVE-2009-1014" modified="2011-02-04" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)" CVSS_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_base_score="5.8">
    <desc>
      <descript source="cve">Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Enterprise and JD Edwards EnterpriseOne 8.49.19 allows remote attackers to affect confidentiality and integrity via unknown vectors.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-105A.html" source="CERT">TA09-105A</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuapr2009.html" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuapr2009.html</ref>
      <ref url="http://www.securitytracker.com/id?1022057" source="SECTRACK">1022057</ref>
      <ref url="http://www.securityfocus.com/bid/34461" source="BID">34461</ref>
      <ref url="http://secunia.com/advisories/34693" source="SECUNIA">34693</ref>
      <ref url="http://osvdb.org/53757" source="OSVDB">53757</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="jd_edwards_enterpriseone">
        <vers num="8.49.19" />
      </prod>
      <prod vendor="oracle" name="peoplesoft_enterprise">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1015" published="2009-07-14" name="CVE-2009-1015" modified="2009-08-12" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:N/I:P/A:N)" CVSS_score="4.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.0" CVSS_base_score="4.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Core RDBMS component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.05, and 10.2.04 allows remote authenticated users to affect integrity via unknown vectors.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujul2009.html" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujul2009.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/51747" source="XF">oracle-database-core-rdbms-unspecified(51747)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1900" source="VUPEN">ADV-2009-1900</ref>
      <ref url="http://www.securitytracker.com/id?1022560" source="SECTRACK">1022560</ref>
      <ref url="http://www.securityfocus.com/bid/35682" source="BID">35682</ref>
      <ref url="http://secunia.com/advisories/35776" source="SECUNIA">35776</ref>
      <ref url="http://osvdb.org/55893" source="OSVDB">55893</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="database_server">
        <vers num="10.1.0.5" />
        <vers num="10.2.0.4" />
        <vers num="9.2.0.8" />
        <vers num="9.2.0.8dv" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1016" published="2009-04-15" name="CVE-2009-1016" modified="2011-02-04" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:S/C:C/I:C/A:C)" CVSS_score="8.5" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="6.8" CVSS_base_score="8.5">
    <desc>
      <descript source="cve">Unspecified vulnerability in the WebLogic Server component in BEA Product Suite 10.3, 10.0 MP1, 9.2 MP3, 9.1, 9.0, 8.1 SP6, and 7.0 SP7 allows remote authenticated users to affect confidentiality, integrity, and availability, related to IIS.  NOTE: the previous information was obtained from the April 2009 CPU.  Oracle has not commented on claims from a reliable researcher that this is a stack-based buffer overflow involving an unspecified Server Plug-in and a crafted SSL certificate.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-105A.html" source="CERT">TA09-105A</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuapr2009.html" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuapr2009.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/64934" source="XF">oracle-bea-ssl-bo(64934)</ref>
      <ref url="http://www.securitytracker.com/id?1022059" source="SECTRACK">1022059</ref>
      <ref url="http://www.securityfocus.com/bid/34461" source="BID">34461</ref>
      <ref url="http://secunia.com/secunia_research/2009-23/" source="MISC">http://secunia.com/secunia_research/2009-23/</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="bea_product_suite">
        <vers num="10.0" edition="mp1" />
        <vers num="10.3" />
        <vers num="7.0" edition="sp7" />
        <vers num="8.1" edition="sp6" />
        <vers num="9.0" />
        <vers num="9.1" />
        <vers num="9.2" edition="mp3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1017" published="2009-04-15" name="CVE-2009-1017" modified="2011-02-04" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:N/A:N)" CVSS_score="4.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.0" CVSS_base_score="4.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the BI Publisher component in Oracle Application Server 5.6.2, 10.1.3.2.1, 10.1.3.3.3, and 10.1.3.4 allows remote authenticated users to affect confidentiality via unknown vectors.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-105A.html" source="CERT">TA09-105A</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuapr2009.html" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuapr2009.html</ref>
      <ref url="http://www.securitytracker.com/id?1022055" source="SECTRACK">1022055</ref>
      <ref url="http://www.securityfocus.com/bid/34461" source="BID">34461</ref>
      <ref url="http://secunia.com/advisories/34693" source="SECUNIA">34693</ref>
      <ref url="http://osvdb.org/53746" source="OSVDB">53746</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="application_server">
        <vers num="5.6.2" />
      </prod>
      <prod vendor="oracle" name="application_server_10g">
        <vers num="10.1.3.2.1" />
        <vers num="10.1.3.3.3" />
        <vers num="10.1.3.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1018" published="2009-10-22" name="CVE-2009-1018" modified="2009-10-31" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:N)" CVSS_score="5.5" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.0" CVSS_base_score="5.5">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Workspace Manager component in Oracle Database 10.2.0.4 allows remote authenticated users to affect confidentiality and integrity, related to SYS.LTRIC (WMSYS.LTRIC).</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-294A.html" source="CERT">TA09-294A</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuoct2009.html" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuoct2009.html</ref>
      <ref url="http://www.securitytracker.com/id?1023057" source="SECTRACK">1023057</ref>
      <ref url="http://www.securityfocus.com/bid/36765" source="BID">36765</ref>
      <ref url="http://secunia.com/advisories/37027" source="SECUNIA">37027</ref>
      <ref url="http://osvdb.org/59112" source="OSVDB">59112</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="database_server">
        <vers num="10.2.0.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1019" published="2009-07-14" name="CVE-2009-1019" modified="2009-08-12" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Network Authentication component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.0.5, 10.2.0.4, and 11.1.0.7 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujul2009.html" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujul2009.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/51748" source="XF">oracle-database-netauth-unspecified(51748)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1900" source="VUPEN">ADV-2009-1900</ref>
      <ref url="http://www.securitytracker.com/id?1022560" source="SECTRACK">1022560</ref>
      <ref url="http://www.securityfocus.com/bid/35680" source="BID">35680</ref>
      <ref url="http://secunia.com/advisories/35776" source="SECUNIA">35776</ref>
      <ref url="http://osvdb.org/55884" source="OSVDB">55884</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="database_server">
        <vers num="10.1.0.4" />
        <vers num="10.1.0.5" />
        <vers num="11.1.0.7" />
        <vers num="9.2.0.8" />
        <vers num="9.2.0.8dv" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1020" published="2009-07-14" name="CVE-2009-1020" modified="2009-08-12" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:C/I:C/A:C)" CVSS_score="9.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.0" CVSS_base_score="9.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Network Foundation component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.0.5, 10.2.0.4, and 11.1.0.7 allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujul2009.html" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujul2009.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/51749" source="XF">oracle-database-netfoundation-unspecified(51749)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1900" source="VUPEN">ADV-2009-1900</ref>
      <ref url="http://www.securitytracker.com/id?1022560" source="SECTRACK">1022560</ref>
      <ref url="http://www.securityfocus.com/bid/35684" source="BID">35684</ref>
      <ref url="http://secunia.com/advisories/35776" source="SECUNIA">35776</ref>
      <ref url="http://osvdb.org/55897" source="OSVDB">55897</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="database_server">
        <vers num="10.1.0.5" />
        <vers num="10.2.0.4" />
        <vers num="11.1.0.7" />
        <vers num="9.2.0.8" />
        <vers num="9.2.0.8dv" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1021" published="2009-07-14" name="CVE-2009-1021" modified="2009-08-12" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:N)" CVSS_score="5.5" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.0" CVSS_base_score="5.5">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Advanced Replication component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.0.5, and 10.2.0.3 allows remote authenticated users to affect confidentiality and integrity via unknown vectors.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujul2009.html" source="CONFIRM" patch="1" adv="1">http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujul2009.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/51750" source="XF">oracle-database-adv-replication-unspecified(51750)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1900" source="VUPEN">ADV-2009-1900</ref>
      <ref url="http://www.securitytracker.com/id?1022560" source="SECTRACK">1022560</ref>
      <ref url="http://www.securityfocus.com/bid/35685" source="BID">35685</ref>
      <ref url="http://secunia.com/advisories/35776" source="SECUNIA">35776</ref>
      <ref url="http://osvdb.org/55886" source="OSVDB">55886</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="database_server">
        <vers num="10.1.0.5" />
        <vers num="10.2.0.3" />
        <vers num="9.2.0.8" />
        <vers num="9.2.0.8dv" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1022" published="2009-03-19" name="CVE-2009-1022" modified="2009-03-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Heap-based buffer overflow in the Preview/ Set Segment function in Gretech GOMlab GOM Encoder 1.0.0.11 and earlier allows user-assisted remote attackers to cause a denial of service (memory corruption and application crash) or execute arbitrary code via a long text field in a subtitle (.srt) file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/49252" source="XF">gomencoder-srt-bo(49252)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0735" source="VUPEN" adv="1">ADV-2009-0735</ref>
      <ref url="http://www.securityfocus.com/bid/34120" source="BID">34120</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/501846/100/0/threaded" source="BUGTRAQ">20090316 [Bkis-04-2009] GOM Encoder Heap-based Buffer Overflow</ref>
      <ref url="http://www.milw0rm.com/exploits/8225" source="MILW0RM">8225</ref>
      <ref url="http://security.bkis.vn/?p=352" source="MISC">http://security.bkis.vn/?p=352</ref>
      <ref url="http://secunia.com/advisories/34314" source="SECUNIA" adv="1">34314</ref>
      <ref url="http://osvdb.org/52677" source="OSVDB">52677</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gomlab" name="gom_encoder">
        <vers prev="1" num="1.0.0.11" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1023" published="2009-03-19" name="CVE-2009-1023" modified="2009-04-02" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in index.php in phpComasy 0.9.1 allows remote attackers to execute arbitrary SQL commands via the entry_id parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/49268" source="XF">phpcomasy-entryid-sql-injection(49268)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0734" source="VUPEN">ADV-2009-0734</ref>
      <ref url="http://www.securityfocus.com/bid/34131" source="BID">34131</ref>
      <ref url="http://www.milw0rm.com/exploits/8220" source="MILW0RM">8220</ref>
      <ref url="http://osvdb.org/52817" source="OSVDB">52817</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpcomasy" name="phpcomasy">
        <vers num="0.9.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1024" published="2009-03-19" name="CVE-2009-1024" modified="2009-03-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in Beerwin PHPLinkAdmin 1.0 allow remote attackers to execute arbitrary SQL commands via the linkid parameter to edlink.php, and unspecified other vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/49265" source="XF">phplinkadmin-edlink-sql-injection(49265)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0733" source="VUPEN" adv="1">ADV-2009-0733</ref>
      <ref url="http://www.securityfocus.com/bid/34129" source="BID">34129</ref>
      <ref url="http://www.milw0rm.com/exploits/8216" source="MILW0RM">8216</ref>
      <ref url="http://secunia.com/advisories/34323" source="SECUNIA" adv="1">34323</ref>
      <ref url="http://osvdb.org/52778" source="OSVDB">52778</ref>
    </refs>
    <vuln_soft>
      <prod vendor="beerwin" name="phplinkadmin">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1025" published="2009-03-19" name="CVE-2009-1025" modified="2009-03-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in linkadmin.php in Beerwin PHPLinkAdmin 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the page parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/49265" source="XF">phplinkadmin-edlink-sql-injection(49265)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0733" source="VUPEN" adv="1">ADV-2009-0733</ref>
      <ref url="http://www.securityfocus.com/bid/34129" source="BID">34129</ref>
      <ref url="http://www.milw0rm.com/exploits/8216" source="MILW0RM">8216</ref>
      <ref url="http://secunia.com/advisories/34323" source="SECUNIA" adv="1">34323</ref>
      <ref url="http://osvdb.org/52779" source="OSVDB">52779</ref>
    </refs>
    <vuln_soft>
      <prod vendor="beerwin" name="phplinkadmin">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1026" published="2009-03-19" name="CVE-2009-1026" modified="2009-03-20" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in login.php in Kim Websites 1.0 allow remote attackers to execute arbitrary SQL commands via the (1) username and (2) password parameters.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/49259" source="XF">kimwebsites-login-sql-injection(49259)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0732" source="VUPEN" adv="1">ADV-2009-0732</ref>
      <ref url="http://www.securityfocus.com/bid/34116" source="BID">34116</ref>
      <ref url="http://www.milw0rm.com/exploits/8209" source="MILW0RM">8209</ref>
    </refs>
    <vuln_soft>
      <prod vendor="kimwebsites" name="kim_websites">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1027" published="2009-03-19" name="CVE-2009-1027" modified="2009-04-02" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in OpenCart 1.1.8 allows remote attackers to execute arbitrary SQL commands via the order parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/49262" source="XF">opencart-order-sql-injection(49262)</ref>
      <ref url="http://www.securityfocus.com/bid/34121" source="BID">34121</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/501843/100/0/threaded" source="BUGTRAQ">20090316 NGENUITY-2009-005 OpenCart Order By Blind SQL Injection</ref>
      <ref url="http://www.ngenuity.org/wordpress/2009/03/10/ngenuity-2009-005-opencart-order-by-blind-sql-injection/" source="MISC">http://www.ngenuity.org/wordpress/2009/03/10/ngenuity-2009-005-opencart-order-by-blind-sql-injection/</ref>
      <ref url="http://secunia.com/advisories/34313" source="SECUNIA">34313</ref>
    </refs>
    <vuln_soft>
      <prod vendor="opencart" name="opencart">
        <vers num="1.1.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1028" published="2009-03-19" name="CVE-2009-1028" modified="2011-09-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Stack-based buffer overflow in ediSys eZip Wizard 3.0 allows remote attackers to execute arbitrary code via a crafted .zip file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/49148" source="XF">ezipwizard-zip-bo(49148)</ref>
      <ref url="http://www.securityfocus.com/bid/34044" source="BID">34044</ref>
      <ref url="http://www.milw0rm.com/exploits/8180" source="MILW0RM">8180</ref>
      <ref url="http://securityreason.com/securityalert/8217" source="SREASON">8217</ref>
      <ref url="http://secunia.com/advisories/39169" source="SECUNIA">39169</ref>
    </refs>
    <vuln_soft>
      <prod vendor="edisys" name="ezip_wizard">
        <vers num="3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1029" published="2009-03-19" name="CVE-2009-1029" modified="2009-03-20" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Stack-based buffer overflow in POP Peeper 3.4.0.0 and earlier allows remote POP3 servers to execute arbitrary code via a long Date header, related to Imap.dll.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/49215" source="XF">poppeeper-date-bo(49215)</ref>
      <ref url="http://www.securityfocus.com/bid/34093" source="BID">34093</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/501701/100/0/threaded" source="BUGTRAQ">20090312 POP Peeper 3.4.0.0 Date Remote Buffer Overflow Vulnerability</ref>
      <ref url="http://www.milw0rm.com/exploits/8203" source="MILW0RM">8203</ref>
      <ref url="http://www.krakowlabs.com/res/adv/KL0309ADV-poppeeper_date-bof.txt" source="MISC">http://www.krakowlabs.com/res/adv/KL0309ADV-poppeeper_date-bof.txt</ref>
      <ref url="http://secunia.com/advisories/34077" source="SECUNIA" adv="1">34077</ref>
    </refs>
    <vuln_soft>
      <prod vendor="poppeeper" name="pop_peeper">
        <vers num="2.4.3" />
        <vers num="3.0" />
        <vers num="3.0.1" />
        <vers prev="1" num="3.4.0.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1030" published="2009-03-19" name="CVE-2009-1030" modified="2009-04-03" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the choose_primary_blog function in wp-includes/wpmu-functions.php in WordPress MU (WPMU) before 2.7 allows remote attackers to inject arbitrary web script or HTML via the HTTP Host header.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/49184" source="XF">wordpressmu-wpmufunctions-xss(49184)</ref>
      <ref url="http://www.securitytracker.com/id?1021838" source="SECTRACK">1021838</ref>
      <ref url="http://www.securityfocus.com/bid/34075" source="BID">34075</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/501667/100/0/threaded" source="BUGTRAQ">20090310 [ISecAuditors Security Advisories] WordPress MU HTTP Header XSS Vulnerability</ref>
      <ref url="http://www.milw0rm.com/exploits/8196" source="MILW0RM">8196</ref>
    </refs>
    <vuln_soft>
      <prod vendor="wordpress" name="wordpress_mu">
        <vers num="1.0" edition="rc1" />
        <vers num="1.0" edition="rc2" />
        <vers num="1.0" edition="rc3" />
        <vers num="1.0" edition="rc4" />
        <vers num="1.1" />
        <vers num="1.1.1" />
        <vers num="1.2" />
        <vers num="1.2.1" />
        <vers num="1.2.2" />
        <vers num="1.2.3" />
        <vers num="1.2.4" edition="rc1" />
        <vers num="1.2.5a" />
        <vers num="1.3" />
        <vers num="1.3.1" />
        <vers num="1.3.2" />
        <vers num="1.3.3" />
        <vers num="1.5" edition="rc1" />
        <vers num="1.5.1" />
        <vers prev="1" num="2.6" />
        <vers num="2.6.1" />
        <vers num="2.6.2" />
        <vers num="2.6.3" />
        <vers num="2.6.5" />
        <vers num="2.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1031" published="2009-03-19" name="CVE-2009-1031" modified="2010-04-27" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:C/A:N)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Directory traversal vulnerability in the FTP server in Rhino Software Serv-U File Server 7.0.0.1 through 7.4.0.1 allows remote attackers to create arbitrary directories via a \.. (backslash dot dot) in an MKD request.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/49258" source="XF">servuftp-mkd-dir-traversal(49258)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0738" source="VUPEN" adv="1">ADV-2009-0738</ref>
      <ref url="http://www.securityfocus.com/bid/34125" source="BID">34125</ref>
      <ref url="http://www.milw0rm.com/exploits/8211" source="MILW0RM">8211</ref>
      <ref url="http://secunia.com/advisories/34329" source="SECUNIA" adv="1">34329</ref>
      <ref url="http://osvdb.org/52773" source="OSVDB">52773</ref>
    </refs>
    <vuln_soft>
      <prod vendor="serv-u" name="serv-u">
        <vers num="7.0.0.1" />
        <vers num="7.0.0.2" />
        <vers num="7.0.0.3" />
        <vers num="7.0.0.4" />
        <vers num="7.1.0.0" />
        <vers num="7.1.0.1" />
        <vers num="7.1.0.2" />
        <vers num="7.2.0.0" />
        <vers num="7.2.0.1" />
        <vers num="7.3.0.0" />
        <vers num="7.3.0.1" />
        <vers num="7.3.0.2" />
        <vers num="7.4.0.0" />
        <vers num="7.4.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1032" published="2009-03-20" name="CVE-2009-1032" modified="2009-04-01" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in gallery_list.php in YABSoft Advanced Image Hosting (AIH) Script 2.3 allows remote attackers to execute arbitrary SQL commands via the gal parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/49316" source="XF">advancedimage-gallerylist-sql-injection(49316)</ref>
      <ref url="http://www.securityfocus.com/bid/34176" source="BID">34176</ref>
      <ref url="http://www.milw0rm.com/exploits/8238" source="MILW0RM">8238</ref>
      <ref url="http://secunia.com/advisories/34366" source="SECUNIA" adv="1">34366</ref>
      <ref url="http://osvdb.org/52813" source="OSVDB">52813</ref>
    </refs>
    <vuln_soft>
      <prod vendor="yabsoft" name="advanced_image_hosting_script">
        <vers num="2.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1033" published="2009-03-20" name="CVE-2009-1033" modified="2009-04-01" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in misc.php in DeluxeBB 1.3 and earlier allows remote attackers to execute arbitrary SQL commands via the qorder parameter, a different vector than CVE-2005-2989 and CVE-2006-2503.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/49313" source="XF">deluxebb-qorder-sql-injection(49313)</ref>
      <ref url="http://www.securityfocus.com/bid/34174" source="BID">34174</ref>
      <ref url="http://www.milw0rm.com/exploits/8240" source="MILW0RM">8240</ref>
      <ref url="http://secunia.com/advisories/34365" source="SECUNIA" adv="1">34365</ref>
      <ref url="http://osvdb.org/52788" source="OSVDB">52788</ref>
    </refs>
    <vuln_soft>
      <prod vendor="deluxebb" name="deluxebb">
        <vers num="1.0" />
        <vers num="1.05" />
        <vers num="1.06" />
        <vers num="1.07" />
        <vers num="1.08" />
        <vers num="1.09" />
        <vers num="1.1" />
        <vers num="1.2" />
        <vers prev="1" num="1.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1034" published="2009-03-20" name="CVE-2009-1034" modified="2009-04-01" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">SQL injection vulnerability in the Tasklist module 5.x-1.x before 5.x-1.3 and 5.x-2.x before 5.x-2.0-alpha1, a module for Drupal, allows remote attackers to execute arbitrary SQL commands via values in the URI.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://drupal.org/node/406316" source="CONFIRM" patch="1" adv="1">http://drupal.org/node/406316</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/49320" source="XF">tasklist-unspecifed-sql-injection(49320)</ref>
      <ref url="http://www.securityfocus.com/bid/34171" source="BID">34171</ref>
      <ref url="http://www.osvdb.org/52781" source="OSVDB">52781</ref>
      <ref url="http://secunia.com/advisories/34376" source="SECUNIA">34376</ref>
    </refs>
    <vuln_soft>
      <prod vendor="drupal" name="tasklist">
        <vers prev="1" num="5.x-1.x" />
        <vers prev="1" num="5.x-2.x" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1035" published="2009-03-20" name="CVE-2009-1035" modified="2010-08-30" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the Tasklist module 5.x-1.x before 5.x-1.3 and 5.x-2.x before 5.x-2.0-alpha1, a module for Drupal, allows remote authenticated users to inject arbitrary web script or HTML via Cascading Style Sheets (CSS).</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/49319" source="XF">tasklist-css-xss(49319)</ref>
      <ref url="http://www.securityfocus.com/bid/34170" source="BID">34170</ref>
      <ref url="http://secunia.com/advisories/34376" source="SECUNIA" adv="1">34376</ref>
      <ref url="http://osvdb.org/52782" source="OSVDB">52782</ref>
      <ref url="http://drupal.org/node/406316" source="CONFIRM" adv="1">http://drupal.org/node/406316</ref>
    </refs>
    <vuln_soft>
      <prod vendor="jake_gordon" name="tasks">
        <vers num="5.x-1.0" />
        <vers num="5.x-1.2" />
        <vers num="5.x-2.x-dev" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1036" published="2009-03-20" name="CVE-2009-1036" modified="2009-04-02" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site request forgery (CSRF) vulnerability in the Plus 1 module before 6.x-2.6, a module for Drupal, allows remote attackers to cast votes for content via unspecified aspects of the URI.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://drupal.org/node/406314" source="CONFIRM" patch="1" adv="1">http://drupal.org/node/406314</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/49310" source="XF">plus1-unspecified-csrf(49310)</ref>
      <ref url="http://www.securityfocus.com/bid/34168" source="BID">34168</ref>
      <ref url="http://secunia.com/advisories/34378" source="SECUNIA">34378</ref>
      <ref url="http://osvdb.org/52786" source="OSVDB">52786</ref>
      <ref url="http://drupal.org/node/405672" source="CONFIRM">http://drupal.org/node/405672</ref>
    </refs>
    <vuln_soft>
      <prod vendor="drupal" name="plus1">
        <vers num="6.x-1.0" />
        <vers num="6.x-1.1" />
        <vers num="6.x-1.2" />
        <vers num="6.x-1.3" />
        <vers num="6.x-2.0" edition="beta2" />
        <vers num="6.x-2.0" edition="beta3" />
        <vers num="6.x-2.0" edition="beta4" />
        <vers num="6.x-2.0" edition="beta5" />
        <vers num="6.x-2.1" />
        <vers num="6.x-2.2" />
        <vers num="6.x-2.3" />
        <vers num="6.x-2.4" />
        <vers prev="1" num="6.x-2.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1037" published="2009-03-20" name="CVE-2009-1037" modified="2009-03-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Send by e-mail module in the "Printer, e-mail and PDF versions" module 5.x before 5.x-4.4 and 6.x before 6.x-1.4, a module for Drupal, allows remote attackers to send unlimited spam messages via unknown vectors related to the flood control API.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://drupal.org/node/406516" source="CONFIRM" patch="1" adv="1">http://drupal.org/node/406516</ref>
      <ref url="http://www.securityfocus.com/bid/34173" source="BID">34173</ref>
      <ref url="http://secunia.com/advisories/34374" source="SECUNIA" adv="1">34374</ref>
      <ref url="http://osvdb.org/52785" source="OSVDB">52785</ref>
    </refs>
    <vuln_soft>
      <prod vendor="drupal" name="print">
        <vers num="5.x" />
        <vers num="5.x-1.0" />
        <vers num="5.x-1.1" />
        <vers num="5.x-1.2" />
        <vers num="5.x-1.x-dev" />
        <vers num="5.x-2.1" />
        <vers num="5.x-2.2" />
        <vers num="5.x-2.x-dev" />
        <vers num="5.x-3.0" />
        <vers num="5.x-3.1" />
        <vers num="5.x-3.2" />
        <vers num="5.x-3.3" />
        <vers num="5.x-3.4" />
        <vers num="5.x-3.5" />
        <vers num="5.x-3.6" />
        <vers num="5.x-3.7" />
        <vers num="5.x-4.0" />
        <vers num="5.x-4.1" />
        <vers num="5.x-4.2" />
        <vers num="5.x-4.3" />
        <vers num="5.x-4.x" edition="dev" />
        <vers num="6.x-1.0" />
        <vers num="6.x-1.0-rc3" />
        <vers num="6.x-1.0-rc4" />
        <vers num="6.x-1.0-rc5" />
        <vers num="6.x-1.0-rc8" />
        <vers num="6.x-1.0-rc9" />
        <vers num="6.x-1.1" />
        <vers num="6.x-1.2" />
        <vers num="6.x-1.3" />
        <vers num="6.x-1.x-dev" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1038" published="2009-03-20" name="CVE-2009-1038" modified="2009-04-02" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)" CVSS_score="6.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.0" CVSS_base_score="6.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in YAP Blog 1.1.1 allow remote attackers to execute arbitrary SQL commands via the (1) image_id parameter to comments.php, and remote authenticated administrators to execute arbitrary SQL commands via the (2) user parameter in a modif action to admin/index.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/34274" source="BID">34274</ref>
      <ref url="http://www.milw0rm.com/exploits/8217" source="MILW0RM">8217</ref>
      <ref url="http://osvdb.org/52762" source="OSVDB">52762</ref>
      <ref url="http://osvdb.org/52761" source="OSVDB">52761</ref>
    </refs>
    <vuln_soft>
      <prod vendor="yap" name="yap_blog">
        <vers num="1.1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1039" published="2009-03-20" name="CVE-2009-1039" modified="2009-04-01" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Buffer overflow in CDex 1.70b2 allows remote attackers to execute arbitrary code via a crafted Info header in an Ogg Vorbis (.ogg) file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/49304" source="XF">cdex-ogg-bo(49304)</ref>
      <ref url="http://www.securityfocus.com/bid/34164" source="BID">34164</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/501928/100/0/threaded" source="BUGTRAQ">20090317 CDex v1.70b2 (.ogg) local buffer overflow exploit poc</ref>
      <ref url="http://www.milw0rm.com/exploits/8231" source="MILW0RM">8231</ref>
      <ref url="http://retrogod.altervista.org/9sg_cdex_ogg.html" source="MISC">http://retrogod.altervista.org/9sg_cdex_ogg.html</ref>
      <ref url="http://osvdb.org/52812" source="OSVDB">52812</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cdexos" name="cdex">
        <vers num="170b2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1040" published="2009-03-20" name="CVE-2009-1040" modified="2009-03-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Buffer overflow in WinAsm Studio 5.1.5.0 allows user-assisted remote attackers to execute arbitrary code via a crafted project (.wap) file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/49266" source="XF">winasmstudio-wap-bo(49266)</ref>
      <ref url="http://www.securityfocus.com/bid/34132" source="BID">34132</ref>
      <ref url="http://www.milw0rm.com/exploits/8224" source="MILW0RM">8224</ref>
      <ref url="http://secunia.com/advisories/34309" source="SECUNIA" adv="1">34309</ref>
      <ref url="http://osvdb.org/52776" source="OSVDB">52776</ref>
    </refs>
    <vuln_soft>
      <prod vendor="winasm" name="winasm_studio">
        <vers num="5.1.5.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1041" published="2009-03-26" name="CVE-2009-1041" modified="2009-04-02" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">The ktimer feature (sys/kern/kern_time.c) in FreeBSD 7.0, 7.1, and 7.2 allows local users to overwrite arbitrary kernel memory via an out-of-bounds timer value.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/49362" source="XF">freebsd-ktimer-memory-overwrite(49362)</ref>
      <ref url="http://www.securitytracker.com/id?1021882" source="SECTRACK">1021882</ref>
      <ref url="http://www.securityfocus.com/bid/34196" source="BID">34196</ref>
      <ref url="http://www.milw0rm.com/exploits/8261" source="MILW0RM">8261</ref>
      <ref url="http://security.freebsd.org/advisories/FreeBSD-SA-09:06.ktimer.asc" source="FREEBSD">FreeBSD-SA-09:06</ref>
    </refs>
    <vuln_soft>
      <prod vendor="freebsd" name="freebsd">
        <vers num="7.0" edition="pre-release" />
        <vers num="7.0" edition="release" />
        <vers num="7.0" edition="release-p8" />
        <vers num="7.0" edition="release-p9" />
        <vers num="7.0" edition="releng" />
        <vers num="7.0" edition="stable" />
        <vers num="7.1" edition="pre-release" />
        <vers num="7.1" edition="release-p1" />
        <vers num="7.1" edition="release-p2" />
        <vers num="7.1" edition="stable" />
        <vers num="7.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1042" published="2009-03-23" name="CVE-2009-1042" modified="2011-01-20" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Unspecified vulnerability in Apple Safari on Mac OS X 10.5.6 allows remote attackers to execute arbitrary code via unknown vectors triggered by clicking on a link, as demonstrated by Nils during a PWN2OWN competition at CanSecWest 2009.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/49388" source="XF">apple-safari-unspecified-code-execution(49388)</ref>
      <ref url="http://www.securitytracker.com/id?1021879" source="SECTRACK">1021879</ref>
      <ref url="http://www.securityfocus.com/bid/34183" source="BID">34183</ref>
      <ref url="http://www.h-online.com/security/Pwn2Own-2009-Safari-IE-8-and-Firefox-exploited--/news/112889" source="MISC">http://www.h-online.com/security/Pwn2Own-2009-Safari-IE-8-and-Firefox-exploited--/news/112889</ref>
      <ref url="http://twitter.com/tippingpoint1/status/1351485521" source="MISC">http://twitter.com/tippingpoint1/status/1351485521</ref>
      <ref url="http://osvdb.org/52888" source="OSVDB">52888</ref>
      <ref url="http://news.cnet.com/8301-1009_3-10199652-83.html" source="MISC">http://news.cnet.com/8301-1009_3-10199652-83.html</ref>
      <ref url="http://dvlabs.tippingpoint.com/blog/2009/03/18/pwn2own-2009-day-1---safari-internet-explorer-and-firefox-taken-down-by-four-zero-day-exploits" source="MISC">http://dvlabs.tippingpoint.com/blog/2009/03/18/pwn2own-2009-day-1---safari-internet-explorer-and-firefox-taken-down-by-four-zero-day-exploits</ref>
      <ref url="http://dvlabs.tippingpoint.com/blog/2009/02/25/pwn2own-2009" source="MISC">http://dvlabs.tippingpoint.com/blog/2009/02/25/pwn2own-2009</ref>
      <ref url="http://cansecwest.com/index.html" source="MISC">http://cansecwest.com/index.html</ref>
      <ref url="http://blogs.zdnet.com/security/?p=2934" source="MISC">http://blogs.zdnet.com/security/?p=2934</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="safari">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1043" published="2009-03-23" name="CVE-2009-1043" modified="2009-04-02" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in Microsoft Internet Explorer 8 on Windows 7 allows remote attackers to execute arbitrary code via unknown vectors triggered by clicking on a link, as demonstrated by Nils during a PWN2OWN competition at CanSecWest 2009.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/49389" source="XF">microsoft-ie-unspecified-code-execution(49389)</ref>
      <ref url="http://www.securitytracker.com/id?1021880" source="SECTRACK">1021880</ref>
      <ref url="http://www.securityfocus.com/bid/34182" source="BID">34182</ref>
      <ref url="http://www.h-online.com/security/Pwn2Own-2009-Safari-IE-8-and-Firefox-exploited--/news/112889" source="MISC">http://www.h-online.com/security/Pwn2Own-2009-Safari-IE-8-and-Firefox-exploited--/news/112889</ref>
      <ref url="http://osvdb.org/52892" source="OSVDB">52892</ref>
      <ref url="http://news.cnet.com/8301-1009_3-10199652-83.html" source="MISC">http://news.cnet.com/8301-1009_3-10199652-83.html</ref>
      <ref url="http://dvlabs.tippingpoint.com/blog/2009/03/20/pwn2own-day-2" source="MISC">http://dvlabs.tippingpoint.com/blog/2009/03/20/pwn2own-day-2</ref>
      <ref url="http://dvlabs.tippingpoint.com/blog/2009/03/18/pwn2own-2009-day-1---safari-internet-explorer-and-firefox-taken-down-by-four-zero-day-exploits" source="MISC">http://dvlabs.tippingpoint.com/blog/2009/03/18/pwn2own-2009-day-1---safari-internet-explorer-and-firefox-taken-down-by-four-zero-day-exploits</ref>
      <ref url="http://dvlabs.tippingpoint.com/blog/2009/02/25/pwn2own-2009" source="MISC">http://dvlabs.tippingpoint.com/blog/2009/02/25/pwn2own-2009</ref>
      <ref url="http://cansecwest.com/index.html" source="MISC">http://cansecwest.com/index.html</ref>
      <ref url="http://blogs.zdnet.com/security/?p=2934" source="MISC">http://blogs.zdnet.com/security/?p=2934</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1044" published="2009-03-23" name="CVE-2009-1044" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Mozilla Firefox 3.0.7 on Windows 7 allows remote attackers to execute arbitrary code via unknown vectors related to the _moveToEdgeShift XUL tree method, which triggers garbage collection on objects that are still in use, as demonstrated by Nils during a PWN2OWN competition at CanSecWest 2009.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=484320" source="CONFIRM" patch="1">https://bugzilla.mozilla.org/show_bug.cgi?id=484320</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0864" source="VUPEN" patch="1" adv="1">ADV-2009-0864</ref>
      <ref url="http://www.securityfocus.com/bid/34181" source="BID" patch="1">34181</ref>
      <ref url="http://www.mozilla.org/security/announce/2009/mfsa2009-13.html" source="CONFIRM" patch="1" adv="1">http://www.mozilla.org/security/announce/2009/mfsa2009-13.html</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-March/msg01077.html" source="FEDORA">FEDORA-2009-3101</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-March/msg01040.html" source="FEDORA">FEDORA-2009-3100</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-March/msg01023.html" source="FEDORA">FEDORA-2009-3099</ref>
      <ref url="http://www.zerodayinitiative.com/advisories/ZDI-09-015" source="MISC">http://www.zerodayinitiative.com/advisories/ZDI-09-015</ref>
      <ref url="http://www.ubuntu.com/usn/usn-745-1" source="UBUNTU">USN-745-1</ref>
      <ref url="http://www.securitytracker.com/id?1021878" source="SECTRACK">1021878</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/502303/100/0/threaded" source="BUGTRAQ">20090330 ZDI-09-015: Mozilla Firefox XUL _moveToEdgeShift() Memory Corruption Vulnerability</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-0398.html" source="REDHAT">RHSA-2009:0398</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-0397.html" source="REDHAT">RHSA-2009:0397</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:084" source="MANDRIVA">MDVSA-2009:084</ref>
      <ref url="http://www.h-online.com/security/Pwn2Own-2009-Safari-IE-8-and-Firefox-exploited--/news/112889" source="MISC">http://www.h-online.com/security/Pwn2Own-2009-Safari-IE-8-and-Firefox-exploited--/news/112889</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1756" source="DEBIAN">DSA-1756</ref>
      <ref url="http://twitter.com/tippingpoint1/status/1351635812" source="MISC">http://twitter.com/tippingpoint1/status/1351635812</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2009-113.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2009-113.htm</ref>
      <ref url="http://secunia.com/advisories/34792" source="SECUNIA" adv="1">34792</ref>
      <ref url="http://secunia.com/advisories/34550" source="SECUNIA" adv="1">34550</ref>
      <ref url="http://secunia.com/advisories/34549" source="SECUNIA" adv="1">34549</ref>
      <ref url="http://secunia.com/advisories/34527" source="SECUNIA" adv="1">34527</ref>
      <ref url="http://secunia.com/advisories/34521" source="SECUNIA" adv="1">34521</ref>
      <ref url="http://secunia.com/advisories/34511" source="SECUNIA" adv="1">34511</ref>
      <ref url="http://secunia.com/advisories/34510" source="SECUNIA" adv="1">34510</ref>
      <ref url="http://secunia.com/advisories/34505" source="SECUNIA" adv="1">34505</ref>
      <ref url="http://secunia.com/advisories/34471" source="SECUNIA" adv="1">34471</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11368" source="OVAL">oval:org.mitre.oval:def:11368</ref>
      <ref url="http://osvdb.org/52896" source="OSVDB">52896</ref>
      <ref url="http://news.cnet.com/8301-1009_3-10199652-83.html" source="MISC">http://news.cnet.com/8301-1009_3-10199652-83.html</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-04/msg00008.html" source="SUSE">SUSE-SA:2009:022</ref>
      <ref url="http://dvlabs.tippingpoint.com/blog/2009/03/18/pwn2own-2009-day-1---safari-internet-explorer-and-firefox-taken-down-by-four-zero-day-exploits" source="MISC">http://dvlabs.tippingpoint.com/blog/2009/03/18/pwn2own-2009-day-1---safari-internet-explorer-and-firefox-taken-down-by-four-zero-day-exploits</ref>
      <ref url="http://dvlabs.tippingpoint.com/blog/2009/02/25/pwn2own-2009" source="MISC">http://dvlabs.tippingpoint.com/blog/2009/02/25/pwn2own-2009</ref>
      <ref url="http://cansecwest.com/index.html" source="MISC">http://cansecwest.com/index.html</ref>
      <ref url="http://blogs.zdnet.com/security/?p=2941" source="MISC">http://blogs.zdnet.com/security/?p=2941</ref>
      <ref url="http://blogs.zdnet.com/security/?p=2934" source="MISC">http://blogs.zdnet.com/security/?p=2934</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="3.0.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1045" published="2009-03-23" name="CVE-2009-1045" modified="2012-01-27" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">requests/status.xml in VLC 0.9.8a allows remote attackers to cause a denial of service (stack consumption and crash) via a long input argument in an in_play action.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/49249" source="XF">vlcmediaplayer-web-status-bo(49249)</ref>
      <ref url="http://www.securityfocus.com/bid/34126" source="BID">34126</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2009/03/17/4" source="MLIST">[oss-security] 20090317 CVE request -- firefox, vlc, WeeChat</ref>
      <ref url="http://www.milw0rm.com/exploits/8213" source="MILW0RM">8213</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:14357" source="OVAL">oval:org.mitre.oval:def:14357</ref>
      <ref url="http://bugs.gentoo.org/show_bug.cgi?id=262708" source="MISC">http://bugs.gentoo.org/show_bug.cgi?id=262708</ref>
    </refs>
    <vuln_soft>
      <prod vendor="videolan" name="vlc_media_player">
        <vers num="0.9.8a" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1046" published="2009-03-23" name="CVE-2009-1046" modified="2009-05-23" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:N/I:N/A:C)" CVSS_score="4.7" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="3.4" CVSS_base_score="4.7">
    <desc>
      <descript source="cve">The console selection feature in the Linux kernel 2.6.28 before 2.6.28.4, 2.6.25, and possibly earlier versions, when the UTF-8 console is used, allows physically proximate attackers to cause a denial of service (memory corruption) by selecting a small number of 3-byte UTF-8 characters, which triggers an "an off-by-two memory error." NOTE: it is not clear whether this issue crosses privilege boundaries.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/33672" source="BID" patch="1">33672</ref>
      <ref url="http://lists.openwall.net/linux-kernel/2009/02/02/364" source="MLIST" patch="1">[linux-kernel] 20090202 Re: [PATCH] Fix memory corruption in console selection</ref>
      <ref url="http://lists.openwall.net/linux-kernel/2009/01/30/333" source="MLIST" patch="1">[linux-kernel] 20090130 [PATCH] Fix memory corruption in console selection</ref>
      <ref url="http://www.ubuntu.com/usn/usn-751-1" source="UBUNTU">USN-751-1</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-0451.html" source="REDHAT">RHSA-2009:0451</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2009/02/12/9" source="MLIST">[oss-security] 20090212 http://www.securityfocus.com/bid/33672/info kernel issue</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2009/02/12/11" source="MLIST">[oss-security] 20090212 Re: http://www.securityfocus.com/bid/33672/info kernel issue</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2009/02/12/10" source="MLIST">[oss-security] 20090212 Re: http://www.securityfocus.com/bid/33672/info kernel</ref>
      <ref url="http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.28.4" source="CONFIRM">http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.28.4</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1800" source="DEBIAN">DSA-1800</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1787" source="DEBIAN">DSA-1787</ref>
      <ref url="http://secunia.com/advisories/35121" source="SECUNIA">35121</ref>
      <ref url="http://secunia.com/advisories/34981" source="SECUNIA">34981</ref>
      <ref url="http://secunia.com/advisories/34917" source="SECUNIA">34917</ref>
    </refs>
    <vuln_soft>
      <prod vendor="kernel" name="linux">
        <vers num="2.6.25" />
        <vers num="2.6.28" />
        <vers num="2.6.28.1" />
        <vers num="2.6.28.2" />
        <vers num="2.6.28.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1047" published="2009-03-23" name="CVE-2009-1047" modified="2009-04-01" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the Send by e-mail module in the "Printer, e-mail and PDF versions" module 5.x before 5.x-4.4 and 6.x before 6.x-1.4, a module for Drupal, allows remote attackers to inject arbitrary web script or HTML via vectors involving outbound HTML e-mail.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://drupal.org/node/406516" source="CONFIRM" patch="1" adv="1">http://drupal.org/node/406516</ref>
      <ref url="http://osvdb.org/52852" source="OSVDB">52852</ref>
    </refs>
    <vuln_soft>
      <prod vendor="drupal" name="drupal">
        <vers num="" />
      </prod>
      <prod vendor="drupal" name="print">
        <vers num="5.x" />
        <vers num="5.x-1.0" />
        <vers num="5.x-1.1" />
        <vers num="5.x-1.2" />
        <vers num="5.x-1.x-dev" />
        <vers num="5.x-2.1" />
        <vers num="5.x-2.2" />
        <vers num="5.x-2.x-dev" />
        <vers num="5.x-3.0" />
        <vers num="5.x-3.1" />
        <vers num="5.x-3.2" />
        <vers num="5.x-3.3" />
        <vers num="5.x-3.4" />
        <vers num="5.x-3.5" />
        <vers num="5.x-3.6" />
        <vers num="5.x-3.7" />
        <vers num="5.x-4.0" />
        <vers num="5.x-4.1" />
        <vers num="5.x-4.2" />
        <vers num="5.x-4.3" />
        <vers num="5.x-4.x" edition="dev" />
        <vers num="6.x-1.0" />
        <vers num="6.x-1.0-rc3" />
        <vers num="6.x-1.0-rc4" />
        <vers num="6.x-1.0-rc5" />
        <vers num="6.x-1.0-rc8" />
        <vers num="6.x-1.0-rc9" />
        <vers num="6.x-1.1" />
        <vers num="6.x-1.2" />
        <vers num="6.x-1.3" />
        <vers num="6.x-1.4" />
        <vers num="6.x-1.x-dev" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1048" published="2009-08-14" name="CVE-2009-1048" modified="2009-08-19" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">The web interface on the snom VoIP phones snom 300, snom 320, snom 360, snom 370, and snom 820 with firmware 6.5 before 6.5.20, 7.1 before 7.1.39, and 7.3 before 7.3.14 allows remote attackers to bypass authentication, and reconfigure the phone or make arbitrary use of the phone, via a (1) http or (2) https request with 127.0.0.1 in the Host header.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/52424" source="XF">snom-httphost-security-bypass(52424)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/505723/100/0/threaded" source="BUGTRAQ">20090812 Authentication Bypass of Snom Phone Web Interface</ref>
      <ref url="http://www.csnc.ch/misc/files/advisories/cve-2009-1048.txt" source="MISC">http://www.csnc.ch/misc/files/advisories/cve-2009-1048.txt</ref>
      <ref url="http://secunia.com/advisories/36293" source="SECUNIA" adv="1">36293</ref>
    </refs>
    <vuln_soft>
      <prod vendor="snom" name="snom_300">
        <vers num="6.5.13" />
        <vers num="6.5.15" />
        <vers num="6.5.16" />
        <vers num="6.5.17" />
        <vers num="6.5.2" />
        <vers num="6.5.8" />
        <vers num="7.1.30" />
        <vers num="7.1.33" />
        <vers num="7.1.35" />
        <vers num="7.3.10a" />
        <vers num="7.3.4" />
        <vers num="7.3.7" />
      </prod>
      <prod vendor="snom" name="snom_320">
        <vers num="6.5.13" />
        <vers num="6.5.16" />
        <vers num="6.5.17" />
        <vers num="6.5.2" />
        <vers num="6.5.8" />
        <vers num="7.1.30" />
        <vers num="7.1.33" />
        <vers num="7.1.35" />
        <vers num="7.3.4" />
        <vers num="7.3.7" />
      </prod>
      <prod vendor="snom" name="snom_360">
        <vers num="6.5.13" />
        <vers num="6.5.15" />
        <vers num="6.5.16" />
        <vers num="6.5.17" />
        <vers num="6.5.2" />
        <vers num="6.5.8" />
        <vers num="7.1.30" />
        <vers num="7.1.33" />
        <vers num="7.1.35" />
        <vers num="7.3.10a" />
        <vers num="7.3.4" />
        <vers num="7.3.7" />
      </prod>
      <prod vendor="snom" name="snom_370">
        <vers num="7.1.30" />
        <vers num="7.1.33" />
        <vers num="7.1.35" />
        <vers num="7.3.10a" />
        <vers num="7.3.4" />
        <vers num="7.3.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1049" published="2009-03-24" name="CVE-2009-1049" modified="2009-04-03" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in articleCall.php in Bloginator 1A allows remote attackers to execute arbitrary SQL commands via the id parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/49325" source="XF">bloginator-articlecall-sql-injection(49325)</ref>
      <ref url="http://www.securityfocus.com/bid/34187" source="BID">34187</ref>
      <ref url="http://www.milw0rm.com/exploits/8244" source="MILW0RM">8244</ref>
      <ref url="http://www.milw0rm.com/exploits/8243" source="MILW0RM">8243</ref>
      <ref url="http://secunia.com/advisories/34395" source="SECUNIA" adv="1">34395</ref>
      <ref url="http://osvdb.org/52839" source="OSVDB">52839</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1050" published="2009-03-24" name="CVE-2009-1050" modified="2009-04-03" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Bloginator 1A allows remote attackers to bypass authentication and gain administrative access by setting the identifyYourself cookie.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/49324" source="XF">bloginator-cookie-security-bypass(49324)</ref>
      <ref url="http://www.securityfocus.com/bid/34187" source="BID">34187</ref>
      <ref url="http://www.milw0rm.com/exploits/8243" source="MILW0RM">8243</ref>
      <ref url="http://secunia.com/advisories/34395" source="SECUNIA" adv="1">34395</ref>
      <ref url="http://osvdb.org/52838" source="OSVDB">52838</ref>
    </refs>
    <vuln_soft>
      <prod vendor="kamads" name="bloginator">
        <vers num="1a" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1051" published="2009-03-24" name="CVE-2009-1051" modified="2009-04-02" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">FubarForum 1.6 and earlier stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing user credentials via a direct request for user.tsv.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/501902/100/0/threaded" source="BUGTRAQ">20090317 [ECHO_ADV_107$2009] FubarForum &lt;= 1.6 Critical File Disclosure Vulnerability</ref>
      <ref url="http://secunia.com/advisories/34358" source="SECUNIA">34358</ref>
      <ref url="http://e-rdc.org/v1/news.php?readmore=131" source="MISC">http://e-rdc.org/v1/news.php?readmore=131</ref>
    </refs>
    <vuln_soft>
      <prod vendor="chaozz" name="fubarforum">
        <vers num="1.0" />
        <vers num="1.1" />
        <vers num="1.2" />
        <vers num="1.3" />
        <vers num="1.4" />
        <vers num="1.5" />
        <vers prev="1" num="1.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1052" published="2009-03-24" name="CVE-2009-1052" modified="2009-04-02" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">FireAnt 1.3 and earlier stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing user credentials via a direct request for user.tsv.</descript>
    </desc>
    <impacts>
      <impact source="nvd">Additional information available at:

http://secunia.com/advisories/34359/</impact>
    </impacts>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/501905/100/0/threaded" source="BUGTRAQ">20090317 [ECHO_ADV_106$2009] FireAnt &lt;= 1.3 Critical File Disclosure Vulnerability</ref>
      <ref url="http://secunia.com/advisories/34359" source="SECUNIA">34359</ref>
      <ref url="http://e-rdc.org/v1/news.php?readmore=130" source="MISC">http://e-rdc.org/v1/news.php?readmore=130</ref>
    </refs>
    <vuln_soft>
      <prod vendor="chaozz" name="fireant">
        <vers num="1.0" />
        <vers num="1.2" />
        <vers prev="1" num="1.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1053" published="2009-03-24" name="CVE-2009-1053" modified="2009-03-24" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">chaozzDB 1.2 and earlier stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing user credentials via a direct request for user.tsv.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/501901/100/0/threaded" source="BUGTRAQ">20090317 [ECHO_ADV_105$2009] chaozzDB &lt;= 1.2 Critical File Disclosure Vulnerability</ref>
      <ref url="http://e-rdc.org/v1/news.php?readmore=129" source="MISC">http://e-rdc.org/v1/news.php?readmore=129</ref>
    </refs>
    <vuln_soft>
      <prod vendor="chaozz" name="chaozzdb">
        <vers num="1.0" />
        <vers num="1.1" />
        <vers prev="1" num="1.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1054" published="2009-03-24" name="CVE-2009-1054" modified="2009-03-25" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Unspecified vulnerability in JustSystems Ichitaro 13, 2004 through 2008, Lite2, and Ichitaro viewer 5.1.5.0 and earlier allows remote attackers to execute arbitrary code via a crafted file, as exploited in the wild by Trojan.Tarodrop.H in March 2009.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.justsystems.com/jp/info/js09001.html" source="CONFIRM" patch="1" adv="1">http://www.justsystems.com/jp/info/js09001.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/49280" source="XF">ichitaro-webpuraguinbyua-code-execution(49280)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0769" source="VUPEN" adv="1">ADV-2009-0769</ref>
      <ref url="http://www.symantec.com/business/security_response/writeup.jsp?docid=2009-031608-2424-99" source="MISC">http://www.symantec.com/business/security_response/writeup.jsp?docid=2009-031608-2424-99</ref>
      <ref url="http://www.securityfocus.com/bid/34138" source="BID">34138</ref>
      <ref url="http://secunia.com/advisories/34405" source="SECUNIA" adv="1">34405</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ichitaro" name="ichitaro">
        <vers num="13" />
        <vers num="2004" />
        <vers num="2005" />
        <vers num="2006" />
        <vers num="2007" />
        <vers num="2008" />
        <vers num="lite2" />
      </prod>
      <prod vendor="ichitaro" name="ichitaro_viewer">
        <vers prev="1" num="5.1.5.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1055" published="2009-03-24" name="CVE-2009-1055" modified="2009-03-24" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:N/A:N)" CVSS_score="4.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.0" CVSS_base_score="4.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the web service in Sitecore CMS 5.3.1 rev. 071114 allows remote authenticated users to gain access to security databases, and obtain administrative and user credentials, via unknown vectors related to SOAP and XML requests.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/49298" source="XF">sitecore-web-service-info-disclosure(49298)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0753" source="VUPEN" adv="1">ADV-2009-0753</ref>
      <ref url="http://www.securityfocus.com/bid/34162" source="BID">34162</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/501929/100/0/threaded" source="BUGTRAQ">20090317 Sitecore .NET 5.3.x - web service information disclosure</ref>
      <ref url="http://secunia.com/advisories/34356" source="SECUNIA" adv="1">34356</ref>
      <ref url="http://sdn5.sitecore.net/Products/Sitecore%20V5/Sitecore%20CMS%205,-d-,3/ReleaseNotes/V5,-d-,3,-d-,2/ChangeLog.aspx" source="CONFIRM" adv="1">http://sdn5.sitecore.net/Products/Sitecore%20V5/Sitecore%20CMS%205,-d-,3/ReleaseNotes/V5,-d-,3,-d-,2/ChangeLog.aspx</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sitecore" name="cms">
        <vers num="5.3.0" />
        <vers num="5.3.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1056" published="2009-03-24" name="CVE-2009-1056" modified="2009-04-02" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">IBM Rational AppScan Enterprise before 5.5 FP1 allows remote attackers to read arbitrary exported reports by "forcefully browsing."</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2009/0768" source="VUPEN">ADV-2009-0768</ref>
      <ref url="http://www.securitytracker.com/id?1021863" source="SECTRACK">1021863</ref>
      <ref url="http://www.securityfocus.com/bid/34163" source="BID">34163</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg1PK79991" source="AIXAPAR" adv="1">PK79991</ref>
      <ref url="http://secunia.com/advisories/34349" source="SECUNIA" adv="1">34349</ref>
      <ref url="http://osvdb.org/52764" source="OSVDB">52764</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="rational_appscan">
        <vers prev="1" num="5.5" edition="" />
        <vers prev="1" num="5.5" edition=":enterprise" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1057" published="2009-03-24" name="CVE-2009-1057" modified="2009-04-02" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">MicroSmarts Enterprise ZipItFast! 3.0 allows remote attackers to execute arbitrary code via a crafted .zip file that triggers memory corruption, related to a "format string buffer overflow." NOTE: CVE has not investigated whether the specified file.zip file can be used for exploitation of this product.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/49491" source="XF">zipitfast-zip-bo(49491)</ref>
      <ref url="http://www.milw0rm.com/exploits/8180" source="MILW0RM">8180</ref>
      <ref url="http://secunia.com/advisories/34223" source="SECUNIA" adv="1">34223</ref>
      <ref url="http://osvdb.org/52550" source="OSVDB">52550</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsmarts" name="zipitfast!">
        <vers num="3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1058" published="2009-03-24" name="CVE-2009-1058" modified="2009-04-02" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Stack-based buffer overflow in ZipGenius might allow remote attackers to execute arbitrary code via a crafted .zip file that triggers an SEH overwrite.  NOTE: it is possible that this overlaps CVE-2005-3317. NOTE: CVE has not investigated whether the specified file.zip file can be used for exploitation of this product.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/49490" source="XF">zipgenius-zip-bo(49490)</ref>
      <ref url="http://www.milw0rm.com/exploits/8180" source="MILW0RM">8180</ref>
    </refs>
    <vuln_soft>
      <prod vendor="zipgenius" name="zipgenius">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1059" published="2009-03-24" name="CVE-2009-1059" modified="2009-04-02" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Stack-based buffer overflow in Trident PowerZip 7.2 might allow remote attackers to execute arbitrary code via a crafted .zip file.  NOTE: CVE has not investigated whether the specified file.zip file can be used for exploitation of this product.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/49492" source="XF">powerzip-zip-bo(49492)</ref>
      <ref url="http://www.milw0rm.com/exploits/8180" source="MILW0RM">8180</ref>
    </refs>
    <vuln_soft>
      <prod vendor="powerzip" name="powerzip">
        <vers num="7.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1060" published="2009-03-24" name="CVE-2009-1060" modified="2009-04-08" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Unspecified vulnerability in Apple Safari on Mac OS X 10.5.6 allows remote attackers to execute arbitrary code via unknown vectors triggered by clicking on a link, as demonstrated by Charlie Miller during a PWN2OWN competition at CanSecWest 2009.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/49463" source="XF">apple-safari-unspecified-code-execution1(49463)</ref>
      <ref url="http://www.securitytracker.com/id?1021879" source="SECTRACK">1021879</ref>
      <ref url="http://www.securityfocus.com/bid/34179" source="BID">34179</ref>
      <ref url="http://www.computerworld.com/action/article.do?command=viewArticleBasic&amp;articleId=9129978" source="MISC">http://www.computerworld.com/action/article.do?command=viewArticleBasic&amp;articleId=9129978</ref>
      <ref url="http://osvdb.org/52888" source="OSVDB">52888</ref>
      <ref url="http://news.cnet.com/8301-1009_3-10199652-83.html" source="MISC">http://news.cnet.com/8301-1009_3-10199652-83.html</ref>
      <ref url="http://dvlabs.tippingpoint.com/blog/2009/03/18/pwn2own-2009-day-1---safari-internet-explorer-and-firefox-taken-down-by-four-zero-day-exploits" source="MISC">http://dvlabs.tippingpoint.com/blog/2009/03/18/pwn2own-2009-day-1---safari-internet-explorer-and-firefox-taken-down-by-four-zero-day-exploits</ref>
      <ref url="http://dvlabs.tippingpoint.com/blog/2009/02/25/pwn2own-2009" source="MISC">http://dvlabs.tippingpoint.com/blog/2009/02/25/pwn2own-2009</ref>
      <ref url="http://cansecwest.com/index.html" source="MISC">http://cansecwest.com/index.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="safari">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1061" published="2009-03-24" name="CVE-2009-1061" modified="2009-04-28" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Unspecified vulnerability in Adobe Acrobat Reader 9 before 9.1, 8 before 8.1.4, and 7 before 7.1.1 might allow remote attackers to execute arbitrary code via unknown attack vectors related to JBIG2 and "input validation," a different vulnerability than CVE-2009-0193 and CVE-2009-1062.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.adobe.com/support/security/bulletins/apsb09-04.html" source="CONFIRM" patch="1" adv="1">http://www.adobe.com/support/security/bulletins/apsb09-04.html</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1019" source="VUPEN">ADV-2009-1019</ref>
      <ref url="http://www.securitytracker.com/id?1021892" source="SECTRACK">1021892</ref>
      <ref url="http://www.securityfocus.com/bid/34229" source="BID">34229</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-0376.html" source="REDHAT">RHSA-2009:0376</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-256788-1" source="SUNALERT">256788</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200904-17.xml" source="GENTOO">GLSA-200904-17</ref>
      <ref url="http://secunia.com/advisories/34790" source="SECUNIA">34790</ref>
      <ref url="http://secunia.com/advisories/34706" source="SECUNIA">34706</ref>
      <ref url="http://secunia.com/advisories/34490" source="SECUNIA">34490</ref>
      <ref url="http://secunia.com/advisories/34392" source="SECUNIA">34392</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-04/msg00010.html" source="SUSE">SUSE-SR:2009:009</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-03/msg00005.html" source="SUSE">SUSE-SA:2009:014</ref>
    </refs>
    <vuln_soft>
      <prod vendor="adobe" name="acrobat">
        <vers num="7.0" />
        <vers num="7.0.1" />
        <vers num="7.0.2" />
        <vers num="7.0.3" />
        <vers num="7.0.5" />
        <vers num="7.0.7" />
        <vers num="7.0.8" />
        <vers num="7.0.9" />
        <vers prev="1" num="7.1.0" />
        <vers num="8.0" />
        <vers num="8.1" />
        <vers num="8.1.1" />
        <vers prev="1" num="8.1.2" />
        <vers prev="1" num="9.0" />
      </prod>
      <prod vendor="adobe" name="reader">
        <vers num="7.0.1" />
        <vers num="7.0.2" />
        <vers num="7.0.3" />
        <vers num="7.0.5" />
        <vers num="7.0.7" />
        <vers num="7.0.8" />
        <vers num="7.0.9" />
        <vers prev="1" num="7.1.0" />
        <vers num="8.1.1" />
        <vers prev="1" num="8.1.2" />
        <vers prev="1" num="9.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1062" published="2009-03-24" name="CVE-2009-1062" modified="2009-10-06" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Adobe Acrobat Reader 9 before 9.1, 8 before 8.1.4, and 7 before 7.1.1 might allow remote attackers to trigger memory corruption and possibly execute arbitrary code via unknown attack vectors related to JBIG2, a different vulnerability than CVE-2009-0193 and CVE-2009-1061.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/34229" source="BID" patch="1">34229</ref>
      <ref url="http://www.ivizsecurity.com/security-advisory-iviz-sr-09001.html" source="MISC" patch="1">http://www.ivizsecurity.com/security-advisory-iviz-sr-09001.html</ref>
      <ref url="http://www.adobe.com/support/security/bulletins/apsb09-04.html" source="CONFIRM" patch="1" adv="1">http://www.adobe.com/support/security/bulletins/apsb09-04.html</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1019" source="VUPEN" adv="1">ADV-2009-1019</ref>
      <ref url="http://www.securitytracker.com/id?1021892" source="SECTRACK">1021892</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-0376.html" source="REDHAT">RHSA-2009:0376</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-256788-1" source="SUNALERT">256788</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200904-17.xml" source="GENTOO">GLSA-200904-17</ref>
      <ref url="http://secunia.com/advisories/34790" source="SECUNIA" adv="1">34790</ref>
      <ref url="http://secunia.com/advisories/34706" source="SECUNIA" adv="1">34706</ref>
      <ref url="http://secunia.com/advisories/34490" source="SECUNIA" adv="1">34490</ref>
      <ref url="http://secunia.com/advisories/34392" source="SECUNIA" adv="1">34392</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-04/msg00010.html" source="SUSE">SUSE-SR:2009:009</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-03/msg00005.html" source="SUSE">SUSE-SA:2009:014</ref>
    </refs>
    <vuln_soft>
      <prod vendor="adobe" name="acrobat">
        <vers num="7.0" edition="" />
        <vers num="7.0" edition=":standard" />
        <vers num="7.0" edition=":professional" />
        <vers num="7.0.1" edition="" />
        <vers num="7.0.1" edition=":professional" />
        <vers num="7.0.1" edition=":standard" />
        <vers num="7.0.2" edition="" />
        <vers num="7.0.2" edition=":professional" />
        <vers num="7.0.2" edition=":standard" />
        <vers num="7.0.3" edition="" />
        <vers num="7.0.3" edition=":professional" />
        <vers num="7.0.3" edition=":standard" />
        <vers num="7.0.4" edition="" />
        <vers num="7.0.4" edition=":professional" />
        <vers num="7.0.4" edition=":standard" />
        <vers num="7.0.5" edition="" />
        <vers num="7.0.5" edition=":professional" />
        <vers num="7.0.5" edition=":standard" />
        <vers num="7.0.6" edition="" />
        <vers num="7.0.6" edition=":professional" />
        <vers num="7.0.6" edition=":standard" />
        <vers num="7.0.7" edition="" />
        <vers num="7.0.7" edition=":professional" />
        <vers num="7.0.7" edition=":standard" />
        <vers num="7.0.8" edition="" />
        <vers num="7.0.8" edition=":standard" />
        <vers num="7.0.8" edition=":professional" />
        <vers num="7.0.9" edition="" />
        <vers num="7.0.9" edition=":professional" />
        <vers num="7.1" edition="" />
        <vers num="7.1" edition=":standard" />
        <vers num="7.1" edition=":professional" />
        <vers num="7.1.1" edition="" />
        <vers num="7.1.1" edition=":standard" />
        <vers num="8.0" edition="" />
        <vers num="8.0" edition=":professional" />
        <vers num="8.0" edition=":standard" />
        <vers num="8.1" edition="" />
        <vers num="8.1" edition=":standard" />
        <vers num="8.1.1" edition="" />
        <vers num="8.1.1" edition=":standard" />
        <vers num="8.1.1" edition=":professional" />
        <vers num="8.1.2" edition="" />
        <vers num="8.1.2" edition=":standard" />
        <vers num="8.1.2" edition=":professional" />
        <vers num="8.1.2" edition="security_update" />
        <vers num="8.1.2" edition="security_update:professional" />
        <vers num="8.1.3" edition="" />
        <vers num="8.1.3" edition=":standard" />
        <vers num="8.1.3" edition=":professional" />
        <vers num="8.1.4" edition="" />
        <vers num="8.1.4" edition=":standard" />
        <vers num="8.1.4" edition=":professional" />
        <vers prev="1" num="9.0" edition="" />
        <vers prev="1" num="9.0" edition=":standard" />
        <vers prev="1" num="9.0" edition=":professional" />
      </prod>
      <prod vendor="adobe" name="reader">
        <vers num="3.0" />
        <vers num="4.0" />
        <vers num="4.0.5" />
        <vers num="4.0.5a" />
        <vers num="4.0.5c" />
        <vers num="4.5" />
        <vers num="5.0" />
        <vers num="5.0.10" />
        <vers num="5.0.11" />
        <vers num="5.0.5" />
        <vers num="5.0.6" />
        <vers num="5.0.7" />
        <vers num="5.0.9" />
        <vers num="5.1" />
        <vers num="6.0" />
        <vers num="6.0.1" />
        <vers num="6.0.2" />
        <vers num="6.0.3" />
        <vers num="6.0.4" />
        <vers num="6.0.5" />
        <vers num="7" />
        <vers num="7.0.1" />
        <vers num="7.0.2" />
        <vers num="7.0.3" />
        <vers num="7.0.5" />
        <vers num="7.0.7" />
        <vers num="7.0.8" />
        <vers num="7.0.9" />
        <vers num="7.1.0" />
        <vers num="7.1.1" />
        <vers num="8.1.1" />
        <vers num="8.1.2" />
        <vers num="8.1.4" />
        <vers prev="1" num="9.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1063" published="2009-03-26" name="CVE-2009-1063" modified="2009-04-03" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Buffer overflow in eXeScope 6.50 allows user-assisted remote attackers to execute arbitrary code via a crafted executable (.exe) file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/49379" source="XF">exescope-exe-bo(49379)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0821" source="VUPEN">ADV-2009-0821</ref>
      <ref url="http://www.securityfocus.com/bid/34219" source="BID" adv="1">34219</ref>
      <ref url="http://www.milw0rm.com/exploits/8270" source="MILW0RM">8270</ref>
      <ref url="http://secunia.com/advisories/34413" source="SECUNIA">34413</ref>
      <ref url="http://osvdb.org/52868" source="OSVDB">52868</ref>
    </refs>
    <vuln_soft>
      <prod vendor="brother_soft" name="exescope">
        <vers num="6" edition="50" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1064" published="2009-03-26" name="CVE-2009-1064" modified="2009-07-24" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:P)" CVSS_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_base_score="5.8">
    <desc>
      <descript source="cve">Argument injection vulnerability in orbitmxt.dll 2.1.0.2 in the Orbit Downloader 2.8.7 and earlier ActiveX control allows remote attackers to overwrite arbitrary files via whitespace and a command-line switch, followed by a full pathname, in the third argument to the download method.</descript>
    </desc>
    <loss_types>
      <avail />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/49353" source="XF">orbitdownloader-activex-file-deletion(49353)</ref>
      <ref url="http://www.waraxe.us/advisory-73.html" source="MISC">http://www.waraxe.us/advisory-73.html</ref>
      <ref url="http://www.securityfocus.com/bid/34200" source="BID">34200</ref>
      <ref url="http://www.milw0rm.com/exploits/8257" source="MILW0RM">8257</ref>
    </refs>
    <vuln_soft>
      <prod vendor="orbit_downloader" name="orbit_downloader">
        <vers num="2.6.3" />
        <vers num="2.6.4" />
      </prod>
      <prod vendor="orbitdownloader" name="orbit_downloader">
        <vers num="2.6.1" />
        <vers num="2.6.3" />
        <vers num="2.6.4" />
        <vers num="2.6.5" />
        <vers num="2.7.1" />
        <vers num="2.7.3" />
        <vers num="2.7.5" />
        <vers num="2.7.6" />
        <vers num="2.7.7" />
        <vers num="2.7.8" />
        <vers num="2.7.9" />
        <vers num="2.8.1" />
        <vers num="2.8.2" />
        <vers num="2.8.3" />
        <vers num="2.8.4" />
        <vers num="2.8.5" />
        <vers prev="1" num="2.8.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1065" published="2009-03-26" name="CVE-2009-1065" modified="2009-03-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in index.php in Pixie CMS 1.01a allows remote attackers to execute arbitrary SQL commands via the x parameter.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/49334" source="XF">pixiecms-index-sql-injection(49334)</ref>
      <ref url="http://secunia.com/advisories/34364" source="SECUNIA" adv="1">34364</ref>
      <ref url="http://osvdb.org/52834" source="OSVDB">52834</ref>
    </refs>
    <vuln_soft>
      <prod vendor="getpixie" name="pixie_cms">
        <vers num="1.01a" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1066" published="2009-03-26" name="CVE-2009-1066" modified="2009-03-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in the referral function in admin/lib/lib_logs.php in Pixie CMS 1.01a allows remote attackers to execute arbitrary SQL commands via the Referer HTTP header in a request.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/49335" source="XF">pixiecms-referral-sql-injection(49335)</ref>
      <ref url="http://www.securityfocus.com/bid/34189" source="BID">34189</ref>
      <ref url="http://www.milw0rm.com/exploits/8252" source="MILW0RM">8252</ref>
      <ref url="http://secunia.com/advisories/34364" source="SECUNIA" adv="1">34364</ref>
      <ref url="http://osvdb.org/52833" source="OSVDB">52833</ref>
      <ref url="http://lampsecurity.org/Pixie-CMS-Multiple-Vulnerabilities" source="MISC">http://lampsecurity.org/Pixie-CMS-Multiple-Vulnerabilities</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2009-03/0324.html" source="FULLDISC">20090319 Pixie CMS Multiple Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="getpixie" name="pixie_cms">
        <vers num="1.01a" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1067" published="2009-03-26" name="CVE-2009-1067" modified="2009-03-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in index.php in Pixie CMS 1.01a allows remote attackers to inject arbitrary web script or HTML via the x parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/49333" source="XF">pixiecms-index-xss(49333)</ref>
      <ref url="http://www.securityfocus.com/bid/34189" source="BID">34189</ref>
      <ref url="http://www.milw0rm.com/exploits/8252" source="MILW0RM">8252</ref>
      <ref url="http://secunia.com/advisories/34364" source="SECUNIA" adv="1">34364</ref>
      <ref url="http://osvdb.org/52832" source="OSVDB">52832</ref>
      <ref url="http://lampsecurity.org/Pixie-CMS-Multiple-Vulnerabilities" source="MISC">http://lampsecurity.org/Pixie-CMS-Multiple-Vulnerabilities</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2009-03/0324.html" source="FULLDISC">20090319 Pixie CMS Multiple Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="getpixie" name="pixie_cms">
        <vers num="1.01a" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1068" published="2009-03-26" name="CVE-2009-1068" modified="2009-04-03" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Stack-based buffer overflow in BS.Player (bsplayer) 2.32 Build 975 Free and 2.34 Build 980 PRO and earlier allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via a long hostname in a .bsl playlist file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/49342" source="XF">bsplayer-bsl-bo(49342)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0800" source="VUPEN">ADV-2009-0800</ref>
      <ref url="http://www.securityfocus.com/bid/34190" source="BID">34190</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/502016/100/0/threaded" source="BUGTRAQ">20090320 Bs.Player &lt;= 2.34 Build 980 (.bsl) local buffer overflow 0day exploit (seh)</ref>
      <ref url="http://www.milw0rm.com/exploits/8251" source="MILW0RM">8251</ref>
      <ref url="http://www.milw0rm.com/exploits/8249" source="MILW0RM">8249</ref>
      <ref url="http://secunia.com/advisories/34412" source="SECUNIA" adv="1">34412</ref>
      <ref url="http://retrogod.altervista.org/9sg_bsplayer_seh.html" source="MISC">http://retrogod.altervista.org/9sg_bsplayer_seh.html</ref>
      <ref url="http://osvdb.org/52841" source="OSVDB">52841</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bsplayer" name="bs.player">
        <vers num="2.32" edition="free" />
        <vers num="2.34" edition="pro" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1069" published="2009-03-26" name="CVE-2009-1069" modified="2009-03-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in the node edit form feature in Drupal Content Construction Kit (CCK) 6.x before 6.x-2.2, a module for Drupal, allow remote attackers to inject arbitrary web script or HTML via the (1) titles of candidate referenced nodes in the Node reference sub-module and the (2) names of candidate referenced users in the User reference sub-module.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://drupal.org/node/406520" source="CONFIRM" patch="1" adv="1">http://drupal.org/node/406520</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/49317" source="XF">cck-node-user-xss(49317)</ref>
      <ref url="http://www.securityfocus.com/bid/34172" source="BID">34172</ref>
      <ref url="http://secunia.com/advisories/34370" source="SECUNIA" adv="1">34370</ref>
      <ref url="http://osvdb.org/52784" source="OSVDB">52784</ref>
      <ref url="http://osvdb.org/52783" source="OSVDB">52783</ref>
    </refs>
    <vuln_soft>
      <prod vendor="drupal" name="content_construction_kit">
        <vers num="6.x-1.0" edition="alpha" />
        <vers num="6.x-1.x-dev" />
        <vers num="6.x-2.0" edition="beta" />
        <vers num="6.x-2.0" edition="rc1" />
        <vers num="6.x-2.0" edition="rc10" />
        <vers num="6.x-2.0" edition="rc2" />
        <vers num="6.x-2.0" edition="rc3" />
        <vers num="6.x-2.0" edition="rc4" />
        <vers num="6.x-2.0" edition="rc5" />
        <vers num="6.x-2.0" edition="rc6" />
        <vers num="6.x-2.0" edition="rc7" />
        <vers num="6.x-2.0" edition="rc8" />
        <vers num="6.x-2.0" edition="rc9" />
        <vers num="6.x-2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1070" published="2009-03-26" name="CVE-2009-1070" modified="2009-03-27" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in system/index.php in ExpressionEngine 1.6.4 through 1.6.6, and possibly earlier versions, allows remote attackers to inject arbitrary web script or HTML via the avatar parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/49359" source="XF">expressionengine-avatar-xss(49359)</ref>
      <ref url="http://www.securityfocus.com/bid/34193" source="BID">34193</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/502045/100/0/threaded" source="BUGTRAQ">20090322 ExpressionEngine Persistent Cross-Site Scripting</ref>
      <ref url="http://www.ngenuity.org/wordpress/2009/01/28/ngenuity-2009-003-expressionengine-persistent-cross-site-scripting/" source="MISC">http://www.ngenuity.org/wordpress/2009/01/28/ngenuity-2009-003-expressionengine-persistent-cross-site-scripting/</ref>
      <ref url="http://secunia.com/advisories/34379" source="SECUNIA" adv="1">34379</ref>
      <ref url="http://expressionengine.com/docs/changelog.html#v167" source="CONFIRM">http://expressionengine.com/docs/changelog.html#v167</ref>
    </refs>
    <vuln_soft>
      <prod vendor="expressionengine" name="expressionengine">
        <vers num="1.6.4" />
        <vers num="1.6.5" />
        <vers num="1.6.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1071" published="2009-03-26" name="CVE-2009-1071" modified="2009-03-27" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Stack-based buffer overflow in Icarus 2.0 allows remote attackers to cause a denial of service (application crach) or execute arbitrary code via a crafted Portable Game Notation (.pgn) file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/49309" source="XF">icarus-pgn-bo(49309)</ref>
      <ref url="http://www.securityfocus.com/bid/34167" source="BID">34167</ref>
      <ref url="http://www.milw0rm.com/exploits/8236" source="MILW0RM">8236</ref>
      <ref url="http://secunia.com/advisories/34368" source="SECUNIA" adv="1">34368</ref>
      <ref url="http://osvdb.org/52780" source="OSVDB">52780</ref>
    </refs>
    <vuln_soft>
      <prod vendor="randomsoftware" name="icarus">
        <vers num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1072" published="2009-03-24" name="CVE-2009-1072" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:C/A:N)" CVSS_score="4.9" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="3.9" CVSS_base_score="4.9">
    <desc>
      <descript source="cve">nfsd in the Linux kernel before 2.6.28.9 does not drop the CAP_MKNOD capability before handling a user request in a thread, which allows local users to create device nodes, as demonstrated on a filesystem that has been exported with the root_squash option.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/49356" source="XF">linux-kernel-capmknod-security-bypass(49356)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/3316" source="VUPEN">ADV-2009-3316</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0802" source="VUPEN" adv="1">ADV-2009-0802</ref>
      <ref url="http://www.vmware.com/security/advisories/VMSA-2009-0016.html" source="CONFIRM">http://www.vmware.com/security/advisories/VMSA-2009-0016.html</ref>
      <ref url="http://www.ubuntu.com/usn/usn-793-1" source="UBUNTU">USN-793-1</ref>
      <ref url="http://www.securityfocus.com/bid/34205" source="BID">34205</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/507985/100/0/threaded" source="BUGTRAQ">20091120 VMSA-2009-0016 VMware vCenter and ESX update release and vMA patch release address multiple security issue in third party components</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-1081.html" source="REDHAT">RHSA-2009:1081</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2009/03/23/1" source="MLIST">[oss-security] 20090323 CVE request: kernel: nfsd did not drop CAP_MKNOD for non-root</ref>
      <ref url="http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.28.9" source="CONFIRM">http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.28.9</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1800" source="DEBIAN">DSA-1800</ref>
      <ref url="http://thread.gmane.org/gmane.linux.kernel/805280" source="MLIST">[linux-kernel] 20090311 VFS, NFS security bug? Should CAP_MKNOD and CAP_LINUX_IMMUTABLE be added to CAP_FS_MASK?</ref>
      <ref url="http://secunia.com/advisories/37471" source="SECUNIA">37471</ref>
      <ref url="http://secunia.com/advisories/35656" source="SECUNIA">35656</ref>
      <ref url="http://secunia.com/advisories/35394" source="SECUNIA">35394</ref>
      <ref url="http://secunia.com/advisories/35390" source="SECUNIA">35390</ref>
      <ref url="http://secunia.com/advisories/35343" source="SECUNIA">35343</ref>
      <ref url="http://secunia.com/advisories/35185" source="SECUNIA">35185</ref>
      <ref url="http://secunia.com/advisories/35121" source="SECUNIA">35121</ref>
      <ref url="http://secunia.com/advisories/34786" source="SECUNIA">34786</ref>
      <ref url="http://secunia.com/advisories/34432" source="SECUNIA" adv="1">34432</ref>
      <ref url="http://secunia.com/advisories/34422" source="SECUNIA" adv="1">34422</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:8382" source="OVAL">oval:org.mitre.oval:def:8382</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10314" source="OVAL">oval:org.mitre.oval:def:10314</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-06/msg00001.html" source="SUSE">SUSE-SA:2009:031</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-06/msg00000.html" source="SUSE">SUSE-SA:2009:030</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-05/msg00002.html" source="SUSE">SUSE-SA:2009:028</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-04/msg00007.html" source="SUSE">SUSE-SA:2009:021</ref>
      <ref url="http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commitdiff;h=76a67ec6fb79ff3570dcb5342142c16098299911" source="CONFIRM">http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commitdiff;h=76a67ec6fb79ff3570dcb5342142c16098299911</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="kernel">
        <vers num="2.2.27" />
        <vers num="2.4.36" />
        <vers num="2.4.36.1" />
        <vers num="2.4.36.2" />
        <vers num="2.4.36.3" />
        <vers num="2.4.36.4" />
        <vers num="2.4.36.5" />
        <vers num="2.4.36.6" />
        <vers num="2.6" />
        <vers num="2.6.0" />
        <vers num="2.6.1" />
        <vers num="2.6.10" />
        <vers num="2.6.11" />
        <vers num="2.6.11.1" />
        <vers num="2.6.11.10" />
        <vers num="2.6.11.11" />
        <vers num="2.6.11.12" />
        <vers num="2.6.11.2" />
        <vers num="2.6.11.3" />
        <vers num="2.6.11.4" />
        <vers num="2.6.11.5" />
        <vers num="2.6.11.6" />
        <vers num="2.6.11.7" />
        <vers num="2.6.11.8" />
        <vers num="2.6.11.9" />
        <vers num="2.6.12" />
        <vers num="2.6.12.1" />
        <vers num="2.6.12.2" />
        <vers num="2.6.12.3" />
        <vers num="2.6.12.4" />
        <vers num="2.6.12.5" />
        <vers num="2.6.12.6" />
        <vers num="2.6.13" />
        <vers num="2.6.13.1" />
        <vers num="2.6.13.2" />
        <vers num="2.6.13.3" />
        <vers num="2.6.13.4" />
        <vers num="2.6.13.5" />
        <vers num="2.6.14" />
        <vers num="2.6.14.1" />
        <vers num="2.6.14.2" />
        <vers num="2.6.14.3" />
        <vers num="2.6.14.4" />
        <vers num="2.6.14.5" />
        <vers num="2.6.14.6" />
        <vers num="2.6.14.7" />
        <vers num="2.6.15" />
        <vers num="2.6.15.1" />
        <vers num="2.6.15.2" />
        <vers num="2.6.15.3" />
        <vers num="2.6.15.4" />
        <vers num="2.6.15.5" />
        <vers num="2.6.15.6" />
        <vers num="2.6.15.7" />
        <vers num="2.6.16" />
        <vers num="2.6.16.1" />
        <vers num="2.6.16.10" />
        <vers num="2.6.16.11" />
        <vers num="2.6.16.12" />
        <vers num="2.6.16.13" />
        <vers num="2.6.16.14" />
        <vers num="2.6.16.15" />
        <vers num="2.6.16.16" />
        <vers num="2.6.16.17" />
        <vers num="2.6.16.18" />
        <vers num="2.6.16.19" />
        <vers num="2.6.16.2" />
        <vers num="2.6.16.20" />
        <vers num="2.6.16.21" />
        <vers num="2.6.16.22" />
        <vers num="2.6.16.23" />
        <vers num="2.6.16.24" />
        <vers num="2.6.16.25" />
        <vers num="2.6.16.26" />
        <vers num="2.6.16.27" />
        <vers num="2.6.16.28" />
        <vers num="2.6.16.29" />
        <vers num="2.6.16.3" />
        <vers num="2.6.16.30" />
        <vers num="2.6.16.31" />
        <vers num="2.6.16.32" />
        <vers num="2.6.16.33" />
        <vers num="2.6.16.34" />
        <vers num="2.6.16.35" />
        <vers num="2.6.16.36" />
        <vers num="2.6.16.37" />
        <vers num="2.6.16.38" />
        <vers num="2.6.16.39" />
        <vers num="2.6.16.4" />
        <vers num="2.6.16.40" />
        <vers num="2.6.16.41" />
        <vers num="2.6.16.42" />
        <vers num="2.6.16.43" />
        <vers num="2.6.16.44" />
        <vers num="2.6.16.45" />
        <vers num="2.6.16.46" />
        <vers num="2.6.16.47" />
        <vers num="2.6.16.48" />
        <vers num="2.6.16.49" />
        <vers num="2.6.16.5" />
        <vers num="2.6.16.50" />
        <vers num="2.6.16.51" />
        <vers num="2.6.16.52" />
        <vers num="2.6.16.53" />
        <vers num="2.6.16.54" />
        <vers num="2.6.16.55" />
        <vers num="2.6.16.56" />
        <vers num="2.6.16.57" />
        <vers num="2.6.16.58" />
        <vers num="2.6.16.59" />
        <vers num="2.6.16.6" />
        <vers num="2.6.16.60" />
        <vers num="2.6.16.61" />
        <vers num="2.6.16.62" />
        <vers num="2.6.16.7" />
        <vers num="2.6.16.8" />
        <vers num="2.6.16.9" />
        <vers num="2.6.17" />
        <vers num="2.6.17.1" />
        <vers num="2.6.17.10" />
        <vers num="2.6.17.11" />
        <vers num="2.6.17.12" />
        <vers num="2.6.17.13" />
        <vers num="2.6.17.14" />
        <vers num="2.6.17.2" />
        <vers num="2.6.17.3" />
        <vers num="2.6.17.4" />
        <vers num="2.6.17.5" />
        <vers num="2.6.17.6" />
        <vers num="2.6.17.7" />
        <vers num="2.6.17.8" />
        <vers num="2.6.17.9" />
        <vers num="2.6.18" edition="rc1" />
        <vers num="2.6.18" edition="rc2" />
        <vers num="2.6.18" edition="rc3" />
        <vers num="2.6.18" edition="rc4" />
        <vers num="2.6.18" edition="rc5" />
        <vers num="2.6.18" edition="rc6" />
        <vers num="2.6.18" edition="rc7" />
        <vers num="2.6.18.1" />
        <vers num="2.6.18.2" />
        <vers num="2.6.18.3" />
        <vers num="2.6.18.4" />
        <vers num="2.6.18.5" />
        <vers num="2.6.18.6" />
        <vers num="2.6.18.7" />
        <vers num="2.6.18.8" />
        <vers num="2.6.19" />
        <vers num="2.6.19.1" />
        <vers num="2.6.19.2" />
        <vers num="2.6.19.3" />
        <vers num="2.6.19.4" />
        <vers num="2.6.19.5" />
        <vers num="2.6.19.6" />
        <vers num="2.6.19.7" />
        <vers num="2.6.2" />
        <vers num="2.6.2.27.13" />
        <vers num="2.6.20" />
        <vers num="2.6.20.1" />
        <vers num="2.6.20.10" />
        <vers num="2.6.20.11" />
        <vers num="2.6.20.12" />
        <vers num="2.6.20.13" />
        <vers num="2.6.20.14" />
        <vers num="2.6.20.15" />
        <vers num="2.6.20.16" />
        <vers num="2.6.20.17" />
        <vers num="2.6.20.18" />
        <vers num="2.6.20.19" />
        <vers num="2.6.20.2" />
        <vers num="2.6.20.20" />
        <vers num="2.6.20.21" />
        <vers num="2.6.20.3" />
        <vers num="2.6.20.4" />
        <vers num="2.6.20.5" />
        <vers num="2.6.20.6" />
        <vers num="2.6.20.7" />
        <vers num="2.6.20.8" />
        <vers num="2.6.20.9" />
        <vers num="2.6.21" />
        <vers num="2.6.21.1" />
        <vers num="2.6.21.2" />
        <vers num="2.6.21.3" />
        <vers num="2.6.21.4" />
        <vers num="2.6.21.5" />
        <vers num="2.6.21.6" />
        <vers num="2.6.21.7" />
        <vers num="2.6.22" />
        <vers num="2.6.22.1" />
        <vers num="2.6.22.10" />
        <vers num="2.6.22.11" />
        <vers num="2.6.22.12" />
        <vers num="2.6.22.13" />
        <vers num="2.6.22.14" />
        <vers num="2.6.22.15" />
        <vers num="2.6.22.16" />
        <vers num="2.6.22.17" />
        <vers num="2.6.22.18" />
        <vers num="2.6.22.19" />
        <vers num="2.6.22.2" />
        <vers num="2.6.22.20" />
        <vers num="2.6.22.21" />
        <vers num="2.6.22.22" />
        <vers num="2.6.22.3" />
        <vers num="2.6.22.4" />
        <vers num="2.6.22.5" />
        <vers num="2.6.22.6" />
        <vers num="2.6.22.7" />
        <vers num="2.6.22.8" />
        <vers num="2.6.22.9" />
        <vers num="2.6.22_rc1" />
        <vers num="2.6.22_rc7" />
        <vers num="2.6.23" edition="rc1" />
        <vers num="2.6.23" edition="rc2" />
        <vers num="2.6.23.1" />
        <vers num="2.6.23.10" />
        <vers num="2.6.23.11" />
        <vers num="2.6.23.12" />
        <vers num="2.6.23.13" />
        <vers num="2.6.23.14" />
        <vers num="2.6.23.15" />
        <vers num="2.6.23.16" />
        <vers num="2.6.23.17" />
        <vers num="2.6.23.2" />
        <vers num="2.6.23.3" />
        <vers num="2.6.23.4" />
        <vers num="2.6.23.5" />
        <vers num="2.6.23.6" />
        <vers num="2.6.23.7" />
        <vers num="2.6.23.8" />
        <vers num="2.6.23.9" />
        <vers num="2.6.23_rc1" />
        <vers num="2.6.24" edition="rc1" />
        <vers num="2.6.24" edition="rc2" />
        <vers num="2.6.24" edition="rc3" />
        <vers num="2.6.24" edition="rc4" />
        <vers num="2.6.24" edition="rc5" />
        <vers num="2.6.24.1" />
        <vers num="2.6.24.2" />
        <vers num="2.6.24.3" />
        <vers num="2.6.24.4" />
        <vers num="2.6.24.5" />
        <vers num="2.6.24.6" />
        <vers num="2.6.24.7" />
        <vers num="2.6.24_rc1" />
        <vers num="2.6.24_rc4" />
        <vers num="2.6.24_rc5" />
        <vers num="2.6.25" edition="" />
        <vers num="2.6.25" edition=":x86_64" />
        <vers num="2.6.25.1" edition="" />
        <vers num="2.6.25.1" edition=":x86_64" />
        <vers num="2.6.25.10" edition="" />
        <vers num="2.6.25.10" edition=":x86_64" />
        <vers num="2.6.25.11" edition="" />
        <vers num="2.6.25.11" edition=":x86_64" />
        <vers num="2.6.25.12" edition="" />
        <vers num="2.6.25.12" edition=":x86_64" />
        <vers num="2.6.25.13" />
        <vers num="2.6.25.14" />
        <vers num="2.6.25.15" />
        <vers num="2.6.25.16" />
        <vers num="2.6.25.17" />
        <vers num="2.6.25.18" />
        <vers num="2.6.25.19" />
        <vers num="2.6.25.2" edition="" />
        <vers num="2.6.25.2" edition=":x86_64" />
        <vers num="2.6.25.20" />
        <vers num="2.6.25.3" edition="" />
        <vers num="2.6.25.3" edition=":x86_64" />
        <vers num="2.6.25.4" edition="" />
        <vers num="2.6.25.4" edition=":x86_64" />
        <vers num="2.6.25.5" edition="" />
        <vers num="2.6.25.5" edition=":x86_64" />
        <vers num="2.6.25.6" edition="" />
        <vers num="2.6.25.6" edition=":x86_64" />
        <vers num="2.6.25.7" edition="" />
        <vers num="2.6.25.7" edition=":x86_64" />
        <vers num="2.6.25.8" edition="" />
        <vers num="2.6.25.8" edition=":x86_64" />
        <vers num="2.6.25.9" edition="" />
        <vers num="2.6.25.9" edition=":x86_64" />
        <vers num="2.6.26" edition="rc4" />
        <vers num="2.6.26.1" />
        <vers num="2.6.26.2" />
        <vers num="2.6.26.3" />
        <vers num="2.6.26.4" />
        <vers num="2.6.26.5" />
        <vers num="2.6.26.6" />
        <vers num="2.6.26.7" />
        <vers num="2.6.26.8" />
        <vers num="2.6.27" edition="rc1" />
        <vers num="2.6.27" edition="rc2" />
        <vers num="2.6.27" edition="rc3" />
        <vers num="2.6.27" edition="rc4" />
        <vers num="2.6.27" edition="rc5" />
        <vers num="2.6.27" edition="rc6" />
        <vers num="2.6.27" edition="rc7" />
        <vers num="2.6.27" edition="rc8" />
        <vers num="2.6.27" edition="rc9" />
        <vers num="2.6.27.1" />
        <vers num="2.6.27.10" />
        <vers num="2.6.27.11" />
        <vers num="2.6.27.12" />
        <vers num="2.6.27.13" />
        <vers num="2.6.27.14" />
        <vers num="2.6.27.15" />
        <vers num="2.6.27.16" />
        <vers num="2.6.27.17" />
        <vers num="2.6.27.18" />
        <vers num="2.6.27.19" />
        <vers num="2.6.27.2" />
        <vers num="2.6.27.20" />
        <vers num="2.6.27.3" />
        <vers num="2.6.27.4" />
        <vers num="2.6.27.5" />
        <vers num="2.6.27.6" />
        <vers num="2.6.27.7" />
        <vers num="2.6.27.8" />
        <vers num="2.6.27.9" />
        <vers num="2.6.28" edition="rc1" />
        <vers num="2.6.28" edition="rc2" />
        <vers num="2.6.28" edition="rc3" />
        <vers num="2.6.28" edition="rc4" />
        <vers num="2.6.28" edition="rc5" />
        <vers num="2.6.28" edition="rc6" />
        <vers num="2.6.28" edition="rc7" />
        <vers num="2.6.28.1" />
        <vers num="2.6.28.2" />
        <vers num="2.6.28.3" />
        <vers num="2.6.28.4" />
        <vers num="2.6.28.5" />
        <vers num="2.6.28.6" />
        <vers num="2.6.28.7" />
        <vers num="2.6.28.8" />
        <vers num="2.6.3" />
        <vers num="2.6.4" />
        <vers num="2.6.5" />
        <vers num="2.6.6" />
        <vers num="2.6.7" />
        <vers num="2.6.8" />
        <vers num="2.6.8.1" />
        <vers num="2.6.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1073" published="2009-03-31" name="CVE-2009-1073" modified="2009-04-08" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:N/A:N)" CVSS_score="4.9" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="3.9" CVSS_base_score="4.9">
    <desc>
      <descript source="cve">nss-ldapd before 0.6.8 uses world-readable permissions for the /etc/nss-ldapd.conf file, which allows local users to obtain a cleartext password for the LDAP server by reading the bindpw field.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2009/dsa-1758" source="DEBIAN" patch="1">DSA-1758</ref>
      <ref url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=520476" source="CONFIRM" patch="1">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=520476</ref>
      <ref url="http://www.securityfocus.com/bid/34211" source="BID">34211</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2009/03/25/4" source="MLIST">[oss-security] 20090324 Re: CVE request -- ucd-snmp / net-snmp, libnss-ldapd / nss_ldap</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2009/03/25/3" source="MLIST">[oss-security] 20090324 Re: CVE request -- ucd-snmp / net-snmp, libnss-ldapd / nss_ldap</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2009/03/24/2" source="MLIST">[oss-security] 20090324 Re: CVE request -- ucd-snmp / net-snmp, libnss-ldapd / nss_ldap</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2009/03/23/3" source="MLIST">[oss-security] 20090323 CVE request -- ucd-snmp / net-snmp, libnss-ldapd / nss_ldap</ref>
      <ref url="http://secunia.com/advisories/34523" source="SECUNIA">34523</ref>
      <ref url="http://launchpad.net/bugs/cve/2009-1073" source="MISC">http://launchpad.net/bugs/cve/2009-1073</ref>
      <ref url="http://ch.tudelft.nl/~arthur/nss-ldapd/news.html#20090322" source="CONFIRM">http://ch.tudelft.nl/~arthur/nss-ldapd/news.html#20090322</ref>
      <ref url="http://arthurenhella.demon.nl/viewvc/nss-ldapd/nss-ldapd/man/nss-ldapd.conf.5.xml?r1=805&amp;r2=806" source="CONFIRM">http://arthurenhella.demon.nl/viewvc/nss-ldapd/nss-ldapd/man/nss-ldapd.conf.5.xml?r1=805&amp;r2=806</ref>
      <ref url="http://arthurenhella.demon.nl/viewvc/nss-ldapd/nss-ldapd/debian/libnss-ldapd.postinst?r1=795&amp;r2=813" source="CONFIRM">http://arthurenhella.demon.nl/viewvc/nss-ldapd/nss-ldapd/debian/libnss-ldapd.postinst?r1=795&amp;r2=813</ref>
    </refs>
    <vuln_soft>
      <prod vendor="debian" name="nss-ldap">
        <vers num="0.1" />
        <vers num="0.2" />
        <vers num="0.2.1" />
        <vers num="0.3" />
        <vers num="0.4" />
        <vers num="0.4.1" />
        <vers num="0.5" />
        <vers num="0.6" />
        <vers num="0.6.1" />
        <vers num="0.6.2" />
        <vers num="0.6.3" />
        <vers num="0.6.4" />
        <vers num="0.6.5" />
        <vers num="0.6.6" />
        <vers prev="1" num="0.6.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1074" published="2009-03-25" name="CVE-2009-1074" modified="2009-10-06" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Sun Java System Identity Manager (IdM) 7.0 through 8.0 does not use SSL in all expected circumstances, which makes it easier for remote attackers to obtain sensitive information by sniffing the network, related to "ssl termination devices" and lack of support for relative URLs.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/34191" source="BID" patch="1">34191</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-253267-1" source="SUNALERT" patch="1" adv="1">253267</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-21-140935-01-1" source="CONFIRM" patch="1" adv="1">http://sunsolve.sun.com/search/document.do?assetkey=1-21-140935-01-1</ref>
      <ref url="http://blogs.sun.com/security/entry/sun_alert_253267_sun_java" source="CONFIRM" patch="1">http://blogs.sun.com/security/entry/sun_alert_253267_sun_java</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0797" source="VUPEN" adv="1">ADV-2009-0797</ref>
      <ref url="http://securitytracker.com/id?1021881" source="SECTRACK">1021881</ref>
      <ref url="http://secunia.com/advisories/34380" source="SECUNIA" adv="1">34380</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="java_system_identity_manager">
        <vers num="7.0" />
        <vers num="7.1" />
        <vers num="7.1.1" />
        <vers num="8.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1075" published="2009-03-25" name="CVE-2009-1075" modified="2009-10-06" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Sun Java System Identity Manager (IdM) 7.0 through 8.0 responds differently to failed use of the Forgot Password feature depending on whether the user account exists, which allows remote attackers to enumerate valid usernames.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/34191" source="BID" patch="1">34191</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-253267-1" source="SUNALERT" patch="1" adv="1">253267</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-21-140936-01-1" source="CONFIRM" patch="1">http://sunsolve.sun.com/search/document.do?assetkey=1-21-140936-01-1</ref>
      <ref url="http://blogs.sun.com/security/entry/sun_alert_253267_sun_java" source="CONFIRM" patch="1" adv="1">http://blogs.sun.com/security/entry/sun_alert_253267_sun_java</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0797" source="VUPEN" adv="1">ADV-2009-0797</ref>
      <ref url="http://securitytracker.com/id?1021881" source="SECTRACK">1021881</ref>
      <ref url="http://secunia.com/advisories/34380" source="SECUNIA" adv="1">34380</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="java_system_identity_manager">
        <vers num="7.0" />
        <vers num="7.1" />
        <vers num="7.1.1" />
        <vers num="8.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1076" published="2009-03-25" name="CVE-2009-1076" modified="2009-03-25" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Sun Java System Identity Manager (IdM) 7.0 through 8.0 responds differently to failed use of the end-user question-based login feature depending on whether the user account exists, which allows remote attackers to enumerate valid usernames.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/34191" source="BID" patch="1">34191</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-21-140936-01-1" source="CONFIRM" patch="1">http://sunsolve.sun.com/search/document.do?assetkey=1-21-140936-01-1</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-21-137621-11-1" source="CONFIRM" patch="1">http://sunsolve.sun.com/search/document.do?assetkey=1-21-137621-11-1</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0797" source="VUPEN" adv="1">ADV-2009-0797</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-253267-1" source="SUNALERT" adv="1">253267</ref>
      <ref url="http://securitytracker.com/id?1021881" source="SECTRACK">1021881</ref>
      <ref url="http://secunia.com/advisories/34380" source="SECUNIA" adv="1">34380</ref>
      <ref url="http://blogs.sun.com/security/entry/sun_alert_253267_sun_java" source="CONFIRM" adv="1">http://blogs.sun.com/security/entry/sun_alert_253267_sun_java</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="java_system_identity_manager">
        <vers num="7.0" />
        <vers num="7.1" />
        <vers num="7.1.1" />
        <vers num="8.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1077" published="2009-03-25" name="CVE-2009-1077" modified="2009-10-06" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)" CVSS_score="6.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.0" CVSS_base_score="6.5">
    <desc>
      <descript source="cve">The Change My Password implementation in the admin interface in Sun Java System Identity Manager (IdM) 7.0 through 8.0 does not enforce the RequiresChallenge property setting, which allows remote authenticated users to change the passwords of other users, as demonstrated by changing the administrator's password.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/34191" source="BID" patch="1">34191</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-253267-1" source="SUNALERT" patch="1" adv="1">253267</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-21-140936-01-1" source="CONFIRM" patch="1" adv="1">http://sunsolve.sun.com/search/document.do?assetkey=1-21-140936-01-1</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-21-140935-01-1" source="CONFIRM" patch="1">http://sunsolve.sun.com/search/document.do?assetkey=1-21-140935-01-1</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-21-139010-06-1" source="CONFIRM" patch="1">http://sunsolve.sun.com/search/document.do?assetkey=1-21-139010-06-1</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-21-137621-11-1" source="CONFIRM" patch="1">http://sunsolve.sun.com/search/document.do?assetkey=1-21-137621-11-1</ref>
      <ref url="http://blogs.sun.com/security/entry/sun_alert_253267_sun_java" source="CONFIRM" patch="1" adv="1">http://blogs.sun.com/security/entry/sun_alert_253267_sun_java</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0797" source="VUPEN" adv="1">ADV-2009-0797</ref>
      <ref url="http://securitytracker.com/id?1021881" source="SECTRACK">1021881</ref>
      <ref url="http://secunia.com/advisories/34380" source="SECUNIA" adv="1">34380</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="java_system_identity_manager">
        <vers num="7.0" />
        <vers num="7.1" />
        <vers num="7.1.1" />
        <vers num="8.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1078" published="2009-03-25" name="CVE-2009-1078" modified="2009-10-06" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:N/I:P/A:N)" CVSS_score="4.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.0" CVSS_base_score="4.0">
    <desc>
      <descript source="cve">Sun Java System Identity Manager (IdM) 7.0 through 8.0 does not enforce the expected privilege requirements for (1) deleting audit policies and (2) modifying workflows, which allows remote authenticated users to have an unspecified impact.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/34191" source="BID" patch="1">34191</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-253267-1" source="SUNALERT" patch="1" adv="1">253267</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-21-140935-01-1" source="CONFIRM" patch="1">http://sunsolve.sun.com/search/document.do?assetkey=1-21-140935-01-1</ref>
      <ref url="http://blogs.sun.com/security/entry/sun_alert_253267_sun_java" source="CONFIRM" patch="1" adv="1">http://blogs.sun.com/security/entry/sun_alert_253267_sun_java</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0797" source="VUPEN" adv="1">ADV-2009-0797</ref>
      <ref url="http://securitytracker.com/id?1021881" source="SECTRACK">1021881</ref>
      <ref url="http://secunia.com/advisories/34380" source="SECUNIA" adv="1">34380</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="java_system_identity_manager">
        <vers num="7.0" />
        <vers num="7.1" />
        <vers num="7.1.1" />
        <vers num="8.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1079" published="2009-03-25" name="CVE-2009-1079" modified="2009-10-06" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Sun Java System Identity Manager (IdM) 7.0 through 8.0 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka Bug IDs 19659, 19660, and 19683.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/34191" source="BID" patch="1">34191</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-253267-1" source="SUNALERT" patch="1" adv="1">253267</ref>
      <ref url="http://blogs.sun.com/security/entry/sun_alert_253267_sun_java" source="CONFIRM" patch="1" adv="1">http://blogs.sun.com/security/entry/sun_alert_253267_sun_java</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0797" source="VUPEN" adv="1">ADV-2009-0797</ref>
      <ref url="http://securitytracker.com/id?1021881" source="SECTRACK">1021881</ref>
      <ref url="http://secunia.com/advisories/34380" source="SECUNIA" adv="1">34380</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="java_system_identity_manager">
        <vers num="7.0" />
        <vers num="7.1" />
        <vers num="7.1.1" />
        <vers num="8.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1080" published="2009-03-25" name="CVE-2009-1080" modified="2009-10-06" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Sun Java System Identity Manager (IdM) 7.0 through 8.0 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka Bug ID 19033.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/34191" source="BID" patch="1">34191</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-253267-1" source="SUNALERT" patch="1" adv="1">253267</ref>
      <ref url="http://blogs.sun.com/security/entry/sun_alert_253267_sun_java" source="CONFIRM" patch="1" adv="1">http://blogs.sun.com/security/entry/sun_alert_253267_sun_java</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0797" source="VUPEN" adv="1">ADV-2009-0797</ref>
      <ref url="http://securitytracker.com/id?1021881" source="SECTRACK">1021881</ref>
      <ref url="http://secunia.com/advisories/34380" source="SECUNIA" adv="1">34380</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="java_system_identity_manager">
        <vers num="7.0" />
        <vers num="7.1" />
        <vers num="7.1.1" />
        <vers num="8.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1081" published="2009-03-25" name="CVE-2009-1081" modified="2009-03-25" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Sun Java System Identity Manager (IdM) 7.0 through 8.0 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka Bug IDs 19595 and 19661.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/34191" source="BID" patch="1">34191</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-253267-1" source="SUNALERT" patch="1" adv="1">253267</ref>
      <ref url="http://blogs.sun.com/security/entry/sun_alert_253267_sun_java" source="CONFIRM" patch="1" adv="1">http://blogs.sun.com/security/entry/sun_alert_253267_sun_java</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0797" source="VUPEN" adv="1">ADV-2009-0797</ref>
      <ref url="http://securitytracker.com/id?1021881" source="SECTRACK">1021881</ref>
      <ref url="http://secunia.com/advisories/34380" source="SECUNIA" adv="1">34380</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="java_system_identity_manager">
        <vers num="7.0" />
        <vers num="7.1" />
        <vers num="7.1.1" />
        <vers num="8.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1082" published="2009-03-25" name="CVE-2009-1082" modified="2009-03-25" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:C/I:C/A:C)" CVSS_score="9.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.0" CVSS_base_score="9.0">
    <desc>
      <descript source="cve">Sun Java System Identity Manager (IdM) 7.0 through 8.0 allows remote authenticated users to gain privileges by submitting crafted commands to the Admin Console, as demonstrated by privileges for account creation and other administrative capabilities, related to the saveNoValidate action and saveNoValidateAllowedFormsAndWorkflows IDs.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/34191" source="BID" patch="1">34191</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-21-140936-01-1" source="CONFIRM" patch="1">http://sunsolve.sun.com/search/document.do?assetkey=1-21-140936-01-1</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-21-140935-01-1" source="CONFIRM" patch="1">http://sunsolve.sun.com/search/document.do?assetkey=1-21-140935-01-1</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-21-137621-11-1" source="CONFIRM" patch="1">http://sunsolve.sun.com/search/document.do?assetkey=1-21-137621-11-1</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0797" source="VUPEN" adv="1">ADV-2009-0797</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-253267-1" source="SUNALERT" adv="1">253267</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-21-139010-06-1" source="CONFIRM">http://sunsolve.sun.com/search/document.do?assetkey=1-21-139010-06-1</ref>
      <ref url="http://securitytracker.com/id?1021881" source="SECTRACK">1021881</ref>
      <ref url="http://secunia.com/advisories/34380" source="SECUNIA" adv="1">34380</ref>
      <ref url="http://blogs.sun.com/security/entry/sun_alert_253267_sun_java" source="CONFIRM" adv="1">http://blogs.sun.com/security/entry/sun_alert_253267_sun_java</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="java_system_identity_manager">
        <vers num="7.0" />
        <vers num="7.1" />
        <vers num="7.1.1" />
        <vers num="8.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1083" published="2009-03-25" name="CVE-2009-1083" modified="2009-10-06" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:C/I:C/A:C)" CVSS_score="9.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.0" CVSS_base_score="9.0">
    <desc>
      <descript source="cve">Sun Java System Identity Manager (IdM) 7.0 through 8.0 on Linux, AIX, Solaris, and HP-UX permits "control characters" in the passwords of user accounts, which allows remote attackers to execute arbitrary commands via vectors involving "resource adapters."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-253267-1" source="SUNALERT" patch="1" adv="1">253267</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-21-140935-01-1" source="CONFIRM" patch="1">http://sunsolve.sun.com/search/document.do?assetkey=1-21-140935-01-1</ref>
      <ref url="http://blogs.sun.com/security/entry/sun_alert_253267_sun_java" source="CONFIRM" patch="1" adv="1">http://blogs.sun.com/security/entry/sun_alert_253267_sun_java</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0797" source="VUPEN" adv="1">ADV-2009-0797</ref>
      <ref url="http://www.securityfocus.com/bid/34191" source="BID">34191</ref>
      <ref url="http://securitytracker.com/id?1021881" source="SECTRACK">1021881</ref>
      <ref url="http://secunia.com/advisories/34380" source="SECUNIA" adv="1">34380</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="java_system_identity_manager">
        <vers num="7.0" />
        <vers num="7.1" />
        <vers num="7.1.1" />
        <vers num="8.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1084" published="2009-03-25" name="CVE-2009-1084" modified="2009-04-16" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">Sun Java System Identity Manager (IdM) 7.0 through 8.0 does not properly restrict access to the System Configuration object, which allows remote authenticated administrators and possibly remote attackers to have an unspecified impact by modifying this object.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-253267-1" source="SUNALERT" patch="1" adv="1">253267</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-21-140935-01-1" source="CONFIRM" patch="1">http://sunsolve.sun.com/search/document.do?assetkey=1-21-140935-01-1</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-21-139010-06-1" source="CONFIRM" patch="1">http://sunsolve.sun.com/search/document.do?assetkey=1-21-139010-06-1</ref>
      <ref url="http://blogs.sun.com/security/entry/sun_alert_253267_sun_java" source="CONFIRM" patch="1">http://blogs.sun.com/security/entry/sun_alert_253267_sun_java</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/49607" source="XF">jsim-sco-unspecified(49607)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0797" source="VUPEN" adv="1">ADV-2009-0797</ref>
      <ref url="http://www.securityfocus.com/bid/34191" source="BID">34191</ref>
      <ref url="http://securitytracker.com/id?1021881" source="SECTRACK">1021881</ref>
      <ref url="http://secunia.com/advisories/34380" source="SECUNIA" adv="1">34380</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="java_system_identity_manager">
        <vers num="7.0" />
        <vers num="7.1" />
        <vers num="7.1.1" />
        <vers num="8.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1085" published="2009-03-25" name="CVE-2009-1085" modified="2009-06-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Piwik 0.2.32 and earlier stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain the API key and other sensitive information via a direct request for misc/cron/archive.sh.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.openwall.com/lists/oss-security/2009/03/23/2" source="MLIST">[oss-security] 20090323 CVE request: API key disclosure in piwik</ref>
      <ref url="http://marco-ziesing.de/archives/35-Schluesselloch-in-Piwik.html" source="MISC">http://marco-ziesing.de/archives/35-Schluesselloch-in-Piwik.html</ref>
      <ref url="http://dev.piwik.org/trac/ticket/599" source="CONFIRM">http://dev.piwik.org/trac/ticket/599</ref>
    </refs>
    <vuln_soft>
      <prod vendor="piwik" name="piwik">
        <vers num="0.2.25" />
        <vers num="0.2.26" />
        <vers num="0.2.27" />
        <vers num="0.2.28" />
        <vers num="0.2.29" />
        <vers num="0.2.30" />
        <vers num="0.2.31" />
        <vers prev="1" num="0.2.32" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1086" published="2009-03-25" name="CVE-2009-1086" modified="2009-05-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:P)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">Heap-based buffer overflow in the ldns_rr_new_frm_str_internal function in ldns 1.4.x allows remote attackers to cause a denial of service (memory corruption) and possibly execute arbitrary code via a DNS resource record (RR) with a long (1) class field (clas variable) and possibly (2) TTL field.</descript>
    </desc>
    <loss_types>
      <avail />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/34233" source="BID">34233</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2009/03/24/4" source="MLIST">[oss-security] 20090324 CVE id request: ldns</ref>
      <ref url="http://www.nlnetlabs.nl/svn/ldns/tags/release-1.5.0/Changelog" source="CONFIRM">http://www.nlnetlabs.nl/svn/ldns/tags/release-1.5.0/Changelog</ref>
      <ref url="http://www.nlnetlabs.nl/bugs/show_bug.cgi?id=232" source="MISC">http://www.nlnetlabs.nl/bugs/show_bug.cgi?id=232</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1795" source="DEBIAN">DSA-1795</ref>
      <ref url="http://secunia.com/advisories/35065" source="SECUNIA">35065</ref>
      <ref url="http://secunia.com/advisories/35013" source="SECUNIA">35013</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-05/msg00000.html" source="SUSE">SUSE-SR:2009:010</ref>
    </refs>
    <vuln_soft>
      <prod vendor="nlnetlabs" name="ldns">
        <vers num="1.4.0" />
        <vers num="1.4.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1087" published="2009-03-25" name="CVE-2009-1087" modified="2009-07-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Multiple argument injection vulnerabilities in PPLive.exe in PPLive 1.9.21 and earlier allow remote attackers to execute arbitrary code via a UNC share pathname in the LoadModule argument to the (1) synacast, (2) Play, (3) pplsv, or (4) ppvod URI handler.  NOTE: some of these details are obtained from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/49263" source="XF">pplive-uri-code-execution(49263)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0739" source="VUPEN" adv="1">ADV-2009-0739</ref>
      <ref url="http://www.milw0rm.com/exploits/8215" source="MILW0RM">8215</ref>
      <ref url="http://secunia.com/advisories/34327" source="SECUNIA" adv="1">34327</ref>
    </refs>
    <vuln_soft>
      <prod vendor="pplive" name="pplive">
        <vers num="1.9.15" />
        <vers prev="1" num="1.9.21" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1088" published="2009-03-25" name="CVE-2009-1088" modified="2009-10-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:C/I:C/A:C)" CVSS_score="9.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.0" CVSS_base_score="9.0">
    <desc>
      <descript source="cve">Hannon Hill Cascade Server 5.7 and other versions allows remote authenticated users to execute arbitrary programs or Java code via a crafted XSLT stylesheet with "extension elements and extension functions" that trigger code execution by Xalan-Java, as demonstrated using xalan://java.lang.Runtime.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/49332" source="XF">cascadeserver-xlst-command-execution(49332)</ref>
      <ref url="http://www.securityfocus.com/bid/34186" source="BID">34186</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/501981/100/0/threaded" source="BUGTRAQ">20090319 Command Execution in Hannon Hill Cascade Server</ref>
      <ref url="http://www.milw0rm.com/exploits/8247" source="MILW0RM">8247</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hannonhill" name="cascade">
        <vers num="5.7" edition="svr" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1089" published="2009-03-25" name="CVE-2009-1089" modified="2009-03-25" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Absolute path traversal vulnerability in upload.php in Rapidleech rev.36 and earlier allows remote attackers to read arbitrary files via a base64-encoded absolute path in the filename parameter.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/49253" source="XF">rapidleech-filename-info-disclosure(49253)</ref>
      <ref url="http://www.securityfocus.com/bid/34119" source="BID">34119</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/501854/100/0/threaded" source="BUGTRAQ">20090314 [Bkis-03-2009] Multiple Vulnerabilities found in Rapidleech rev.36</ref>
      <ref url="http://secunia.com/advisories/34300" source="SECUNIA" adv="1">34300</ref>
    </refs>
    <vuln_soft>
      <prod vendor="rapidleech" name="rapid_leech">
        <vers prev="1" num="rev.36" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1090" published="2009-03-25" name="CVE-2009-1090" modified="2009-07-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Directory traversal vulnerability in upload.php in Rapidleech rev.36 and earlier allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the uploaded parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/49256" source="XF">rapidleech-uploaded-file-include(49256)</ref>
      <ref url="http://www.securityfocus.com/bid/34119" source="BID">34119</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/501854/100/0/threaded" source="BUGTRAQ">20090314 [Bkis-03-2009] Multiple Vulnerabilities found in Rapidleech rev.36</ref>
      <ref url="http://security.bkis.vn/?p=345" source="MISC">http://security.bkis.vn/?p=345</ref>
      <ref url="http://secunia.com/advisories/34300" source="SECUNIA" adv="1">34300</ref>
      <ref url="http://osvdb.org/52753" source="OSVDB">52753</ref>
    </refs>
    <vuln_soft>
      <prod vendor="rapidleech" name="rapidleech">
        <vers prev="1" num="rev.36" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1091" published="2009-03-25" name="CVE-2009-1091" modified="2009-10-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in upload.php in Rapidleech rev.36 and earlier allows remote attackers to inject arbitrary web script or HTML via the uploaded parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/49257" source="XF">rapidleech-upload-xss(49257)</ref>
      <ref url="http://www.securityfocus.com/bid/34119" source="BID">34119</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/501854/100/0/threaded" source="BUGTRAQ">20090314 [Bkis-03-2009] Multiple Vulnerabilities found in Rapidleech rev.36</ref>
      <ref url="http://secunia.com/advisories/34300" source="SECUNIA" adv="1">34300</ref>
      <ref url="http://osvdb.org/52754" source="OSVDB">52754</ref>
    </refs>
    <vuln_soft>
      <prod vendor="rapidleech" name="rapid_leech">
        <vers prev="1" num="rev.36" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1092" published="2009-03-25" name="CVE-2009-1092" modified="2009-06-19" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Use-after-free vulnerability in the LIVEAUDIO.LiveAudioCtrl.1 ActiveX control in LIVEAU~1.OCX 7.0 for GeoVision DVR systems allows remote attackers to execute arbitrary code by calling the GetAudioPlayingTime method with certain arguments.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/49238" source="XF">geovision-liveaudio-activex-dos(49238)</ref>
      <ref url="http://www.securityfocus.com/bid/34115" source="BID">34115</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/501773/100/0/threaded" source="BUGTRAQ">20090313 GeoVision LiveAudio ActiveX Control GetAudioPlayingTime() remote freed-memory access exploit</ref>
      <ref url="http://www.milw0rm.com/exploits/8206" source="MILW0RM">8206</ref>
      <ref url="http://retrogod.altervista.org/9sg_geovision_liveaudio_freedmem.html" source="MISC">http://retrogod.altervista.org/9sg_geovision_liveaudio_freedmem.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="geovision" name="liveaudio_activex_control">
        <vers num="7.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1093" published="2009-03-25" name="CVE-2009-1093" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">LdapCtx in the LDAP service in Java SE Development Kit (JDK) and Java Runtime Environment (JRE) 5.0 Update 17 and earlier; 6 Update 12 and earlier; SDK and JRE 1.3.1_24 and earlier; and 1.4.2_19 and earlier does not close the connection when initialization fails, which allows remote attackers to cause a denial of service (LDAP service hang).</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-254569-1" source="SUNALERT" patch="1" adv="1">254569</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-21-118667-19-1" source="MISC" patch="1">http://sunsolve.sun.com/search/document.do?assetkey=1-21-118667-19-1</ref>
      <ref url="https://rhn.redhat.com/errata/RHSA-2009-1198.html" source="REDHAT">RHSA-2009:1198</ref>
      <ref url="https://rhn.redhat.com/errata/RHSA-2009-0377.html" source="REDHAT">RHSA-2009:0377</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/3316" source="VUPEN">ADV-2009-3316</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1426" source="VUPEN">ADV-2009-1426</ref>
      <ref url="http://www.vmware.com/security/advisories/VMSA-2009-0016.html" source="CONFIRM">http://www.vmware.com/security/advisories/VMSA-2009-0016.html</ref>
      <ref url="http://www.ubuntu.com/usn/usn-748-1" source="UBUNTU">USN-748-1</ref>
      <ref url="http://www.securitytracker.com/id?1021893" source="SECTRACK">1021893</ref>
      <ref url="http://www.securityfocus.com/bid/34240" source="BID">34240</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/507985/100/0/threaded" source="BUGTRAQ">20091120 VMSA-2009-0016 VMware vCenter and ESX update release and vMA patch release address multiple security issue in third party components</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-1038.html" source="REDHAT">RHSA-2009:1038</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-0394.html" source="REDHAT">RHSA-2009:0394</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-0392.html" source="REDHAT">RHSA-2009:0392</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujul2009.html" source="CONFIRM">http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujul2009.html</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:162" source="MANDRIVA">MDVSA-2009:162</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:137" source="MANDRIVA">MDVSA-2009:137</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1769" source="DEBIAN">DSA-1769</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2009-109.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2009-109.htm</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2009-108.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2009-108.htm</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200911-02.xml" source="GENTOO">GLSA-200911-02</ref>
      <ref url="http://secunia.com/advisories/37460" source="SECUNIA">37460</ref>
      <ref url="http://secunia.com/advisories/37386" source="SECUNIA">37386</ref>
      <ref url="http://secunia.com/advisories/36185" source="SECUNIA">36185</ref>
      <ref url="http://secunia.com/advisories/35776" source="SECUNIA">35776</ref>
      <ref url="http://secunia.com/advisories/35416" source="SECUNIA">35416</ref>
      <ref url="http://secunia.com/advisories/35255" source="SECUNIA">35255</ref>
      <ref url="http://secunia.com/advisories/35223" source="SECUNIA">35223</ref>
      <ref url="http://secunia.com/advisories/35156" source="SECUNIA">35156</ref>
      <ref url="http://secunia.com/advisories/34675" source="SECUNIA">34675</ref>
      <ref url="http://secunia.com/advisories/34632" source="SECUNIA">34632</ref>
      <ref url="http://secunia.com/advisories/34496" source="SECUNIA">34496</ref>
      <ref url="http://secunia.com/advisories/34495" source="SECUNIA">34495</ref>
      <ref url="http://secunia.com/advisories/34489" source="SECUNIA">34489</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6676" source="OVAL">oval:org.mitre.oval:def:6676</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11343" source="OVAL">oval:org.mitre.oval:def:11343</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=124344236532162&amp;w=2" source="HP">HPSBUX02429</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-07/msg00001.html" source="SUSE">SUSE-SA:2009:036</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-06/msg00003.html" source="SUSE">SUSE-SR:2009:011</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-05/msg00003.html" source="SUSE">SUSE-SA:2009:029</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-04/msg00001.html" source="SUSE">SUSE-SA:2009:016</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&amp;cc=us&amp;objectID=c01745133" source="HP">HPSBMA02429</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&amp;cc=us&amp;objectID=c01745133" source="HP">HPSBMA02429</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="jdk">
        <vers num="1.3.0" />
        <vers num="1.3.0_01" />
        <vers num="1.3.0_02" />
        <vers num="1.3.0_03" />
        <vers num="1.3.0_04" />
        <vers num="1.3.0_05" />
        <vers num="1.3.1" />
        <vers num="1.3.1_01" />
        <vers num="1.3.1_01a" />
        <vers num="1.3.1_02" />
        <vers num="1.3.1_03" />
        <vers num="1.3.1_04" />
        <vers num="1.3.1_05" />
        <vers num="1.3.1_06" />
        <vers num="1.3.1_07" />
        <vers num="1.3.1_08" />
        <vers num="1.3.1_09" />
        <vers num="1.3.1_10" />
        <vers num="1.3.1_11" />
        <vers num="1.3.1_12" />
        <vers num="1.3.1_13" />
        <vers num="1.3.1_14" />
        <vers num="1.3.1_15" />
        <vers num="1.3.1_16" />
        <vers num="1.3.1_17" />
        <vers num="1.3.1_18" />
        <vers num="1.3.1_19" />
        <vers num="1.3.1_20" />
        <vers num="1.3.1_21" />
        <vers num="1.3.1_22" />
        <vers num="1.3.1_23" />
        <vers prev="1" num="1.3.1_24" />
        <vers num="1.4.0" />
        <vers num="1.4.0_01" />
        <vers num="1.4.0_02" />
        <vers num="1.4.0_03" />
        <vers num="1.4.0_04" />
        <vers num="1.4.1" />
        <vers num="1.4.1_01" />
        <vers num="1.4.1_02" />
        <vers num="1.4.1_03" />
        <vers num="1.4.1_04" />
        <vers num="1.4.1_05" />
        <vers num="1.4.1_06" />
        <vers num="1.4.1_07" />
        <vers num="1.4.2" />
        <vers num="1.4.2_1" />
        <vers num="1.4.2_10" />
        <vers num="1.4.2_11" />
        <vers num="1.4.2_12" />
        <vers num="1.4.2_13" />
        <vers num="1.4.2_14" />
        <vers num="1.4.2_15" />
        <vers num="1.4.2_16" />
        <vers num="1.4.2_17" />
        <vers num="1.4.2_18" />
        <vers prev="1" num="1.4.2_19" />
        <vers num="1.4.2_2" />
        <vers num="1.4.2_3" />
        <vers num="1.4.2_4" />
        <vers num="1.4.2_5" />
        <vers num="1.4.2_6" />
        <vers num="1.4.2_7" />
        <vers num="1.4.2_8" />
        <vers num="1.4.2_9" />
        <vers prev="1" num="5.0" edition="update_1" />
        <vers prev="1" num="5.0" edition="update_10" />
        <vers prev="1" num="5.0" edition="update_11" />
        <vers prev="1" num="5.0" edition="update_12" />
        <vers prev="1" num="5.0" edition="update_13" />
        <vers prev="1" num="5.0" edition="update_14" />
        <vers prev="1" num="5.0" edition="update_15" />
        <vers prev="1" num="5.0" edition="update_16" />
        <vers prev="1" num="5.0" edition="update_17" />
        <vers prev="1" num="5.0" edition="update_2" />
        <vers prev="1" num="5.0" edition="update_3" />
        <vers prev="1" num="5.0" edition="update_4" />
        <vers prev="1" num="5.0" edition="update_5" />
        <vers prev="1" num="5.0" edition="update_6" />
        <vers prev="1" num="5.0" edition="update_7" />
        <vers prev="1" num="5.0" edition="update_8" />
        <vers prev="1" num="5.0" edition="update_9" />
        <vers prev="1" num="6" edition="update_1" />
        <vers prev="1" num="6" edition="update_10" />
        <vers prev="1" num="6" edition="update_11" />
        <vers prev="1" num="6" edition="update_12" />
        <vers prev="1" num="6" edition="update_2" />
        <vers prev="1" num="6" edition="update_3" />
        <vers prev="1" num="6" edition="update_4" />
        <vers prev="1" num="6" edition="update_5" />
        <vers prev="1" num="6" edition="update_6" />
        <vers prev="1" num="6" edition="update_7" />
      </prod>
      <prod vendor="sun" name="jre">
        <vers num="1.3.0" />
        <vers num="1.3.0_01" />
        <vers num="1.3.0_02" />
        <vers num="1.3.0_03" />
        <vers num="1.3.0_04" />
        <vers num="1.3.0_05" />
        <vers num="1.3.1" />
        <vers num="1.3.1_01" />
        <vers num="1.3.1_01a" />
        <vers num="1.3.1_02" />
        <vers num="1.3.1_03" />
        <vers num="1.3.1_04" />
        <vers num="1.3.1_05" />
        <vers num="1.3.1_06" />
        <vers num="1.3.1_07" />
        <vers num="1.3.1_08" />
        <vers num="1.3.1_09" />
        <vers num="1.3.1_10" />
        <vers num="1.3.1_11" />
        <vers num="1.3.1_12" />
        <vers num="1.3.1_13" />
        <vers num="1.3.1_14" />
        <vers num="1.3.1_15" />
        <vers num="1.3.1_16" />
        <vers num="1.3.1_17" />
        <vers num="1.3.1_18" />
        <vers num="1.3.1_19" />
        <vers num="1.3.1_20" />
        <vers num="1.3.1_21" />
        <vers num="1.3.1_22" />
        <vers num="1.3.1_23" />
        <vers prev="1" num="1.3.1_24" />
        <vers num="1.4.0" />
        <vers num="1.4.0_01" />
        <vers num="1.4.0_02" />
        <vers num="1.4.0_03" />
        <vers num="1.4.0_04" />
        <vers num="1.4.1" />
        <vers num="1.4.1_01" />
        <vers num="1.4.1_02" />
        <vers num="1.4.1_03" />
        <vers num="1.4.1_04" />
        <vers num="1.4.1_05" />
        <vers num="1.4.1_06" />
        <vers num="1.4.1_07" />
        <vers num="1.4.2" />
        <vers num="1.4.2_01" />
        <vers num="1.4.2_02" />
        <vers num="1.4.2_03" />
        <vers num="1.4.2_04" />
        <vers num="1.4.2_05" />
        <vers num="1.4.2_06" />
        <vers num="1.4.2_07" />
        <vers num="1.4.2_08" />
        <vers num="1.4.2_09" />
        <vers num="1.4.2_10" />
        <vers num="1.4.2_11" />
        <vers num="1.4.2_12" />
        <vers num="1.4.2_13" />
        <vers num="1.4.2_14" />
        <vers num="1.4.2_15" />
        <vers num="1.4.2_16" />
        <vers num="1.4.2_17" />
        <vers num="1.4.2_18" />
        <vers prev="1" num="1.4.2_19" />
        <vers prev="1" num="5.0" edition="update_1" />
        <vers prev="1" num="5.0" edition="update_10" />
        <vers prev="1" num="5.0" edition="update_11" />
        <vers prev="1" num="5.0" edition="update_12" />
        <vers prev="1" num="5.0" edition="update_13" />
        <vers prev="1" num="5.0" edition="update_14" />
        <vers prev="1" num="5.0" edition="update_15" />
        <vers prev="1" num="5.0" edition="update_16" />
        <vers prev="1" num="5.0" edition="update_17" />
        <vers prev="1" num="5.0" edition="update_2" />
        <vers prev="1" num="5.0" edition="update_3" />
        <vers prev="1" num="5.0" edition="update_4" />
        <vers prev="1" num="5.0" edition="update_5" />
        <vers prev="1" num="5.0" edition="update_6" />
        <vers prev="1" num="5.0" edition="update_7" />
        <vers prev="1" num="5.0" edition="update_8" />
        <vers prev="1" num="5.0" edition="update_9" />
        <vers prev="1" num="6" edition="update_1" />
        <vers prev="1" num="6" edition="update_10" />
        <vers prev="1" num="6" edition="update_11" />
        <vers prev="1" num="6" edition="update_12" />
        <vers prev="1" num="6" edition="update_2" />
        <vers prev="1" num="6" edition="update_3" />
        <vers prev="1" num="6" edition="update_4" />
        <vers prev="1" num="6" edition="update_5" />
        <vers prev="1" num="6" edition="update_6" />
        <vers prev="1" num="6" edition="update_7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1094" published="2009-03-25" name="CVE-2009-1094" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the LDAP implementation in Java SE Development Kit (JDK) and Java Runtime Environment (JRE) 5.0 Update 17 and earlier; 6 Update 12 and earlier; SDK and JRE 1.3.1_24 and earlier; and 1.4.2_19 and earlier allows remote LDAP servers to execute arbitrary code via unknown vectors related to serialized data.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-254569-1" source="SUNALERT" patch="1" adv="1">254569</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-21-118667-19-1" source="MISC" patch="1">http://sunsolve.sun.com/search/document.do?assetkey=1-21-118667-19-1</ref>
      <ref url="https://rhn.redhat.com/errata/RHSA-2009-1198.html" source="REDHAT">RHSA-2009:1198</ref>
      <ref url="https://rhn.redhat.com/errata/RHSA-2009-0377.html" source="REDHAT">RHSA-2009:0377</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/3316" source="VUPEN">ADV-2009-3316</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1900" source="VUPEN">ADV-2009-1900</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1426" source="VUPEN">ADV-2009-1426</ref>
      <ref url="http://www.vmware.com/security/advisories/VMSA-2009-0016.html" source="CONFIRM">http://www.vmware.com/security/advisories/VMSA-2009-0016.html</ref>
      <ref url="http://www.ubuntu.com/usn/usn-748-1" source="UBUNTU">USN-748-1</ref>
      <ref url="http://www.securitytracker.com/id?1021893" source="SECTRACK">1021893</ref>
      <ref url="http://www.securityfocus.com/bid/34240" source="BID">34240</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/507985/100/0/threaded" source="BUGTRAQ">20091120 VMSA-2009-0016 VMware vCenter and ESX update release and vMA patch release address multiple security issue in third party components</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-1038.html" source="REDHAT">RHSA-2009:1038</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-0394.html" source="REDHAT">RHSA-2009:0394</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-0392.html" source="REDHAT">RHSA-2009:0392</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujul2009.html" source="CONFIRM">http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujul2009.html</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:162" source="MANDRIVA">MDVSA-2009:162</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:137" source="MANDRIVA">MDVSA-2009:137</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1769" source="DEBIAN">DSA-1769</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2009-109.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2009-109.htm</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2009-108.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2009-108.htm</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200911-02.xml" source="GENTOO">GLSA-200911-02</ref>
      <ref url="http://secunia.com/advisories/37460" source="SECUNIA">37460</ref>
      <ref url="http://secunia.com/advisories/37386" source="SECUNIA">37386</ref>
      <ref url="http://secunia.com/advisories/36185" source="SECUNIA">36185</ref>
      <ref url="http://secunia.com/advisories/35776" source="SECUNIA">35776</ref>
      <ref url="http://secunia.com/advisories/35416" source="SECUNIA">35416</ref>
      <ref url="http://secunia.com/advisories/35255" source="SECUNIA">35255</ref>
      <ref url="http://secunia.com/advisories/35223" source="SECUNIA">35223</ref>
      <ref url="http://secunia.com/advisories/35156" source="SECUNIA">35156</ref>
      <ref url="http://secunia.com/advisories/34675" source="SECUNIA">34675</ref>
      <ref url="http://secunia.com/advisories/34632" source="SECUNIA">34632</ref>
      <ref url="http://secunia.com/advisories/34496" source="SECUNIA">34496</ref>
      <ref url="http://secunia.com/advisories/34495" source="SECUNIA">34495</ref>
      <ref url="http://secunia.com/advisories/34489" source="SECUNIA">34489</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6598" source="OVAL">oval:org.mitre.oval:def:6598</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11064" source="OVAL">oval:org.mitre.oval:def:11064</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=124344236532162&amp;w=2" source="HP">HPSBUX02429</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-07/msg00001.html" source="SUSE">SUSE-SA:2009:036</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-06/msg00003.html" source="SUSE">SUSE-SR:2009:011</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-05/msg00003.html" source="SUSE">SUSE-SA:2009:029</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-04/msg00001.html" source="SUSE">SUSE-SA:2009:016</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&amp;cc=us&amp;objectID=c01745133" source="HP">HPSBMA02429</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&amp;cc=us&amp;objectID=c01745133" source="HP">HPSBMA02429</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="jdk">
        <vers num="1.3.0" />
        <vers num="1.3.0_01" />
        <vers num="1.3.0_02" />
        <vers num="1.3.0_03" />
        <vers num="1.3.0_04" />
        <vers num="1.3.0_05" />
        <vers num="1.3.1" />
        <vers num="1.3.1_01" />
        <vers num="1.3.1_01a" />
        <vers num="1.3.1_02" />
        <vers num="1.3.1_03" />
        <vers num="1.3.1_04" />
        <vers num="1.3.1_05" />
        <vers num="1.3.1_06" />
        <vers num="1.3.1_07" />
        <vers num="1.3.1_08" />
        <vers num="1.3.1_09" />
        <vers num="1.3.1_10" />
        <vers num="1.3.1_11" />
        <vers num="1.3.1_12" />
        <vers num="1.3.1_13" />
        <vers num="1.3.1_14" />
        <vers num="1.3.1_15" />
        <vers num="1.3.1_16" />
        <vers num="1.3.1_17" />
        <vers num="1.3.1_18" />
        <vers num="1.3.1_19" />
        <vers num="1.3.1_20" />
        <vers num="1.3.1_21" />
        <vers num="1.3.1_22" />
        <vers num="1.3.1_23" />
        <vers prev="1" num="1.3.1_24" />
        <vers num="1.4.0" />
        <vers num="1.4.0_01" />
        <vers num="1.4.0_02" />
        <vers num="1.4.0_03" />
        <vers num="1.4.0_04" />
        <vers num="1.4.1" />
        <vers num="1.4.1_01" />
        <vers num="1.4.1_02" />
        <vers num="1.4.1_03" />
        <vers num="1.4.1_04" />
        <vers num="1.4.1_05" />
        <vers num="1.4.1_06" />
        <vers num="1.4.1_07" />
        <vers num="1.4.2" />
        <vers num="1.4.2_1" />
        <vers num="1.4.2_10" />
        <vers num="1.4.2_11" />
        <vers num="1.4.2_12" />
        <vers num="1.4.2_13" />
        <vers num="1.4.2_14" />
        <vers num="1.4.2_15" />
        <vers num="1.4.2_16" />
        <vers num="1.4.2_17" />
        <vers num="1.4.2_18" />
        <vers prev="1" num="1.4.2_19" />
        <vers num="1.4.2_2" />
        <vers num="1.4.2_3" />
        <vers num="1.4.2_4" />
        <vers num="1.4.2_5" />
        <vers num="1.4.2_6" />
        <vers num="1.4.2_7" />
        <vers num="1.4.2_8" />
        <vers num="1.4.2_9" />
        <vers prev="1" num="5.0" edition="update_1" />
        <vers prev="1" num="5.0" edition="update_10" />
        <vers prev="1" num="5.0" edition="update_11" />
        <vers prev="1" num="5.0" edition="update_12" />
        <vers prev="1" num="5.0" edition="update_13" />
        <vers prev="1" num="5.0" edition="update_14" />
        <vers prev="1" num="5.0" edition="update_15" />
        <vers prev="1" num="5.0" edition="update_16" />
        <vers prev="1" num="5.0" edition="update_17" />
        <vers prev="1" num="5.0" edition="update_2" />
        <vers prev="1" num="5.0" edition="update_3" />
        <vers prev="1" num="5.0" edition="update_4" />
        <vers prev="1" num="5.0" edition="update_5" />
        <vers prev="1" num="5.0" edition="update_6" />
        <vers prev="1" num="5.0" edition="update_7" />
        <vers prev="1" num="5.0" edition="update_8" />
        <vers prev="1" num="5.0" edition="update_9" />
        <vers prev="1" num="6" edition="update_1" />
        <vers prev="1" num="6" edition="update_10" />
        <vers prev="1" num="6" edition="update_11" />
        <vers prev="1" num="6" edition="update_12" />
        <vers prev="1" num="6" edition="update_2" />
        <vers prev="1" num="6" edition="update_3" />
        <vers prev="1" num="6" edition="update_4" />
        <vers prev="1" num="6" edition="update_5" />
        <vers prev="1" num="6" edition="update_6" />
        <vers prev="1" num="6" edition="update_7" />
      </prod>
      <prod vendor="sun" name="jre">
        <vers num="1.3.0" />
        <vers num="1.3.0_01" />
        <vers num="1.3.0_02" />
        <vers num="1.3.0_03" />
        <vers num="1.3.0_04" />
        <vers num="1.3.0_05" />
        <vers num="1.3.1" />
        <vers num="1.3.1_01" />
        <vers num="1.3.1_01a" />
        <vers num="1.3.1_02" />
        <vers num="1.3.1_03" />
        <vers num="1.3.1_04" />
        <vers num="1.3.1_05" />
        <vers num="1.3.1_06" />
        <vers num="1.3.1_07" />
        <vers num="1.3.1_08" />
        <vers num="1.3.1_09" />
        <vers num="1.3.1_10" />
        <vers num="1.3.1_11" />
        <vers num="1.3.1_12" />
        <vers num="1.3.1_13" />
        <vers num="1.3.1_14" />
        <vers num="1.3.1_15" />
        <vers num="1.3.1_16" />
        <vers num="1.3.1_17" />
        <vers num="1.3.1_18" />
        <vers num="1.3.1_19" />
        <vers num="1.3.1_20" />
        <vers num="1.3.1_21" />
        <vers num="1.3.1_22" />
        <vers num="1.3.1_23" />
        <vers prev="1" num="1.3.1_24" />
        <vers num="1.4.0" />
        <vers num="1.4.0_01" />
        <vers num="1.4.0_02" />
        <vers num="1.4.0_03" />
        <vers num="1.4.0_04" />
        <vers num="1.4.1" />
        <vers num="1.4.1_01" />
        <vers num="1.4.1_02" />
        <vers num="1.4.1_03" />
        <vers num="1.4.1_04" />
        <vers num="1.4.1_05" />
        <vers num="1.4.1_06" />
        <vers num="1.4.1_07" />
        <vers num="1.4.2" />
        <vers num="1.4.2_01" />
        <vers num="1.4.2_02" />
        <vers num="1.4.2_03" />
        <vers num="1.4.2_04" />
        <vers num="1.4.2_05" />
        <vers num="1.4.2_06" />
        <vers num="1.4.2_07" />
        <vers num="1.4.2_08" />
        <vers num="1.4.2_09" />
        <vers num="1.4.2_10" />
        <vers num="1.4.2_11" />
        <vers num="1.4.2_12" />
        <vers num="1.4.2_13" />
        <vers num="1.4.2_14" />
        <vers num="1.4.2_15" />
        <vers num="1.4.2_16" />
        <vers num="1.4.2_17" />
        <vers num="1.4.2_18" />
        <vers prev="1" num="1.4.2_19" />
        <vers prev="1" num="5.0" edition="update_1" />
        <vers prev="1" num="5.0" edition="update_10" />
        <vers prev="1" num="5.0" edition="update_11" />
        <vers prev="1" num="5.0" edition="update_12" />
        <vers prev="1" num="5.0" edition="update_13" />
        <vers prev="1" num="5.0" edition="update_14" />
        <vers prev="1" num="5.0" edition="update_15" />
        <vers prev="1" num="5.0" edition="update_16" />
        <vers prev="1" num="5.0" edition="update_17" />
        <vers prev="1" num="5.0" edition="update_2" />
        <vers prev="1" num="5.0" edition="update_3" />
        <vers prev="1" num="5.0" edition="update_4" />
        <vers prev="1" num="5.0" edition="update_5" />
        <vers prev="1" num="5.0" edition="update_6" />
        <vers prev="1" num="5.0" edition="update_7" />
        <vers prev="1" num="5.0" edition="update_8" />
        <vers prev="1" num="5.0" edition="update_9" />
        <vers prev="1" num="6" edition="update_1" />
        <vers prev="1" num="6" edition="update_10" />
        <vers prev="1" num="6" edition="update_11" />
        <vers prev="1" num="6" edition="update_12" />
        <vers prev="1" num="6" edition="update_2" />
        <vers prev="1" num="6" edition="update_3" />
        <vers prev="1" num="6" edition="update_4" />
        <vers prev="1" num="6" edition="update_5" />
        <vers prev="1" num="6" edition="update_6" />
        <vers prev="1" num="6" edition="update_7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1095" published="2009-03-25" name="CVE-2009-1095" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Integer overflow in unpack200 in Java SE Development Kit (JDK) and Java Runtime Environment (JRE) 5.0 Update 17 and earlier, and 6 Update 12 and earlier, allows remote attackers to access files or execute arbitrary code via a JAR file with crafted Pack200 headers.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-254570-1" source="SUNALERT" patch="1" adv="1">254570</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-21-125137-14-1" source="MISC" patch="1">http://sunsolve.sun.com/search/document.do?assetkey=1-21-125137-14-1</ref>
      <ref url="https://rhn.redhat.com/errata/RHSA-2009-1198.html" source="REDHAT">RHSA-2009:1198</ref>
      <ref url="https://rhn.redhat.com/errata/RHSA-2009-0377.html" source="REDHAT">RHSA-2009:0377</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/3316" source="VUPEN">ADV-2009-3316</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1426" source="VUPEN">ADV-2009-1426</ref>
      <ref url="http://www.vmware.com/security/advisories/VMSA-2009-0016.html" source="CONFIRM">http://www.vmware.com/security/advisories/VMSA-2009-0016.html</ref>
      <ref url="http://www.ubuntu.com/usn/usn-748-1" source="UBUNTU">USN-748-1</ref>
      <ref url="http://www.securitytracker.com/id?1021894" source="SECTRACK">1021894</ref>
      <ref url="http://www.securityfocus.com/bid/34240" source="BID">34240</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/507985/100/0/threaded" source="BUGTRAQ">20091120 VMSA-2009-0016 VMware vCenter and ESX update release and vMA patch release address multiple security issue in third party components</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-1038.html" source="REDHAT">RHSA-2009:1038</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-0394.html" source="REDHAT">RHSA-2009:0394</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-0392.html" source="REDHAT">RHSA-2009:0392</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujul2009.html" source="CONFIRM">http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujul2009.html</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:162" source="MANDRIVA">MDVSA-2009:162</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:137" source="MANDRIVA">MDVSA-2009:137</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1769" source="DEBIAN">DSA-1769</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2009-109.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2009-109.htm</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2009-108.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2009-108.htm</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-77-1020225.1-1" source="SUNALERT">1020225</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200911-02.xml" source="GENTOO">GLSA-200911-02</ref>
      <ref url="http://secunia.com/advisories/37460" source="SECUNIA">37460</ref>
      <ref url="http://secunia.com/advisories/37386" source="SECUNIA">37386</ref>
      <ref url="http://secunia.com/advisories/36185" source="SECUNIA">36185</ref>
      <ref url="http://secunia.com/advisories/35776" source="SECUNIA">35776</ref>
      <ref url="http://secunia.com/advisories/35416" source="SECUNIA">35416</ref>
      <ref url="http://secunia.com/advisories/35255" source="SECUNIA">35255</ref>
      <ref url="http://secunia.com/advisories/35223" source="SECUNIA">35223</ref>
      <ref url="http://secunia.com/advisories/35156" source="SECUNIA">35156</ref>
      <ref url="http://secunia.com/advisories/34675" source="SECUNIA">34675</ref>
      <ref url="http://secunia.com/advisories/34632" source="SECUNIA">34632</ref>
      <ref url="http://secunia.com/advisories/34496" source="SECUNIA">34496</ref>
      <ref url="http://secunia.com/advisories/34495" source="SECUNIA">34495</ref>
      <ref url="http://secunia.com/advisories/34489" source="SECUNIA">34489</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6643" source="OVAL">oval:org.mitre.oval:def:6643</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10124" source="OVAL">oval:org.mitre.oval:def:10124</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=124344236532162&amp;w=2" source="HP">HPSBUX02429</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-07/msg00001.html" source="SUSE">SUSE-SA:2009:036</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-06/msg00003.html" source="SUSE">SUSE-SR:2009:011</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-05/msg00003.html" source="SUSE">SUSE-SA:2009:029</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-04/msg00001.html" source="SUSE">SUSE-SA:2009:016</ref>
      <ref url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=781" source="IDEFENSE">20090326 Sun Java Runtime Environment (JRE) Pack200 Decompression Integer Overflow Vulnerability</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&amp;cc=us&amp;objectID=c01745133" source="HP">SSRT090058</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&amp;cc=us&amp;objectID=c01745133" source="HP">SSRT090058</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="jdk">
        <vers prev="1" num="5.0" edition="update_1" />
        <vers prev="1" num="5.0" edition="update_10" />
        <vers prev="1" num="5.0" edition="update_11" />
        <vers prev="1" num="5.0" edition="update_12" />
        <vers prev="1" num="5.0" edition="update_13" />
        <vers prev="1" num="5.0" edition="update_14" />
        <vers prev="1" num="5.0" edition="update_15" />
        <vers prev="1" num="5.0" edition="update_16" />
        <vers prev="1" num="5.0" edition="update_17" />
        <vers prev="1" num="5.0" edition="update_2" />
        <vers prev="1" num="5.0" edition="update_3" />
        <vers prev="1" num="5.0" edition="update_4" />
        <vers prev="1" num="5.0" edition="update_5" />
        <vers prev="1" num="5.0" edition="update_6" />
        <vers prev="1" num="5.0" edition="update_7" />
        <vers prev="1" num="5.0" edition="update_8" />
        <vers prev="1" num="5.0" edition="update_9" />
        <vers prev="1" num="6" edition="update_1" />
        <vers prev="1" num="6" edition="update_10" />
        <vers prev="1" num="6" edition="update_11" />
        <vers prev="1" num="6" edition="update_12" />
        <vers prev="1" num="6" edition="update_2" />
        <vers prev="1" num="6" edition="update_3" />
        <vers prev="1" num="6" edition="update_4" />
        <vers prev="1" num="6" edition="update_5" />
        <vers prev="1" num="6" edition="update_6" />
        <vers prev="1" num="6" edition="update_7" />
        <vers prev="1" num="6" edition="update_8" />
        <vers prev="1" num="6" edition="update_9" />
      </prod>
      <prod vendor="sun" name="jre">
        <vers prev="1" num="5.0" edition="update_1" />
        <vers prev="1" num="5.0" edition="update_10" />
        <vers prev="1" num="5.0" edition="update_11" />
        <vers prev="1" num="5.0" edition="update_12" />
        <vers prev="1" num="5.0" edition="update_13" />
        <vers prev="1" num="5.0" edition="update_14" />
        <vers prev="1" num="5.0" edition="update_15" />
        <vers prev="1" num="5.0" edition="update_16" />
        <vers prev="1" num="5.0" edition="update_17" />
        <vers prev="1" num="5.0" edition="update_2" />
        <vers prev="1" num="5.0" edition="update_3" />
        <vers prev="1" num="5.0" edition="update_4" />
        <vers prev="1" num="5.0" edition="update_5" />
        <vers prev="1" num="5.0" edition="update_5:" />
        <vers prev="1" num="5.0" edition="update_5::windows" />
        <vers prev="1" num="5.0" edition="update_5::linux" />
        <vers prev="1" num="5.0" edition="update_5::solaris" />
        <vers prev="1" num="5.0" edition="update_6" />
        <vers prev="1" num="5.0" edition="update_6:" />
        <vers prev="1" num="5.0" edition="update_6::windows" />
        <vers prev="1" num="5.0" edition="update_6::solaris" />
        <vers prev="1" num="5.0" edition="update_6::linux" />
        <vers prev="1" num="5.0" edition="update_7" />
        <vers prev="1" num="5.0" edition="update_7:" />
        <vers prev="1" num="5.0" edition="update_7::linux" />
        <vers prev="1" num="5.0" edition="update_7::windows" />
        <vers prev="1" num="5.0" edition="update_7::solaris" />
        <vers prev="1" num="5.0" edition="update_8" />
        <vers prev="1" num="5.0" edition="update_8:" />
        <vers prev="1" num="5.0" edition="update_8::solaris" />
        <vers prev="1" num="5.0" edition="update_8::linux" />
        <vers prev="1" num="5.0" edition="update_8::windows" />
        <vers prev="1" num="5.0" edition="update_9" />
        <vers prev="1" num="5.0" edition="update_9:" />
        <vers prev="1" num="5.0" edition="update_9::linux" />
        <vers prev="1" num="5.0" edition="update_9::solaris" />
        <vers prev="1" num="5.0" edition="update_9::windows" />
        <vers prev="1" num="6" edition="update_1" />
        <vers prev="1" num="6" edition="update_10" />
        <vers prev="1" num="6" edition="update_11" />
        <vers prev="1" num="6" edition="update_12" />
        <vers prev="1" num="6" edition="update_2" />
        <vers prev="1" num="6" edition="update_3" />
        <vers prev="1" num="6" edition="update_4" />
        <vers prev="1" num="6" edition="update_5" />
        <vers prev="1" num="6" edition="update_6" />
        <vers prev="1" num="6" edition="update_7" />
        <vers prev="1" num="6" edition="update_8" />
        <vers prev="1" num="6" edition="update_9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1096" published="2009-03-25" name="CVE-2009-1096" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in unpack200 in Java SE Development Kit (JDK) and Java Runtime Environment (JRE) 5.0 Update 17 and earlier, and 6 Update 12 and earlier, allows remote attackers to access files or execute arbitrary code via a JAR file with crafted Pack200 headers.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-254570-1" source="SUNALERT" patch="1" adv="1">254570</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-21-125137-14-1" source="MISC" patch="1">http://sunsolve.sun.com/search/document.do?assetkey=1-21-125137-14-1</ref>
      <ref url="https://rhn.redhat.com/errata/RHSA-2009-1198.html" source="REDHAT">RHSA-2009:1198</ref>
      <ref url="https://rhn.redhat.com/errata/RHSA-2009-0377.html" source="REDHAT">RHSA-2009:0377</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/3316" source="VUPEN">ADV-2009-3316</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1426" source="VUPEN">ADV-2009-1426</ref>
      <ref url="http://www.vmware.com/security/advisories/VMSA-2009-0016.html" source="CONFIRM">http://www.vmware.com/security/advisories/VMSA-2009-0016.html</ref>
      <ref url="http://www.ubuntu.com/usn/usn-748-1" source="UBUNTU">USN-748-1</ref>
      <ref url="http://www.securitytracker.com/id?1021894" source="SECTRACK">1021894</ref>
      <ref url="http://www.securityfocus.com/bid/34240" source="BID">34240</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/507985/100/0/threaded" source="BUGTRAQ">20091120 VMSA-2009-0016 VMware vCenter and ESX update release and vMA patch release address multiple security issue in third party components</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-1038.html" source="REDHAT">RHSA-2009:1038</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-0394.html" source="REDHAT">RHSA-2009:0394</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-0392.html" source="REDHAT">RHSA-2009:0392</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:162" source="MANDRIVA">MDVSA-2009:162</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:137" source="MANDRIVA">MDVSA-2009:137</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1769" source="DEBIAN">DSA-1769</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2009-109.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2009-109.htm</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2009-108.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2009-108.htm</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-77-1020225.1-1" source="SUNALERT">1020225</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200911-02.xml" source="GENTOO">GLSA-200911-02</ref>
      <ref url="http://secunia.com/advisories/37460" source="SECUNIA">37460</ref>
      <ref url="http://secunia.com/advisories/37386" source="SECUNIA">37386</ref>
      <ref url="http://secunia.com/advisories/36185" source="SECUNIA">36185</ref>
      <ref url="http://secunia.com/advisories/35416" source="SECUNIA">35416</ref>
      <ref url="http://secunia.com/advisories/35255" source="SECUNIA">35255</ref>
      <ref url="http://secunia.com/advisories/35223" source="SECUNIA">35223</ref>
      <ref url="http://secunia.com/advisories/35156" source="SECUNIA">35156</ref>
      <ref url="http://secunia.com/advisories/34675" source="SECUNIA">34675</ref>
      <ref url="http://secunia.com/advisories/34632" source="SECUNIA">34632</ref>
      <ref url="http://secunia.com/advisories/34496" source="SECUNIA">34496</ref>
      <ref url="http://secunia.com/advisories/34495" source="SECUNIA">34495</ref>
      <ref url="http://secunia.com/advisories/34489" source="SECUNIA">34489</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:8844" source="OVAL">oval:org.mitre.oval:def:8844</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6659" source="OVAL">oval:org.mitre.oval:def:6659</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=124344236532162&amp;w=2" source="HP">HPSBUX02429</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-07/msg00001.html" source="SUSE">SUSE-SA:2009:036</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-06/msg00003.html" source="SUSE">SUSE-SR:2009:011</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-05/msg00003.html" source="SUSE">SUSE-SA:2009:029</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-04/msg00001.html" source="SUSE">SUSE-SA:2009:016</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&amp;cc=us&amp;objectID=c01745133" source="HP">HPSBMA02429</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&amp;cc=us&amp;objectID=c01745133" source="HP">HPSBMA02429</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="jdk">
        <vers prev="1" num="5.0" edition="update_1" />
        <vers prev="1" num="5.0" edition="update_10" />
        <vers prev="1" num="5.0" edition="update_11" />
        <vers prev="1" num="5.0" edition="update_12" />
        <vers prev="1" num="5.0" edition="update_13" />
        <vers prev="1" num="5.0" edition="update_14" />
        <vers prev="1" num="5.0" edition="update_15" />
        <vers prev="1" num="5.0" edition="update_16" />
        <vers prev="1" num="5.0" edition="update_17" />
        <vers prev="1" num="5.0" edition="update_2" />
        <vers prev="1" num="5.0" edition="update_3" />
        <vers prev="1" num="5.0" edition="update_4" />
        <vers prev="1" num="5.0" edition="update_5" />
        <vers prev="1" num="5.0" edition="update_6" />
        <vers prev="1" num="5.0" edition="update_7" />
        <vers prev="1" num="5.0" edition="update_8" />
        <vers prev="1" num="5.0" edition="update_9" />
        <vers prev="1" num="6" edition="update_1" />
        <vers prev="1" num="6" edition="update_10" />
        <vers prev="1" num="6" edition="update_11" />
        <vers prev="1" num="6" edition="update_12" />
        <vers prev="1" num="6" edition="update_2" />
        <vers prev="1" num="6" edition="update_3" />
        <vers prev="1" num="6" edition="update_4" />
        <vers prev="1" num="6" edition="update_5" />
        <vers prev="1" num="6" edition="update_6" />
        <vers prev="1" num="6" edition="update_7" />
        <vers prev="1" num="6" edition="update_8" />
        <vers prev="1" num="6" edition="update_9" />
      </prod>
      <prod vendor="sun" name="jre">
        <vers prev="1" num="5.0" edition="update_1" />
        <vers prev="1" num="5.0" edition="update_10" />
        <vers prev="1" num="5.0" edition="update_11" />
        <vers prev="1" num="5.0" edition="update_12" />
        <vers prev="1" num="5.0" edition="update_13" />
        <vers prev="1" num="5.0" edition="update_14" />
        <vers prev="1" num="5.0" edition="update_15" />
        <vers prev="1" num="5.0" edition="update_16" />
        <vers prev="1" num="5.0" edition="update_17" />
        <vers prev="1" num="5.0" edition="update_2" />
        <vers prev="1" num="5.0" edition="update_3" />
        <vers prev="1" num="5.0" edition="update_4" />
        <vers prev="1" num="5.0" edition="update_5" />
        <vers prev="1" num="5.0" edition="update_6" />
        <vers prev="1" num="5.0" edition="update_7" />
        <vers prev="1" num="5.0" edition="update_8" />
        <vers prev="1" num="5.0" edition="update_9" />
        <vers prev="1" num="6" edition="update_1" />
        <vers prev="1" num="6" edition="update_10" />
        <vers prev="1" num="6" edition="update_11" />
        <vers prev="1" num="6" edition="update_12" />
        <vers prev="1" num="6" edition="update_2" />
        <vers prev="1" num="6" edition="update_3" />
        <vers prev="1" num="6" edition="update_4" />
        <vers prev="1" num="6" edition="update_5" />
        <vers prev="1" num="6" edition="update_6" />
        <vers prev="1" num="6" edition="update_7" />
        <vers prev="1" num="6" edition="update_8" />
        <vers prev="1" num="6" edition="update_9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1097" published="2009-03-25" name="CVE-2009-1097" modified="2011-12-29" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple buffer overflows in Java SE Development Kit (JDK) and Java Runtime Environment (JRE) 6 Update 12 and earlier allow remote attackers to access files or execute arbitrary code via (1) a crafted PNG image that triggers an integer overflow during memory allocation for display on the splash screen, aka CR 6804996; and (2) a crafted GIF image from which unspecified values are used in calculation of offsets, leading to object-pointer corruption, aka CR 6804997.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-254571-1" source="SUNALERT" patch="1" adv="1">254571</ref>
      <ref url="https://rhn.redhat.com/errata/RHSA-2009-1198.html" source="REDHAT">RHSA-2009:1198</ref>
      <ref url="https://rhn.redhat.com/errata/RHSA-2009-0377.html" source="REDHAT">RHSA-2009:0377</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/49475" source="XF">jre-gif-file-bo(49475)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/3316" source="VUPEN" adv="1">ADV-2009-3316</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1426" source="VUPEN" adv="1">ADV-2009-1426</ref>
      <ref url="http://www.vmware.com/security/advisories/VMSA-2009-0016.html" source="CONFIRM">http://www.vmware.com/security/advisories/VMSA-2009-0016.html</ref>
      <ref url="http://www.ubuntu.com/usn/usn-748-1" source="UBUNTU">USN-748-1</ref>
      <ref url="http://www.securitytracker.com/id?1021913" source="SECTRACK">1021913</ref>
      <ref url="http://www.securityfocus.com/bid/34240" source="BID">34240</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/507985/100/0/threaded" source="BUGTRAQ">20091120 VMSA-2009-0016 VMware vCenter and ESX update release and vMA patch release address multiple security issue in third party components</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-1038.html" source="REDHAT">RHSA-2009:1038</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-0392.html" source="REDHAT">RHSA-2009:0392</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujul2009.html" source="CONFIRM">http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujul2009.html</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:162" source="MANDRIVA">MDVSA-2009:162</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:137" source="MANDRIVA">MDVSA-2009:137</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1769" source="DEBIAN">DSA-1769</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2009-108.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2009-108.htm</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200911-02.xml" source="GENTOO">GLSA-200911-02</ref>
      <ref url="http://secunia.com/advisories/37460" source="SECUNIA" adv="1">37460</ref>
      <ref url="http://secunia.com/advisories/37386" source="SECUNIA" adv="1">37386</ref>
      <ref url="http://secunia.com/advisories/36185" source="SECUNIA" adv="1">36185</ref>
      <ref url="http://secunia.com/advisories/35776" source="SECUNIA" adv="1">35776</ref>
      <ref url="http://secunia.com/advisories/35255" source="SECUNIA" adv="1">35255</ref>
      <ref url="http://secunia.com/advisories/35223" source="SECUNIA" adv="1">35223</ref>
      <ref url="http://secunia.com/advisories/35156" source="SECUNIA" adv="1">35156</ref>
      <ref url="http://secunia.com/advisories/34675" source="SECUNIA" adv="1">34675</ref>
      <ref url="http://secunia.com/advisories/34632" source="SECUNIA" adv="1">34632</ref>
      <ref url="http://secunia.com/advisories/34496" source="SECUNIA" adv="1">34496</ref>
      <ref url="http://secunia.com/advisories/34489" source="SECUNIA" adv="1">34489</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6288" source="OVAL">oval:org.mitre.oval:def:6288</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11241" source="OVAL">oval:org.mitre.oval:def:11241</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=124344236532162&amp;w=2" source="HP">HPSBUX02429</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-07/msg00001.html" source="SUSE">SUSE-SA:2009:036</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-05/msg00003.html" source="SUSE">SUSE-SA:2009:029</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-04/msg00001.html" source="SUSE">SUSE-SA:2009:016</ref>
      <ref url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=780" source="IDEFENSE">20090326 Sun Java Web Start (JWS ) PNG Decoding Integer Overflow Vulnerability</ref>
      <ref url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=779" source="IDEFENSE">20090326 Sun Java Runtine Environment (JRE) GIF Decoding Heap Corruption Vulnerability</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&amp;cc=us&amp;objectID=c01745133" source="HP">HPSBMA02429</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&amp;cc=us&amp;objectID=c01745133" source="HP">HPSBMA02429</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="jdk">
        <vers prev="1" num="6" edition="update_1" />
        <vers prev="1" num="6" edition="update_10" />
        <vers prev="1" num="6" edition="update_11" />
        <vers prev="1" num="6" edition="update_12" />
        <vers prev="1" num="6" edition="update_2" />
        <vers prev="1" num="6" edition="update_3" />
        <vers prev="1" num="6" edition="update_4" />
        <vers prev="1" num="6" edition="update_5" />
        <vers prev="1" num="6" edition="update_6" />
        <vers prev="1" num="6" edition="update_7" />
        <vers prev="1" num="6" edition="update_8" />
        <vers prev="1" num="6" edition="update_9" />
      </prod>
      <prod vendor="sun" name="jre">
        <vers prev="1" num="6" edition="update_1" />
        <vers prev="1" num="6" edition="update_10" />
        <vers prev="1" num="6" edition="update_11" />
        <vers prev="1" num="6" edition="update_12" />
        <vers prev="1" num="6" edition="update_2" />
        <vers prev="1" num="6" edition="update_3" />
        <vers prev="1" num="6" edition="update_4" />
        <vers prev="1" num="6" edition="update_5" />
        <vers prev="1" num="6" edition="update_6" />
        <vers prev="1" num="6" edition="update_7" />
        <vers prev="1" num="6" edition="update_8" />
        <vers prev="1" num="6" edition="update_9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1098" published="2009-03-25" name="CVE-2009-1098" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in Java SE Development Kit (JDK) and Java Runtime Environment (JRE) 5.0 Update 17 and earlier; 6 Update 12 and earlier; 1.4.2_19 and earlier; and 1.3.1_24 and earlier allows remote attackers to access files or execute arbitrary code via a crafted GIF image, aka CR 6804998.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-254571-1" source="SUNALERT" patch="1" adv="1">254571</ref>
      <ref url="https://rhn.redhat.com/errata/RHSA-2009-1198.html" source="REDHAT">RHSA-2009:1198</ref>
      <ref url="https://rhn.redhat.com/errata/RHSA-2009-0377.html" source="REDHAT">RHSA-2009:0377</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/3316" source="VUPEN">ADV-2009-3316</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1426" source="VUPEN">ADV-2009-1426</ref>
      <ref url="http://www.vmware.com/security/advisories/VMSA-2009-0016.html" source="CONFIRM">http://www.vmware.com/security/advisories/VMSA-2009-0016.html</ref>
      <ref url="http://www.ubuntu.com/usn/usn-748-1" source="UBUNTU">USN-748-1</ref>
      <ref url="http://www.securitytracker.com/id?1021913" source="SECTRACK">1021913</ref>
      <ref url="http://www.securityfocus.com/bid/34240" source="BID">34240</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/507985/100/0/threaded" source="BUGTRAQ">20091120 VMSA-2009-0016 VMware vCenter and ESX update release and vMA patch release address multiple security issue in third party components</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-1038.html" source="REDHAT">RHSA-2009:1038</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-0394.html" source="REDHAT">RHSA-2009:0394</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-0392.html" source="REDHAT">RHSA-2009:0392</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujul2009.html" source="CONFIRM">http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujul2009.html</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:162" source="MANDRIVA">MDVSA-2009:162</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:137" source="MANDRIVA">MDVSA-2009:137</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1769" source="DEBIAN">DSA-1769</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2009-109.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2009-109.htm</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2009-108.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2009-108.htm</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200911-02.xml" source="GENTOO">GLSA-200911-02</ref>
      <ref url="http://secunia.com/advisories/37460" source="SECUNIA">37460</ref>
      <ref url="http://secunia.com/advisories/37386" source="SECUNIA">37386</ref>
      <ref url="http://secunia.com/advisories/36185" source="SECUNIA">36185</ref>
      <ref url="http://secunia.com/advisories/35776" source="SECUNIA">35776</ref>
      <ref url="http://secunia.com/advisories/35416" source="SECUNIA">35416</ref>
      <ref url="http://secunia.com/advisories/35255" source="SECUNIA">35255</ref>
      <ref url="http://secunia.com/advisories/35223" source="SECUNIA">35223</ref>
      <ref url="http://secunia.com/advisories/35156" source="SECUNIA">35156</ref>
      <ref url="http://secunia.com/advisories/34675" source="SECUNIA">34675</ref>
      <ref url="http://secunia.com/advisories/34632" source="SECUNIA">34632</ref>
      <ref url="http://secunia.com/advisories/34496" source="SECUNIA">34496</ref>
      <ref url="http://secunia.com/advisories/34495" source="SECUNIA">34495</ref>
      <ref url="http://secunia.com/advisories/34489" source="SECUNIA">34489</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9956" source="OVAL">oval:org.mitre.oval:def:9956</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6008" source="OVAL">oval:org.mitre.oval:def:6008</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=124344236532162&amp;w=2" source="HP">HPSBUX02429</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-07/msg00001.html" source="SUSE">SUSE-SA:2009:036</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-06/msg00003.html" source="SUSE">SUSE-SR:2009:011</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-05/msg00003.html" source="SUSE">SUSE-SA:2009:029</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-04/msg00001.html" source="SUSE">SUSE-SA:2009:016</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&amp;cc=us&amp;objectID=c01745133" source="HP">SSRT090058</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&amp;cc=us&amp;objectID=c01745133" source="HP">SSRT090058</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="jdk">
        <vers num="1.4.0" />
        <vers num="1.4.0_01" />
        <vers num="1.4.0_02" />
        <vers num="1.4.0_03" />
        <vers num="1.4.0_04" />
        <vers num="1.4.1" />
        <vers num="1.4.1_01" />
        <vers num="1.4.1_02" />
        <vers num="1.4.1_03" />
        <vers num="1.4.1_04" />
        <vers num="1.4.1_05" />
        <vers num="1.4.1_06" />
        <vers num="1.4.1_07" />
        <vers num="1.4.2" />
        <vers num="1.4.2_1" />
        <vers num="1.4.2_10" />
        <vers num="1.4.2_11" />
        <vers num="1.4.2_12" />
        <vers num="1.4.2_13" />
        <vers num="1.4.2_14" />
        <vers num="1.4.2_15" />
        <vers num="1.4.2_16" />
        <vers num="1.4.2_17" />
        <vers num="1.4.2_18" />
        <vers prev="1" num="1.4.2_19" />
        <vers num="1.4.2_2" />
        <vers num="1.4.2_3" />
        <vers num="1.4.2_4" />
        <vers num="1.4.2_5" />
        <vers num="1.4.2_6" />
        <vers num="1.4.2_7" />
        <vers num="1.4.2_8" />
        <vers num="1.4.2_9" />
        <vers prev="1" num="5.0" edition="update_1" />
        <vers prev="1" num="5.0" edition="update_10" />
        <vers prev="1" num="5.0" edition="update_11" />
        <vers prev="1" num="5.0" edition="update_12" />
        <vers prev="1" num="5.0" edition="update_13" />
        <vers prev="1" num="5.0" edition="update_14" />
        <vers prev="1" num="5.0" edition="update_15" />
        <vers prev="1" num="5.0" edition="update_16" />
        <vers prev="1" num="5.0" edition="update_17" />
        <vers prev="1" num="5.0" edition="update_2" />
        <vers prev="1" num="5.0" edition="update_3" />
        <vers prev="1" num="5.0" edition="update_4" />
        <vers prev="1" num="5.0" edition="update_5" />
        <vers prev="1" num="5.0" edition="update_6" />
        <vers prev="1" num="5.0" edition="update_7" />
        <vers prev="1" num="5.0" edition="update_8" />
        <vers prev="1" num="5.0" edition="update_9" />
        <vers prev="1" num="6" edition="update_1" />
        <vers prev="1" num="6" edition="update_10" />
        <vers prev="1" num="6" edition="update_11" />
        <vers prev="1" num="6" edition="update_12" />
        <vers prev="1" num="6" edition="update_2" />
        <vers prev="1" num="6" edition="update_3" />
        <vers prev="1" num="6" edition="update_4" />
        <vers prev="1" num="6" edition="update_5" />
        <vers prev="1" num="6" edition="update_6" />
        <vers prev="1" num="6" edition="update_7" />
      </prod>
      <prod vendor="sun" name="jre">
        <vers num="1.4.0" />
        <vers num="1.4.0_01" />
        <vers num="1.4.0_02" />
        <vers num="1.4.0_03" />
        <vers num="1.4.0_04" />
        <vers num="1.4.1" />
        <vers num="1.4.1_01" />
        <vers num="1.4.1_02" />
        <vers num="1.4.1_03" />
        <vers num="1.4.1_04" />
        <vers num="1.4.1_05" />
        <vers num="1.4.1_06" />
        <vers num="1.4.1_07" />
        <vers num="1.4.2" />
        <vers num="1.4.2_01" />
        <vers num="1.4.2_02" />
        <vers num="1.4.2_03" />
        <vers num="1.4.2_04" />
        <vers num="1.4.2_05" />
        <vers num="1.4.2_06" />
        <vers num="1.4.2_07" />
        <vers num="1.4.2_08" />
        <vers num="1.4.2_09" />
        <vers num="1.4.2_10" />
        <vers num="1.4.2_11" />
        <vers num="1.4.2_12" />
        <vers num="1.4.2_13" />
        <vers num="1.4.2_14" />
        <vers num="1.4.2_15" />
        <vers num="1.4.2_16" />
        <vers num="1.4.2_17" />
        <vers num="1.4.2_18" />
        <vers prev="1" num="1.4.2_19" />
        <vers prev="1" num="5.0" edition="update_1" />
        <vers prev="1" num="5.0" edition="update_10" />
        <vers prev="1" num="5.0" edition="update_11" />
        <vers prev="1" num="5.0" edition="update_12" />
        <vers prev="1" num="5.0" edition="update_13" />
        <vers prev="1" num="5.0" edition="update_14" />
        <vers prev="1" num="5.0" edition="update_15" />
        <vers prev="1" num="5.0" edition="update_16" />
        <vers prev="1" num="5.0" edition="update_17" />
        <vers prev="1" num="5.0" edition="update_2" />
        <vers prev="1" num="5.0" edition="update_3" />
        <vers prev="1" num="5.0" edition="update_4" />
        <vers prev="1" num="5.0" edition="update_5" />
        <vers prev="1" num="5.0" edition="update_6" />
        <vers prev="1" num="5.0" edition="update_7" />
        <vers prev="1" num="5.0" edition="update_8" />
        <vers prev="1" num="5.0" edition="update_9" />
        <vers prev="1" num="6" edition="update_1" />
        <vers prev="1" num="6" edition="update_10" />
        <vers prev="1" num="6" edition="update_11" />
        <vers prev="1" num="6" edition="update_12" />
        <vers prev="1" num="6" edition="update_2" />
        <vers prev="1" num="6" edition="update_3" />
        <vers prev="1" num="6" edition="update_4" />
        <vers prev="1" num="6" edition="update_5" />
        <vers prev="1" num="6" edition="update_6" />
        <vers prev="1" num="6" edition="update_7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1099" published="2009-03-25" name="CVE-2009-1099" modified="2012-01-06" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Integer signedness error in Java SE Development Kit (JDK) and Java Runtime Environment (JRE) 5.0 Update 17 and earlier, and 6 Update 12 and earlier, allows remote attackers to access files or execute arbitrary code via crafted glyph descriptions in a Type1 font, which bypasses a signed comparison and triggers a buffer overflow.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-254571-1" source="SUNALERT" patch="1" adv="1">254571</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-21-118669-19-1" source="MISC" patch="1" adv="1">http://sunsolve.sun.com/search/document.do?assetkey=1-21-118669-19-1</ref>
      <ref url="https://rhn.redhat.com/errata/RHSA-2009-1198.html" source="REDHAT">RHSA-2009:1198</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/3316" source="VUPEN" adv="1">ADV-2009-3316</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1426" source="VUPEN" adv="1">ADV-2009-1426</ref>
      <ref url="http://www.vmware.com/security/advisories/VMSA-2009-0016.html" source="CONFIRM">http://www.vmware.com/security/advisories/VMSA-2009-0016.html</ref>
      <ref url="http://www.securitytracker.com/id?1021913" source="SECTRACK">1021913</ref>
      <ref url="http://www.securityfocus.com/bid/34240" source="BID">34240</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/507985/100/0/threaded" source="BUGTRAQ">20091120 VMSA-2009-0016 VMware vCenter and ESX update release and vMA patch release address multiple security issue in third party components</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-1038.html" source="REDHAT">RHSA-2009:1038</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-0394.html" source="REDHAT">RHSA-2009:0394</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-0392.html" source="REDHAT">RHSA-2009:0392</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujul2009.html" source="CONFIRM">http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujul2009.html</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2009-109.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2009-109.htm</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2009-108.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2009-108.htm</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200911-02.xml" source="GENTOO">GLSA-200911-02</ref>
      <ref url="http://secunia.com/advisories/37460" source="SECUNIA" adv="1">37460</ref>
      <ref url="http://secunia.com/advisories/37386" source="SECUNIA" adv="1">37386</ref>
      <ref url="http://secunia.com/advisories/36185" source="SECUNIA" adv="1">36185</ref>
      <ref url="http://secunia.com/advisories/35776" source="SECUNIA" adv="1">35776</ref>
      <ref url="http://secunia.com/advisories/35416" source="SECUNIA" adv="1">35416</ref>
      <ref url="http://secunia.com/advisories/35255" source="SECUNIA" adv="1">35255</ref>
      <ref url="http://secunia.com/advisories/35223" source="SECUNIA" adv="1">35223</ref>
      <ref url="http://secunia.com/advisories/35156" source="SECUNIA" adv="1">35156</ref>
      <ref url="http://secunia.com/advisories/34496" source="SECUNIA" adv="1">34496</ref>
      <ref url="http://secunia.com/advisories/34495" source="SECUNIA" adv="1">34495</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5726" source="OVAL">oval:org.mitre.oval:def:5726</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=124344236532162&amp;w=2" source="HP">HPSBUX02429</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-07/msg00001.html" source="SUSE">SUSE-SA:2009:036</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-06/msg00003.html" source="SUSE">SUSE-SR:2009:011</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-05/msg00003.html" source="SUSE">SUSE-SA:2009:029</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-04/msg00001.html" source="SUSE">SUSE-SA:2009:016</ref>
      <ref url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=777" source="IDEFENSE">20090326 Sun Java Runtine Environment (JRE) Type1 Font Parsing Integer Signedness Vulnerability</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&amp;cc=us&amp;objectID=c01745133" source="HP">HPSBMA02429</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&amp;cc=us&amp;objectID=c01745133" source="HP">HPSBMA02429</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="java_runtime_environment">
        <vers num="5.0" edition="" />
        <vers num="5.0" edition=":17" />
        <vers num="6.0" edition="" />
        <vers num="6.0" edition=":12" />
      </prod>
      <prod vendor="sun" name="java_se_development_kit">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1100" published="2009-03-25" name="CVE-2009-1100" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Multiple unspecified vulnerabilities in Java SE Development Kit (JDK) and Java Runtime Environment (JRE) 5.0 Update 17 and earlier, and 6 Update 12 and earlier, allow remote attackers to cause a denial of service (disk consumption) via vectors related to temporary font files and (1) "limits on Font creation," aka CR 6522586, and (2) another unspecified vector, aka CR 6632886.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-254608-1" source="SUNALERT" patch="1" adv="1">254608</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-21-118667-19-1" source="MISC" patch="1">http://sunsolve.sun.com/search/document.do?assetkey=1-21-118667-19-1</ref>
      <ref url="https://rhn.redhat.com/errata/RHSA-2009-1198.html" source="REDHAT">RHSA-2009:1198</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/3316" source="VUPEN">ADV-2009-3316</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1426" source="VUPEN">ADV-2009-1426</ref>
      <ref url="http://www.vmware.com/security/advisories/VMSA-2009-0016.html" source="CONFIRM">http://www.vmware.com/security/advisories/VMSA-2009-0016.html</ref>
      <ref url="http://www.ubuntu.com/usn/usn-748-1" source="UBUNTU">USN-748-1</ref>
      <ref url="http://www.securitytracker.com/id?1021917" source="SECTRACK">1021917</ref>
      <ref url="http://www.securityfocus.com/bid/34240" source="BID">34240</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/507985/100/0/threaded" source="BUGTRAQ">20091120 VMSA-2009-0016 VMware vCenter and ESX update release and vMA patch release address multiple security issue in third party components</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-1038.html" source="REDHAT">RHSA-2009:1038</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-0394.html" source="REDHAT">RHSA-2009:0394</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-0392.html" source="REDHAT">RHSA-2009:0392</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujul2009.html" source="CONFIRM">http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujul2009.html</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2009-109.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2009-109.htm</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2009-108.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2009-108.htm</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200911-02.xml" source="GENTOO">GLSA-200911-02</ref>
      <ref url="http://secunia.com/advisories/37460" source="SECUNIA">37460</ref>
      <ref url="http://secunia.com/advisories/37386" source="SECUNIA">37386</ref>
      <ref url="http://secunia.com/advisories/36185" source="SECUNIA">36185</ref>
      <ref url="http://secunia.com/advisories/35776" source="SECUNIA">35776</ref>
      <ref url="http://secunia.com/advisories/35416" source="SECUNIA">35416</ref>
      <ref url="http://secunia.com/advisories/35255" source="SECUNIA">35255</ref>
      <ref url="http://secunia.com/advisories/35223" source="SECUNIA">35223</ref>
      <ref url="http://secunia.com/advisories/35156" source="SECUNIA">35156</ref>
      <ref url="http://secunia.com/advisories/34496" source="SECUNIA">34496</ref>
      <ref url="http://secunia.com/advisories/34495" source="SECUNIA">34495</ref>
      <ref url="http://secunia.com/advisories/34489" source="SECUNIA">34489</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6224" source="OVAL">oval:org.mitre.oval:def:6224</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=124344236532162&amp;w=2" source="HP">HPSBUX02429</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-07/msg00001.html" source="SUSE">SUSE-SA:2009:036</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-06/msg00003.html" source="SUSE">SUSE-SR:2009:011</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-05/msg00003.html" source="SUSE">SUSE-SA:2009:029</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-04/msg00001.html" source="SUSE">SUSE-SA:2009:016</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&amp;cc=us&amp;objectID=c01745133" source="HP">HPSBMA02429</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&amp;cc=us&amp;objectID=c01745133" source="HP">HPSBMA02429</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="jdk">
        <vers num="1.4.0" />
        <vers num="1.4.0_01" />
        <vers num="1.4.0_02" />
        <vers num="1.4.0_03" />
        <vers num="1.4.0_04" />
        <vers num="1.4.1" />
        <vers num="1.4.1_01" />
        <vers num="1.4.1_02" />
        <vers num="1.4.1_03" />
        <vers num="1.4.1_04" />
        <vers num="1.4.1_05" />
        <vers num="1.4.1_06" />
        <vers num="1.4.1_07" />
        <vers num="1.4.2" />
        <vers num="1.4.2_1" />
        <vers num="1.4.2_10" />
        <vers num="1.4.2_11" />
        <vers num="1.4.2_12" />
        <vers num="1.4.2_13" />
        <vers num="1.4.2_14" />
        <vers num="1.4.2_15" />
        <vers num="1.4.2_16" />
        <vers num="1.4.2_17" />
        <vers num="1.4.2_18" />
        <vers prev="1" num="1.4.2_19" />
        <vers num="1.4.2_2" />
        <vers num="1.4.2_3" />
        <vers num="1.4.2_4" />
        <vers num="1.4.2_5" />
        <vers num="1.4.2_6" />
        <vers num="1.4.2_7" />
        <vers num="1.4.2_8" />
        <vers num="1.4.2_9" />
        <vers prev="1" num="5.0" edition="update_1" />
        <vers prev="1" num="5.0" edition="update_10" />
        <vers prev="1" num="5.0" edition="update_11" />
        <vers prev="1" num="5.0" edition="update_12" />
        <vers prev="1" num="5.0" edition="update_13" />
        <vers prev="1" num="5.0" edition="update_14" />
        <vers prev="1" num="5.0" edition="update_15" />
        <vers prev="1" num="5.0" edition="update_16" />
        <vers prev="1" num="5.0" edition="update_17" />
        <vers prev="1" num="5.0" edition="update_2" />
        <vers prev="1" num="5.0" edition="update_3" />
        <vers prev="1" num="5.0" edition="update_4" />
        <vers prev="1" num="5.0" edition="update_5" />
        <vers prev="1" num="5.0" edition="update_6" />
        <vers prev="1" num="5.0" edition="update_7" />
        <vers prev="1" num="5.0" edition="update_8" />
        <vers prev="1" num="5.0" edition="update_9" />
        <vers prev="1" num="6" edition="update_1" />
        <vers prev="1" num="6" edition="update_10" />
        <vers prev="1" num="6" edition="update_11" />
        <vers prev="1" num="6" edition="update_12" />
        <vers prev="1" num="6" edition="update_2" />
        <vers prev="1" num="6" edition="update_3" />
        <vers prev="1" num="6" edition="update_4" />
        <vers prev="1" num="6" edition="update_5" />
        <vers prev="1" num="6" edition="update_6" />
        <vers prev="1" num="6" edition="update_7" />
      </prod>
      <prod vendor="sun" name="jre">
        <vers num="1.4.0" />
        <vers num="1.4.0_01" />
        <vers num="1.4.0_02" />
        <vers num="1.4.0_03" />
        <vers num="1.4.0_04" />
        <vers num="1.4.1" />
        <vers num="1.4.1_01" />
        <vers num="1.4.1_02" />
        <vers num="1.4.1_03" />
        <vers num="1.4.1_04" />
        <vers num="1.4.1_05" />
        <vers num="1.4.1_06" />
        <vers num="1.4.1_07" />
        <vers num="1.4.2" />
        <vers num="1.4.2_01" />
        <vers num="1.4.2_02" />
        <vers num="1.4.2_03" />
        <vers num="1.4.2_04" />
        <vers num="1.4.2_05" />
        <vers num="1.4.2_06" />
        <vers num="1.4.2_07" />
        <vers num="1.4.2_08" />
        <vers num="1.4.2_09" />
        <vers num="1.4.2_10" />
        <vers num="1.4.2_11" />
        <vers num="1.4.2_12" />
        <vers num="1.4.2_13" />
        <vers num="1.4.2_14" />
        <vers num="1.4.2_15" />
        <vers num="1.4.2_16" />
        <vers num="1.4.2_17" />
        <vers num="1.4.2_18" />
        <vers prev="1" num="1.4.2_19" />
        <vers prev="1" num="5.0" edition="update_1" />
        <vers prev="1" num="5.0" edition="update_10" />
        <vers prev="1" num="5.0" edition="update_11" />
        <vers prev="1" num="5.0" edition="update_12" />
        <vers prev="1" num="5.0" edition="update_13" />
        <vers prev="1" num="5.0" edition="update_14" />
        <vers prev="1" num="5.0" edition="update_15" />
        <vers prev="1" num="5.0" edition="update_16" />
        <vers prev="1" num="5.0" edition="update_17" />
        <vers prev="1" num="5.0" edition="update_2" />
        <vers prev="1" num="5.0" edition="update_3" />
        <vers prev="1" num="5.0" edition="update_4" />
        <vers prev="1" num="5.0" edition="update_5" />
        <vers prev="1" num="5.0" edition="update_6" />
        <vers prev="1" num="5.0" edition="update_7" />
        <vers prev="1" num="5.0" edition="update_8" />
        <vers prev="1" num="5.0" edition="update_9" />
        <vers prev="1" num="6" edition="update_1" />
        <vers prev="1" num="6" edition="update_10" />
        <vers prev="1" num="6" edition="update_11" />
        <vers prev="1" num="6" edition="update_12" />
        <vers prev="1" num="6" edition="update_2" />
        <vers prev="1" num="6" edition="update_3" />
        <vers prev="1" num="6" edition="update_4" />
        <vers prev="1" num="6" edition="update_5" />
        <vers prev="1" num="6" edition="update_6" />
        <vers prev="1" num="6" edition="update_7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1101" published="2009-03-25" name="CVE-2009-1101" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:P)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">Unspecified vulnerability in the lightweight HTTP server implementation in Java SE Development Kit (JDK) and Java Runtime Environment (JRE) 6 Update 12 and earlier allows remote attackers to cause a denial of service (probably resource consumption) for a JAX-WS service endpoint via a connection without any data, which triggers a file descriptor "leak."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-254609-1" source="SUNALERT" patch="1" adv="1">254609</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-21-125137-14-1" source="MISC" patch="1">http://sunsolve.sun.com/search/document.do?assetkey=1-21-125137-14-1</ref>
      <ref url="https://rhn.redhat.com/errata/RHSA-2009-1198.html" source="REDHAT">RHSA-2009:1198</ref>
      <ref url="https://rhn.redhat.com/errata/RHSA-2009-0377.html" source="REDHAT">RHSA-2009:0377</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/3316" source="VUPEN">ADV-2009-3316</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1426" source="VUPEN">ADV-2009-1426</ref>
      <ref url="http://www.vmware.com/security/advisories/VMSA-2009-0016.html" source="CONFIRM">http://www.vmware.com/security/advisories/VMSA-2009-0016.html</ref>
      <ref url="http://www.ubuntu.com/usn/usn-748-1" source="UBUNTU">USN-748-1</ref>
      <ref url="http://www.securitytracker.com/id?1021918" source="SECTRACK">1021918</ref>
      <ref url="http://www.securityfocus.com/bid/34240" source="BID">34240</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/507985/100/0/threaded" source="BUGTRAQ">20091120 VMSA-2009-0016 VMware vCenter and ESX update release and vMA patch release address multiple security issue in third party components</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-1038.html" source="REDHAT">RHSA-2009:1038</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-0392.html" source="REDHAT">RHSA-2009:0392</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujul2009.html" source="CONFIRM">http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujul2009.html</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:162" source="MANDRIVA">MDVSA-2009:162</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:137" source="MANDRIVA">MDVSA-2009:137</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1769" source="DEBIAN">DSA-1769</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2009-108.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2009-108.htm</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200911-02.xml" source="GENTOO">GLSA-200911-02</ref>
      <ref url="http://secunia.com/advisories/37460" source="SECUNIA">37460</ref>
      <ref url="http://secunia.com/advisories/37386" source="SECUNIA">37386</ref>
      <ref url="http://secunia.com/advisories/36185" source="SECUNIA">36185</ref>
      <ref url="http://secunia.com/advisories/35776" source="SECUNIA">35776</ref>
      <ref url="http://secunia.com/advisories/35255" source="SECUNIA">35255</ref>
      <ref url="http://secunia.com/advisories/35223" source="SECUNIA">35223</ref>
      <ref url="http://secunia.com/advisories/35156" source="SECUNIA">35156</ref>
      <ref url="http://secunia.com/advisories/34675" source="SECUNIA">34675</ref>
      <ref url="http://secunia.com/advisories/34632" source="SECUNIA">34632</ref>
      <ref url="http://secunia.com/advisories/34496" source="SECUNIA">34496</ref>
      <ref url="http://secunia.com/advisories/34489" source="SECUNIA">34489</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6412" source="OVAL">oval:org.mitre.oval:def:6412</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10152" source="OVAL">oval:org.mitre.oval:def:10152</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=124344236532162&amp;w=2" source="HP">HPSBUX02429</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-07/msg00001.html" source="SUSE">SUSE-SA:2009:036</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-05/msg00003.html" source="SUSE">SUSE-SA:2009:029</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-04/msg00001.html" source="SUSE">SUSE-SA:2009:016</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&amp;cc=us&amp;objectID=c01745133" source="HP">SSRT090058</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&amp;cc=us&amp;objectID=c01745133" source="HP">SSRT090058</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="jdk">
        <vers prev="1" num="6" edition="update_1" />
        <vers prev="1" num="6" edition="update_10" />
        <vers prev="1" num="6" edition="update_11" />
        <vers prev="1" num="6" edition="update_12" />
        <vers prev="1" num="6" edition="update_2" />
        <vers prev="1" num="6" edition="update_3" />
        <vers prev="1" num="6" edition="update_4" />
        <vers prev="1" num="6" edition="update_5" />
        <vers prev="1" num="6" edition="update_6" />
        <vers prev="1" num="6" edition="update_7" />
        <vers prev="1" num="6" edition="update_8" />
        <vers prev="1" num="6" edition="update_9" />
      </prod>
      <prod vendor="sun" name="jre">
        <vers prev="1" num="6" edition="update_1" />
        <vers prev="1" num="6" edition="update_10" />
        <vers prev="1" num="6" edition="update_11" />
        <vers prev="1" num="6" edition="update_12" />
        <vers prev="1" num="6" edition="update_2" />
        <vers prev="1" num="6" edition="update_3" />
        <vers prev="1" num="6" edition="update_4" />
        <vers prev="1" num="6" edition="update_5" />
        <vers prev="1" num="6" edition="update_6" />
        <vers prev="1" num="6" edition="update_7" />
        <vers prev="1" num="6" edition="update_8" />
        <vers prev="1" num="6" edition="update_9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1102" published="2009-03-25" name="CVE-2009-1102" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Virtual Machine in Java SE Development Kit (JDK) and Java Runtime Environment (JRE) 6 Update 12 and earlier allows remote attackers to access files and execute arbitrary code via unknown vectors related to "code generation."</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-254610-1" source="SUNALERT" patch="1" adv="1">254610</ref>
      <ref url="https://rhn.redhat.com/errata/RHSA-2009-0377.html" source="REDHAT">RHSA-2009:0377</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/3316" source="VUPEN">ADV-2009-3316</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1426" source="VUPEN">ADV-2009-1426</ref>
      <ref url="http://www.vmware.com/security/advisories/VMSA-2009-0016.html" source="CONFIRM">http://www.vmware.com/security/advisories/VMSA-2009-0016.html</ref>
      <ref url="http://www.ubuntu.com/usn/usn-748-1" source="UBUNTU">USN-748-1</ref>
      <ref url="http://www.securitytracker.com/id?1021919" source="SECTRACK">1021919</ref>
      <ref url="http://www.securityfocus.com/bid/34240" source="BID">34240</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/507985/100/0/threaded" source="BUGTRAQ">20091120 VMSA-2009-0016 VMware vCenter and ESX update release and vMA patch release address multiple security issue in third party components</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-0392.html" source="REDHAT">RHSA-2009:0392</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:162" source="MANDRIVA">MDVSA-2009:162</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:137" source="MANDRIVA">MDVSA-2009:137</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2009-108.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2009-108.htm</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200911-02.xml" source="GENTOO">GLSA-200911-02</ref>
      <ref url="http://secunia.com/advisories/37460" source="SECUNIA">37460</ref>
      <ref url="http://secunia.com/advisories/37386" source="SECUNIA">37386</ref>
      <ref url="http://secunia.com/advisories/35255" source="SECUNIA">35255</ref>
      <ref url="http://secunia.com/advisories/35223" source="SECUNIA">35223</ref>
      <ref url="http://secunia.com/advisories/34632" source="SECUNIA">34632</ref>
      <ref url="http://secunia.com/advisories/34496" source="SECUNIA">34496</ref>
      <ref url="http://secunia.com/advisories/34489" source="SECUNIA">34489</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6722" source="OVAL">oval:org.mitre.oval:def:6722</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10300" source="OVAL">oval:org.mitre.oval:def:10300</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=124344236532162&amp;w=2" source="HP">HPSBUX02429</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-05/msg00003.html" source="SUSE">SUSE-SA:2009:029</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-04/msg00001.html" source="SUSE">SUSE-SA:2009:016</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&amp;cc=us&amp;objectID=c01745133" source="HP">HPSBMA02429</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&amp;cc=us&amp;objectID=c01745133" source="HP">HPSBMA02429</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="java">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1103" published="2009-03-25" name="CVE-2009-1103" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Java Plug-in in Java SE Development Kit (JDK) and Java Runtime Environment (JRE) 5.0 Update 17 and earlier; 6 Update 12 and earlier; 1.4.2_19 and earlier; and 1.3.1_24 and earlier allows remote attackers to access files and execute arbitrary code via unknown vectors related to "deserializing applets," aka CR 6646860.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-254611-1" source="SUNALERT" patch="1" adv="1">254611</ref>
      <ref url="https://rhn.redhat.com/errata/RHSA-2009-1198.html" source="REDHAT">RHSA-2009:1198</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/49456" source="XF">jre-javaplugin-privilege-escalation(49456)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/3316" source="VUPEN">ADV-2009-3316</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1426" source="VUPEN">ADV-2009-1426</ref>
      <ref url="http://www.vmware.com/security/advisories/VMSA-2009-0016.html" source="CONFIRM">http://www.vmware.com/security/advisories/VMSA-2009-0016.html</ref>
      <ref url="http://www.securitytracker.com/id?1021920" source="SECTRACK">1021920</ref>
      <ref url="http://www.securityfocus.com/bid/34240" source="BID">34240</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/507985/100/0/threaded" source="BUGTRAQ">20091120 VMSA-2009-0016 VMware vCenter and ESX update release and vMA patch release address multiple security issue in third party components</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-1038.html" source="REDHAT">RHSA-2009:1038</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-0394.html" source="REDHAT">RHSA-2009:0394</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-0392.html" source="REDHAT">RHSA-2009:0392</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2009-109.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2009-109.htm</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2009-108.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2009-108.htm</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200911-02.xml" source="GENTOO">GLSA-200911-02</ref>
      <ref url="http://secunia.com/advisories/37460" source="SECUNIA">37460</ref>
      <ref url="http://secunia.com/advisories/37386" source="SECUNIA">37386</ref>
      <ref url="http://secunia.com/advisories/36185" source="SECUNIA">36185</ref>
      <ref url="http://secunia.com/advisories/35416" source="SECUNIA">35416</ref>
      <ref url="http://secunia.com/advisories/35255" source="SECUNIA">35255</ref>
      <ref url="http://secunia.com/advisories/35156" source="SECUNIA">35156</ref>
      <ref url="http://secunia.com/advisories/34496" source="SECUNIA">34496</ref>
      <ref url="http://secunia.com/advisories/34495" source="SECUNIA">34495</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6542" source="OVAL">oval:org.mitre.oval:def:6542</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=124344236532162&amp;w=2" source="HP">HPSBUX02429</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-07/msg00001.html" source="SUSE">SUSE-SA:2009:036</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-06/msg00003.html" source="SUSE">SUSE-SR:2009:011</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-04/msg00001.html" source="SUSE">SUSE-SA:2009:016</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&amp;cc=us&amp;objectID=c01745133" source="HP">SSRT090058</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&amp;cc=us&amp;objectID=c01745133" source="HP">SSRT090058</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="java">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1104" published="2009-03-25" name="CVE-2009-1104" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)" CVSS_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_base_score="5.8">
    <desc>
      <descript source="cve">The Java Plug-in in Java SE Development Kit (JDK) and Java Runtime Environment (JRE) 5.0 Update 17 and earlier; 6 Update 12 and earlier; and 1.4.2_19 and earlier does not prevent Javascript that is loaded from the localhost from connecting to other ports on the system, which allows user-assisted attackers to bypass intended access restrictions via LiveConnect, aka CR 6724331.  NOTE: this vulnerability can be leveraged with separate cross-site scripting (XSS) vulnerabilities for remote attack vectors.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-254611-1" source="SUNALERT" patch="1" adv="1">254611</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-21-118669-19-1" source="MISC" patch="1">http://sunsolve.sun.com/search/document.do?assetkey=1-21-118669-19-1</ref>
      <ref url="https://rhn.redhat.com/errata/RHSA-2009-1198.html" source="REDHAT">RHSA-2009:1198</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/49457" source="XF">jre-plugin-javascriptcode-unauthorized-access(49457)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/3316" source="VUPEN">ADV-2009-3316</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1426" source="VUPEN">ADV-2009-1426</ref>
      <ref url="http://www.vmware.com/security/advisories/VMSA-2009-0016.html" source="CONFIRM">http://www.vmware.com/security/advisories/VMSA-2009-0016.html</ref>
      <ref url="http://www.securitytracker.com/id?1021920" source="SECTRACK">1021920</ref>
      <ref url="http://www.securityfocus.com/bid/34240" source="BID">34240</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/507985/100/0/threaded" source="BUGTRAQ">20091120 VMSA-2009-0016 VMware vCenter and ESX update release and vMA patch release address multiple security issue in third party components</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-1038.html" source="REDHAT">RHSA-2009:1038</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-0394.html" source="REDHAT">RHSA-2009:0394</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-0392.html" source="REDHAT">RHSA-2009:0392</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2009-109.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2009-109.htm</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2009-108.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2009-108.htm</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200911-02.xml" source="GENTOO">GLSA-200911-02</ref>
      <ref url="http://secunia.com/advisories/37460" source="SECUNIA">37460</ref>
      <ref url="http://secunia.com/advisories/37386" source="SECUNIA">37386</ref>
      <ref url="http://secunia.com/advisories/36185" source="SECUNIA">36185</ref>
      <ref url="http://secunia.com/advisories/35416" source="SECUNIA">35416</ref>
      <ref url="http://secunia.com/advisories/35255" source="SECUNIA">35255</ref>
      <ref url="http://secunia.com/advisories/35156" source="SECUNIA">35156</ref>
      <ref url="http://secunia.com/advisories/34496" source="SECUNIA">34496</ref>
      <ref url="http://secunia.com/advisories/34495" source="SECUNIA">34495</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6584" source="OVAL">oval:org.mitre.oval:def:6584</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=124344236532162&amp;w=2" source="HP">HPSBUX02429</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-07/msg00001.html" source="SUSE">SUSE-SA:2009:036</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-06/msg00003.html" source="SUSE">SUSE-SR:2009:011</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-04/msg00001.html" source="SUSE">SUSE-SA:2009:016</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&amp;cc=us&amp;objectID=c01745133" source="HP">SSRT090058</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&amp;cc=us&amp;objectID=c01745133" source="HP">SSRT090058</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="java">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1105" published="2009-03-25" name="CVE-2009-1105" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The Java Plug-in in Java SE Development Kit (JDK) and Java Runtime Environment (JRE) 6 Update 12, 11, and 10 allows user-assisted remote attackers to cause a trusted applet to run in an older JRE version, which can be used to exploit vulnerabilities in that older version, aka CR 6706490.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-254611-1" source="SUNALERT" patch="1" adv="1">254611</ref>
      <ref url="https://rhn.redhat.com/errata/RHSA-2009-1198.html" source="REDHAT">RHSA-2009:1198</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/49458" source="XF">jre-plugin-weak-security(49458)</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1191" source="VUPEN">ADV-2010-1191</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/3316" source="VUPEN">ADV-2009-3316</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1426" source="VUPEN">ADV-2009-1426</ref>
      <ref url="http://www.vmware.com/security/advisories/VMSA-2009-0016.html" source="CONFIRM">http://www.vmware.com/security/advisories/VMSA-2009-0016.html</ref>
      <ref url="http://www.securitytracker.com/id?1021920" source="SECTRACK">1021920</ref>
      <ref url="http://www.securityfocus.com/bid/34240" source="BID">34240</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/507985/100/0/threaded" source="BUGTRAQ">20091120 VMSA-2009-0016 VMware vCenter and ESX update release and vMA patch release address multiple security issue in third party components</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-1038.html" source="REDHAT">RHSA-2009:1038</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-0392.html" source="REDHAT">RHSA-2009:0392</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2009-108.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2009-108.htm</ref>
      <ref url="http://support.apple.com/kb/HT4171" source="CONFIRM">http://support.apple.com/kb/HT4171</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200911-02.xml" source="GENTOO">GLSA-200911-02</ref>
      <ref url="http://secunia.com/advisories/39819" source="SECUNIA">39819</ref>
      <ref url="http://secunia.com/advisories/37460" source="SECUNIA">37460</ref>
      <ref url="http://secunia.com/advisories/37386" source="SECUNIA">37386</ref>
      <ref url="http://secunia.com/advisories/36185" source="SECUNIA">36185</ref>
      <ref url="http://secunia.com/advisories/35255" source="SECUNIA">35255</ref>
      <ref url="http://secunia.com/advisories/35156" source="SECUNIA">35156</ref>
      <ref url="http://secunia.com/advisories/34496" source="SECUNIA">34496</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6642" source="OVAL">oval:org.mitre.oval:def:6642</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=124344236532162&amp;w=2" source="HP">HPSBUX02429</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-07/msg00001.html" source="SUSE">SUSE-SA:2009:036</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-04/msg00001.html" source="SUSE">SUSE-SA:2009:016</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//May/msg00001.html" source="APPLE">APPLE-SA-2010-05-18-1</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&amp;cc=us&amp;objectID=c01745133" source="HP">SSRT090058</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&amp;cc=us&amp;objectID=c01745133" source="HP">SSRT090058</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="java">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1106" published="2009-03-25" name="CVE-2009-1106" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:P)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">The Java Plug-in in Java SE Development Kit (JDK) and Java Runtime Environment (JRE) 6 Update 12, 11, and 10 does not properly parse crossdomain.xml files, which allows remote attackers to bypass intended access restrictions and connect to arbitrary sites via unknown vectors, aka CR 6798948.</descript>
    </desc>
    <loss_types>
      <avail />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-254611-1" source="SUNALERT" patch="1" adv="1">254611</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-21-125137-14-1" source="MISC" patch="1">http://sunsolve.sun.com/search/document.do?assetkey=1-21-125137-14-1</ref>
      <ref url="https://rhn.redhat.com/errata/RHSA-2009-1198.html" source="REDHAT">RHSA-2009:1198</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/49459" source="XF">jre-plugin-crossdomain-info-disclosure(49459)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/3316" source="VUPEN">ADV-2009-3316</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1426" source="VUPEN">ADV-2009-1426</ref>
      <ref url="http://www.vmware.com/security/advisories/VMSA-2009-0016.html" source="CONFIRM">http://www.vmware.com/security/advisories/VMSA-2009-0016.html</ref>
      <ref url="http://www.securitytracker.com/id?1021920" source="SECTRACK">1021920</ref>
      <ref url="http://www.securityfocus.com/bid/34240" source="BID">34240</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/507985/100/0/threaded" source="BUGTRAQ">20091120 VMSA-2009-0016 VMware vCenter and ESX update release and vMA patch release address multiple security issue in third party components</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-1038.html" source="REDHAT">RHSA-2009:1038</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-0392.html" source="REDHAT">RHSA-2009:0392</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2009-108.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2009-108.htm</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200911-02.xml" source="GENTOO">GLSA-200911-02</ref>
      <ref url="http://secunia.com/advisories/37460" source="SECUNIA">37460</ref>
      <ref url="http://secunia.com/advisories/37386" source="SECUNIA">37386</ref>
      <ref url="http://secunia.com/advisories/36185" source="SECUNIA">36185</ref>
      <ref url="http://secunia.com/advisories/35255" source="SECUNIA">35255</ref>
      <ref url="http://secunia.com/advisories/35156" source="SECUNIA">35156</ref>
      <ref url="http://secunia.com/advisories/34496" source="SECUNIA">34496</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6619" source="OVAL">oval:org.mitre.oval:def:6619</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=124344236532162&amp;w=2" source="HP">HPSBUX02429</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-07/msg00001.html" source="SUSE">SUSE-SA:2009:036</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-04/msg00001.html" source="SUSE">SUSE-SA:2009:016</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&amp;cc=us&amp;objectID=c01745133" source="HP">SSRT090058</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&amp;cc=us&amp;objectID=c01745133" source="HP">SSRT090058</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="jdk">
        <vers num="6" edition="update_10" />
        <vers num="6" edition="update_11" />
        <vers num="6" edition="update_12" />
      </prod>
      <prod vendor="sun" name="jre">
        <vers num="6" edition="update_10" />
        <vers num="6" edition="update_11" />
        <vers num="6" edition="update_12" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1107" published="2009-03-25" name="CVE-2009-1107" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">The Java Plug-in in Java SE Development Kit (JDK) and Java Runtime Environment (JRE) 6 Update 12 and earlier, and 5.0 Update 17 and earlier, allows remote attackers to trick a user into trusting a signed applet via unknown vectors that misrepresent the security warning dialog, related to a "Swing JLabel HTML parsing vulnerability," aka CR 6782871.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-254611-1" source="SUNALERT" patch="1" adv="1">254611</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-21-125139-14-1" source="MISC" patch="1">http://sunsolve.sun.com/search/document.do?assetkey=1-21-125139-14-1</ref>
      <ref url="https://rhn.redhat.com/errata/RHSA-2009-1198.html" source="REDHAT">RHSA-2009:1198</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/49460" source="XF">jre-plugin-signedapplet-unauth-access(49460)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/3316" source="VUPEN">ADV-2009-3316</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1426" source="VUPEN">ADV-2009-1426</ref>
      <ref url="http://www.vmware.com/security/advisories/VMSA-2009-0016.html" source="CONFIRM">http://www.vmware.com/security/advisories/VMSA-2009-0016.html</ref>
      <ref url="http://www.securitytracker.com/id?1021920" source="SECTRACK">1021920</ref>
      <ref url="http://www.securityfocus.com/bid/34240" source="BID">34240</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/507985/100/0/threaded" source="BUGTRAQ">20091120 VMSA-2009-0016 VMware vCenter and ESX update release and vMA patch release address multiple security issue in third party components</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-1038.html" source="REDHAT">RHSA-2009:1038</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-0394.html" source="REDHAT">RHSA-2009:0394</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-0392.html" source="REDHAT">RHSA-2009:0392</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2009-109.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2009-109.htm</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2009-108.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2009-108.htm</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200911-02.xml" source="GENTOO">GLSA-200911-02</ref>
      <ref url="http://secunia.com/advisories/37460" source="SECUNIA">37460</ref>
      <ref url="http://secunia.com/advisories/37386" source="SECUNIA">37386</ref>
      <ref url="http://secunia.com/advisories/36185" source="SECUNIA">36185</ref>
      <ref url="http://secunia.com/advisories/35416" source="SECUNIA">35416</ref>
      <ref url="http://secunia.com/advisories/35255" source="SECUNIA">35255</ref>
      <ref url="http://secunia.com/advisories/35156" source="SECUNIA">35156</ref>
      <ref url="http://secunia.com/advisories/34496" source="SECUNIA">34496</ref>
      <ref url="http://secunia.com/advisories/34495" source="SECUNIA">34495</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6585" source="OVAL">oval:org.mitre.oval:def:6585</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=124344236532162&amp;w=2" source="HP">HPSBUX02429</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-07/msg00001.html" source="SUSE">SUSE-SA:2009:036</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-06/msg00003.html" source="SUSE">SUSE-SR:2009:011</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-04/msg00001.html" source="SUSE">SUSE-SA:2009:016</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&amp;cc=us&amp;objectID=c01745133" source="HP">HPSBMA02429</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&amp;cc=us&amp;objectID=c01745133" source="HP">HPSBMA02429</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="java">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1119" published="2009-04-15" name="CVE-2009-1119" modified="2009-04-18" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Multiple heap-based buffer overflows in EMC RepliStor 6.2 before SP5 and 6.3 before SP2 allow remote attackers to execute arbitrary code via a crafted message to (1) ctrlservice.exe or (2) rep_srv.exe, possibly related to an integer overflow.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2009/1018" source="VUPEN" adv="1">ADV-2009-1018</ref>
      <ref url="http://www.securitytracker.com/id?1022026" source="SECTRACK">1022026</ref>
      <ref url="http://www.securityfocus.com/bid/34449" source="BID">34449</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/502575/100/0/threaded" source="BUGTRAQ">20090409 FGA-2009-003:EMC RepliStor Buffer Overflow Vulnerability</ref>
      <ref url="http://www.fortiguardcenter.com/advisory/FGA-2009-13.html" source="MISC">http://www.fortiguardcenter.com/advisory/FGA-2009-13.html</ref>
      <ref url="http://secunia.com/advisories/34699" source="SECUNIA" adv="1">34699</ref>
    </refs>
    <vuln_soft>
      <prod vendor="emc" name="replistor">
        <vers prev="1" num="6.2" edition="sp4" />
        <vers prev="1" num="6.3" edition="sp1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1122" published="2009-06-10" name="CVE-2009-1122" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)" CVSS_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_base_score="7.6">
    <desc>
      <descript source="cve">The WebDAV extension in Microsoft Internet Information Services (IIS) 5.0 on Windows 2000 SP4 does not properly decode URLs, which allows remote attackers to bypass authentication, and possibly read or create files, via a crafted HTTP request, aka "IIS 5.0 WebDAV Authentication Bypass Vulnerability," a different vulnerability than CVE-2009-1535.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-160A.html" source="CERT">TA09-160A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS09-020.mspx" source="MS" patch="1" adv="1">MS09-020</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1539" source="VUPEN">ADV-2009-1539</ref>
      <ref url="http://www.securitytracker.com/id?1022358" source="SECTRACK">1022358</ref>
      <ref url="http://www.securityfocus.com/bid/35232" source="BID">35232</ref>
      <ref url="http://www.attrition.org/pipermail/vim/2009-June/002192.html" source="VIM">20090616 IIS WebDav Vulnerability CVE ID</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5861" source="OVAL">oval:org.mitre.oval:def:5861</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="iis">
        <vers num="5.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1123" published="2009-06-10" name="CVE-2009-1123" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">The kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 SP2 does not properly validate changes to unspecified kernel objects, which allows local users to gain privileges via a crafted application, aka "Windows Kernel Desktop Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-160A.html" source="CERT">TA09-160A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS09-025.mspx" source="MS" patch="1" adv="1">MS09-025</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1544" source="VUPEN">ADV-2009-1544</ref>
      <ref url="http://www.securitytracker.com/id?1022359" source="SECTRACK">1022359</ref>
      <ref url="http://secunia.com/advisories/35372" source="SECUNIA">35372</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6206" source="OVAL">oval:org.mitre.oval:def:6206</ref>
      <ref url="http://osvdb.org/54940" source="OSVDB">54940</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition="sp4" />
      </prod>
      <prod vendor="microsoft" name="windows_server_2003">
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:itanium" />
        <vers num="" edition="sp2:x64" />
      </prod>
      <prod vendor="microsoft" name="windows_server_2008">
        <vers num="" edition=":x64" />
        <vers num="" edition=":x32" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:itanium" />
        <vers num="sp2" edition="x32" />
        <vers num="sp2" edition="x64" />
      </prod>
      <prod vendor="microsoft" name="windows_vista">
        <vers num="" edition=":x64" />
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:x64" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:x64" />
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition="sp2" />
        <vers num="" edition="sp3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1124" published="2009-06-10" name="CVE-2009-1124" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">The kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 SP2 does not properly validate user-mode pointers in unspecified error conditions, which allows local users to gain privileges via a crafted application, aka "Windows Kernel Pointer Validation Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-160A.html" source="CERT">TA09-160A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS09-025.mspx" source="MS" patch="1" adv="1">MS09-025</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1544" source="VUPEN">ADV-2009-1544</ref>
      <ref url="http://www.securitytracker.com/id?1022359" source="SECTRACK">1022359</ref>
      <ref url="http://www.securityfocus.com/bid/35238" source="BID">35238</ref>
      <ref url="http://secunia.com/advisories/35372" source="SECUNIA">35372</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6231" source="OVAL">oval:org.mitre.oval:def:6231</ref>
      <ref url="http://osvdb.org/54941" source="OSVDB">54941</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition="sp4" />
      </prod>
      <prod vendor="microsoft" name="windows_server_2003">
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:itanium" />
        <vers num="" edition="sp2:x64" />
      </prod>
      <prod vendor="microsoft" name="windows_server_2008">
        <vers num="" edition=":x64" />
        <vers num="" edition=":x32" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:itanium" />
        <vers num="sp2" edition="x32" />
        <vers num="sp2" edition="x64" />
      </prod>
      <prod vendor="microsoft" name="windows_vista">
        <vers num="" edition=":x64" />
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:x64" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:x64" />
        <vers num="gold" />
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition="sp2" />
        <vers num="" edition="sp3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1125" published="2009-06-10" name="CVE-2009-1125" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">The kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 SP2 does not properly validate an argument to an unspecified system call, which allows local users to gain privileges via a crafted application, aka "Windows Driver Class Registration Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-160A.html" source="CERT">TA09-160A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS09-025.mspx" source="MS" patch="1" adv="1">MS09-025</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1544" source="VUPEN">ADV-2009-1544</ref>
      <ref url="http://www.securitytracker.com/id?1022359" source="SECTRACK">1022359</ref>
      <ref url="http://www.securityfocus.com/bid/35240" source="BID">35240</ref>
      <ref url="http://secunia.com/advisories/35372" source="SECUNIA">35372</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5912" source="OVAL">oval:org.mitre.oval:def:5912</ref>
      <ref url="http://osvdb.org/54942" source="OSVDB">54942</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition="sp4" />
      </prod>
      <prod vendor="microsoft" name="windows_server_2003">
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:itanium" />
        <vers num="" edition="sp2:x64" />
      </prod>
      <prod vendor="microsoft" name="windows_server_2008">
        <vers num="" edition=":x64" />
        <vers num="" edition=":x32" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:itanium" />
        <vers num="sp2" edition="x32" />
        <vers num="sp2" edition="x64" />
      </prod>
      <prod vendor="microsoft" name="windows_vista">
        <vers num="" edition=":x64" />
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:x64" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:x64" />
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition="sp2" />
        <vers num="" edition="sp3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1126" published="2009-06-10" name="CVE-2009-1126" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">The kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 does not properly validate the user-mode input associated with the editing of an unspecified desktop parameter, which allows local users to gain privileges via a crafted application, aka "Windows Desktop Parameter Edit Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-160A.html" source="CERT">TA09-160A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS09-025.mspx" source="MS" patch="1" adv="1">MS09-025</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1544" source="VUPEN">ADV-2009-1544</ref>
      <ref url="http://www.securitytracker.com/id?1022359" source="SECTRACK">1022359</ref>
      <ref url="http://secunia.com/advisories/35372" source="SECUNIA">35372</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6016" source="OVAL">oval:org.mitre.oval:def:6016</ref>
      <ref url="http://osvdb.org/54943" source="OSVDB">54943</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition="sp4" />
      </prod>
      <prod vendor="microsoft" name="windows_server_2003">
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:itanium" />
        <vers num="" edition="sp2:x64" />
      </prod>
      <prod vendor="microsoft" name="windows_server_2008">
        <vers num="" edition=":x64" />
        <vers num="" edition=":x32" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:itanium" />
        <vers num="sp2" edition="x32" />
        <vers num="sp2" edition="x64" />
      </prod>
      <prod vendor="microsoft" name="windows_vista">
        <vers num="" edition=":x64" />
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:x64" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:x64" />
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition="sp2" />
        <vers num="" edition="sp3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1127" published="2009-11-11" name="CVE-2009-1127" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:S/C:C/I:C/A:C)" CVSS_score="6.8" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.1" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">win32k.sys in the kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 does not correctly validate an argument to an unspecified system call, which allows local users to gain privileges via a crafted application that triggers a NULL pointer dereference, aka "Win32k NULL Pointer Dereferencing Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-314A.html" source="CERT">TA09-314A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS09-065.mspx" source="MS" patch="1" adv="1">MS09-065</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5588" source="OVAL">oval:org.mitre.oval:def:5588</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition="sp4" />
      </prod>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:itanium" />
        <vers num="" edition="sp2:x64" />
      </prod>
      <prod vendor="microsoft" name="windows_server_2008">
        <vers num="" edition=":x64" />
        <vers num="" edition=":x32" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:x64" />
        <vers num="" edition="sp2:x32" />
        <vers num="-" edition="gold" />
        <vers num="-" edition="gold:itanium" />
        <vers num="-" edition="sp2" />
        <vers num="-" edition="sp2:itanium" />
      </prod>
      <prod vendor="microsoft" name="windows_vista">
        <vers num="" edition=":x64" />
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:x64" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:x64" />
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition="sp2" />
        <vers num="" edition="sp3" />
        <vers num="-" edition="sp2" />
        <vers num="-" edition="sp2:x64" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1128" published="2009-05-12" name="CVE-2009-1128" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Microsoft Office PowerPoint 2000 SP3, 2002 SP3, and 2003 SP3 allows remote attackers to execute arbitrary code via crafted sound data in a file that uses a PowerPoint 95 native file format, leading to memory corruption, aka "PP7 Memory Corruption Vulnerability," a different vulnerability than CVE-2009-1129.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-132A.html" source="CERT">TA09-132A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS09-017.mspx" source="MS" patch="1" adv="1">MS09-017</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1290" source="VUPEN">ADV-2009-1290</ref>
      <ref url="http://www.securitytracker.com/id?1022205" source="SECTRACK">1022205</ref>
      <ref url="http://www.securityfocus.com/bid/34837" source="BID">34837</ref>
      <ref url="http://secunia.com/advisories/32428" source="SECUNIA">32428</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5416" source="OVAL">oval:org.mitre.oval:def:5416</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="office_powerpoint">
        <vers num="2000" edition="sp3" />
        <vers num="2002" edition="sp3" />
        <vers num="2003" edition="sp3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1129" published="2009-05-12" name="CVE-2009-1129" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Multiple stack-based buffer overflows in the PowerPoint 95 importer (PP7X32.DLL) in Microsoft Office PowerPoint 2000 SP3, 2002 SP3, and 2003 SP3 allow remote attackers to execute arbitrary code via an inconsistent record length in sound data in a file that uses a PowerPoint 95 (PPT95) native file format, aka "PP7 Memory Corruption Vulnerability," a different vulnerability than CVE-2009-1128.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-132A.html" source="CERT">TA09-132A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS09-017.mspx" source="MS" patch="1" adv="1">MS09-017</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1290" source="VUPEN" adv="1">ADV-2009-1290</ref>
      <ref url="http://www.securitytracker.com/id?1022205" source="SECTRACK">1022205</ref>
      <ref url="http://www.securityfocus.com/bid/34839" source="BID">34839</ref>
      <ref url="http://secunia.com/advisories/32428" source="SECUNIA" adv="1">32428</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6176" source="OVAL">oval:org.mitre.oval:def:6176</ref>
      <ref url="http://osvdb.org/54387" source="OSVDB">54387</ref>
      <ref url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=791" source="IDEFENSE">20090512 Microsoft PowerPoint PPT95 Import Multiple Stack Buffer Overflow Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="office_powerpoint">
        <vers num="2000" edition="sp3" />
        <vers num="2002" edition="sp3" />
        <vers num="2003" edition="sp3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1130" published="2009-05-12" name="CVE-2009-1130" modified="2012-01-06" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Heap-based buffer overflow in Microsoft Office PowerPoint 2002 SP3 and 2003 SP3, and PowerPoint in Microsoft Office 2004 for Mac, allows remote attackers to execute arbitrary code via a crafted structure in a Notes container in a PowerPoint file that causes PowerPoint to read more data than was allocated when creating a C++ object, leading to an overwrite of a function pointer, aka "Heap Corruption Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-132A.html" source="CERT">TA09-132A</ref>
      <ref url="http://www.zerodayinitiative.com/advisories/ZDI-09-020/" source="MISC">http://www.zerodayinitiative.com/advisories/ZDI-09-020/</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1290" source="VUPEN" adv="1">ADV-2009-1290</ref>
      <ref url="http://www.securitytracker.com/id?1022205" source="SECTRACK">1022205</ref>
      <ref url="http://www.securityfocus.com/bid/34840" source="BID">34840</ref>
      <ref url="http://www.securityfocus.com/archive/1/503454" source="BUGTRAQ">20090512 ZDI-09-020: Microsoft Office PowerPoint Notes Container Heap Overflow Vulnerability</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS09-017.mspx" source="MS" adv="1">MS09-017</ref>
      <ref url="http://secunia.com/advisories/32428" source="SECUNIA" adv="1">32428</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5961" source="OVAL">oval:org.mitre.oval:def:5961</ref>
      <ref url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=794" source="IDEFENSE">20090512 Microsoft PowerPoint Notes Container Heap Corruption Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="office">
        <vers num="2004" edition="" />
        <vers num="2004" edition=":mac" />
      </prod>
      <prod vendor="microsoft" name="office_powerpoint">
        <vers num="2002" edition="sp3" />
        <vers num="2003" edition="sp3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1131" published="2009-05-12" name="CVE-2009-1131" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Multiple stack-based buffer overflows in Microsoft Office PowerPoint 2000 SP3 allow remote attackers to execute arbitrary code via a large amount of data associated with unspecified atoms in a PowerPoint file that triggers memory corruption, aka "Data Out of Bounds Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-132A.html" source="CERT">TA09-132A</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1290" source="VUPEN" adv="1">ADV-2009-1290</ref>
      <ref url="http://www.securitytracker.com/id?1022205" source="SECTRACK">1022205</ref>
      <ref url="http://www.securityfocus.com/bid/34841" source="BID">34841</ref>
      <ref url="http://www.securityfocus.com/archive/1/503451" source="BUGTRAQ">20090512 Secunia Research: Microsoft PowerPoint Atom Parsing Buffer Overflows</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS09-017.mspx" source="MS" adv="1">MS09-017</ref>
      <ref url="http://secunia.com/secunia_research/2008-46/" source="MISC" adv="1">http://secunia.com/secunia_research/2008-46/</ref>
      <ref url="http://secunia.com/advisories/32428" source="SECUNIA" adv="1">32428</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5351" source="OVAL">oval:org.mitre.oval:def:5351</ref>
      <ref url="http://osvdb.org/54393" source="OSVDB">54393</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="office_powerpoint">
        <vers num="2000" edition="sp3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1132" published="2009-09-08" name="CVE-2009-1132" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Heap-based buffer overflow in the Wireless LAN AutoConfig Service (aka Wlansvc) in Microsoft Windows Vista Gold, SP1, and SP2 and Server 2008 Gold and SP2 allows remote attackers to execute arbitrary code via a malformed wireless frame, aka "Wireless Frame Parsing Remote Code Execution Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-251A.html" source="CERT">TA09-251A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS09-049.mspx" source="MS" patch="1" adv="1">MS09-049</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6389" source="OVAL">oval:org.mitre.oval:def:6389</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_server_2008">
        <vers num="-" edition="-" />
        <vers num="-" edition="-:x32" />
        <vers num="-" edition="-:x64" />
        <vers num="-" edition="sp2" />
        <vers num="-" edition="sp2:x64" />
        <vers num="-" edition="sp2:x32" />
      </prod>
      <prod vendor="microsoft" name="windows_vista">
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:x64" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:x64" />
        <vers num="-" edition="-" />
        <vers num="-" edition="-:x64" />
        <vers num="-" edition="sp1" />
        <vers num="-" edition="sp2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1133" published="2009-08-12" name="CVE-2009-1133" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Heap-based buffer overflow in Microsoft Remote Desktop Connection (formerly Terminal Services Client) running RDP 5.0 through 6.1 on Windows, and Remote Desktop Connection Client for Mac 2.0, allows remote attackers to execute arbitrary code via unspecified parameters, aka "Remote Desktop Connection Heap Overflow Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-223A.html" source="CERT">TA09-223A</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/2238" source="VUPEN" patch="1" adv="1">ADV-2009-2238</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS09-044.mspx" source="MS" patch="1" adv="1">MS09-044</ref>
      <ref url="http://www.securitytracker.com/id?1022709" source="SECTRACK">1022709</ref>
      <ref url="http://secunia.com/advisories/36229" source="SECUNIA" adv="1">36229</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5693" source="OVAL">oval:org.mitre.oval:def:5693</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="-" edition="sp4" />
      </prod>
      <prod vendor="microsoft" name="windows_server">
        <vers num="2003" edition="sp2" />
      </prod>
      <prod vendor="microsoft" name="windows_server_2003">
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:itanium" />
        <vers num="" edition="sp2:x64" />
      </prod>
      <prod vendor="microsoft" name="windows_server_2008">
        <vers num="" edition=":itanium" />
        <vers num="" edition=":x64" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:itanium" />
        <vers num="-" edition="-" />
        <vers num="-" edition="-:x32" />
        <vers num="-" edition="sp2" />
        <vers num="-" edition="sp2:x64" />
      </prod>
      <prod vendor="microsoft" name="windows_vista">
        <vers num="" edition=":x64" />
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:x64" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:x64" />
        <vers num="-" edition="sp1" />
        <vers num="-" edition="sp2" />
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:pro_x64" />
        <vers num="-" edition="sp2" />
        <vers num="-" edition="sp3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1134" published="2009-06-10" name="CVE-2009-1134" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Excel in 2007 Microsoft Office System SP1 and SP2; Microsoft Office Excel Viewer; and Microsoft Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2 allow remote attackers to execute arbitrary code via a BIFF file with a malformed Qsir (0x806) record object, aka "Record Pointer Corruption Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-160A.html" source="CERT">TA09-160A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS09-021.mspx" source="MS" patch="1" adv="1">MS09-021</ref>
      <ref url="http://www.zerodayinitiative.com/advisories/ZDI-09-040/" source="MISC">http://www.zerodayinitiative.com/advisories/ZDI-09-040/</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1540" source="VUPEN">ADV-2009-1540</ref>
      <ref url="http://www.securitytracker.com/id?1022351" source="SECTRACK">1022351</ref>
      <ref url="http://www.securityfocus.com/bid/35246" source="BID">35246</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/504213/100/0/threaded" source="BUGTRAQ">20090610 ZDI-09-040: Microsoft Office Excel QSIR Record Pointer Corruption Vulnerability</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5922" source="OVAL">oval:org.mitre.oval:def:5922</ref>
      <ref url="http://osvdb.org/54958" source="OSVDB">54958</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="office">
        <vers num="2004" edition="" />
        <vers num="2004" edition=":mac" />
        <vers num="2008" edition="" />
        <vers num="2008" edition=":mac" />
        <vers num="xp" edition="sp3" />
      </prod>
      <prod vendor="microsoft" name="office_compatibility_pack_for_word_excel_ppt_2007">
        <vers num="" edition="sp1" />
        <vers num="" edition="sp2" />
      </prod>
      <prod vendor="microsoft" name="office_excel">
        <vers num="2000" edition="sp3" />
        <vers num="2003" edition="sp3" />
        <vers num="2007" edition="sp1" />
        <vers num="2007" edition="sp2" />
      </prod>
      <prod vendor="microsoft" name="office_excel_viewer">
        <vers num="2003" edition="sp3" />
      </prod>
      <prod vendor="microsoft" name="office_sharepoint_server">
        <vers num="2007" edition="sp1" />
        <vers num="2007" edition="sp1:x64" />
        <vers num="2007" edition="sp1:x32" />
        <vers num="2007" edition="sp2" />
        <vers num="2007" edition="sp2:x64" />
        <vers num="2007" edition="sp2:x32" />
      </prod>
      <prod vendor="microsoft" name="open_xml_file_format_converter">
        <vers num="" edition=":mac" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1135" published="2009-07-15" name="CVE-2009-1135" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:C/I:C/A:C)" CVSS_score="9.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.0" CVSS_base_score="9.0">
    <desc>
      <descript source="cve">Microsoft Internet Security and Acceleration (ISA) Server 2006 Gold and SP1, when Radius OTP is enabled, uses the HTTP-Basic authentication method, which allows remote attackers to gain the privileges of an arbitrary account, and access published web pages, via vectors involving attempted access to a network resource behind the ISA Server, aka "Radius OTP Bypass Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-195A.html" source="CERT">TA09-195A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS09-031.mspx" source="MS" patch="1" adv="1">MS09-031</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1889" source="VUPEN">ADV-2009-1889</ref>
      <ref url="http://www.securitytracker.com/id?1022547" source="SECTRACK">1022547</ref>
      <ref url="http://secunia.com/advisories/35784" source="SECUNIA">35784</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5649" source="OVAL">oval:org.mitre.oval:def:5649</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="isa_server">
        <vers num="2006" edition="sp1" />
        <vers num="2006" edition="supportability" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1136" published="2009-07-15" name="CVE-2009-1136" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">The Microsoft Office Web Components Spreadsheet ActiveX control (aka OWC10 or OWC11), as distributed in Office XP SP3 and Office 2003 SP3, Office XP Web Components SP3, Office 2003 Web Components SP3, Office 2003 Web Components SP1 for the 2007 Microsoft Office System, Internet Security and Acceleration (ISA) Server 2004 SP3 and 2006 Gold and SP1, and Office Small Business Accounting 2006, when used in Internet Explorer, allows remote attackers to execute arbitrary code via a crafted call to the msDataSourceObject method, as exploited in the wild in July and August 2009, aka "Office Web Components HTML Script Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-223A.html" source="CERT">TA09-223A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS09-043.mspx" source="MS" patch="1" adv="1">MS09-043</ref>
      <ref url="http://xeye.us/blog/2009/07/one-0day/" source="MISC">http://xeye.us/blog/2009/07/one-0day/</ref>
      <ref url="http://www.microsoft.com/technet/security/advisory/973472.mspx" source="CONFIRM" adv="1">http://www.microsoft.com/technet/security/advisory/973472.mspx</ref>
      <ref url="http://trac.metasploit.com/browser/framework3/trunk/modules/exploits/windows/browser/owc_spreadsheet_msdso.rb" source="MISC">http://trac.metasploit.com/browser/framework3/trunk/modules/exploits/windows/browser/owc_spreadsheet_msdso.rb</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5809" source="OVAL">oval:org.mitre.oval:def:5809</ref>
      <ref url="http://isc.sans.org/diary.html?storyid=6778" source="MISC">http://isc.sans.org/diary.html?storyid=6778</ref>
      <ref url="http://blogs.technet.com/srd/archive/2009/07/13/more-information-about-the-office-web-components-activex-vulnerability.aspx" source="CONFIRM">http://blogs.technet.com/srd/archive/2009/07/13/more-information-about-the-office-web-components-activex-vulnerability.aspx</ref>
      <ref url="http://blogs.technet.com/msrc/archive/2009/07/13/microsoft-security-advisory-973472-released.aspx" source="CONFIRM">http://blogs.technet.com/msrc/archive/2009/07/13/microsoft-security-advisory-973472-released.aspx</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="isa_server">
        <vers num="2004" edition="sp3" />
        <vers num="2004" edition="sp3:standard" />
        <vers num="2004" edition="sp3:enterprise" />
        <vers num="2006" edition="sp1" />
        <vers num="2006" edition="supportability" />
      </prod>
      <prod vendor="microsoft" name="office">
        <vers num="2003" edition="" />
        <vers num="2003" edition=":small_business_accounting_2006" />
        <vers num="2003" edition="sp3" />
      </prod>
      <prod vendor="microsoft" name="office_web_components">
        <vers num="2003" edition="sp1" />
        <vers num="2003" edition="sp1:2007_microsoft_office" />
        <vers num="2003" edition="sp3" />
        <vers num="xp" edition="sp3" />
      </prod>
      <prod vendor="microsoft" name="office_xp">
        <vers num="sp3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1137" published="2009-05-12" name="CVE-2009-1137" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Microsoft Office PowerPoint 2000 SP3, 2002 SP3, and 2003 SP3 allows remote attackers to execute arbitrary code via crafted sound data in a file that uses a PowerPoint 4.0 native file format, leading to memory corruption, aka "Legacy File Format Vulnerability," a different vulnerability than CVE-2009-0222, CVE-2009-0223, CVE-2009-0226, and CVE-2009-0227.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-132A.html" source="CERT">TA09-132A</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/50425" source="XF">powerpoint-sounddata-code-execution(50425)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1290" source="VUPEN" adv="1">ADV-2009-1290</ref>
      <ref url="http://www.securitytracker.com/id?1022205" source="SECTRACK">1022205</ref>
      <ref url="http://www.securityfocus.com/bid/34876" source="BID">34876</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS09-017.mspx" source="MS" adv="1">MS09-017</ref>
      <ref url="http://secunia.com/advisories/32428" source="SECUNIA" adv="1">32428</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5946" source="OVAL">oval:org.mitre.oval:def:5946</ref>
      <ref url="http://osvdb.org/54381" source="OSVDB">54381</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="office_powerpoint">
        <vers num="2000" edition="sp3" />
        <vers num="2002" edition="sp3" />
        <vers num="2003" edition="sp3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1138" published="2009-06-10" name="CVE-2009-1138" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">The LDAP service in Active Directory on Microsoft Windows 2000 SP4 does not properly free memory for LDAP and LDAPS requests, which allows remote attackers to execute arbitrary code via a request that uses hexadecimal encoding, whose associated memory is not released, related to a "DN AttributeValue," aka "Active Directory Invalid Free Vulnerability."  NOTE: this issue is probably a memory leak.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-160A.html" source="CERT">TA09-160A</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1537" source="VUPEN" patch="1" adv="1">ADV-2009-1537</ref>
      <ref url="http://www.securityfocus.com/bid/35226" source="BID" patch="1">35226</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS09-018.mspx" source="MS" patch="1" adv="1">MS09-018</ref>
      <ref url="http://www.securitytracker.com/id?1022349" source="SECTRACK">1022349</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2009-214.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2009-214.htm</ref>
      <ref url="http://secunia.com/advisories/35355" source="SECUNIA" adv="1">35355</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6180" source="OVAL">oval:org.mitre.oval:def:6180</ref>
      <ref url="http://osvdb.org/54937" source="OSVDB">54937</ref>
      <ref url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=804" source="IDEFENSE">20090611 Microsoft Active Directory Hexdecimal DN AttributeValue Invalid Free Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition="sp4" />
        <vers num="" edition="sp4:server" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1139" published="2009-06-10" name="CVE-2009-1139" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Memory leak in the LDAP service in Active Directory on Microsoft Windows 2000 SP4 and Server 2003 SP2, and Active Directory Application Mode (ADAM) on Windows XP SP2 and SP3 and Server 2003 SP2, allows remote attackers to cause a denial of service (memory consumption and service outage) via (1) LDAP or (2) LDAPS requests with unspecified OID filters, aka "Active Directory Memory Leak Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-160A.html" source="CERT">TA09-160A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS09-018.mspx" source="MS" patch="1" adv="1">MS09-018</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1537" source="VUPEN">ADV-2009-1537</ref>
      <ref url="http://www.securitytracker.com/id?1022349" source="SECTRACK">1022349</ref>
      <ref url="http://www.securityfocus.com/bid/35225" source="BID">35225</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2009-214.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2009-214.htm</ref>
      <ref url="http://secunia.com/advisories/35355" source="SECUNIA">35355</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6253" source="OVAL">oval:org.mitre.oval:def:6253</ref>
      <ref url="http://osvdb.org/54938" source="OSVDB">54938</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="adam">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition="sp4" />
        <vers num="" edition="sp4:server" />
      </prod>
      <prod vendor="microsoft" name="windows_server_2003">
        <vers num="" edition=":x64" />
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:itanium" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:itanium" />
        <vers num="" edition="sp2:x64" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1140" published="2009-06-10" name="CVE-2009-1140" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:N/A:N)" CVSS_score="7.1" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="8.6" CVSS_base_score="7.1">
    <desc>
      <descript source="cve">Microsoft Internet Explorer 5.01 SP4; 6 SP1; 6 and 7 for Windows XP SP2 and SP3; 6 and 7 for Server 2003 SP2; 7 for Vista Gold, SP1, and SP2; and 7 for Server 2008 SP2 does not prevent HTML rendering of cached content, which allows remote attackers to bypass the Same Origin Policy via unspecified vectors, aka "Cross-Domain Information Disclosure Vulnerability."</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-160A.html" source="CERT">TA09-160A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS09-019.mspx" source="MS" patch="1" adv="1">MS09-019</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1538" source="VUPEN">ADV-2009-1538</ref>
      <ref url="http://www.securitytracker.com/id?1022350" source="SECTRACK">1022350</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6278" source="OVAL">oval:org.mitre.oval:def:6278</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="5.01" edition="sp4" />
        <vers num="6" edition="sp1" />
        <vers num="7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1141" published="2009-06-10" name="CVE-2009-1141" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Microsoft Internet Explorer 6 for Windows XP SP2 and SP3 and Server 2003 SP2 allows remote attackers to execute arbitrary code via unspecified DHTML function calls related to a tr element and the "insertion, deletion and attributes of a table cell," which trigger memory corruption when the window is destroyed, aka "DHTML Object Memory Corruption Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-160A.html" source="CERT">TA09-160A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS09-019.mspx" source="MS" patch="1" adv="1">MS09-019</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1538" source="VUPEN" adv="1">ADV-2009-1538</ref>
      <ref url="http://www.securitytracker.com/id?1022350" source="SECTRACK">1022350</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/504207/100/0/threaded" source="BUGTRAQ">20090610 FortiGuard Advisory: Microsoft Internet Explorer DHTML Handling Remote Memory Corruption Vulnerability</ref>
      <ref url="http://www.fortiguardcenter.com/advisory/FGA-2009-22.html" source="MISC">http://www.fortiguardcenter.com/advisory/FGA-2009-22.html</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5554" source="OVAL">oval:org.mitre.oval:def:5554</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1144" published="2009-04-09" name="CVE-2009-1144" modified="2009-04-16" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="6.9" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.4" CVSS_base_score="6.9">
    <desc>
      <descript source="cve">Untrusted search path vulnerability in the Gentoo package of Xpdf before 3.02-r2 allows local users to gain privileges via a Trojan horse xpdfrc file in the current working directory, related to an unset SYSTEM_XPDFRC macro in a Gentoo build process that uses the poppler library.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <local />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/34401" source="BID">34401</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200904-07.xml" source="GENTOO">GLSA-200904-07</ref>
      <ref url="http://secunia.com/advisories/34610" source="SECUNIA" adv="1">34610</ref>
      <ref url="http://osvdb.org/53529" source="OSVDB">53529</ref>
      <ref url="http://bugs.gentoo.org/show_bug.cgi?id=242930" source="CONFIRM" adv="1">http://bugs.gentoo.org/show_bug.cgi?id=242930</ref>
      <ref url="http://bugs.gentoo.org/show_bug.cgi?id=200023" source="CONFIRM" adv="1">http://bugs.gentoo.org/show_bug.cgi?id=200023</ref>
    </refs>
    <vuln_soft>
      <prod vendor="foolabs" name="xpdf">
        <vers num="0.2" />
        <vers num="0.3" />
        <vers num="0.4" />
        <vers num="0.5" />
        <vers num="0.5a" />
        <vers num="0.6" />
        <vers num="0.7" />
        <vers num="0.7a" />
        <vers num="0.80" />
        <vers num="0.90" />
        <vers num="0.91" />
        <vers num="0.91a" />
        <vers num="0.91b" />
        <vers num="0.91c" />
        <vers num="0.92a" />
        <vers num="0.92b" />
        <vers num="0.92c" />
        <vers num="0.92d" />
        <vers num="0.92e" />
        <vers num="0.93" />
        <vers num="0.93a" />
        <vers num="0.93b" />
        <vers num="0.93c" />
        <vers num="1.00" />
        <vers num="1.00a" />
        <vers num="1.01" />
        <vers num="2.00" />
        <vers num="2.01" />
        <vers num="2.02" />
        <vers num="2.03" />
        <vers num="3.00" />
        <vers prev="1" num="3.02" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1146" published="2009-04-06" name="CVE-2009-1146" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="4.9" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="3.9" CVSS_base_score="4.9">
    <desc>
      <descript source="cve">Unspecified vulnerability in an ioctl in hcmon.sys in VMware Workstation 6.5.1 and earlier, VMware Player 2.5.1 and earlier, VMware ACE 2.5.1 and earlier, and VMware Server 1.0.x before 1.0.9 build 156507 and 2.0.x before 2.0.1 build 156745 allows local users to cause a denial of service via unknown vectors, a different vulnerability than CVE-2008-3761.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://seclists.org/fulldisclosure/2009/Apr/0036.html" source="FULLDISC" patch="1">20090403 VMSA-2009-0005 VMware Hosted products, VI Client and patches for ESX and ESXi resolve multiple security issues</ref>
      <ref url="http://lists.vmware.com/pipermail/security-announce/2009/000054.html" source="MLIST" patch="1" adv="1">[security-announce] 20090403 VMSA-2009-0005 VMware Hosted products, VI Client and patches for ESX and ESXi resolve multiple security issues</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0944" source="VUPEN">ADV-2009-0944</ref>
      <ref url="http://www.vmware.com/security/advisories/VMSA-2009-0005.html" source="CONFIRM">http://www.vmware.com/security/advisories/VMSA-2009-0005.html</ref>
      <ref url="http://www.securitytracker.com/id?1021977" source="SECTRACK">1021977</ref>
      <ref url="http://www.securityfocus.com/bid/34373" source="BID">34373</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6310" source="OVAL">oval:org.mitre.oval:def:6310</ref>
    </refs>
    <vuln_soft>
      <prod vendor="vmware" name="ace">
        <vers num="1.0" />
        <vers num="1.0.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.5" />
        <vers num="1.0.6" />
        <vers num="1.0.7" />
        <vers num="2.0" />
        <vers num="2.0.1" />
        <vers num="2.0.2" />
        <vers num="2.0.3" />
        <vers num="2.0.4" />
        <vers num="2.0.5" />
        <vers num="2.5.0" />
        <vers prev="1" num="2.5.1" />
      </prod>
      <prod vendor="vmware" name="player">
        <vers num="1.0" />
        <vers num="1.0.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.5" />
        <vers num="1.0.6" />
        <vers num="1.0.7" />
        <vers num="1.0.8" />
        <vers num="2.0" />
        <vers num="2.0.1" />
        <vers num="2.0.2" />
        <vers num="2.0.3" />
        <vers num="2.0.4" />
        <vers num="2.0.5" />
        <vers num="2.5" />
        <vers prev="1" num="2.5.1" />
      </prod>
      <prod vendor="vmware" name="server">
        <vers num="1.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.5" />
        <vers num="1.0.6" />
        <vers num="1.0.7" />
        <vers num="1.0.8" />
        <vers num="2.0" />
      </prod>
      <prod vendor="vmware" name="workstation">
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.4" />
        <vers num="1.0.5" />
        <vers num="1.1" />
        <vers num="1.1.1" />
        <vers num="1.1.2" />
        <vers num="2.0" />
        <vers num="2.0.1" />
        <vers num="3.2.1" edition="patch1" />
        <vers num="3.4" />
        <vers num="4.0" />
        <vers num="4.0.1" />
        <vers num="4.0.2" />
        <vers num="4.5.2" />
        <vers num="5" />
        <vers num="5.5" />
        <vers num="5.5.1" />
        <vers num="5.5.2" />
        <vers num="5.5.3" />
        <vers num="5.5.4" />
        <vers num="5.5.5" />
        <vers num="5.5.6" />
        <vers num="5.5.7" />
        <vers num="5.5.8" />
        <vers num="6.0" />
        <vers num="6.0.1" />
        <vers num="6.0.2" />
        <vers num="6.0.3" />
        <vers num="6.0.4" />
        <vers num="6.0.5" />
        <vers num="6.5" />
        <vers prev="1" num="6.5.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1147" published="2009-04-06" name="CVE-2009-1147" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Unspecified vulnerability in vmci.sys in the Virtual Machine Communication Interface (VMCI) in VMware Workstation 6.5.1 and earlier, VMware Player 2.5.1 and earlier, VMware ACE 2.5.1 and earlier, and VMware Server 2.0.x before 2.0.1 build 156745 allows local users to gain privileges via unknown vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2009/0944" source="VUPEN">ADV-2009-0944</ref>
      <ref url="http://www.vmware.com/security/advisories/VMSA-2009-0005.html" source="CONFIRM">http://www.vmware.com/security/advisories/VMSA-2009-0005.html</ref>
      <ref url="http://www.securitytracker.com/id?1021976" source="SECTRACK">1021976</ref>
      <ref url="http://www.securityfocus.com/bid/34373" source="BID">34373</ref>
      <ref url="http://seclists.org/fulldisclosure/2009/Apr/0036.html" source="FULLDISC">20090403 VMSA-2009-0005 VMware Hosted products, VI Client and patches for ESX and ESXi resolve multiple security issues</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5471" source="OVAL">oval:org.mitre.oval:def:5471</ref>
      <ref url="http://lists.vmware.com/pipermail/security-announce/2009/000054.html" source="MLIST">[security-announce] 20090403 VMSA-2009-0005 VMware Hosted products, VI Client and patches for ESX and ESXi resolve multiple security issues</ref>
    </refs>
    <vuln_soft>
      <prod vendor="vmware" name="ace">
        <vers num="1.0" />
        <vers num="1.0.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.3_build_54075" />
        <vers num="1.0.4" />
        <vers num="1.0.5" />
        <vers num="1.0.6" />
        <vers num="1.0.7" />
        <vers num="2.0" />
        <vers num="2.0.1" />
        <vers num="2.0.1_build_55017" />
        <vers num="2.0.2" />
        <vers num="2.0.3" />
        <vers num="2.0.4" />
        <vers num="2.0.5" />
        <vers num="2.5.0" />
        <vers num="2.5.1" />
      </prod>
      <prod vendor="vmware" name="player">
        <vers num="1.0" />
        <vers num="1.0.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.5" />
        <vers num="1.0.5_build_56455" />
        <vers num="1.0.6" />
        <vers num="1.0.7" />
        <vers num="1.0.8" />
        <vers num="2.0" />
        <vers num="2.0.1" />
        <vers num="2.0.1_build_55017" />
        <vers num="2.0.2" />
        <vers num="2.0.3" />
        <vers num="2.0.4" />
        <vers num="2.0.5" />
        <vers num="2.5" />
        <vers num="2.5.1" />
      </prod>
      <prod vendor="vmware" name="server">
        <vers num="2.0" />
      </prod>
      <prod vendor="vmware" name="workstation">
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.4" />
        <vers num="1.0.5" />
        <vers num="1.1" />
        <vers num="1.1.1" />
        <vers num="1.1.2" />
        <vers num="2.0" />
        <vers num="2.0.1" />
        <vers num="3.2.1" edition="patch1" />
        <vers num="3.4" />
        <vers num="4.0" />
        <vers num="4.0.1" />
        <vers num="4.0.1_build_5289" />
        <vers num="4.0.2" />
        <vers num="4.5.2" />
        <vers num="4.5.2_build_8848" edition="r4" />
        <vers num="5" />
        <vers num="5.0.0_build_13124" />
        <vers num="5.5" />
        <vers num="5.5.0_build_13124" />
        <vers num="5.5.1" />
        <vers num="5.5.1_build_19175" />
        <vers num="5.5.2" />
        <vers num="5.5.3" edition="42958" />
        <vers num="5.5.3_build_34685" />
        <vers num="5.5.3_build_42958" />
        <vers num="5.5.4" />
        <vers num="5.5.4_build_44386" />
        <vers num="5.5.5" />
        <vers num="5.5.5_build_56455" />
        <vers num="5.5.6" />
        <vers num="5.5.7" />
        <vers num="5.5.8" />
        <vers num="6.0" />
        <vers num="6.0.1" />
        <vers num="6.0.1_build_55017" />
        <vers num="6.0.2" />
        <vers num="6.0.3" />
        <vers num="6.0.4" />
        <vers num="6.0.5" />
        <vers num="6.5" />
        <vers num="6.5.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1148" published="2009-03-26" name="CVE-2009-1148" modified="2009-04-16" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in bs_disp_as_mime_type.php in the BLOB streaming feature in phpMyAdmin before 3.1.3.1 allows remote attackers to read arbitrary files via directory traversal sequences in the file_path parameter ($filename variable).</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.phpmyadmin.net/home_page/security/PMASA-2009-1.php" source="CONFIRM" patch="1" adv="1">http://www.phpmyadmin.net/home_page/security/PMASA-2009-1.php</ref>
      <ref url="http://secunia.com/advisories/34642" source="SECUNIA">34642</ref>
      <ref url="http://secunia.com/advisories/34468" source="SECUNIA">34468</ref>
      <ref url="http://phpmyadmin.svn.sourceforge.net/viewvc/phpmyadmin/branches/MAINT_3_1_3/phpMyAdmin/bs_disp_as_mime_type.php?r1=12303&amp;r2=12302&amp;pathrev=12303" source="MISC">http://phpmyadmin.svn.sourceforge.net/viewvc/phpmyadmin/branches/MAINT_3_1_3/phpMyAdmin/bs_disp_as_mime_type.php?r1=12303&amp;r2=12302&amp;pathrev=12303</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-04/msg00003.html" source="SUSE">SUSE-SR:2009:008</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpmyadmin" name="phpmyadmin">
        <vers num="3.1.0" />
        <vers num="3.1.0.0" />
        <vers num="3.1.1" edition="rc1" />
        <vers num="3.1.2" edition="rc1" />
        <vers prev="1" num="3.1.3" edition="rc1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1149" published="2009-03-26" name="CVE-2009-1149" modified="2009-04-16" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">CRLF injection vulnerability in bs_disp_as_mime_type.php in the BLOB streaming feature in phpMyAdmin before 3.1.3.1 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the (1) c_type and possibly (2) file_type parameters.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.phpmyadmin.net/home_page/security/PMASA-2009-1.php" source="CONFIRM" patch="1" adv="1">http://www.phpmyadmin.net/home_page/security/PMASA-2009-1.php</ref>
      <ref url="http://phpmyadmin.svn.sourceforge.net/viewvc/phpmyadmin/branches/MAINT_3_1_3/phpMyAdmin/bs_disp_as_mime_type.php?r1=12303&amp;r2=12302&amp;pathrev=12303" source="MISC" patch="1">http://phpmyadmin.svn.sourceforge.net/viewvc/phpmyadmin/branches/MAINT_3_1_3/phpMyAdmin/bs_disp_as_mime_type.php?r1=12303&amp;r2=12302&amp;pathrev=12303</ref>
      <ref url="http://secunia.com/advisories/34642" source="SECUNIA">34642</ref>
      <ref url="http://secunia.com/advisories/34468" source="SECUNIA">34468</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-04/msg00003.html" source="SUSE">SUSE-SR:2009:008</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpmyadmin" name="phpmyadmin">
        <vers num="3.1.0" />
        <vers num="3.1.0.0" />
        <vers num="3.1.1" edition="rc1" />
        <vers num="3.1.2" edition="rc1" />
        <vers prev="1" num="3.1.3" edition="rc1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1150" published="2009-03-26" name="CVE-2009-1150" modified="2009-07-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in the export page (display_export.lib.php) in phpMyAdmin 2.11.x before 2.11.9.5 and 3.x before 3.1.3.1 allow remote attackers to inject arbitrary web script or HTML via the pma_db_filename_template cookie.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.phpmyadmin.net/home_page/security/PMASA-2009-2.php" source="CONFIRM" patch="1" adv="1">http://www.phpmyadmin.net/home_page/security/PMASA-2009-2.php</ref>
      <ref url="http://www.securityfocus.com/bid/34251" source="BID">34251</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:115" source="MANDRIVA">MDVSA-2009:115</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1824" source="DEBIAN">DSA-1824</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200906-03.xml" source="GENTOO">GLSA-200906-03</ref>
      <ref url="http://secunia.com/advisories/35635" source="SECUNIA" adv="1">35635</ref>
      <ref url="http://secunia.com/advisories/35585" source="SECUNIA" adv="1">35585</ref>
      <ref url="http://secunia.com/advisories/34642" source="SECUNIA" adv="1">34642</ref>
      <ref url="http://secunia.com/advisories/34430" source="SECUNIA" adv="1">34430</ref>
      <ref url="http://phpmyadmin.svn.sourceforge.net/viewvc/phpmyadmin/trunk/phpMyAdmin/libraries/display_export.lib.php?r1=11986&amp;r2=12302&amp;pathrev=12302" source="CONFIRM">http://phpmyadmin.svn.sourceforge.net/viewvc/phpmyadmin/trunk/phpMyAdmin/libraries/display_export.lib.php?r1=11986&amp;r2=12302&amp;pathrev=12302</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-04/msg00003.html" source="SUSE">SUSE-SR:2009:008</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpmyadmin" name="phpmyadmin">
        <vers num="2.11.0" edition="beta1" />
        <vers num="2.11.0" edition="rc1" />
        <vers num="2.11.1" edition="rc1" />
        <vers num="2.11.1.0" />
        <vers num="2.11.1.1" />
        <vers num="2.11.1.2" />
        <vers num="2.11.2" />
        <vers num="2.11.2.0" />
        <vers num="2.11.2.1" />
        <vers num="2.11.2.2" />
        <vers num="2.11.3" edition="rc1" />
        <vers num="2.11.3.0" />
        <vers num="2.11.4" edition="rc1" />
        <vers num="2.11.5" edition="rc1" />
        <vers num="2.11.5.0" />
        <vers num="2.11.5.1" />
        <vers num="2.11.5.2" />
        <vers num="2.11.6" edition="rc1" />
        <vers num="2.11.6.0" />
        <vers num="2.11.7" />
        <vers num="2.11.7.0" />
        <vers num="2.11.8" />
        <vers num="2.11.9" />
        <vers num="2.11.9.0" />
        <vers num="2.11.9.1" />
        <vers num="2.11.9.2" />
        <vers num="2.11.9.3" />
        <vers num="2.11.9.4" />
        <vers num="3.1.0" />
        <vers num="3.1.1" edition="rc1" />
        <vers num="3.1.2" edition="rc1" />
        <vers num="3.1.3" edition="rc1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1151" published="2009-03-26" name="CVE-2009-1151" modified="2009-07-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Static code injection vulnerability in setup.php in phpMyAdmin 2.11.x before 2.11.9.5 and 3.x before 3.1.3.1 allows remote attackers to inject arbitrary PHP code into a configuration file via the save action.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.phpmyadmin.net/home_page/security/PMASA-2009-3.php" source="CONFIRM" patch="1" adv="1">http://www.phpmyadmin.net/home_page/security/PMASA-2009-3.php</ref>
      <ref url="http://www.securityfocus.com/bid/34236" source="BID">34236</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/504191/100/0/threaded" source="BUGTRAQ">20090609 CVE-2009-1151: phpMyAdmin Remote Code Execution Proof of Concept</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:115" source="MANDRIVA">MDVSA-2009:115</ref>
      <ref url="http://www.gnucitizen.org/blog/cve-2009-1151-phpmyadmin-remote-code-execution-proof-of-concept/" source="MISC">http://www.gnucitizen.org/blog/cve-2009-1151-phpmyadmin-remote-code-execution-proof-of-concept/</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1824" source="DEBIAN">DSA-1824</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200906-03.xml" source="GENTOO">GLSA-200906-03</ref>
      <ref url="http://secunia.com/advisories/35635" source="SECUNIA" adv="1">35635</ref>
      <ref url="http://secunia.com/advisories/35585" source="SECUNIA" adv="1">35585</ref>
      <ref url="http://secunia.com/advisories/34642" source="SECUNIA" adv="1">34642</ref>
      <ref url="http://secunia.com/advisories/34430" source="SECUNIA" adv="1">34430</ref>
      <ref url="http://phpmyadmin.svn.sourceforge.net/viewvc/phpmyadmin/branches/MAINT_2_11_9/phpMyAdmin/scripts/setup.php?r1=11514&amp;r2=12301&amp;pathrev=12301" source="CONFIRM" adv="1">http://phpmyadmin.svn.sourceforge.net/viewvc/phpmyadmin/branches/MAINT_2_11_9/phpMyAdmin/scripts/setup.php?r1=11514&amp;r2=12301&amp;pathrev=12301</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-04/msg00003.html" source="SUSE">SUSE-SR:2009:008</ref>
      <ref url="http://labs.neohapsis.com/2009/04/06/about-cve-2009-1151/" source="MISC">http://labs.neohapsis.com/2009/04/06/about-cve-2009-1151/</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpmyadmin" name="phpmyadmin">
        <vers num="2.11.0" edition="beta1" />
        <vers num="2.11.0" edition="rc1" />
        <vers num="2.11.1" edition="rc1" />
        <vers num="2.11.1.0" />
        <vers num="2.11.1.1" />
        <vers num="2.11.1.2" />
        <vers num="2.11.2" />
        <vers num="2.11.2.0" />
        <vers num="2.11.2.1" />
        <vers num="2.11.2.2" />
        <vers num="2.11.3" edition="rc1" />
        <vers num="2.11.3.0" />
        <vers num="2.11.4" edition="rc1" />
        <vers num="2.11.5" edition="rc1" />
        <vers num="2.11.5.0" />
        <vers num="2.11.5.1" />
        <vers num="2.11.5.2" />
        <vers num="2.11.6" edition="rc1" />
        <vers num="2.11.6.0" />
        <vers num="2.11.7" />
        <vers num="2.11.7.0" />
        <vers num="2.11.8" />
        <vers num="2.11.9" />
        <vers num="2.11.9.0" />
        <vers num="2.11.9.1" />
        <vers num="2.11.9.2" />
        <vers num="2.11.9.3" />
        <vers num="2.11.9.4" />
        <vers num="3.1.0" />
        <vers num="3.1.1" edition="rc1" />
        <vers num="3.1.2" edition="rc1" />
        <vers prev="1" num="3.1.3" edition="rc1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1152" published="2009-03-26" name="CVE-2009-1152" modified="2009-03-26" CVSS_version="2.0" CVSS_vector="(AV:A/AC:M/Au:N/C:N/I:C/A:C)" CVSS_score="7.3" CVSS_impact_subscore="9.2" CVSS_exploit_subscore="5.5" CVSS_base_score="7.3">
    <desc>
      <descript source="cve">Siemens Gigaset SE461 WiMAX router 1.5-BL024.9.6401, and possibly other versions, allows remote attackers to cause a denial of service (device restart and loss of configuration) by connecting to TCP port 53, then closing the connection.</descript>
    </desc>
    <loss_types>
      <avail />
      <int />
    </loss_types>
    <range>
      <local_network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/49365" source="XF">gigaset-se461-html-dos(49365)</ref>
      <ref url="http://www.securityfocus.com/bid/34220" source="BID">34220</ref>
      <ref url="http://www.milw0rm.com/exploits/8260" source="MILW0RM">8260</ref>
      <ref url="http://helith.net/txt/siemens_gigaset_se461_wimax_router_remote_dos.txt" source="MISC">http://helith.net/txt/siemens_gigaset_se461_wimax_router_remote_dos.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="siemens" name="gigaset_se461__wimax_router">
        <vers num="1.5-bl024.9.6401" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2009-1154" published="2009-08-21" name="CVE-2009-1154" modified="2009-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:M/C:N/I:N/A:P)" CVSS_score="3.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="6.4" CVSS_base_score="3.3">
    <desc>
      <descript source="cve">Cisco IOS XR 3.8.1 and earlier allows remote attackers to cause a denial of service (process crash) via a long BGP UPDATE message, as demonstrated by a message with many AS numbers in the AS Path Attribute.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.cisco.com/en/US/products/products_security_advisory09186a0080af150f.shtml" source="CISCO" patch="1" adv="1">20090818 Cisco IOS XR Software Border Gateway Protocol Vulnerability</ref>
      <ref url="http://securitytracker.com/id?1022756" source="SECTRACK">1022756</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="ios_xr">
        <vers num="3.4" />
        <vers num="3.4.0" />
        <vers num="3.4.1" />
        <vers num="3.4.2" />
        <vers num="3.4.3" />
        <vers num="3.5" />
        <vers num="3.5.2" />
        <vers num="3.5.3" />
        <vers num="3.5.4" />
        <vers num="3.6.0" />
        <vers num="3.6.1" />
        <vers num="3.6.2" />
        <vers num="3.6.3" />
        <vers num="3.7.0" />
        <vers num="3.7.1" />
        <vers num="3.7.2" />
        <vers num="3.7.3" />
        <vers num="3.8.0" />
        <vers prev="1" num="3.8.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1155" published="2009-04-09" name="CVE-2009-1155" modified="2009-04-28" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:N/A:N)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Cisco Adaptive Security Appliances (ASA) 5500 Series and PIX Security Appliances 7.1(1) through 7.1(2)82, 7.2 before 7.2(4)27, 8.0 before 8.0(4)25, and 8.1 before 8.1(2)15, when AAA override-account-disable is entered in a general-attributes field, allow remote attackers to bypass authentication and establish a VPN session to an ASA device via unspecified vectors.</descript>
    </desc>
    <impacts>
      <impact source="nvd">Per vendor advisory: http://www.cisco.com/en/US/products/products_security_advisory09186a0080a994f6.shtml

"VPN Authentication Bypass Vulnerability

Cisco ASA or Cisco PIX security appliances that are configured for IPsec or SSL-based remote access VPN and have the Override Account Disabled feature enabled are affected by this vulnerability.

Note:  The Override Account Disabled feature was introduced in Cisco ASA software version 7.1(1). Cisco ASA and PIX software versions 7.1, 7.2, 8.0, and 8.1 are affected by this vulnerability. This feature is disabled by default. "</impact>
    </impacts>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.cisco.com/en/US/products/products_security_advisory09186a0080a994f6.shtml" source="CISCO" patch="1" adv="1">20090408 Multiple Vulnerabilities in Cisco ASA Adaptive Security Appliance and Cisco PIX Security Appliances</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0981" source="VUPEN">ADV-2009-0981</ref>
      <ref url="http://www.securitytracker.com/id?1022016" source="SECTRACK">1022016</ref>
      <ref url="http://www.securityfocus.com/bid/34429" source="BID">34429</ref>
      <ref url="http://secunia.com/advisories/34607" source="SECUNIA">34607</ref>
      <ref url="http://osvdb.org/53441" source="OSVDB">53441</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="adaptive_security_appliance_5500">
        <vers num="7.1" />
        <vers num="7.2" />
        <vers num="8.0" />
        <vers num="8.1" />
      </prod>
      <prod vendor="cisco" name="pix">
        <vers num="7.1" />
        <vers num="7.2" />
        <vers num="8.0" />
        <vers num="8.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1156" published="2009-04-09" name="CVE-2009-1156" modified="2009-04-28" CVSS_version="2.0" CVSS_vector="(AV:A/AC:M/Au:N/C:N/I:N/A:C)" CVSS_score="5.7" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="5.5" CVSS_base_score="5.7">
    <desc>
      <descript source="cve">Unspecified vulnerability on Cisco Adaptive Security Appliances (ASA) 5500 Series devices 8.0 before 8.0(4)25 and 8.1 before 8.1(2)15, when an SSL VPN or ASDM access is configured, allows remote attackers to cause a denial of service (device reload) via a crafted (1) SSL or (2) HTTP packet.</descript>
    </desc>
    <impacts>
      <impact source="nvd">Per vendor advisory: http://www.cisco.com/en/US/products/products_security_advisory09186a0080a994f6.shtml

VPN Authentication Bypass Vulnerability

The Cisco ASA or Cisco PIX security appliance can be configured to override an account-disabled indication from a AAA server and allow the user to log on anyway. However, the user must provide the correct credentials in order to login to the VPN. A vulnerability exists in the Cisco ASA and Cisco PIX security appliances where VPN users can bypass authentication when the override account feature is enabled.

Note:  The override account feature was introduced in Cisco ASA software version 7.1(1).

The override account feature is enabled with the override-account-disable command in tunnel-group general-attributes configuration mode, as shown in the following example. The following example allows overriding the "account-disabled" indicator from the AAA server for the WebVPN tunnel group "testgroup":

    hostname(config)#tunnel-group testgroup type webvpn
    hostname(config)#tunnel-group testgroup general-attributes
    hostname(config-tunnel-general)#override-account-disable

Note:  The override account feature is disabled by default. </impact>
    </impacts>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <local_network />
    </range>
    <refs>
      <ref url="http://www.cisco.com/en/US/products/products_security_advisory09186a0080a994f6.shtml" source="CISCO" patch="1" adv="1">20090408 Multiple Vulnerabilities in Cisco ASA Adaptive Security Appliance and Cisco PIX Security Appliances</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0981" source="VUPEN">ADV-2009-0981</ref>
      <ref url="http://www.securitytracker.com/id?1022015" source="SECTRACK">1022015</ref>
      <ref url="http://www.securityfocus.com/bid/34429" source="BID">34429</ref>
      <ref url="http://secunia.com/advisories/34607" source="SECUNIA">34607</ref>
      <ref url="http://osvdb.org/53442" source="OSVDB">53442</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="adaptive_security_appliance_5500">
        <vers num="8.0" />
        <vers num="8.1" />
      </prod>
      <prod vendor="cisco" name="pix">
        <vers num="8.0" />
        <vers num="8.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1157" published="2009-04-09" name="CVE-2009-1157" modified="2009-04-28" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Memory leak on Cisco Adaptive Security Appliances (ASA) 5500 Series and PIX Security Appliances 7.0 before 7.0(8)6, 7.1 before 7.1(2)82, 7.2 before 7.2(4)30, 8.0 before 8.0(4)28, and 8.1 before 8.1(2)19 allows remote attackers to cause a denial of service (memory consumption or device reload) via a crafted TCP packet.</descript>
    </desc>
    <impacts>
      <impact source="nvd">Per vendor advisory: http://www.cisco.com/en/US/products/products_security_advisory09186a0080a994f6.shtml

Crafted TCP Packet DoS Vulnerability

Cisco ASA and Cisco PIX security appliances may experience a memory leak that can be triggered by a series of crafted TCP packets. Cisco ASA and Cisco PIX security appliances running versions 7.0, 7.1, 7.2, 8.0, and 8.1 are affected when configured for any of the following features:

    * SSL VPNs
    * ASDM Administrative Access
    * Telnet Access
    * SSH Access
    * Cisco Tunneling Control Protocol (cTCP) for Remote Access VPNs
    * Virtual Telnet
    * Virtual HTTP
    * Transport Layer Security (TLS) Proxy for Encrypted Voice Inspection
    * Cut-Through Proxy for Network Access
    * TCP Intercept </impact>
    </impacts>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.cisco.com/en/US/products/products_security_advisory09186a0080a994f6.shtml" source="CISCO" patch="1" adv="1">20090408 Multiple Vulnerabilities in Cisco ASA Adaptive Security Appliance and Cisco PIX Security Appliances</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0981" source="VUPEN">ADV-2009-0981</ref>
      <ref url="http://www.securitytracker.com/id?1022015" source="SECTRACK">1022015</ref>
      <ref url="http://www.securityfocus.com/bid/34429" source="BID">34429</ref>
      <ref url="http://secunia.com/advisories/34607" source="SECUNIA">34607</ref>
      <ref url="http://osvdb.org/53445" source="OSVDB">53445</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="adaptive_security_appliance_5500">
        <vers num="7.0" />
        <vers num="7.1" />
        <vers num="7.2" />
        <vers num="8.0" />
        <vers num="8.1" />
      </prod>
      <prod vendor="cisco" name="pix">
        <vers num="7.0" />
        <vers num="7.1" />
        <vers num="7.2" />
        <vers num="8.0" />
        <vers num="8.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1158" published="2009-04-09" name="CVE-2009-1158" modified="2009-04-28" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Unspecified vulnerability on Cisco Adaptive Security Appliances (ASA) 5500 Series devices 7.0 before 7.0(8)6, 7.1 before 7.1(2)82, 7.2 before 7.2(4)26, 8.0 before 8.0(4)24, and 8.1 before 8.1(2)14, when H.323 inspection is enabled, allows remote attackers to cause a denial of service (device reload) via a crafted H.323 packet.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.cisco.com/en/US/products/products_security_advisory09186a0080a994f6.shtml" source="CISCO" patch="1" adv="1">20090408 Multiple Vulnerabilities in Cisco ASA Adaptive Security Appliance and Cisco PIX Security Appliances</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0981" source="VUPEN">ADV-2009-0981</ref>
      <ref url="http://www.securitytracker.com/id?1022015" source="SECTRACK">1022015</ref>
      <ref url="http://www.securityfocus.com/bid/34429" source="BID">34429</ref>
      <ref url="http://secunia.com/advisories/34607" source="SECUNIA">34607</ref>
      <ref url="http://osvdb.org/53444" source="OSVDB">53444</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="adaptive_security_appliance_5500">
        <vers num="7.0" />
        <vers num="7.1" />
        <vers num="7.2" />
        <vers num="8.0" />
        <vers num="8.1" />
      </prod>
      <prod vendor="cisco" name="pix">
        <vers num="7.0" />
        <vers num="7.1" />
        <vers num="7.2" />
        <vers num="8.0" />
        <vers num="8.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1159" published="2009-04-09" name="CVE-2009-1159" modified="2009-04-28" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Unspecified vulnerability on Cisco Adaptive Security Appliances (ASA) 5500 Series and PIX Security Appliances 7.2 before 7.2(4)26, 8.0 before 8.0(4)22, and 8.1 before 8.1(2)12, when SQL*Net inspection is enabled, allows remote attackers to cause a denial of service (traceback and device reload) via a series of SQL*Net packets.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.cisco.com/en/US/products/products_security_advisory09186a0080a994f6.shtml" source="CISCO" patch="1" adv="1">20090408 Multiple Vulnerabilities in Cisco ASA Adaptive Security Appliance and Cisco PIX Security Appliances</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0981" source="VUPEN">ADV-2009-0981</ref>
      <ref url="http://www.securitytracker.com/id?1022015" source="SECTRACK">1022015</ref>
      <ref url="http://www.securityfocus.com/bid/34429" source="BID">34429</ref>
      <ref url="http://secunia.com/advisories/34607" source="SECUNIA">34607</ref>
      <ref url="http://osvdb.org/53446" source="OSVDB">53446</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="adaptive_security_appliance_5500">
        <vers num="7.2" />
        <vers num="8.0" />
        <vers num="8.1" />
      </prod>
      <prod vendor="cisco" name="pix">
        <vers num="7.2" />
        <vers num="8.0" />
        <vers num="8.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1160" published="2009-04-09" name="CVE-2009-1160" modified="2009-04-28" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cisco Adaptive Security Appliances (ASA) 5500 Series and PIX Security Appliances 7.0 before 7.0(8)1, 7.1 before 7.1(2)74, 7.2 before 7.2(4)9, and 8.0 before 8.0(4)5 do not properly implement the implicit deny statement, which might allow remote attackers to successfully send packets that bypass intended access restrictions, aka Bug ID CSCsq91277.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.cisco.com/en/US/products/products_security_advisory09186a0080a994f6.shtml" source="CISCO" patch="1" adv="1">20090408 Multiple Vulnerabilities in Cisco ASA Adaptive Security Appliance and Cisco PIX Security Appliances</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0981" source="VUPEN">ADV-2009-0981</ref>
      <ref url="http://www.securitytracker.com/id?1022017" source="SECTRACK">1022017</ref>
      <ref url="http://www.securityfocus.com/bid/34429" source="BID">34429</ref>
      <ref url="http://secunia.com/advisories/34607" source="SECUNIA">34607</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="adaptive_security_appliance_5500">
        <vers num="7.0" />
        <vers num="7.1" />
        <vers num="7.2" />
        <vers num="8.0" />
        <vers num="8.1" />
      </prod>
      <prod vendor="cisco" name="pix">
        <vers num="7.0" />
        <vers num="7.1" />
        <vers num="7.2" />
        <vers num="8.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1161" published="2009-05-21" name="CVE-2009-1161" modified="2009-06-09" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in the TFTP service in Cisco CiscoWorks Common Services (CWCS) 3.0.x through 3.2.x on Windows, as used in Cisco Unified Service Monitor, Security Manager, TelePresence Readiness Assessment Manager, Unified Operations Manager, Unified Provisioning Manager, and other products, allows remote attackers to access arbitrary files via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.cisco.com/en/US/products/products_security_advisory09186a0080ab7b56.shtml" source="CISCO" patch="1" adv="1">20090520 CiscoWorks TFTP Directory Traversal Vulnerability</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1390" source="VUPEN">ADV-2009-1390</ref>
      <ref url="http://www.securityfocus.com/bid/35040" source="BID">35040</ref>
      <ref url="http://securitytracker.com/id?1022263" source="SECTRACK">1022263</ref>
      <ref url="http://secunia.com/advisories/35179" source="SECUNIA">35179</ref>
      <ref url="http://osvdb.org/54616" source="OSVDB">54616</ref>
      <ref url="http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-000032.html" source="JVNDB">JVNDB-2009-000032</ref>
      <ref url="http://jvn.jp/en/jp/JVN62527913/index.html" source="JVN">JVN#62527913</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="ciscoworks_common_services">
        <vers num="3.0.3" edition="" />
        <vers num="3.0.3" edition=":windows" />
        <vers num="3.0.4" edition="" />
        <vers num="3.0.4" edition=":windows" />
        <vers num="3.0.5" edition="" />
        <vers num="3.0.5" edition=":windows" />
        <vers num="3.0.6" edition="" />
        <vers num="3.0.6" edition=":windows" />
        <vers num="3.1" edition="" />
        <vers num="3.1" edition=":windows" />
        <vers num="3.1.1" edition="" />
        <vers num="3.1.1" edition=":windows" />
        <vers num="3.2" edition="" />
        <vers num="3.2" edition=":windows" />
      </prod>
      <prod vendor="cisco" name="ciscoworks_health_and_utilization_monitor">
        <vers num="1.0" />
        <vers num="1.1" />
      </prod>
      <prod vendor="cisco" name="ciscoworks_lan_management_solution">
        <vers num="2.5" />
        <vers num="2.6" />
        <vers num="3.0" />
        <vers num="3.1" />
      </prod>
      <prod vendor="cisco" name="ciscoworks_qos_policy_manager">
        <vers num="4.0" />
        <vers num="4.1" />
      </prod>
      <prod vendor="cisco" name="ciscoworks_voice_manager">
        <vers num="3.0" />
        <vers num="3.1" />
      </prod>
      <prod vendor="cisco" name="security_manager">
        <vers num="3.0" />
        <vers num="3.1" />
        <vers num="3.2" />
      </prod>
      <prod vendor="cisco" name="telepresence_readiness_assessment_manager">
        <vers num="1.0" />
      </prod>
      <prod vendor="cisco" name="unified_operations_manager">
        <vers num="1.0" />
        <vers num="1.1" />
        <vers num="2.0" />
        <vers num="2.1" />
      </prod>
      <prod vendor="cisco" name="unified_provisioning_manager">
        <vers num="1.0" />
        <vers num="1.1" />
        <vers num="1.2" />
        <vers num="1.3" />
      </prod>
      <prod vendor="cisco" name="unified_service_monitor">
        <vers num="1.0" />
        <vers num="1.1" />
        <vers num="2.0" />
        <vers num="2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1162" published="2009-06-05" name="CVE-2009-1162" modified="2009-06-12" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the Spam Quarantine login page in Cisco IronPort AsyncOS before 6.5.2 on Series C, M, and X appliances allows remote attackers to inject arbitrary web script or HTML via the referrer parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/50948" source="XF">ironport-asyncos-referrer-xss(50948)</ref>
      <ref url="http://www.securitytracker.com/id?1022335" source="SECTRACK">1022335</ref>
      <ref url="http://www.securityfocus.com/bid/35203" source="BID">35203</ref>
      <ref url="http://tools.cisco.com/security/center/viewAlert.x?alertId=18365" source="CONFIRM" adv="1">http://tools.cisco.com/security/center/viewAlert.x?alertId=18365</ref>
      <ref url="http://secunia.com/advisories/34895" source="SECUNIA" adv="1">34895</ref>
      <ref url="http://osvdb.org/54884" source="OSVDB">54884</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="ironport_email_security_appliances">
        <vers num="" edition="c" />
        <vers num="" edition="m" />
        <vers num="" edition="x" />
      </prod>
      <prod vendor="cisco" name="ironport_asyncos">
        <vers num="6.0.0-754" />
        <vers num="6.0.0-757" />
        <vers num="6.1.0-301" />
        <vers num="6.1.0-304" />
        <vers num="6.1.0-306" />
        <vers num="6.1.0-307" />
        <vers num="6.1.5-110" />
        <vers num="6.1.6-003" />
        <vers num="6.3.5-003" />
        <vers num="6.3.6-003" />
        <vers num="6.5.0-405" />
        <vers num="6.5.1-005" />
        <vers num="6.6.4.0-273" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1163" published="2009-06-24" name="CVE-2009-1163" modified="2009-07-01" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Memory leak on the Cisco Physical Access Gateway with software before 1.1 allows remote attackers to cause a denial of service (memory consumption) via unspecified TCP packets.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.cisco.com/en/US/products/products_security_advisory09186a0080ad0f8b.shtml" source="CISCO" patch="1" adv="1">20090624 Cisco Physical Access Gateway Denial of Service Vulnerability</ref>
      <ref url="http://www.securitytracker.com/id?1022444" source="SECTRACK">1022444</ref>
      <ref url="http://www.securityfocus.com/bid/35477" source="BID">35477</ref>
      <ref url="http://www.cisco.com/en/US/products/products_applied_mitigation_bulletin09186a0080ad0fb2.html" source="CONFIRM">http://www.cisco.com/en/US/products/products_applied_mitigation_bulletin09186a0080ad0fb2.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="physical_access_gateway">
        <vers prev="1" num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1164" published="2009-07-29" name="CVE-2009-1164" modified="2009-08-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">The administrative web interface on the Cisco Wireless LAN Controller (WLC) platform 4.2 before 4.2.205.0 and 5.x before 5.2.178.0, as used in Cisco 1500 Series, 2000 Series, 2100 Series, 4100 Series, 4200 Series, and 4400 Series Wireless Services Modules (WiSM), WLC Modules for Integrated Services Routers, and Catalyst 3750G Integrated Wireless LAN Controllers, allows remote attackers to cause a denial of service (device reload) via a malformed response to a (1) HTTP or (2) HTTPS authentication request, aka Bug ID CSCsx03715.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.cisco.com/en/US/products/products_security_advisory09186a0080adb3d7.shtml" source="CISCO" patch="1" adv="1">20090727 Multiple Vulnerabilities in Cisco Wireless LAN Controllers</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/2021" source="VUPEN">ADV-2009-2021</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="catalyst_3750g">
        <vers num="" />
      </prod>
      <prod vendor="cisco" name="cisco_1500_wireless_lan_controller">
        <vers num="4.2" />
        <vers num="5.0" />
        <vers num="5.1" />
        <vers num="5.2" />
      </prod>
      <prod vendor="cisco" name="cisco_2000_wireless_lan_controller">
        <vers num="4.2" />
        <vers num="5.0" />
        <vers num="5.1" />
        <vers num="5.2" />
      </prod>
      <prod vendor="cisco" name="cisco_2100_wireless_lan_controller">
        <vers num="4.2" />
        <vers num="5.0" />
        <vers num="5.1" />
        <vers num="5.2" />
      </prod>
      <prod vendor="cisco" name="cisco_4100_wireless_lan_controller">
        <vers num="4.2" />
        <vers num="5.0" />
        <vers num="5.1" />
        <vers num="5.2" />
      </prod>
      <prod vendor="cisco" name="cisco_4200_wireless_lan_controller">
        <vers num="4.2" />
        <vers num="5.0" />
        <vers num="5.1" />
        <vers num="5.2" />
      </prod>
      <prod vendor="cisco" name="cisco_4400_wireless_lan_controller">
        <vers num="4.2" />
        <vers num="5.0" />
        <vers num="5.1" />
        <vers num="5.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1165" published="2009-07-29" name="CVE-2009-1165" modified="2009-08-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Memory leak on the Cisco Wireless LAN Controller (WLC) platform 4.x before 4.2.205.0, 5.1 before 5.1.163.0, and 5.0 and 5.2 before 5.2.178.0, as used in Cisco 1500 Series, 2000 Series, 2100 Series, 4100 Series, 4200 Series, and 4400 Series Wireless Services Modules (WiSM), WLC Modules for Integrated Services Routers, and Catalyst 3750G Integrated Wireless LAN Controllers, allows remote attackers to cause a denial of service (memory consumption and device reload) via SSH management connections, aka Bug ID CSCsw40789.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.cisco.com/en/US/products/products_security_advisory09186a0080adb3d7.shtml" source="CISCO" patch="1" adv="1">20090727 Multiple Vulnerabilities in Cisco Wireless LAN Controllers</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/2021" source="VUPEN">ADV-2009-2021</ref>
      <ref url="http://www.securitytracker.com/id?1022605" source="SECTRACK">1022605</ref>
      <ref url="http://www.securityfocus.com/bid/35817" source="BID">35817</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="catalyst_3750g">
        <vers num="" />
      </prod>
      <prod vendor="cisco" name="cisco_1500_wireless_lan_controller">
        <vers num="4.1" />
        <vers num="4.1m" />
        <vers num="4.2" />
        <vers num="5.0" />
        <vers num="5.1" />
        <vers num="5.2" />
      </prod>
      <prod vendor="cisco" name="cisco_2000_wireless_lan_controller">
        <vers num="4.1" />
        <vers num="4.1m" />
        <vers num="4.2" />
        <vers num="5.0" />
        <vers num="5.1" />
        <vers num="5.2" />
      </prod>
      <prod vendor="cisco" name="cisco_2100_wireless_lan_controller">
        <vers num="4.1" />
        <vers num="4.1m" />
        <vers num="4.2" />
        <vers num="5.0" />
        <vers num="5.1" />
        <vers num="5.2" />
      </prod>
      <prod vendor="cisco" name="cisco_4100_wireless_lan_controller">
        <vers num="4.1" />
        <vers num="4.1m" />
        <vers num="4.2" />
        <vers num="5.0" />
        <vers num="5.1" />
        <vers num="5.2" />
      </prod>
      <prod vendor="cisco" name="cisco_4200_wireless_lan_controller">
        <vers num="4.1" />
        <vers num="4.1m" />
        <vers num="4.2" />
        <vers num="5.0" />
        <vers num="5.1" />
        <vers num="5.2" />
      </prod>
      <prod vendor="cisco" name="cisco_4400_wireless_lan_controller">
        <vers num="4.1" />
        <vers num="4.1m" />
        <vers num="4.2" />
        <vers num="5.0" />
        <vers num="5.1" />
        <vers num="5.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1166" published="2009-07-29" name="CVE-2009-1166" modified="2009-08-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">The administrative web interface on the Cisco Wireless LAN Controller (WLC) platform 4.x before 4.2.205.0 and 5.x before 5.2.191.0, as used in Cisco 1500 Series, 2000 Series, 2100 Series, 4100 Series, 4200 Series, and 4400 Series Wireless Services Modules (WiSM), WLC Modules for Integrated Services Routers, and Catalyst 3750G Integrated Wireless LAN Controllers, allows remote attackers to cause a denial of service (device reload) via a crafted (1) HTTP or (2) HTTPS request, aka Bug ID CSCsy27708.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.cisco.com/en/US/products/products_security_advisory09186a0080adb3d7.shtml" source="CISCO" patch="1" adv="1">20090727 Multiple Vulnerabilities in Cisco Wireless LAN Controllers</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/2021" source="VUPEN">ADV-2009-2021</ref>
      <ref url="http://www.securitytracker.com/id?1022605" source="SECTRACK">1022605</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="catalyst">
        <vers num="3750g" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1167" published="2009-07-29" name="CVE-2009-1167" modified="2009-08-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unspecified vulnerability on the Cisco Wireless LAN Controller (WLC) platform 4.x before 4.2.205.0 and 5.x before 5.2.191.0, as used in Cisco 1500 Series, 2000 Series, 2100 Series, 4100 Series, 4200 Series, and 4400 Series Wireless Services Modules (WiSM), WLC Modules for Integrated Services Routers, and Catalyst 3750G Integrated Wireless LAN Controllers, allows remote attackers to modify the configuration via a crafted (1) HTTP or (2) HTTPS request, aka Bug ID CSCsy44672.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2009/2021" source="VUPEN">ADV-2009-2021</ref>
      <ref url="http://www.securitytracker.com/id?1022606" source="SECTRACK">1022606</ref>
      <ref url="http://www.cisco.com/en/US/products/products_security_advisory09186a0080adb3d7.shtml" source="CISCO" adv="1">20090727 Multiple Vulnerabilities in Cisco Wireless LAN Controllers</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="catalyst_3750g">
        <vers num="" />
      </prod>
      <prod vendor="cisco" name="cisco_1500_wireless_lan_controller">
        <vers num="4.1" />
        <vers num="4.1m" />
        <vers num="4.2" />
        <vers num="5.0" />
        <vers num="5.1" />
        <vers num="5.2" />
      </prod>
      <prod vendor="cisco" name="cisco_2000_wireless_lan_controller">
        <vers num="4.1" />
        <vers num="4.1m" />
        <vers num="4.2" />
        <vers num="5.0" />
        <vers num="5.1" />
        <vers num="5.2" />
      </prod>
      <prod vendor="cisco" name="cisco_2100_wireless_lan_controller">
        <vers num="4.1" />
        <vers num="4.1m" />
        <vers num="4.2" />
        <vers num="5.0" />
        <vers num="5.1" />
        <vers num="5.2" />
      </prod>
      <prod vendor="cisco" name="cisco_4100_wireless_lan_controller">
        <vers num="4.1" />
        <vers num="4.1m" />
        <vers num="4.2" />
        <vers num="5.0" />
        <vers num="5.1" />
        <vers num="5.2" />
      </prod>
      <prod vendor="cisco" name="cisco_4200_wireless_lan_controller">
        <vers num="4.1" />
        <vers num="4.1m" />
        <vers num="4.2" />
        <vers num="5.0" />
        <vers num="5.1" />
        <vers num="5.2" />
      </prod>
      <prod vendor="cisco" name="cisco_4400_wireless_lan_controller">
        <vers num="4.1" />
        <vers num="4.1m" />
        <vers num="4.2" />
        <vers num="5.0" />
        <vers num="5.1" />
        <vers num="5.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1168" published="2009-07-30" name="CVE-2009-1168" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:C)" CVSS_score="7.1" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="8.6" CVSS_base_score="7.1">
    <desc>
      <descript source="cve">Cisco IOS 12.0(32)S12 through 12.0(32)S13 and 12.0(33)S3 through 12.0(33)S4, 12.0(32)SY8 through 12.0(32)SY9, 12.2(33)SXI1, 12.2XNC before 12.2(33)XNC2, 12.2XND before 12.2(33)XND1, and 12.4(24)T1; and IOS XE 2.3 through 2.3.1t and 2.4 through 2.4.0; when RFC4893 BGP routing is enabled, allows remote attackers to cause a denial of service (memory corruption and device reload) by using an RFC4271 peer to send an update with a long series of AS numbers, aka Bug ID CSCsy86021.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.cisco.com/en/US/products/products_security_advisory09186a0080aea4c9.shtml" source="CISCO" patch="1" adv="1">20090729 Cisco IOS Software Border Gateway Protocol 4-Byte Autonomous System Number Vulnerabilities</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/2082" source="VUPEN">ADV-2009-2082</ref>
      <ref url="http://www.securitytracker.com/id?1022619" source="SECTRACK">1022619</ref>
      <ref url="http://www.securityfocus.com/bid/35862" source="BID">35862</ref>
      <ref url="http://secunia.com/advisories/36046" source="SECUNIA">36046</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6697" source="OVAL">oval:org.mitre.oval:def:6697</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="ios">
        <vers num="12.0(32)s12" />
        <vers num="12.0(32)s13" />
        <vers num="12.0(32)sy8" />
        <vers num="12.0(32)sy9" />
        <vers num="12.0(33)s3" />
        <vers num="12.0(33)s4" />
        <vers num="12.2(33)sxi1" />
        <vers num="12.2(33)sxi2" />
        <vers num="12.2xnc" />
        <vers num="12.2xnd" />
        <vers num="12.4(24)t1" />
      </prod>
      <prod vendor="cisco" name="ios_xe">
        <vers num="2.3" />
        <vers num="2.3.1t" />
        <vers num="2.4" />
        <vers num="2.4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1169" published="2009-03-26" name="CVE-2009-1169" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">The txMozillaXSLTProcessor::TransformToDoc function in Mozilla Firefox before 3.0.8 and SeaMonkey before 1.1.16 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via an XML file with a crafted XSLT transform.</descript>
    </desc>
    <impacts>
      <impact source="nvd">Per: http://www.securityfocus.com/bid/34235/info

Mozilla Firefox is prone to a remote memory-corruption vulnerability.

An attacker can exploit this issue to execute arbitrary code within the context of the affected browser. Failed exploit attempt will result in a denial-of-service condition. </impact>
    </impacts>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=485286" source="CONFIRM" patch="1">https://bugzilla.mozilla.org/show_bug.cgi?id=485286</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=485217" source="CONFIRM" patch="1">https://bugzilla.mozilla.org/show_bug.cgi?id=485217</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0853" source="VUPEN" patch="1" adv="1">ADV-2009-0853</ref>
      <ref url="http://www.securityfocus.com/bid/34235" source="BID" patch="1">34235</ref>
      <ref url="http://www.mozilla.org/security/announce/2009/mfsa2009-12.html" source="CONFIRM" patch="1" adv="1">http://www.mozilla.org/security/announce/2009/mfsa2009-12.html</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-04/msg00009.html" source="SUSE" patch="1">SUSE-SA:2009:023</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-04/msg00008.html" source="SUSE" patch="1">SUSE-SA:2009:022</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-March/msg01077.html" source="FEDORA">FEDORA-2009-3101</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-March/msg01040.html" source="FEDORA">FEDORA-2009-3100</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-March/msg01023.html" source="FEDORA">FEDORA-2009-3099</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=460090" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=460090</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/49439" source="XF">mozilla-xslt-code-execution(49439)</ref>
      <ref url="http://www.ubuntu.com/usn/usn-745-1" source="UBUNTU">USN-745-1</ref>
      <ref url="http://www.securitytracker.com/id?1021939" source="SECTRACK">1021939</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-0398.html" source="REDHAT">RHSA-2009:0398</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-0397.html" source="REDHAT">RHSA-2009:0397</ref>
      <ref url="http://www.milw0rm.com/exploits/8285" source="MILW0RM">8285</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:084" source="MANDRIVA">MDVSA-2009:084</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1756" source="DEBIAN">DSA-1756</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2009-113.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2009-113.htm</ref>
      <ref url="http://secunia.com/advisories/34792" source="SECUNIA" adv="1">34792</ref>
      <ref url="http://secunia.com/advisories/34550" source="SECUNIA" adv="1">34550</ref>
      <ref url="http://secunia.com/advisories/34549" source="SECUNIA" adv="1">34549</ref>
      <ref url="http://secunia.com/advisories/34527" source="SECUNIA" adv="1">34527</ref>
      <ref url="http://secunia.com/advisories/34521" source="SECUNIA" adv="1">34521</ref>
      <ref url="http://secunia.com/advisories/34511" source="SECUNIA" adv="1">34511</ref>
      <ref url="http://secunia.com/advisories/34510" source="SECUNIA" adv="1">34510</ref>
      <ref url="http://secunia.com/advisories/34505" source="SECUNIA" adv="1">34505</ref>
      <ref url="http://secunia.com/advisories/34486" source="SECUNIA" adv="1">34486</ref>
      <ref url="http://secunia.com/advisories/34471" source="SECUNIA" adv="1">34471</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11372" source="OVAL">oval:org.mitre.oval:def:11372</ref>
      <ref url="http://blogs.zdnet.com/security/?p=3013" source="MISC">http://blogs.zdnet.com/security/?p=3013</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="0.1" />
        <vers num="0.10" />
        <vers num="0.10.1" />
        <vers num="0.2" />
        <vers num="0.3" />
        <vers num="0.4" />
        <vers num="0.5" />
        <vers num="0.6" />
        <vers num="0.6.1" />
        <vers num="0.7" />
        <vers num="0.7.1" />
        <vers num="0.8" />
        <vers num="0.9" edition="rc" />
        <vers num="0.9.1" />
        <vers num="0.9.2" />
        <vers num="0.9.3" />
        <vers num="0.9_rc" />
        <vers num="1.0" edition="preview_release" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.5" />
        <vers num="1.0.6" edition="" />
        <vers num="1.0.6" edition=":linux" />
        <vers num="1.0.7" />
        <vers num="1.0.8" />
        <vers num="1.5" edition="beta1" />
        <vers num="1.5" edition="beta2" />
        <vers num="1.5.0.1" />
        <vers num="1.5.0.10" />
        <vers num="1.5.0.11" />
        <vers num="1.5.0.12" />
        <vers num="1.5.0.2" />
        <vers num="1.5.0.3" />
        <vers num="1.5.0.4" />
        <vers num="1.5.0.5" />
        <vers num="1.5.0.6" />
        <vers num="1.5.0.7" />
        <vers num="1.5.0.8" />
        <vers num="1.5.0.9" />
        <vers num="1.5.1" />
        <vers num="1.5.2" />
        <vers num="1.5.3" />
        <vers num="1.5.4" />
        <vers num="1.5.5" />
        <vers num="1.5.6" />
        <vers num="1.5.7" />
        <vers num="1.5.8" />
        <vers num="1.8" />
        <vers num="2.0" edition="beta1" />
        <vers num="2.0" edition="beta_1" />
        <vers num="2.0" edition="rc2" />
        <vers num="2.0" edition="rc3" />
        <vers num="2.0.0.1" />
        <vers num="2.0.0.10" />
        <vers num="2.0.0.11" />
        <vers num="2.0.0.12" />
        <vers num="2.0.0.13" />
        <vers num="2.0.0.14" />
        <vers num="2.0.0.15" />
        <vers num="2.0.0.16" />
        <vers num="2.0.0.17" />
        <vers num="2.0.0.18" />
        <vers num="2.0.0.19" />
        <vers num="2.0.0.2" />
        <vers num="2.0.0.20" />
        <vers num="2.0.0.21" />
        <vers num="2.0.0.3" />
        <vers num="2.0.0.4" />
        <vers num="2.0.0.5" />
        <vers num="2.0.0.6" />
        <vers num="2.0.0.7" />
        <vers num="2.0.0.8" />
        <vers num="2.0.0.9" />
        <vers num="2.0_.1" />
        <vers num="2.0_.10" />
        <vers num="2.0_.4" />
        <vers num="2.0_.5" />
        <vers num="2.0_.6" />
        <vers num="2.0_.7" />
        <vers num="2.0_.9" />
        <vers num="2.0_8" />
        <vers num="3.0" edition="alpha" />
        <vers num="3.0" edition="beta2" />
        <vers num="3.0" edition="beta5" />
        <vers num="3.0.1" />
        <vers num="3.0.2" />
        <vers num="3.0.3" />
        <vers num="3.0.4" />
        <vers num="3.0.5" />
        <vers num="3.0.6" />
        <vers prev="1" num="3.0.7" />
        <vers num="3.0beta5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1170" published="2009-03-30" name="CVE-2009-1170" modified="2009-04-02" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="6.9" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.4" CVSS_base_score="6.9">
    <desc>
      <descript source="cve">Unspecified vulnerability in Sun OpenSolaris snv_100 through snv_101 allows local users, with privileges in a non-global zone, to execute arbitrary code in the global zone when a global-zone user is using mdb on a non-global zone process.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/49468" source="XF">opensolaris-mdb-code-execution(49468)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0877" source="VUPEN">ADV-2009-0877</ref>
      <ref url="http://www.securitytracker.com/id?1021944" source="SECTRACK">1021944</ref>
      <ref url="http://www.securityfocus.com/bid/34272" source="BID">34272</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-255608-1" source="SUNALERT" adv="1">255608</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="opensolaris">
        <vers num="snv_100" edition="" />
        <vers num="snv_100" edition=":x86" />
        <vers num="snv_100" edition=":sparc" />
        <vers num="snv_101" edition="" />
        <vers num="snv_101" edition=":sparc" />
        <vers num="snv_101" edition=":x86" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1171" published="2009-03-30" name="CVE-2009-1171" modified="2009-07-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">The TeX filter in Moodle 1.6 before 1.6.9+, 1.7 before 1.7.7+, 1.8 before 1.8.9, and 1.9 before 1.9.5 allows user-assisted attackers to read arbitrary files via an input command in a "$$" sequence, which causes LaTeX to include the contents of the file.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-April/msg00079.html" source="FEDORA">FEDORA-2009-3283</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-April/msg00077.html" source="FEDORA">FEDORA-2009-3280</ref>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-791-2" source="UBUNTU">USN-791-2</ref>
      <ref url="http://www.milw0rm.com/exploits/8297" source="MILW0RM">8297</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1761" source="DEBIAN">DSA-1761</ref>
      <ref url="http://tracker.moodle.org/browse/MDL-18552" source="MISC">http://tracker.moodle.org/browse/MDL-18552</ref>
      <ref url="http://secunia.com/advisories/35570" source="SECUNIA">35570</ref>
      <ref url="http://secunia.com/advisories/34600" source="SECUNIA">34600</ref>
      <ref url="http://secunia.com/advisories/34557" source="SECUNIA">34557</ref>
      <ref url="http://secunia.com/advisories/34517" source="SECUNIA">34517</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-04/msg00010.html" source="SUSE">SUSE-SR:2009:009</ref>
      <ref url="http://cvs.moodle.org/moodle/filter/tex/filter.php?r1=1.18.4.4&amp;r2=1.18.4.5" source="CONFIRM">http://cvs.moodle.org/moodle/filter/tex/filter.php?r1=1.18.4.4&amp;r2=1.18.4.5</ref>
    </refs>
    <vuln_soft>
      <prod vendor="moodle" name="moodle">
        <vers num="1.6" />
        <vers num="1.6.1" />
        <vers num="1.6.2" />
        <vers num="1.6.3" />
        <vers num="1.6.4" />
        <vers num="1.6.5" />
        <vers num="1.6.6" />
        <vers num="1.6.7" />
        <vers num="1.6.8" />
        <vers num="1.7" />
        <vers num="1.7.1" />
        <vers num="1.7.2" />
        <vers num="1.7.3" />
        <vers num="1.7.4" />
        <vers num="1.7.5" />
        <vers num="1.7.6" />
        <vers num="1.8" />
        <vers num="1.8.1" />
        <vers num="1.8.2" />
        <vers num="1.8.3" />
        <vers num="1.8.4" />
        <vers num="1.8.5" />
        <vers num="1.8.6" />
        <vers num="1.8.7" />
        <vers num="1.8.8" />
        <vers num="1.9" />
        <vers num="1.9.1" />
        <vers num="1.9.2" />
        <vers num="1.9.3" />
        <vers num="1.9.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1172" published="2009-03-31" name="CVE-2009-1172" modified="2009-06-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">The JAX-RPC WS-Security runtime in the Web Services Security component in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.23 and 7.0 before 7.0.0.3, when APAR PK41002 is installed, does not properly validate UsernameToken objects, which has unknown impact and attack vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg27014463" source="CONFIRM" patch="1">http://www-01.ibm.com/support/docview.wss?uid=swg27014463</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg27007951" source="CONFIRM" patch="1">http://www-01.ibm.com/support/docview.wss?uid=swg27007951</ref>
      <ref url="http://www.securityfocus.com/bid/34502" source="BID">34502</ref>
      <ref url="http://secunia.com/advisories/34461" source="SECUNIA" adv="1">34461</ref>
      <ref url="http://secunia.com/advisories/34131" source="SECUNIA" adv="1">34131</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="websphere_application_server">
        <vers num="6.1" />
        <vers num="6.1.0" />
        <vers num="6.1.0.0" />
        <vers num="6.1.0.1" />
        <vers num="6.1.0.10" />
        <vers num="6.1.0.11" />
        <vers num="6.1.0.12" />
        <vers num="6.1.0.13" />
        <vers num="6.1.0.14" />
        <vers num="6.1.0.15" />
        <vers num="6.1.0.16" />
        <vers num="6.1.0.17" />
        <vers num="6.1.0.18" />
        <vers num="6.1.0.19" />
        <vers num="6.1.0.2" />
        <vers num="6.1.0.20" />
        <vers num="6.1.0.21" />
        <vers num="6.1.0.22" />
        <vers num="6.1.0.3" />
        <vers num="6.1.0.4" />
        <vers num="6.1.0.5" />
        <vers num="6.1.0.6" />
        <vers num="6.1.0.7" />
        <vers num="6.1.0.8" />
        <vers num="6.1.0.9" />
        <vers num="7.0" />
        <vers num="7.0.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2009-1173" published="2009-03-31" name="CVE-2009-1173" modified="2009-06-16" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.3 uses weak permissions (777) for files associated with unspecified "interim fixes," which allows attackers to modify files that would not have been accessible if the intended 755 permissions were used.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2009/0854" source="VUPEN" patch="1" adv="1">ADV-2009-0854</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg27014463" source="CONFIRM" patch="1">http://www-01.ibm.com/support/docview.wss?uid=swg27014463</ref>
      <ref url="http://www.securityfocus.com/bid/34259" source="BID">34259</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg1PK82988" source="AIXAPAR">PK82988</ref>
      <ref url="http://secunia.com/advisories/34461" source="SECUNIA" adv="1">34461</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="websphere_application_server">
        <vers num="7.0" />
        <vers num="7.0.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1174" published="2009-03-31" name="CVE-2009-1174" modified="2009-06-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">The Web Services Security component in IBM WebSphere Application Server (WAS) 6.0.2 before 6.0.2.35 and 7.0 before 7.0.0.3 has an unspecified "security problem" in the XML digital-signature specification, which has unknown impact and attack vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg27014463" source="CONFIRM" patch="1">http://www-01.ibm.com/support/docview.wss?uid=swg27014463</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1464" source="VUPEN">ADV-2009-1464</ref>
      <ref url="http://www.securityfocus.com/bid/34506" source="BID">34506</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg27006876" source="CONFIRM">http://www-01.ibm.com/support/docview.wss?uid=swg27006876</ref>
      <ref url="http://secunia.com/advisories/35301" source="SECUNIA">35301</ref>
      <ref url="http://secunia.com/advisories/34461" source="SECUNIA" adv="1">34461</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="websphere_application_server">
        <vers num="7.0" />
        <vers num="7.0.0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1175" published="2009-03-31" name="CVE-2009-1175" modified="2009-04-02" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in apps/web/vs_diag.cgi in the DAAP extension in Banshee 1.4.2 allows remote attackers to inject arbitrary web script or HTML via the server parameter, which is not properly handled in an error message.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.openwall.com/lists/oss-security/2009/03/30/2" source="MLIST">[oss-security] 20090330 [Fwd: Cross-Site Scripting in Banshee DAAP Extension]</ref>
      <ref url="http://bugzilla.gnome.org/show_bug.cgi?id=577270" source="CONFIRM">http://bugzilla.gnome.org/show_bug.cgi?id=577270</ref>
    </refs>
    <vuln_soft>
      <prod vendor="banshee-project" name="banshee">
        <vers num="1.4.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1176" published="2009-03-31" name="CVE-2009-1176" modified="2009-04-18" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">mapserv.c in mapserv in MapServer 4.x before 4.10.4 and 5.x before 5.2.2 does not ensure that the string holding the id parameter ends in a '\0' character, which allows remote attackers to conduct buffer-overflow attacks or have unspecified other impact via a long id parameter in a query action.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://lists.osgeo.org/pipermail/mapserver-users/2009-March/060600.html" source="MLIST" patch="1">[mapserver-users] 20090326 MapServer 5.2.2 and 4.10.4 released with security fixes</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-April/msg00170.html" source="FEDORA">FEDORA-2009-3383</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-April/msg00147.html" source="FEDORA">FEDORA-2009-3357</ref>
      <ref url="http://www.securitytracker.com/id?1021952" source="SECTRACK">1021952</ref>
      <ref url="http://www.securityfocus.com/bid/34306" source="BID">34306</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/502271/100/0/threaded" source="BUGTRAQ">20090330 Positron Security Advisory #2009-000: Multiple Vulnerabilities in MapServer v5.2.1 and v4.10.3</ref>
      <ref url="http://www.positronsecurity.com/advisories/2009-000.html" source="MISC">http://www.positronsecurity.com/advisories/2009-000.html</ref>
      <ref url="http://secunia.com/advisories/34603" source="SECUNIA">34603</ref>
    </refs>
    <vuln_soft>
      <prod vendor="umn" name="mapserver">
        <vers num="4.0" edition="beta1" />
        <vers num="4.0" edition="beta2" />
        <vers num="4.10" edition="beta1" />
        <vers num="4.10" edition="beta2" />
        <vers num="4.10" edition="beta3" />
        <vers num="4.10" edition="rc1" />
        <vers num="4.10.0" />
        <vers num="4.10.1" />
        <vers num="4.10.2" />
        <vers num="4.10.3" />
        <vers num="4.2" edition="beta1" />
        <vers num="4.4.0" edition="beta1" />
        <vers num="4.4.0" edition="beta2" />
        <vers num="4.4.0" edition="beta3" />
        <vers num="4.6.0" edition="beta1" />
        <vers num="4.6.0" edition="beta2" />
        <vers num="4.6.0" edition="beta3" />
        <vers num="4.6.0" edition="rc1" />
        <vers num="4.8" edition="beta1" />
        <vers num="4.8" edition="beta2" />
        <vers num="4.8" edition="beta3" />
        <vers num="4.8" edition="rc1" />
        <vers num="4.8" edition="rc2" />
        <vers num="5.0.0" edition="beta1" />
        <vers num="5.0.0" edition="beta2" />
        <vers num="5.0.0" edition="beta3" />
        <vers num="5.0.0" edition="beta4" />
        <vers num="5.0.0" edition="beta5" />
        <vers num="5.0.0" edition="beta6" />
        <vers num="5.0.0" edition="rc1" />
        <vers num="5.0.0" edition="rc2" />
        <vers num="5.2.0" edition="beta1" />
        <vers num="5.2.0" edition="beta2" />
        <vers num="5.2.0" edition="beta3" />
        <vers num="5.2.0" edition="beta4" />
        <vers num="5.2.0" edition="rc1" />
        <vers num="5.2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1177" published="2009-03-31" name="CVE-2009-1177" modified="2009-04-18" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Multiple stack-based buffer overflows in maptemplate.c in mapserv in MapServer 4.x before 4.10.4 and 5.x before 5.2.2 have unknown impact and remote attack vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://lists.osgeo.org/pipermail/mapserver-users/2009-March/060600.html" source="MLIST" patch="1">[mapserver-users] 20090326 MapServer 5.2.2 and 4.10.4 released with security fixes</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-April/msg00170.html" source="FEDORA">FEDORA-2009-3383</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-April/msg00147.html" source="FEDORA">FEDORA-2009-3357</ref>
      <ref url="http://www.securitytracker.com/id?1021952" source="SECTRACK">1021952</ref>
      <ref url="http://www.securityfocus.com/bid/34306" source="BID">34306</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/502271/100/0/threaded" source="BUGTRAQ">20090330 Positron Security Advisory #2009-000: Multiple Vulnerabilities in MapServer v5.2.1 and v4.10.3</ref>
      <ref url="http://www.positronsecurity.com/advisories/2009-000.html" source="MISC">http://www.positronsecurity.com/advisories/2009-000.html</ref>
      <ref url="http://trac.osgeo.org/mapserver/ticket/2944" source="CONFIRM">http://trac.osgeo.org/mapserver/ticket/2944</ref>
      <ref url="http://secunia.com/advisories/34603" source="SECUNIA">34603</ref>
    </refs>
    <vuln_soft>
      <prod vendor="umn" name="mapserver">
        <vers num="4.0" edition="beta1" />
        <vers num="4.0" edition="beta2" />
        <vers num="4.10" edition="beta1" />
        <vers num="4.10" edition="beta2" />
        <vers num="4.10" edition="beta3" />
        <vers num="4.10" edition="rc1" />
        <vers num="4.10.0" />
        <vers num="4.10.1" />
        <vers num="4.10.2" />
        <vers num="4.10.3" />
        <vers num="4.2" edition="beta1" />
        <vers num="4.4.0" edition="beta1" />
        <vers num="4.4.0" edition="beta2" />
        <vers num="4.4.0" edition="beta3" />
        <vers num="4.6.0" edition="beta1" />
        <vers num="4.6.0" edition="beta2" />
        <vers num="4.6.0" edition="beta3" />
        <vers num="4.6.0" edition="rc1" />
        <vers num="4.8" edition="beta1" />
        <vers num="4.8" edition="beta2" />
        <vers num="4.8" edition="beta3" />
        <vers num="4.8" edition="rc1" />
        <vers num="4.8" edition="rc2" />
        <vers num="5.0.0" edition="beta1" />
        <vers num="5.0.0" edition="beta2" />
        <vers num="5.0.0" edition="beta3" />
        <vers num="5.0.0" edition="beta4" />
        <vers num="5.0.0" edition="beta5" />
        <vers num="5.0.0" edition="beta6" />
        <vers num="5.0.0" edition="rc1" />
        <vers num="5.0.0" edition="rc2" />
        <vers num="5.2.0" edition="beta1" />
        <vers num="5.2.0" edition="beta2" />
        <vers num="5.2.0" edition="beta3" />
        <vers num="5.2.0" edition="beta4" />
        <vers num="5.2.0" edition="rc1" />
        <vers num="5.2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1178" published="2009-03-31" name="CVE-2009-1178" modified="2009-04-01" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the server in IBM Tivoli Storage Manager (TSM) 5.3.x before 5.3.2 and 6.x before 6.1 has unknown impact and attack vectors related to the "admin command line."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg21246076" source="CONFIRM" patch="1">http://www-01.ibm.com/support/docview.wss?uid=swg21246076</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0881" source="VUPEN" adv="1">ADV-2009-0881</ref>
      <ref url="http://www.securityfocus.com/bid/34285" source="BID">34285</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg21375360" source="CONFIRM">http://www-01.ibm.com/support/docview.wss?uid=swg21375360</ref>
      <ref url="http://securitytracker.com/id?1021945" source="SECTRACK">1021945</ref>
      <ref url="http://secunia.com/advisories/34498" source="SECUNIA" adv="1">34498</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="tivoli_storage_manager">
        <vers num="5.3.0" />
        <vers num="5.3.1" />
        <vers num="6.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1179" published="2009-04-23" name="CVE-2009-1179" modified="2012-01-18" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Integer overflow in the JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, Poppler before 0.10.6, and other products allows remote attackers to execute arbitrary code via a crafted PDF file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/196617" source="CERT-VN">VU#196617</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-0430.html" source="REDHAT" patch="1">RHSA-2009:0430</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-June/msg01291.html" source="FEDORA">FEDORA-2009-6982</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-June/msg01277.html" source="FEDORA">FEDORA-2009-6973</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-July/msg00567.html" source="FEDORA">FEDORA-2009-6972</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=495889" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=495889</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1040" source="VUPEN" adv="1">ADV-2010-1040</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1621" source="VUPEN" adv="1">ADV-2009-1621</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1522" source="VUPEN" adv="1">ADV-2009-1522</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1077" source="VUPEN" adv="1">ADV-2009-1077</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1076" source="VUPEN" adv="1">ADV-2009-1076</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1066" source="VUPEN" adv="1">ADV-2009-1066</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1065" source="VUPEN" adv="1">ADV-2009-1065</ref>
      <ref url="http://www.securitytracker.com/id?1022073" source="SECTRACK">1022073</ref>
      <ref url="http://www.securityfocus.com/bid/34568" source="BID">34568</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-0480.html" source="REDHAT">RHSA-2009:0480</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-0431.html" source="REDHAT">RHSA-2009:0431</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-0429.html" source="REDHAT">RHSA-2009:0429</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2011:175" source="MANDRIVA">MDVSA-2011:175</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2010:087" source="MANDRIVA">MDVSA-2010:087</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:101" source="MANDRIVA">MDVSA-2009:101</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1793" source="DEBIAN">DSA-1793</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1790" source="DEBIAN">DSA-1790</ref>
      <ref url="http://support.apple.com/kb/HT3639" source="CONFIRM">http://support.apple.com/kb/HT3639</ref>
      <ref url="http://support.apple.com/kb/HT3613" source="CONFIRM">http://support.apple.com/kb/HT3613</ref>
      <ref url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2009&amp;m=slackware-security.578477" source="SLACKWARE">SSA:2009-129-01</ref>
      <ref url="http://secunia.com/advisories/35685" source="SECUNIA" adv="1">35685</ref>
      <ref url="http://secunia.com/advisories/35618" source="SECUNIA" adv="1">35618</ref>
      <ref url="http://secunia.com/advisories/35379" source="SECUNIA" adv="1">35379</ref>
      <ref url="http://secunia.com/advisories/35065" source="SECUNIA" adv="1">35065</ref>
      <ref url="http://secunia.com/advisories/35064" source="SECUNIA" adv="1">35064</ref>
      <ref url="http://secunia.com/advisories/35037" source="SECUNIA" adv="1">35037</ref>
      <ref url="http://secunia.com/advisories/34991" source="SECUNIA" adv="1">34991</ref>
      <ref url="http://secunia.com/advisories/34963" source="SECUNIA" adv="1">34963</ref>
      <ref url="http://secunia.com/advisories/34959" source="SECUNIA" adv="1">34959</ref>
      <ref url="http://secunia.com/advisories/34852" source="SECUNIA" adv="1">34852</ref>
      <ref url="http://secunia.com/advisories/34756" source="SECUNIA" adv="1">34756</ref>
      <ref url="http://secunia.com/advisories/34755" source="SECUNIA" adv="1">34755</ref>
      <ref url="http://secunia.com/advisories/34746" source="SECUNIA" adv="1">34746</ref>
      <ref url="http://secunia.com/advisories/34481" source="SECUNIA" adv="1">34481</ref>
      <ref url="http://secunia.com/advisories/34291" source="SECUNIA" adv="1">34291</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2009-0458.html" source="REDHAT">RHSA-2009:0458</ref>
      <ref url="http://poppler.freedesktop.org/releases.html" source="CONFIRM">http://poppler.freedesktop.org/releases.html</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11892" source="OVAL">oval:org.mitre.oval:def:11892</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-07/msg00002.html" source="SUSE">SUSE-SR:2009:012</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-05/msg00000.html" source="SUSE">SUSE-SR:2009:010</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-04/msg00011.html" source="SUSE">SUSE-SA:2009:024</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2009/Jun/msg00005.html" source="APPLE">APPLE-SA-2009-06-17-1</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2009/jun/msg00002.html" source="APPLE">APPLE-SA-2009-06-08-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="cups">
        <vers num="1.1" />
        <vers num="1.1.1" />
        <vers num="1.1.10" />
        <vers num="1.1.10-1" />
        <vers num="1.1.11" />
        <vers num="1.1.12" />
        <vers num="1.1.13" />
        <vers num="1.1.14" />
        <vers num="1.1.15" />
        <vers num="1.1.16" />
        <vers num="1.1.17" />
        <vers num="1.1.18" />
        <vers num="1.1.19" edition="rc1" />
        <vers num="1.1.19" edition="rc2" />
        <vers num="1.1.19" edition="rc3" />
        <vers num="1.1.19" edition="rc4" />
        <vers num="1.1.19" edition="rc5" />
        <vers num="1.1.2" />
        <vers num="1.1.20" edition="rc1" />
        <vers num="1.1.20" edition="rc2" />
        <vers num="1.1.20" edition="rc3" />
        <vers num="1.1.20" edition="rc4" />
        <vers num="1.1.20" edition="rc5" />
        <vers num="1.1.20" edition="rc6" />
        <vers num="1.1.21" edition="rc1" />
        <vers num="1.1.21" edition="rc2" />
        <vers num="1.1.22" edition="rc1" />
        <vers num="1.1.22" edition="rc2" />
        <vers num="1.1.23" edition="rc1" />
        <vers num="1.1.3" />
        <vers num="1.1.4" />
        <vers num="1.1.5" />
        <vers num="1.1.5-1" />
        <vers num="1.1.5-2" />
        <vers num="1.1.6" />
        <vers num="1.1.6-1" />
        <vers num="1.1.6-2" />
        <vers num="1.1.6-3" />
        <vers num="1.1.7" />
        <vers num="1.1.8" />
        <vers num="1.1.9" />
        <vers num="1.1.9-1" />
        <vers num="1.2.0" />
        <vers num="1.2.1" />
        <vers num="1.2.10" />
        <vers num="1.2.11" />
        <vers num="1.2.12" />
        <vers num="1.2.2" />
        <vers num="1.2.3" />
        <vers num="1.2.4" />
        <vers num="1.2.5" />
        <vers num="1.2.6" />
        <vers num="1.2.7" />
        <vers num="1.2.8" />
        <vers num="1.2.9" />
        <vers num="1.3.0" />
        <vers num="1.3.1" />
        <vers num="1.3.10" />
        <vers num="1.3.11" />
        <vers num="1.3.2" />
        <vers num="1.3.3" />
        <vers num="1.3.4" />
        <vers num="1.3.5" />
        <vers num="1.3.6" />
        <vers num="1.3.7" />
        <vers num="1.3.8" />
        <vers prev="1" num="1.3.9" />
      </prod>
      <prod vendor="foolabs" name="xpdf">
        <vers num="0.2" />
        <vers num="0.3" />
        <vers num="0.4" />
        <vers num="0.5" />
        <vers num="0.5a" />
        <vers num="0.6" />
        <vers num="0.7" />
        <vers num="0.7a" />
        <vers num="0.80" />
        <vers num="0.90" />
        <vers num="0.91" />
        <vers num="0.91a" />
        <vers num="0.91b" />
        <vers num="0.91c" />
        <vers num="0.92" />
        <vers num="0.92a" />
        <vers num="0.92b" />
        <vers num="0.92c" />
        <vers num="0.92d" />
        <vers num="0.92e" />
        <vers num="0.93" />
        <vers num="0.93a" />
        <vers num="0.93b" />
        <vers num="0.93c" />
        <vers num="1.00" />
        <vers num="1.00a" />
        <vers num="1.01" />
        <vers num="2.00" />
        <vers num="2.01" />
        <vers num="2.02" />
        <vers num="2.03" />
        <vers num="3.00" />
        <vers num="3.01" />
        <vers prev="1" num="3.02" />
      </prod>
      <prod vendor="poppler" name="poppler">
        <vers num="0.1" />
        <vers num="0.1.1" />
        <vers num="0.1.2" />
        <vers num="0.10.0" />
        <vers num="0.10.1" />
        <vers num="0.10.2" />
        <vers num="0.10.3" />
        <vers num="0.10.4" />
        <vers prev="1" num="0.10.5" />
        <vers num="0.2.0" />
        <vers num="0.3.0" />
        <vers num="0.3.1" />
        <vers num="0.3.2" />
        <vers num="0.3.3" />
        <vers num="0.4.0" />
        <vers num="0.4.1" />
        <vers num="0.4.2" />
        <vers num="0.4.3" />
        <vers num="0.4.4" />
        <vers num="0.5.0" />
        <vers num="0.5.1" />
        <vers num="0.5.2" />
        <vers num="0.5.3" />
        <vers num="0.5.4" />
        <vers num="0.5.9" />
        <vers num="0.5.90" />
        <vers num="0.5.91" />
        <vers num="0.6.0" />
        <vers num="0.6.1" />
        <vers num="0.6.2" />
        <vers num="0.6.3" />
        <vers num="0.6.4" />
        <vers num="0.7.0" />
        <vers num="0.7.1" />
        <vers num="0.7.2" />
        <vers num="0.7.3" />
        <vers num="0.8.0" />
        <vers num="0.8.1" />
        <vers num="0.8.2" />
        <vers num="0.8.3" />
        <vers num="0.8.4" />
        <vers num="0.8.5" />
        <vers num="0.8.6" />
        <vers num="0.8.7" />
        <vers num="0.9.0" />
        <vers num="0.9.1" />
        <vers num="0.9.2" />
        <vers num="0.9.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1180" published="2009-04-23" name="CVE-2009-1180" modified="2012-01-18" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">The JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, Poppler before 0.10.6, and other products allows remote attackers to execute arbitrary code via a crafted PDF file that triggers a free of invalid data.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/196617" source="CERT-VN">VU#196617</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1076" source="VUPEN" patch="1" adv="1">ADV-2009-1076</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1066" source="VUPEN" patch="1" adv="1">ADV-2009-1066</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1065" source="VUPEN" patch="1" adv="1">ADV-2009-1065</ref>
      <ref url="http://www.securityfocus.com/bid/34568" source="BID" patch="1">34568</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-0480.html" source="REDHAT" patch="1">RHSA-2009:0480</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-0431.html" source="REDHAT" patch="1">RHSA-2009:0431</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-0430.html" source="REDHAT" patch="1">RHSA-2009:0430</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-0429.html" source="REDHAT" patch="1">RHSA-2009:0429</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1793" source="DEBIAN" patch="1">DSA-1793</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1790" source="DEBIAN" patch="1">DSA-1790</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2009-0458.html" source="REDHAT" patch="1">RHSA-2009:0458</ref>
      <ref url="http://poppler.freedesktop.org/releases.html" source="CONFIRM" patch="1" adv="1">http://poppler.freedesktop.org/releases.html</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-June/msg01291.html" source="FEDORA">FEDORA-2009-6982</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-June/msg01277.html" source="FEDORA">FEDORA-2009-6973</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-July/msg00567.html" source="FEDORA">FEDORA-2009-6972</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=495892" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=495892</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1040" source="VUPEN" adv="1">ADV-2010-1040</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1077" source="VUPEN" adv="1">ADV-2009-1077</ref>
      <ref url="http://www.securitytracker.com/id?1022073" source="SECTRACK">1022073</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2011:175" source="MANDRIVA">MDVSA-2011:175</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2010:087" source="MANDRIVA">MDVSA-2010:087</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:101" source="MANDRIVA">MDVSA-2009:101</ref>
      <ref url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2009&amp;m=slackware-security.578477" source="SLACKWARE">SSA:2009-129-01</ref>
      <ref url="http://secunia.com/advisories/35685" source="SECUNIA" adv="1">35685</ref>
      <ref url="http://secunia.com/advisories/35618" source="SECUNIA" adv="1">35618</ref>
      <ref url="http://secunia.com/advisories/35065" source="SECUNIA" adv="1">35065</ref>
      <ref url="http://secunia.com/advisories/35064" source="SECUNIA" adv="1">35064</ref>
      <ref url="http://secunia.com/advisories/35037" source="SECUNIA" adv="1">35037</ref>
      <ref url="http://secunia.com/advisories/34991" source="SECUNIA" adv="1">34991</ref>
      <ref url="http://secunia.com/advisories/34963" source="SECUNIA" adv="1">34963</ref>
      <ref url="http://secunia.com/advisories/34959" source="SECUNIA" adv="1">34959</ref>
      <ref url="http://secunia.com/advisories/34852" source="SECUNIA" adv="1">34852</ref>
      <ref url="http://secunia.com/advisories/34756" source="SECUNIA" adv="1">34756</ref>
      <ref url="http://secunia.com/advisories/34755" source="SECUNIA" adv="1">34755</ref>
      <ref url="http://secunia.com/advisories/34746" source="SECUNIA" adv="1">34746</ref>
      <ref url="http://secunia.com/advisories/34481" source="SECUNIA" adv="1">34481</ref>
      <ref url="http://secunia.com/advisories/34291" source="SECUNIA" adv="1">34291</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9926" source="OVAL">oval:org.mitre.oval:def:9926</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-07/msg00002.html" source="SUSE">SUSE-SR:2009:012</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-05/msg00000.html" source="SUSE">SUSE-SR:2009:010</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-04/msg00011.html" source="SUSE">SUSE-SA:2009:024</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="cups">
        <vers num="1.1" />
        <vers num="1.1.1" />
        <vers num="1.1.10" />
        <vers num="1.1.10-1" />
        <vers num="1.1.11" />
        <vers num="1.1.12" />
        <vers num="1.1.13" />
        <vers num="1.1.14" />
        <vers num="1.1.15" />
        <vers num="1.1.16" />
        <vers num="1.1.17" />
        <vers num="1.1.18" />
        <vers num="1.1.19" edition="rc1" />
        <vers num="1.1.19" edition="rc2" />
        <vers num="1.1.19" edition="rc3" />
        <vers num="1.1.19" edition="rc4" />
        <vers num="1.1.19" edition="rc5" />
        <vers num="1.1.2" />
        <vers num="1.1.20" edition="rc1" />
        <vers num="1.1.20" edition="rc2" />
        <vers num="1.1.20" edition="rc3" />
        <vers num="1.1.20" edition="rc4" />
        <vers num="1.1.20" edition="rc5" />
        <vers num="1.1.20" edition="rc6" />
        <vers num="1.1.21" edition="rc1" />
        <vers num="1.1.21" edition="rc2" />
        <vers num="1.1.22" edition="rc1" />
        <vers num="1.1.22" edition="rc2" />
        <vers num="1.1.23" edition="rc1" />
        <vers num="1.1.3" />
        <vers num="1.1.4" />
        <vers num="1.1.5" />
        <vers num="1.1.5-1" />
        <vers num="1.1.5-2" />
        <vers num="1.1.6" />
        <vers num="1.1.6-1" />
        <vers num="1.1.6-2" />
        <vers num="1.1.6-3" />
        <vers num="1.1.7" />
        <vers num="1.1.8" />
        <vers num="1.1.9" />
        <vers num="1.1.9-1" />
        <vers num="1.2.0" />
        <vers num="1.2.1" />
        <vers num="1.2.10" />
        <vers num="1.2.11" />
        <vers num="1.2.12" />
        <vers num="1.2.2" />
        <vers num="1.2.3" />
        <vers num="1.2.4" />
        <vers num="1.2.5" />
        <vers num="1.2.6" />
        <vers num="1.2.7" />
        <vers num="1.2.8" />
        <vers num="1.2.9" />
        <vers num="1.3.0" />
        <vers num="1.3.1" />
        <vers num="1.3.10" />
        <vers num="1.3.11" />
        <vers num="1.3.2" />
        <vers num="1.3.3" />
        <vers num="1.3.4" />
        <vers num="1.3.5" />
        <vers num="1.3.6" />
        <vers num="1.3.7" />
        <vers num="1.3.8" />
        <vers prev="1" num="1.3.9" />
      </prod>
      <prod vendor="foolabs" name="xpdf">
        <vers num="0.2" />
        <vers num="0.3" />
        <vers num="0.4" />
        <vers num="0.5" />
        <vers num="0.5a" />
        <vers num="0.6" />
        <vers num="0.7" />
        <vers num="0.7a" />
        <vers num="0.80" />
        <vers num="0.90" />
        <vers num="0.91" />
        <vers num="0.91a" />
        <vers num="0.91b" />
        <vers num="0.91c" />
        <vers num="0.92" />
        <vers num="0.92a" />
        <vers num="0.92b" />
        <vers num="0.92c" />
        <vers num="0.92d" />
        <vers num="0.92e" />
        <vers num="0.93" />
        <vers num="0.93a" />
        <vers num="0.93b" />
        <vers num="0.93c" />
        <vers num="1.00" />
        <vers num="1.00a" />
        <vers num="1.01" />
        <vers num="2.00" />
        <vers num="2.01" />
        <vers num="2.02" />
        <vers num="2.03" />
        <vers num="3.00" />
        <vers num="3.01" />
        <vers prev="1" num="3.02" />
      </prod>
      <prod vendor="poppler" name="poppler">
        <vers num="0.1" />
        <vers num="0.1.1" />
        <vers num="0.1.2" />
        <vers num="0.10.0" />
        <vers num="0.10.1" />
        <vers num="0.10.2" />
        <vers num="0.10.3" />
        <vers num="0.10.4" />
        <vers prev="1" num="0.10.5" />
        <vers num="0.2.0" />
        <vers num="0.3.0" />
        <vers num="0.3.1" />
        <vers num="0.3.2" />
        <vers num="0.3.3" />
        <vers num="0.4.0" />
        <vers num="0.4.1" />
        <vers num="0.4.2" />
        <vers num="0.4.3" />
        <vers num="0.4.4" />
        <vers num="0.5.0" />
        <vers num="0.5.1" />
        <vers num="0.5.2" />
        <vers num="0.5.3" />
        <vers num="0.5.4" />
        <vers num="0.5.9" />
        <vers num="0.5.90" />
        <vers num="0.5.91" />
        <vers num="0.6.0" />
        <vers num="0.6.1" />
        <vers num="0.6.2" />
        <vers num="0.6.3" />
        <vers num="0.6.4" />
        <vers num="0.7.0" />
        <vers num="0.7.1" />
        <vers num="0.7.2" />
        <vers num="0.7.3" />
        <vers num="0.8.0" />
        <vers num="0.8.1" />
        <vers num="0.8.2" />
        <vers num="0.8.3" />
        <vers num="0.8.4" />
        <vers num="0.8.5" />
        <vers num="0.8.6" />
        <vers num="0.8.7" />
        <vers num="0.9.0" />
        <vers num="0.9.1" />
        <vers num="0.9.2" />
        <vers num="0.9.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1181" published="2009-04-23" name="CVE-2009-1181" modified="2012-01-18" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">The JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, Poppler before 0.10.6, and other products allows remote attackers to cause a denial of service (crash) via a crafted PDF file that triggers a NULL pointer dereference.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/196617" source="CERT-VN">VU#196617</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1076" source="VUPEN" patch="1" adv="1">ADV-2009-1076</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1066" source="VUPEN" patch="1" adv="1">ADV-2009-1066</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1065" source="VUPEN" patch="1" adv="1">ADV-2009-1065</ref>
      <ref url="http://www.securityfocus.com/bid/34568" source="BID" patch="1">34568</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-0431.html" source="REDHAT" patch="1">RHSA-2009:0431</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-0430.html" source="REDHAT" patch="1">RHSA-2009:0430</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-0429.html" source="REDHAT" patch="1">RHSA-2009:0429</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1793" source="DEBIAN" patch="1">DSA-1793</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1790" source="DEBIAN" patch="1">DSA-1790</ref>
      <ref url="http://secunia.com/advisories/35037" source="SECUNIA" patch="1" adv="1">35037</ref>
      <ref url="http://poppler.freedesktop.org/releases.html" source="CONFIRM" patch="1" adv="1">http://poppler.freedesktop.org/releases.html</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-June/msg01291.html" source="FEDORA">FEDORA-2009-6982</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-June/msg01277.html" source="FEDORA">FEDORA-2009-6973</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-July/msg00567.html" source="FEDORA">FEDORA-2009-6972</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=495894" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=495894</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1040" source="VUPEN" adv="1">ADV-2010-1040</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1077" source="VUPEN" adv="1">ADV-2009-1077</ref>
      <ref url="http://www.securitytracker.com/id?1022072" source="SECTRACK">1022072</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-0480.html" source="REDHAT">RHSA-2009:0480</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2011:175" source="MANDRIVA">MDVSA-2011:175</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2010:087" source="MANDRIVA">MDVSA-2010:087</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:101" source="MANDRIVA">MDVSA-2009:101</ref>
      <ref url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2009&amp;m=slackware-security.578477" source="SLACKWARE">SSA:2009-129-01</ref>
      <ref url="http://secunia.com/advisories/35685" source="SECUNIA" adv="1">35685</ref>
      <ref url="http://secunia.com/advisories/35618" source="SECUNIA" adv="1">35618</ref>
      <ref url="http://secunia.com/advisories/35065" source="SECUNIA" adv="1">35065</ref>
      <ref url="http://secunia.com/advisories/35064" source="SECUNIA" adv="1">35064</ref>
      <ref url="http://secunia.com/advisories/34991" source="SECUNIA" adv="1">34991</ref>
      <ref url="http://secunia.com/advisories/34963" source="SECUNIA" adv="1">34963</ref>
      <ref url="http://secunia.com/advisories/34959" source="SECUNIA" adv="1">34959</ref>
      <ref url="http://secunia.com/advisories/34852" source="SECUNIA" adv="1">34852</ref>
      <ref url="http://secunia.com/advisories/34756" source="SECUNIA" adv="1">34756</ref>
      <ref url="http://secunia.com/advisories/34755" source="SECUNIA" adv="1">34755</ref>
      <ref url="http://secunia.com/advisories/34746" source="SECUNIA" adv="1">34746</ref>
      <ref url="http://secunia.com/advisories/34481" source="SECUNIA" adv="1">34481</ref>
      <ref url="http://secunia.com/advisories/34291" source="SECUNIA" adv="1">34291</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2009-0458.html" source="REDHAT">RHSA-2009:0458</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9683" source="OVAL">oval:org.mitre.oval:def:9683</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-07/msg00002.html" source="SUSE">SUSE-SR:2009:012</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-05/msg00000.html" source="SUSE">SUSE-SR:2009:010</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-04/msg00011.html" source="SUSE">SUSE-SA:2009:024</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="cups">
        <vers num="1.1" />
        <vers num="1.1.1" />
        <vers num="1.1.10" />
        <vers num="1.1.10-1" />
        <vers num="1.1.11" />
        <vers num="1.1.12" />
        <vers num="1.1.13" />
        <vers num="1.1.14" />
        <vers num="1.1.15" />
        <vers num="1.1.16" />
        <vers num="1.1.17" />
        <vers num="1.1.18" />
        <vers num="1.1.19" edition="rc1" />
        <vers num="1.1.19" edition="rc2" />
        <vers num="1.1.19" edition="rc3" />
        <vers num="1.1.19" edition="rc4" />
        <vers num="1.1.19" edition="rc5" />
        <vers num="1.1.2" />
        <vers num="1.1.20" edition="rc1" />
        <vers num="1.1.20" edition="rc2" />
        <vers num="1.1.20" edition="rc3" />
        <vers num="1.1.20" edition="rc4" />
        <vers num="1.1.20" edition="rc5" />
        <vers num="1.1.20" edition="rc6" />
        <vers num="1.1.21" edition="rc1" />
        <vers num="1.1.21" edition="rc2" />
        <vers num="1.1.22" edition="rc1" />
        <vers num="1.1.22" edition="rc2" />
        <vers num="1.1.23" edition="rc1" />
        <vers num="1.1.3" />
        <vers num="1.1.4" />
        <vers num="1.1.5" />
        <vers num="1.1.5-1" />
        <vers num="1.1.5-2" />
        <vers num="1.1.6" />
        <vers num="1.1.6-1" />
        <vers num="1.1.6-2" />
        <vers num="1.1.6-3" />
        <vers num="1.1.7" />
        <vers num="1.1.8" />
        <vers num="1.1.9" />
        <vers num="1.1.9-1" />
        <vers num="1.2.0" />
        <vers num="1.2.1" />
        <vers num="1.2.10" />
        <vers num="1.2.11" />
        <vers num="1.2.12" />
        <vers num="1.2.2" />
        <vers num="1.2.3" />
        <vers num="1.2.4" />
        <vers num="1.2.5" />
        <vers num="1.2.6" />
        <vers num="1.2.7" />
        <vers num="1.2.8" />
        <vers num="1.2.9" />
        <vers num="1.3.0" />
        <vers num="1.3.1" />
        <vers num="1.3.10" />
        <vers num="1.3.11" />
        <vers num="1.3.2" />
        <vers num="1.3.3" />
        <vers num="1.3.4" />
        <vers num="1.3.5" />
        <vers num="1.3.6" />
        <vers num="1.3.7" />
        <vers num="1.3.8" />
        <vers prev="1" num="1.3.9" />
      </prod>
      <prod vendor="foolabs" name="xpdf">
        <vers num="0.2" />
        <vers num="0.3" />
        <vers num="0.4" />
        <vers num="0.5" />
        <vers num="0.5a" />
        <vers num="0.6" />
        <vers num="0.7" />
        <vers num="0.7a" />
        <vers num="0.80" />
        <vers num="0.90" />
        <vers num="0.91" />
        <vers num="0.91a" />
        <vers num="0.91b" />
        <vers num="0.91c" />
        <vers num="0.92" />
        <vers num="0.92a" />
        <vers num="0.92b" />
        <vers num="0.92c" />
        <vers num="0.92d" />
        <vers num="0.92e" />
        <vers num="0.93" />
        <vers num="0.93a" />
        <vers num="0.93b" />
        <vers num="0.93c" />
        <vers num="1.00" />
        <vers num="1.00a" />
        <vers num="1.01" />
        <vers num="2.00" />
        <vers num="2.01" />
        <vers num="2.02" />
        <vers num="2.03" />
        <vers num="3.00" />
        <vers num="3.01" />
        <vers prev="1" num="3.02" />
      </prod>
      <prod vendor="poppler" name="poppler">
        <vers num="0.1" />
        <vers num="0.1.1" />
        <vers num="0.1.2" />
        <vers num="0.10.0" />
        <vers num="0.10.1" />
        <vers num="0.10.2" />
        <vers num="0.10.3" />
        <vers num="0.10.4" />
        <vers prev="1" num="0.10.5" />
        <vers num="0.2.0" />
        <vers num="0.3.0" />
        <vers num="0.3.1" />
        <vers num="0.3.2" />
        <vers num="0.3.3" />
        <vers num="0.4.0" />
        <vers num="0.4.1" />
        <vers num="0.4.2" />
        <vers num="0.4.3" />
        <vers num="0.4.4" />
        <vers num="0.5.0" />
        <vers num="0.5.1" />
        <vers num="0.5.2" />
        <vers num="0.5.3" />
        <vers num="0.5.4" />
        <vers num="0.5.9" />
        <vers num="0.5.90" />
        <vers num="0.5.91" />
        <vers num="0.6.0" />
        <vers num="0.6.1" />
        <vers num="0.6.2" />
        <vers num="0.6.3" />
        <vers num="0.6.4" />
        <vers num="0.7.0" />
        <vers num="0.7.1" />
        <vers num="0.7.2" />
        <vers num="0.7.3" />
        <vers num="0.8.0" />
        <vers num="0.8.1" />
        <vers num="0.8.2" />
        <vers num="0.8.3" />
        <vers num="0.8.4" />
        <vers num="0.8.5" />
        <vers num="0.8.6" />
        <vers num="0.8.7" />
        <vers num="0.9.0" />
        <vers num="0.9.1" />
        <vers num="0.9.2" />
        <vers num="0.9.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1182" published="2009-04-23" name="CVE-2009-1182" modified="2012-01-18" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple buffer overflows in the JBIG2 MMR decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, Poppler before 0.10.6, and other products allow remote attackers to execute arbitrary code via a crafted PDF file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/196617" source="CERT-VN">VU#196617</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-June/msg01291.html" source="FEDORA">FEDORA-2009-6982</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-June/msg01277.html" source="FEDORA">FEDORA-2009-6973</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-July/msg00567.html" source="FEDORA">FEDORA-2009-6972</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=495896" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=495896</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1040" source="VUPEN" adv="1">ADV-2010-1040</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1077" source="VUPEN" adv="1">ADV-2009-1077</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1076" source="VUPEN" adv="1">ADV-2009-1076</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1066" source="VUPEN" adv="1">ADV-2009-1066</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1065" source="VUPEN" adv="1">ADV-2009-1065</ref>
      <ref url="http://www.securitytracker.com/id?1022073" source="SECTRACK">1022073</ref>
      <ref url="http://www.securityfocus.com/bid/34568" source="BID">34568</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-0480.html" source="REDHAT">RHSA-2009:0480</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-0431.html" source="REDHAT">RHSA-2009:0431</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-0430.html" source="REDHAT">RHSA-2009:0430</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-0429.html" source="REDHAT">RHSA-2009:0429</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2011:175" source="MANDRIVA">MDVSA-2011:175</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2010:087" source="MANDRIVA">MDVSA-2010:087</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:101" source="MANDRIVA">MDVSA-2009:101</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1793" source="DEBIAN">DSA-1793</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1790" source="DEBIAN">DSA-1790</ref>
      <ref url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2009&amp;m=slackware-security.578477" source="SLACKWARE">SSA:2009-129-01</ref>
      <ref url="http://secunia.com/advisories/35685" source="SECUNIA" adv="1">35685</ref>
      <ref url="http://secunia.com/advisories/35618" source="SECUNIA" adv="1">35618</ref>
      <ref url="http://secunia.com/advisories/35065" source="SECUNIA" adv="1">35065</ref>
      <ref url="http://secunia.com/advisories/35064" source="SECUNIA" adv="1">35064</ref>
      <ref url="http://secunia.com/advisories/35037" source="SECUNIA" adv="1">35037</ref>
      <ref url="http://secunia.com/advisories/34991" source="SECUNIA" adv="1">34991</ref>
      <ref url="http://secunia.com/advisories/34963" source="SECUNIA" adv="1">34963</ref>
      <ref url="http://secunia.com/advisories/34959" source="SECUNIA" adv="1">34959</ref>
      <ref url="http://secunia.com/advisories/34852" source="SECUNIA" adv="1">34852</ref>
      <ref url="http://secunia.com/advisories/34756" source="SECUNIA" adv="1">34756</ref>
      <ref url="http://secunia.com/advisories/34755" source="SECUNIA" adv="1">34755</ref>
      <ref url="http://secunia.com/advisories/34746" source="SECUNIA" adv="1">34746</ref>
      <ref url="http://secunia.com/advisories/34481" source="SECUNIA" adv="1">34481</ref>
      <ref url="http://secunia.com/advisories/34291" source="SECUNIA" adv="1">34291</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2009-0458.html" source="REDHAT" adv="1">RHSA-2009:0458</ref>
      <ref url="http://poppler.freedesktop.org/releases.html" source="CONFIRM">http://poppler.freedesktop.org/releases.html</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10735" source="OVAL">oval:org.mitre.oval:def:10735</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-07/msg00002.html" source="SUSE">SUSE-SR:2009:012</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-05/msg00000.html" source="SUSE">SUSE-SR:2009:010</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-04/msg00011.html" source="SUSE">SUSE-SA:2009:024</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="cups">
        <vers num="1.1" />
        <vers num="1.1.1" />
        <vers num="1.1.10" />
        <vers num="1.1.10-1" />
        <vers num="1.1.11" />
        <vers num="1.1.12" />
        <vers num="1.1.13" />
        <vers num="1.1.14" />
        <vers num="1.1.15" />
        <vers num="1.1.16" />
        <vers num="1.1.17" />
        <vers num="1.1.18" />
        <vers num="1.1.19" edition="rc1" />
        <vers num="1.1.19" edition="rc2" />
        <vers num="1.1.19" edition="rc3" />
        <vers num="1.1.19" edition="rc4" />
        <vers num="1.1.19" edition="rc5" />
        <vers num="1.1.2" />
        <vers num="1.1.20" edition="rc1" />
        <vers num="1.1.20" edition="rc2" />
        <vers num="1.1.20" edition="rc3" />
        <vers num="1.1.20" edition="rc4" />
        <vers num="1.1.20" edition="rc5" />
        <vers num="1.1.20" edition="rc6" />
        <vers num="1.1.21" edition="rc1" />
        <vers num="1.1.21" edition="rc2" />
        <vers num="1.1.22" edition="rc1" />
        <vers num="1.1.22" edition="rc2" />
        <vers num="1.1.23" edition="rc1" />
        <vers num="1.1.3" />
        <vers num="1.1.4" />
        <vers num="1.1.5" />
        <vers num="1.1.5-1" />
        <vers num="1.1.5-2" />
        <vers num="1.1.6" />
        <vers num="1.1.6-1" />
        <vers num="1.1.6-2" />
        <vers num="1.1.6-3" />
        <vers num="1.1.7" />
        <vers num="1.1.8" />
        <vers num="1.1.9" />
        <vers num="1.1.9-1" />
        <vers num="1.2.0" />
        <vers num="1.2.1" />
        <vers num="1.2.10" />
        <vers num="1.2.11" />
        <vers num="1.2.12" />
        <vers num="1.2.2" />
        <vers num="1.2.3" />
        <vers num="1.2.4" />
        <vers num="1.2.5" />
        <vers num="1.2.6" />
        <vers num="1.2.7" />
        <vers num="1.2.8" />
        <vers num="1.2.9" />
        <vers num="1.3.0" />
        <vers num="1.3.1" />
        <vers num="1.3.10" />
        <vers num="1.3.11" />
        <vers num="1.3.2" />
        <vers num="1.3.3" />
        <vers num="1.3.4" />
        <vers num="1.3.5" />
        <vers num="1.3.6" />
        <vers num="1.3.7" />
        <vers num="1.3.8" />
        <vers prev="1" num="1.3.9" />
      </prod>
      <prod vendor="foolabs" name="xpdf">
        <vers num="0.2" />
        <vers num="0.3" />
        <vers num="0.4" />
        <vers num="0.5" />
        <vers num="0.5a" />
        <vers num="0.6" />
        <vers num="0.7" />
        <vers num="0.7a" />
        <vers num="0.80" />
        <vers num="0.90" />
        <vers num="0.91" />
        <vers num="0.91a" />
        <vers num="0.91b" />
        <vers num="0.91c" />
        <vers num="0.92" />
        <vers num="0.92a" />
        <vers num="0.92b" />
        <vers num="0.92c" />
        <vers num="0.92d" />
        <vers num="0.92e" />
        <vers num="0.93" />
        <vers num="0.93a" />
        <vers num="0.93b" />
        <vers num="0.93c" />
        <vers num="1.00" />
        <vers num="1.00a" />
        <vers num="1.01" />
        <vers num="2.00" />
        <vers num="2.01" />
        <vers num="2.02" />
        <vers num="2.03" />
        <vers num="3.00" />
        <vers num="3.01" />
        <vers prev="1" num="3.02" />
      </prod>
      <prod vendor="poppler" name="poppler">
        <vers num="0.1" />
        <vers num="0.1.1" />
        <vers num="0.1.2" />
        <vers num="0.10.0" />
        <vers num="0.10.1" />
        <vers num="0.10.2" />
        <vers num="0.10.3" />
        <vers num="0.10.4" />
        <vers prev="1" num="0.10.5" />
        <vers num="0.2.0" />
        <vers num="0.3.0" />
        <vers num="0.3.1" />
        <vers num="0.3.2" />
        <vers num="0.3.3" />
        <vers num="0.4.0" />
        <vers num="0.4.1" />
        <vers num="0.4.2" />
        <vers num="0.4.3" />
        <vers num="0.4.4" />
        <vers num="0.5.0" />
        <vers num="0.5.1" />
        <vers num="0.5.2" />
        <vers num="0.5.3" />
        <vers num="0.5.4" />
        <vers num="0.5.9" />
        <vers num="0.5.90" />
        <vers num="0.5.91" />
        <vers num="0.6.0" />
        <vers num="0.6.1" />
        <vers num="0.6.2" />
        <vers num="0.6.3" />
        <vers num="0.6.4" />
        <vers num="0.7.0" />
        <vers num="0.7.1" />
        <vers num="0.7.2" />
        <vers num="0.7.3" />
        <vers num="0.8.0" />
        <vers num="0.8.1" />
        <vers num="0.8.2" />
        <vers num="0.8.3" />
        <vers num="0.8.4" />
        <vers num="0.8.5" />
        <vers num="0.8.6" />
        <vers num="0.8.7" />
        <vers num="0.9.0" />
        <vers num="0.9.1" />
        <vers num="0.9.2" />
        <vers num="0.9.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1183" published="2009-04-23" name="CVE-2009-1183" modified="2012-01-18" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">The JBIG2 MMR decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, Poppler before 0.10.6, and other products allows remote attackers to cause a denial of service (infinite loop and hang) via a crafted PDF file.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/196617" source="CERT-VN">VU#196617</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1065" source="VUPEN" patch="1" adv="1">ADV-2009-1065</ref>
      <ref url="http://www.securityfocus.com/bid/34568" source="BID" patch="1">34568</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-0480.html" source="REDHAT" patch="1">RHSA-2009:0480</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-0430.html" source="REDHAT" patch="1">RHSA-2009:0430</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-0429.html" source="REDHAT" patch="1">RHSA-2009:0429</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1793" source="DEBIAN" patch="1">DSA-1793</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1790" source="DEBIAN" patch="1">DSA-1790</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2009-0458.html" source="REDHAT" patch="1">RHSA-2009:0458</ref>
      <ref url="http://poppler.freedesktop.org/releases.html" source="CONFIRM" patch="1" adv="1">http://poppler.freedesktop.org/releases.html</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-June/msg01291.html" source="FEDORA">FEDORA-2009-6982</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-June/msg01277.html" source="FEDORA">FEDORA-2009-6973</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-July/msg00567.html" source="FEDORA">FEDORA-2009-6972</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=495899" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=495899</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1040" source="VUPEN" adv="1">ADV-2010-1040</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1077" source="VUPEN" adv="1">ADV-2009-1077</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1076" source="VUPEN" adv="1">ADV-2009-1076</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1066" source="VUPEN" adv="1">ADV-2009-1066</ref>
      <ref url="http://www.securitytracker.com/id?1022072" source="SECTRACK">1022072</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-0431.html" source="REDHAT">RHSA-2009:0431</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2011:175" source="MANDRIVA">MDVSA-2011:175</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2010:087" source="MANDRIVA">MDVSA-2010:087</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:101" source="MANDRIVA">MDVSA-2009:101</ref>
      <ref url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2009&amp;m=slackware-security.578477" source="SLACKWARE">SSA:2009-129-01</ref>
      <ref url="http://secunia.com/advisories/35685" source="SECUNIA" adv="1">35685</ref>
      <ref url="http://secunia.com/advisories/35618" source="SECUNIA" adv="1">35618</ref>
      <ref url="http://secunia.com/advisories/35065" source="SECUNIA" adv="1">35065</ref>
      <ref url="http://secunia.com/advisories/35064" source="SECUNIA" adv="1">35064</ref>
      <ref url="http://secunia.com/advisories/35037" source="SECUNIA" adv="1">35037</ref>
      <ref url="http://secunia.com/advisories/34991" source="SECUNIA" adv="1">34991</ref>
      <ref url="http://secunia.com/advisories/34963" source="SECUNIA" adv="1">34963</ref>
      <ref url="http://secunia.com/advisories/34959" source="SECUNIA" adv="1">34959</ref>
      <ref url="http://secunia.com/advisories/34852" source="SECUNIA" adv="1">34852</ref>
      <ref url="http://secunia.com/advisories/34756" source="SECUNIA" adv="1">34756</ref>
      <ref url="http://secunia.com/advisories/34755" source="SECUNIA" adv="1">34755</ref>
      <ref url="http://secunia.com/advisories/34746" source="SECUNIA" adv="1">34746</ref>
      <ref url="http://secunia.com/advisories/34481" source="SECUNIA" adv="1">34481</ref>
      <ref url="http://secunia.com/advisories/34291" source="SECUNIA" adv="1">34291</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10769" source="OVAL">oval:org.mitre.oval:def:10769</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-07/msg00002.html" source="SUSE">SUSE-SR:2009:012</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-05/msg00000.html" source="SUSE">SUSE-SR:2009:010</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-04/msg00011.html" source="SUSE">SUSE-SA:2009:024</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="cups">
        <vers num="1.1" />
        <vers num="1.1.1" />
        <vers num="1.1.10" />
        <vers num="1.1.10-1" />
        <vers num="1.1.11" />
        <vers num="1.1.12" />
        <vers num="1.1.13" />
        <vers num="1.1.14" />
        <vers num="1.1.15" />
        <vers num="1.1.16" />
        <vers num="1.1.17" />
        <vers num="1.1.18" />
        <vers num="1.1.19" edition="rc1" />
        <vers num="1.1.19" edition="rc2" />
        <vers num="1.1.19" edition="rc3" />
        <vers num="1.1.19" edition="rc4" />
        <vers num="1.1.19" edition="rc5" />
        <vers num="1.1.2" />
        <vers num="1.1.20" edition="rc1" />
        <vers num="1.1.20" edition="rc2" />
        <vers num="1.1.20" edition="rc3" />
        <vers num="1.1.20" edition="rc4" />
        <vers num="1.1.20" edition="rc5" />
        <vers num="1.1.20" edition="rc6" />
        <vers num="1.1.21" edition="rc1" />
        <vers num="1.1.21" edition="rc2" />
        <vers num="1.1.22" edition="rc1" />
        <vers num="1.1.22" edition="rc2" />
        <vers num="1.1.23" edition="rc1" />
        <vers num="1.1.3" />
        <vers num="1.1.4" />
        <vers num="1.1.5" />
        <vers num="1.1.5-1" />
        <vers num="1.1.5-2" />
        <vers num="1.1.6" />
        <vers num="1.1.6-1" />
        <vers num="1.1.6-2" />
        <vers num="1.1.6-3" />
        <vers num="1.1.7" />
        <vers num="1.1.8" />
        <vers num="1.1.9" />
        <vers num="1.1.9-1" />
        <vers num="1.2.0" />
        <vers num="1.2.1" />
        <vers num="1.2.10" />
        <vers num="1.2.11" />
        <vers num="1.2.12" />
        <vers num="1.2.2" />
        <vers num="1.2.3" />
        <vers num="1.2.4" />
        <vers num="1.2.5" />
        <vers num="1.2.6" />
        <vers num="1.2.7" />
        <vers num="1.2.8" />
        <vers num="1.2.9" />
        <vers num="1.3.0" />
        <vers num="1.3.1" />
        <vers num="1.3.10" />
        <vers num="1.3.11" />
        <vers num="1.3.2" />
        <vers num="1.3.3" />
        <vers num="1.3.4" />
        <vers num="1.3.5" />
        <vers num="1.3.6" />
        <vers num="1.3.7" />
        <vers num="1.3.8" />
        <vers prev="1" num="1.3.9" />
      </prod>
      <prod vendor="foolabs" name="xpdf">
        <vers num="0.2" />
        <vers num="0.3" />
        <vers num="0.4" />
        <vers num="0.5" />
        <vers num="0.5a" />
        <vers num="0.6" />
        <vers num="0.7" />
        <vers num="0.7a" />
        <vers num="0.80" />
        <vers num="0.90" />
        <vers num="0.91" />
        <vers num="0.91a" />
        <vers num="0.91b" />
        <vers num="0.91c" />
        <vers num="0.92" />
        <vers num="0.92a" />
        <vers num="0.92b" />
        <vers num="0.92c" />
        <vers num="0.92d" />
        <vers num="0.92e" />
        <vers num="0.93" />
        <vers num="0.93a" />
        <vers num="0.93b" />
        <vers num="0.93c" />
        <vers num="1.00" />
        <vers num="1.00a" />
        <vers num="1.01" />
        <vers num="2.00" />
        <vers num="2.01" />
        <vers num="2.02" />
        <vers num="2.03" />
        <vers num="3.00" />
        <vers num="3.01" />
        <vers prev="1" num="3.02" />
      </prod>
      <prod vendor="poppler" name="poppler">
        <vers num="0.1" />
        <vers num="0.1.1" />
        <vers num="0.1.2" />
        <vers num="0.10.0" />
        <vers num="0.10.1" />
        <vers num="0.10.2" />
        <vers num="0.10.3" />
        <vers num="0.10.4" />
        <vers prev="1" num="0.10.5" />
        <vers num="0.2.0" />
        <vers num="0.3.0" />
        <vers num="0.3.1" />
        <vers num="0.3.2" />
        <vers num="0.3.3" />
        <vers num="0.4.0" />
        <vers num="0.4.1" />
        <vers num="0.4.2" />
        <vers num="0.4.3" />
        <vers num="0.4.4" />
        <vers num="0.5.0" />
        <vers num="0.5.1" />
        <vers num="0.5.2" />
        <vers num="0.5.3" />
        <vers num="0.5.4" />
        <vers num="0.5.9" />
        <vers num="0.5.90" />
        <vers num="0.5.91" />
        <vers num="0.6.0" />
        <vers num="0.6.1" />
        <vers num="0.6.2" />
        <vers num="0.6.3" />
        <vers num="0.6.4" />
        <vers num="0.7.0" />
        <vers num="0.7.1" />
        <vers num="0.7.2" />
        <vers num="0.7.3" />
        <vers num="0.8.0" />
        <vers num="0.8.1" />
        <vers num="0.8.2" />
        <vers num="0.8.3" />
        <vers num="0.8.4" />
        <vers num="0.8.5" />
        <vers num="0.8.6" />
        <vers num="0.8.7" />
        <vers num="0.9.0" />
        <vers num="0.9.1" />
        <vers num="0.9.2" />
        <vers num="0.9.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1184" published="2009-05-05" name="CVE-2009-1184" modified="2010-05-04" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="4.4" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.4" CVSS_base_score="4.4">
    <desc>
      <descript source="cve">The selinux_ip_postroute_iptables_compat function in security/selinux/hooks.c in the SELinux subsystem in the Linux kernel before 2.6.27.22, and 2.6.28.x before 2.6.28.10, when compat_net is enabled, omits calls to avc_has_perm for the (1) node and (2) port, which allows local users to bypass intended restrictions on network traffic.  NOTE: this was incorrectly reported as an issue fixed in 2.6.27.21.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://patchwork.ozlabs.org/patch/25238/" source="CONFIRM" patch="1">http://patchwork.ozlabs.org/patch/25238/</ref>
      <ref url="https://launchpad.net/bugs/cve/2009-1184" source="MISC">https://launchpad.net/bugs/cve/2009-1184</ref>
      <ref url="http://www.ubuntu.com/usn/usn-793-1" source="UBUNTU">USN-793-1</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2009/05/04/1" source="MLIST">[oss-security] 20090504 CVE-2009-1184 selinux: skipped node/port send checks in the compat_net=1 case</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:135" source="MANDRIVA">MDVSA-2009:135</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:119" source="MANDRIVA">MDVSA-2009:119</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:118" source="MANDRIVA">MDVSA-2009:118</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1800" source="DEBIAN">DSA-1800</ref>
      <ref url="http://secunia.com/advisories/35656" source="SECUNIA">35656</ref>
      <ref url="http://secunia.com/advisories/35121" source="SECUNIA">35121</ref>
      <ref url="http://lwn.net/Articles/331435/" source="MLIST">[linux-kernel] 20090502 Linux 2.6.28.10</ref>
      <ref url="http://lwn.net/Articles/331434/" source="MLIST">[linux-kernel] 20090502 Linux 2.6.27.21</ref>
      <ref url="http://git.kernel.org/?p=linux/kernel/git/stable/linux-2.6.27.y.git;a=commit;h=910c9e41186762de3717baaf392ab5ff0c454496" source="CONFIRM" adv="1">http://git.kernel.org/?p=linux/kernel/git/stable/linux-2.6.27.y.git;a=commit;h=910c9e41186762de3717baaf392ab5ff0c454496</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="kernel">
        <vers num="2.2.27" />
        <vers num="2.4.36" />
        <vers num="2.4.36.1" />
        <vers num="2.4.36.2" />
        <vers num="2.4.36.3" />
        <vers num="2.4.36.4" />
        <vers num="2.4.36.5" />
        <vers num="2.4.36.6" />
        <vers num="2.6" />
        <vers num="2.6.0" />
        <vers num="2.6.1" />
        <vers num="2.6.10" />
        <vers num="2.6.11" />
        <vers num="2.6.11.1" />
        <vers num="2.6.11.10" />
        <vers num="2.6.11.11" />
        <vers num="2.6.11.12" />
        <vers num="2.6.11.2" />
        <vers num="2.6.11.3" />
        <vers num="2.6.11.4" />
        <vers num="2.6.11.5" />
        <vers num="2.6.11.6" />
        <vers num="2.6.11.7" />
        <vers num="2.6.11.8" />
        <vers num="2.6.11.9" />
        <vers num="2.6.12" />
        <vers num="2.6.12.1" />
        <vers num="2.6.12.2" />
        <vers num="2.6.12.3" />
        <vers num="2.6.12.4" />
        <vers num="2.6.12.5" />
        <vers num="2.6.12.6" />
        <vers num="2.6.13" />
        <vers num="2.6.13.1" />
        <vers num="2.6.13.2" />
        <vers num="2.6.13.3" />
        <vers num="2.6.13.4" />
        <vers num="2.6.13.5" />
        <vers num="2.6.14" />
        <vers num="2.6.14.1" />
        <vers num="2.6.14.2" />
        <vers num="2.6.14.3" />
        <vers num="2.6.14.4" />
        <vers num="2.6.14.5" />
        <vers num="2.6.14.6" />
        <vers num="2.6.14.7" />
        <vers num="2.6.15" />
        <vers num="2.6.15.1" />
        <vers num="2.6.15.2" />
        <vers num="2.6.15.3" />
        <vers num="2.6.15.4" />
        <vers num="2.6.15.5" />
        <vers num="2.6.15.6" />
        <vers num="2.6.15.7" />
        <vers num="2.6.16" />
        <vers num="2.6.16.1" />
        <vers num="2.6.16.10" />
        <vers num="2.6.16.11" />
        <vers num="2.6.16.12" />
        <vers num="2.6.16.13" />
        <vers num="2.6.16.14" />
        <vers num="2.6.16.15" />
        <vers num="2.6.16.16" />
        <vers num="2.6.16.17" />
        <vers num="2.6.16.18" />
        <vers num="2.6.16.19" />
        <vers num="2.6.16.2" />
        <vers num="2.6.16.20" />
        <vers num="2.6.16.21" />
        <vers num="2.6.16.22" />
        <vers num="2.6.16.23" />
        <vers num="2.6.16.24" />
        <vers num="2.6.16.25" />
        <vers num="2.6.16.26" />
        <vers num="2.6.16.27" />
        <vers num="2.6.16.28" />
        <vers num="2.6.16.29" />
        <vers num="2.6.16.3" />
        <vers num="2.6.16.30" />
        <vers num="2.6.16.31" />
        <vers num="2.6.16.32" />
        <vers num="2.6.16.33" />
        <vers num="2.6.16.34" />
        <vers num="2.6.16.35" />
        <vers num="2.6.16.36" />
        <vers num="2.6.16.37" />
        <vers num="2.6.16.38" />
        <vers num="2.6.16.39" />
        <vers num="2.6.16.4" />
        <vers num="2.6.16.40" />
        <vers num="2.6.16.41" />
        <vers num="2.6.16.42" />
        <vers num="2.6.16.43" />
        <vers num="2.6.16.44" />
        <vers num="2.6.16.45" />
        <vers num="2.6.16.46" />
        <vers num="2.6.16.47" />
        <vers num="2.6.16.48" />
        <vers num="2.6.16.49" />
        <vers num="2.6.16.5" />
        <vers num="2.6.16.50" />
        <vers num="2.6.16.51" />
        <vers num="2.6.16.52" />
        <vers num="2.6.16.53" />
        <vers num="2.6.16.54" />
        <vers num="2.6.16.55" />
        <vers num="2.6.16.56" />
        <vers num="2.6.16.57" />
        <vers num="2.6.16.58" />
        <vers num="2.6.16.59" />
        <vers num="2.6.16.6" />
        <vers num="2.6.16.60" />
        <vers num="2.6.16.61" />
        <vers num="2.6.16.62" />
        <vers num="2.6.16.7" />
        <vers num="2.6.16.8" />
        <vers num="2.6.16.9" />
        <vers num="2.6.17" />
        <vers num="2.6.17.1" />
        <vers num="2.6.17.10" />
        <vers num="2.6.17.11" />
        <vers num="2.6.17.12" />
        <vers num="2.6.17.13" />
        <vers num="2.6.17.14" />
        <vers num="2.6.17.2" />
        <vers num="2.6.17.3" />
        <vers num="2.6.17.4" />
        <vers num="2.6.17.5" />
        <vers num="2.6.17.6" />
        <vers num="2.6.17.7" />
        <vers num="2.6.17.8" />
        <vers num="2.6.17.9" />
        <vers num="2.6.18" edition="rc1" />
        <vers num="2.6.18" edition="rc2" />
        <vers num="2.6.18" edition="rc3" />
        <vers num="2.6.18" edition="rc4" />
        <vers num="2.6.18" edition="rc5" />
        <vers num="2.6.18" edition="rc6" />
        <vers num="2.6.18" edition="rc7" />
        <vers num="2.6.18.1" />
        <vers num="2.6.18.2" />
        <vers num="2.6.18.3" />
        <vers num="2.6.18.4" />
        <vers num="2.6.18.5" />
        <vers num="2.6.18.6" />
        <vers num="2.6.18.7" />
        <vers num="2.6.18.8" />
        <vers num="2.6.19" />
        <vers num="2.6.19.1" />
        <vers num="2.6.19.2" />
        <vers num="2.6.19.3" />
        <vers num="2.6.19.4" />
        <vers num="2.6.19.5" />
        <vers num="2.6.19.6" />
        <vers num="2.6.19.7" />
        <vers num="2.6.2" />
        <vers num="2.6.2.27.13" />
        <vers num="2.6.20" />
        <vers num="2.6.20.1" />
        <vers num="2.6.20.10" />
        <vers num="2.6.20.11" />
        <vers num="2.6.20.12" />
        <vers num="2.6.20.13" />
        <vers num="2.6.20.14" />
        <vers num="2.6.20.15" />
        <vers num="2.6.20.16" />
        <vers num="2.6.20.17" />
        <vers num="2.6.20.18" />
        <vers num="2.6.20.19" />
        <vers num="2.6.20.2" />
        <vers num="2.6.20.20" />
        <vers num="2.6.20.21" />
        <vers num="2.6.20.3" />
        <vers num="2.6.20.4" />
        <vers num="2.6.20.5" />
        <vers num="2.6.20.6" />
        <vers num="2.6.20.7" />
        <vers num="2.6.20.8" />
        <vers num="2.6.20.9" />
        <vers num="2.6.21" />
        <vers num="2.6.21.1" />
        <vers num="2.6.21.2" />
        <vers num="2.6.21.3" />
        <vers num="2.6.21.4" />
        <vers num="2.6.21.5" />
        <vers num="2.6.21.6" />
        <vers num="2.6.21.7" />
        <vers num="2.6.22" />
        <vers num="2.6.22.1" />
        <vers num="2.6.22.10" />
        <vers num="2.6.22.11" />
        <vers num="2.6.22.12" />
        <vers num="2.6.22.13" />
        <vers num="2.6.22.14" />
        <vers num="2.6.22.15" />
        <vers num="2.6.22.16" />
        <vers num="2.6.22.17" />
        <vers num="2.6.22.18" />
        <vers num="2.6.22.19" />
        <vers num="2.6.22.2" />
        <vers num="2.6.22.20" />
        <vers num="2.6.22.21" />
        <vers num="2.6.22.22" />
        <vers num="2.6.22.3" />
        <vers num="2.6.22.4" />
        <vers num="2.6.22.5" />
        <vers num="2.6.22.6" />
        <vers num="2.6.22.7" />
        <vers num="2.6.22.8" />
        <vers num="2.6.22.9" />
        <vers num="2.6.22_rc1" />
        <vers num="2.6.22_rc7" />
        <vers num="2.6.23" edition="rc1" />
        <vers num="2.6.23" edition="rc2" />
        <vers num="2.6.23.1" />
        <vers num="2.6.23.10" />
        <vers num="2.6.23.11" />
        <vers num="2.6.23.12" />
        <vers num="2.6.23.13" />
        <vers num="2.6.23.14" />
        <vers num="2.6.23.15" />
        <vers num="2.6.23.16" />
        <vers num="2.6.23.17" />
        <vers num="2.6.23.2" />
        <vers num="2.6.23.3" />
        <vers num="2.6.23.4" />
        <vers num="2.6.23.5" />
        <vers num="2.6.23.6" />
        <vers num="2.6.23.7" />
        <vers num="2.6.23.8" />
        <vers num="2.6.23.9" />
        <vers num="2.6.23_rc1" />
        <vers num="2.6.24" edition="rc1" />
        <vers num="2.6.24" edition="rc2" />
        <vers num="2.6.24" edition="rc3" />
        <vers num="2.6.24" edition="rc4" />
        <vers num="2.6.24" edition="rc5" />
        <vers num="2.6.24.1" />
        <vers num="2.6.24.2" />
        <vers num="2.6.24.3" />
        <vers num="2.6.24.4" />
        <vers num="2.6.24.5" />
        <vers num="2.6.24.6" />
        <vers num="2.6.24.7" />
        <vers num="2.6.24_rc1" />
        <vers num="2.6.24_rc4" />
        <vers num="2.6.24_rc5" />
        <vers num="2.6.25" edition="" />
        <vers num="2.6.25" edition=":x86_64" />
        <vers num="2.6.25.1" edition="" />
        <vers num="2.6.25.1" edition=":x86_64" />
        <vers num="2.6.25.10" edition="" />
        <vers num="2.6.25.10" edition=":x86_64" />
        <vers num="2.6.25.11" edition="" />
        <vers num="2.6.25.11" edition=":x86_64" />
        <vers num="2.6.25.12" edition="" />
        <vers num="2.6.25.12" edition=":x86_64" />
        <vers num="2.6.25.13" />
        <vers num="2.6.25.14" />
        <vers num="2.6.25.15" />
        <vers num="2.6.25.16" />
        <vers num="2.6.25.17" />
        <vers num="2.6.25.18" />
        <vers num="2.6.25.19" />
        <vers num="2.6.25.2" edition="" />
        <vers num="2.6.25.2" edition=":x86_64" />
        <vers num="2.6.25.20" />
        <vers num="2.6.25.3" edition="" />
        <vers num="2.6.25.3" edition=":x86_64" />
        <vers num="2.6.25.4" edition="" />
        <vers num="2.6.25.4" edition=":x86_64" />
        <vers num="2.6.25.5" edition="" />
        <vers num="2.6.25.5" edition=":x86_64" />
        <vers num="2.6.25.6" edition="" />
        <vers num="2.6.25.6" edition=":x86_64" />
        <vers num="2.6.25.7" edition="" />
        <vers num="2.6.25.7" edition=":x86_64" />
        <vers num="2.6.25.8" edition="" />
        <vers num="2.6.25.8" edition=":x86_64" />
        <vers num="2.6.25.9" edition="" />
        <vers num="2.6.25.9" edition=":x86_64" />
        <vers num="2.6.26" edition="rc4" />
        <vers num="2.6.26.1" />
        <vers num="2.6.26.2" />
        <vers num="2.6.26.3" />
        <vers num="2.6.26.4" />
        <vers num="2.6.26.5" />
        <vers num="2.6.26.6" />
        <vers num="2.6.26.7" />
        <vers num="2.6.26.8" />
        <vers num="2.6.27" edition="rc1" />
        <vers num="2.6.27" edition="rc2" />
        <vers num="2.6.27" edition="rc3" />
        <vers num="2.6.27" edition="rc4" />
        <vers num="2.6.27" edition="rc6" />
        <vers num="2.6.27" edition="rc9" />
        <vers num="2.6.27.1" />
        <vers num="2.6.27.10" />
        <vers num="2.6.27.11" />
        <vers num="2.6.27.12" />
        <vers num="2.6.27.13" />
        <vers num="2.6.27.14" />
        <vers num="2.6.27.15" />
        <vers num="2.6.27.16" />
        <vers num="2.6.27.17" />
        <vers num="2.6.27.18" />
        <vers num="2.6.27.19" />
        <vers num="2.6.27.2" />
        <vers num="2.6.27.20" />
        <vers num="2.6.27.21" />
        <vers num="2.6.27.3" />
        <vers num="2.6.27.4" />
        <vers num="2.6.27.5" />
        <vers num="2.6.27.6" />
        <vers num="2.6.27.7" />
        <vers num="2.6.27.9" />
        <vers num="2.6.28" edition="git7" />
        <vers num="2.6.28" edition="rc2" />
        <vers num="2.6.28" edition="rc5" />
        <vers num="2.6.28" edition="rc7" />
        <vers num="2.6.28.4" />
        <vers num="2.6.28.6" />
        <vers num="2.6.28.7" />
        <vers num="2.6.28.9" />
        <vers num="2.6.3" />
        <vers num="2.6.30" />
        <vers num="2.6.4" />
        <vers num="2.6.5" />
        <vers num="2.6.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1185" published="2009-04-17" name="CVE-2009-1185" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">udev before 1.4.1 does not verify whether a NETLINK message originates from kernel space, which allows local users to gain privileges by sending a NETLINK message from user space.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/34536" source="BID" patch="1">34536</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1772" source="DEBIAN" patch="1">DSA-1772</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-April/msg00463.html" source="FEDORA">FEDORA-2009-3711</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-April/msg00462.html" source="FEDORA">FEDORA-2009-3712</ref>
      <ref url="https://launchpad.net/bugs/cve/2009-1185" source="MISC">https://launchpad.net/bugs/cve/2009-1185</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=495051" source="CONFIRM" adv="1">https://bugzilla.redhat.com/show_bug.cgi?id=495051</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1865" source="VUPEN">ADV-2009-1865</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1053" source="VUPEN">ADV-2009-1053</ref>
      <ref url="http://www.vmware.com/security/advisories/VMSA-2009-0009.html" source="CONFIRM">http://www.vmware.com/security/advisories/VMSA-2009-0009.html</ref>
      <ref url="http://www.ubuntu.com/usn/usn-758-1" source="UBUNTU">USN-758-1</ref>
      <ref url="http://www.securitytracker.com/id?1022067" source="SECTRACK">1022067</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/504849/100/0/threaded" source="BUGTRAQ">20090711 VMSA-2009-0009 ESX Service Console updates for udev, sudo, and curl</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/502752/100/0/threaded" source="BUGTRAQ">20090417 rPSA-2009-0063-1 udev</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-0427.html" source="REDHAT">RHSA-2009:0427</ref>
      <ref url="http://www.milw0rm.com/exploits/8572" source="MILW0RM">8572</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:104" source="MANDRIVA">MDVSA-2009:104</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:103" source="MANDRIVA">MDVSA-2009:103</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200904-18.xml" source="GENTOO">GLSA-200904-18</ref>
      <ref url="http://wiki.rpath.com/wiki/Advisories:rPSA-2009-0063" source="MISC">http://wiki.rpath.com/wiki/Advisories:rPSA-2009-0063</ref>
      <ref url="http://wiki.rpath.com/Advisories:rPSA-2009-0063" source="CONFIRM">http://wiki.rpath.com/Advisories:rPSA-2009-0063</ref>
      <ref url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2009&amp;m=slackware-security.446399" source="SLACKWARE">SSA:2009-111-01</ref>
      <ref url="http://secunia.com/advisories/35766" source="SECUNIA">35766</ref>
      <ref url="http://secunia.com/advisories/34801" source="SECUNIA">34801</ref>
      <ref url="http://secunia.com/advisories/34787" source="SECUNIA">34787</ref>
      <ref url="http://secunia.com/advisories/34785" source="SECUNIA">34785</ref>
      <ref url="http://secunia.com/advisories/34776" source="SECUNIA">34776</ref>
      <ref url="http://secunia.com/advisories/34771" source="SECUNIA">34771</ref>
      <ref url="http://secunia.com/advisories/34753" source="SECUNIA" adv="1">34753</ref>
      <ref url="http://secunia.com/advisories/34750" source="SECUNIA" adv="1">34750</ref>
      <ref url="http://secunia.com/advisories/34731" source="SECUNIA" adv="1">34731</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5975" source="OVAL">oval:org.mitre.oval:def:5975</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10925" source="OVAL">oval:org.mitre.oval:def:10925</ref>
      <ref url="http://lists.vmware.com/pipermail/security-announce/2009/000060.html" source="MLIST">[Security-announce] 20090710 VMSA-2009-0009 ESX Service Console updates for udev, sudo, and curl</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-04/msg00012.html" source="SUSE">SUSE-SA:2009:025</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-04/msg00006.html" source="SUSE">SUSE-SA:2009:020</ref>
      <ref url="http://git.kernel.org/?p=linux/hotplug/udev.git;a=commitdiff;h=e86a923d508c2aed371cdd958ce82489cf2ab615" source="CONFIRM" adv="1">http://git.kernel.org/?p=linux/hotplug/udev.git;a=commitdiff;h=e86a923d508c2aed371cdd958ce82489cf2ab615</ref>
      <ref url="http://git.kernel.org/?p=linux/hotplug/udev.git;a=commitdiff;h=e2b362d9f23d4c63018709ab5f81a02f72b91e75" source="CONFIRM" adv="1">http://git.kernel.org/?p=linux/hotplug/udev.git;a=commitdiff;h=e2b362d9f23d4c63018709ab5f81a02f72b91e75</ref>
    </refs>
    <vuln_soft>
      <prod vendor="kernel" name="udev">
        <vers num="0.0.1" />
        <vers num="0.0.2" />
        <vers num="0.0.3" />
        <vers num="0.0.4" />
        <vers num="0.0.4-1" />
        <vers num="0.0.5" />
        <vers num="0.0.5-1" />
        <vers num="0.0.6" />
        <vers num="0.0.7" />
        <vers num="0.0.8" />
        <vers num="0.0.8-1" />
        <vers num="0.0.9" />
        <vers num="0.0.9-1" />
        <vers num="0.1.0-1" />
        <vers num="0.1.1-1" />
        <vers num="0.1.2" />
        <vers num="0.1.3" />
        <vers num="0.1.4" />
        <vers num="0.1.5" />
        <vers num="0.1.6" />
        <vers num="0.1.7" />
        <vers num="0.1.8" />
        <vers num="0.1.9" />
        <vers num="0.2.0" />
        <vers num="0.2.1" />
        <vers num="0.2.2" />
        <vers num="0.2.3" />
        <vers num="0.2.4" />
        <vers num="0.2.5" />
        <vers num="0.2.6" />
        <vers num="0.2.7" />
        <vers num="0.2.8" />
        <vers num="0.2.9" />
        <vers num="0.3.0" />
        <vers num="0.3.1" />
        <vers num="0.3.2" />
        <vers num="0.3.3" />
        <vers num="0.3.4" />
        <vers num="0.3.5" />
        <vers num="0.3.6" />
        <vers num="0.3.7" />
        <vers num="0.3.8" />
        <vers num="0.3.9" />
        <vers num="0.4.0" />
        <vers num="0.4.2" />
        <vers num="0.4.3" />
        <vers num="0.4.4" />
        <vers num="0.4.5" />
        <vers num="0.4.6" />
        <vers num="0.4.7" />
        <vers num="0.4.8" />
        <vers num="0.4.9" />
        <vers num="0.5.0" />
        <vers num="0.5.1" />
        <vers num="0.5.2" />
        <vers num="0.5.3" />
        <vers num="0.5.4" />
        <vers num="0.5.5" />
        <vers num="0.5.6" />
        <vers num="0.5.7" />
        <vers num="0.5.8" />
        <vers num="0.5.9" />
        <vers num="0.6.0" />
        <vers num="0.6.1" />
        <vers num="0.6.2" />
        <vers num="0.6.3" />
        <vers num="0.6.4" />
        <vers num="0.6.5" />
        <vers num="0.6.6" />
        <vers num="0.6.7" />
        <vers num="0.6.8" />
        <vers num="0.6.9" />
        <vers num="0.7.0" />
        <vers num="0.7.1" />
        <vers num="0.7.2" />
        <vers num="0.7.3" />
        <vers num="0.7.4" />
        <vers num="0.7.5" />
        <vers num="0.7.6" />
        <vers num="0.7.7" />
        <vers num="0.7.8" />
        <vers num="0.7.9" />
        <vers num="0.8.0" />
        <vers num="0.8.1" />
        <vers num="0.8.2" />
        <vers num="0.8.3" />
        <vers num="0.8.4" />
        <vers num="0.8.5" />
        <vers num="0.8.6" />
        <vers num="0.8.7" />
        <vers num="0.8.8" />
        <vers num="0.8.9" />
        <vers num="0.9.0" />
        <vers num="0.9.1" />
        <vers num="0.9.2" />
        <vers num="0.9.3" />
        <vers num="0.9.4" />
        <vers num="0.9.5" />
        <vers num="0.9.6" />
        <vers num="0.9.7" />
        <vers num="0.9.8" />
        <vers num="0.9.9" />
        <vers num="1.0.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.5" />
        <vers num="1.0.6" />
        <vers num="1.0.7" />
        <vers num="1.0.8" />
        <vers num="1.0.9" />
        <vers num="1.1.0" />
        <vers num="1.1.1" />
        <vers num="1.1.2" />
        <vers num="1.1.3" />
        <vers num="1.1.4" />
        <vers num="1.1.5" />
        <vers num="1.1.6" />
        <vers num="1.1.7" />
        <vers num="1.1.8" />
        <vers num="1.1.9" />
        <vers num="1.2.0" />
        <vers num="1.2.1" />
        <vers num="1.2.2" />
        <vers num="1.2.3" />
        <vers num="1.2.4" />
        <vers num="1.2.5" />
        <vers num="1.2.6" />
        <vers num="1.2.7" />
        <vers num="1.2.8" />
        <vers num="1.2.9" />
        <vers num="1.3.0" />
        <vers num="1.3.1" />
        <vers num="1.3.2" />
        <vers num="1.3.3" />
        <vers num="1.3.4" />
        <vers num="1.3.5" />
        <vers num="1.3.6" />
        <vers num="1.3.7" />
        <vers num="1.3.8" />
        <vers num="1.3.9" />
        <vers prev="1" num="1.4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2009-1186" published="2009-04-17" name="CVE-2009-1186" modified="2009-06-08" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Buffer overflow in the util_path_encode function in udev/lib/libudev-util.c in udev before 1.4.1 allows local users to cause a denial of service (service outage) via vectors that trigger a call with crafted arguments.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-April/msg00463.html" source="FEDORA">FEDORA-2009-3711</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-April/msg00462.html" source="FEDORA">FEDORA-2009-3712</ref>
      <ref url="https://launchpad.net/bugs/cve/2009-1186" source="MISC">https://launchpad.net/bugs/cve/2009-1186</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=495052" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=495052</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1053" source="VUPEN">ADV-2009-1053</ref>
      <ref url="http://www.ubuntu.com/usn/usn-758-1" source="UBUNTU">USN-758-1</ref>
      <ref url="http://www.securitytracker.com/id?1022068" source="SECTRACK">1022068</ref>
      <ref url="http://www.securityfocus.com/bid/34539" source="BID">34539</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/502752/100/0/threaded" source="BUGTRAQ">20090417 rPSA-2009-0063-1 udev</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:103" source="MANDRIVA">MDVSA-2009:103</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200904-18.xml" source="GENTOO">GLSA-200904-18</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1772" source="DEBIAN">DSA-1772</ref>
      <ref url="http://wiki.rpath.com/wiki/Advisories:rPSA-2009-0063" source="MISC">http://wiki.rpath.com/wiki/Advisories:rPSA-2009-0063</ref>
      <ref url="http://wiki.rpath.com/Advisories:rPSA-2009-0063" source="CONFIRM">http://wiki.rpath.com/Advisories:rPSA-2009-0063</ref>
      <ref url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2009&amp;m=slackware-security.446399" source="SLACKWARE">SSA:2009-111-01</ref>
      <ref url="http://secunia.com/advisories/34801" source="SECUNIA">34801</ref>
      <ref url="http://secunia.com/advisories/34787" source="SECUNIA">34787</ref>
      <ref url="http://secunia.com/advisories/34785" source="SECUNIA">34785</ref>
      <ref url="http://secunia.com/advisories/34776" source="SECUNIA">34776</ref>
      <ref url="http://secunia.com/advisories/34771" source="SECUNIA">34771</ref>
      <ref url="http://secunia.com/advisories/34753" source="SECUNIA" adv="1">34753</ref>
      <ref url="http://secunia.com/advisories/34750" source="SECUNIA" adv="1">34750</ref>
      <ref url="http://secunia.com/advisories/34731" source="SECUNIA" adv="1">34731</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-04/msg00006.html" source="SUSE">SUSE-SA:2009:020</ref>
      <ref url="http://git.kernel.org/?p=linux/hotplug/udev.git;a=commitdiff;h=662c3110803bd8c1aedacc36788e6fd028944314" source="CONFIRM">http://git.kernel.org/?p=linux/hotplug/udev.git;a=commitdiff;h=662c3110803bd8c1aedacc36788e6fd028944314</ref>
    </refs>
    <vuln_soft>
      <prod vendor="kernel" name="udev">
        <vers num="0.0.1" />
        <vers num="0.0.2" />
        <vers num="0.0.3" />
        <vers num="0.0.4" />
        <vers num="0.0.4-1" />
        <vers num="0.0.5" />
        <vers num="0.0.5-1" />
        <vers num="0.0.6" />
        <vers num="0.0.7" />
        <vers num="0.0.8" />
        <vers num="0.0.8-1" />
        <vers num="0.0.9" />
        <vers num="0.0.9-1" />
        <vers num="0.1.0-1" />
        <vers num="0.1.1-1" />
        <vers num="0.1.2" />
        <vers num="0.1.3" />
        <vers num="0.1.4" />
        <vers num="0.1.5" />
        <vers num="0.1.6" />
        <vers num="0.1.7" />
        <vers num="0.1.8" />
        <vers num="0.1.9" />
        <vers num="0.2.0" />
        <vers num="0.2.1" />
        <vers num="0.2.2" />
        <vers num="0.2.3" />
        <vers num="0.2.4" />
        <vers num="0.2.5" />
        <vers num="0.2.6" />
        <vers num="0.2.7" />
        <vers num="0.2.8" />
        <vers num="0.2.9" />
        <vers num="0.3.0" />
        <vers num="0.3.1" />
        <vers num="0.3.2" />
        <vers num="0.3.3" />
        <vers num="0.3.4" />
        <vers num="0.3.5" />
        <vers num="0.3.6" />
        <vers num="0.3.7" />
        <vers num="0.3.8" />
        <vers num="0.3.9" />
        <vers num="0.4.0" />
        <vers num="0.4.2" />
        <vers num="0.4.3" />
        <vers num="0.4.4" />
        <vers num="0.4.5" />
        <vers num="0.4.6" />
        <vers num="0.4.7" />
        <vers num="0.4.8" />
        <vers num="0.4.9" />
        <vers num="0.5.0" />
        <vers num="0.5.1" />
        <vers num="0.5.2" />
        <vers num="0.5.3" />
        <vers num="0.5.4" />
        <vers num="0.5.5" />
        <vers num="0.5.6" />
        <vers num="0.5.7" />
        <vers num="0.5.8" />
        <vers num="0.5.9" />
        <vers num="0.6.0" />
        <vers num="0.6.1" />
        <vers num="0.6.2" />
        <vers num="0.6.3" />
        <vers num="0.6.4" />
        <vers num="0.6.5" />
        <vers num="0.6.6" />
        <vers num="0.6.7" />
        <vers num="0.6.8" />
        <vers num="0.6.9" />
        <vers num="0.7.0" />
        <vers num="0.7.1" />
        <vers num="0.7.2" />
        <vers num="0.7.3" />
        <vers num="0.7.4" />
        <vers num="0.7.5" />
        <vers num="0.7.6" />
        <vers num="0.7.7" />
        <vers num="0.7.8" />
        <vers num="0.7.9" />
        <vers num="0.8.0" />
        <vers num="0.8.1" />
        <vers num="0.8.2" />
        <vers num="0.8.3" />
        <vers num="0.8.4" />
        <vers num="0.8.5" />
        <vers num="0.8.6" />
        <vers num="0.8.7" />
        <vers num="0.8.8" />
        <vers num="0.8.9" />
        <vers num="0.9.0" />
        <vers num="0.9.1" />
        <vers num="0.9.2" />
        <vers num="0.9.3" />
        <vers num="0.9.4" />
        <vers num="0.9.5" />
        <vers num="0.9.6" />
        <vers num="0.9.7" />
        <vers num="0.9.8" />
        <vers num="0.9.9" />
        <vers num="1.0.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.5" />
        <vers num="1.0.6" />
        <vers num="1.0.7" />
        <vers num="1.0.8" />
        <vers num="1.0.9" />
        <vers num="1.1.0" />
        <vers num="1.1.1" />
        <vers num="1.1.2" />
        <vers num="1.1.3" />
        <vers num="1.1.4" />
        <vers num="1.1.5" />
        <vers num="1.1.6" />
        <vers num="1.1.7" />
        <vers num="1.1.8" />
        <vers num="1.1.9" />
        <vers num="1.2.0" />
        <vers num="1.2.1" />
        <vers num="1.2.2" />
        <vers num="1.2.3" />
        <vers num="1.2.4" />
        <vers num="1.2.5" />
        <vers num="1.2.6" />
        <vers num="1.2.7" />
        <vers num="1.2.8" />
        <vers num="1.2.9" />
        <vers num="1.3.0" />
        <vers num="1.3.1" />
        <vers num="1.3.2" />
        <vers num="1.3.3" />
        <vers num="1.3.4" />
        <vers num="1.3.5" />
        <vers num="1.3.6" />
        <vers num="1.3.7" />
        <vers num="1.3.8" />
        <vers num="1.3.9" />
        <vers prev="1" num="1.4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1187" published="2009-04-23" name="CVE-2009-1187" modified="2012-01-18" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Integer overflow in the JBIG2 decoding feature in Poppler before 0.10.6 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via vectors related to CairoOutputDev (CairoOutputDev.cc).</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/196617" source="CERT-VN">VU#196617</ref>
      <ref url="http://bugs.gentoo.org/show_bug.cgi?id=263028#c16" source="CONFIRM" patch="1">http://bugs.gentoo.org/show_bug.cgi?id=263028#c16</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-June/msg01291.html" source="FEDORA">FEDORA-2009-6982</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-June/msg01277.html" source="FEDORA">FEDORA-2009-6973</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-July/msg00567.html" source="FEDORA">FEDORA-2009-6972</ref>
      <ref url="https://bugs.launchpad.net/ubuntu/+source/poppler/+bug/361875" source="CONFIRM">https://bugs.launchpad.net/ubuntu/+source/poppler/+bug/361875</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/50184" source="XF">poppler-jbig2-cairooutputdev-code-excution(50184)</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1040" source="VUPEN">ADV-2010-1040</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1076" source="VUPEN">ADV-2009-1076</ref>
      <ref url="http://www.securityfocus.com/bid/34568" source="BID">34568</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/502761/100/0/threaded" source="BUGTRAQ">20090417 rPSA-2009-0059-1 poppler</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-0480.html" source="REDHAT">RHSA-2009:0480</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2011:175" source="MANDRIVA">MDVSA-2011:175</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2010:087" source="MANDRIVA">MDVSA-2010:087</ref>
      <ref url="http://wiki.rpath.com/Advisories:rPSA-2009-0059" source="CONFIRM">http://wiki.rpath.com/Advisories:rPSA-2009-0059</ref>
      <ref url="http://secunia.com/advisories/35618" source="SECUNIA">35618</ref>
      <ref url="http://secunia.com/advisories/35064" source="SECUNIA">35064</ref>
      <ref url="http://secunia.com/advisories/34746" source="SECUNIA">34746</ref>
      <ref url="http://poppler.freedesktop.org/releases.html" source="CONFIRM">http://poppler.freedesktop.org/releases.html</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10292" source="OVAL">oval:org.mitre.oval:def:10292</ref>
    </refs>
    <vuln_soft>
      <prod vendor="poppler" name="poppler">
        <vers num="0.1" />
        <vers num="0.1.1" />
        <vers num="0.1.2" />
        <vers num="0.10.0" />
        <vers num="0.10.1" />
        <vers num="0.10.2" />
        <vers num="0.10.3" />
        <vers num="0.10.4" />
        <vers prev="1" num="0.10.5" />
        <vers num="0.2.0" />
        <vers num="0.3.0" />
        <vers num="0.3.1" />
        <vers num="0.3.2" />
        <vers num="0.3.3" />
        <vers num="0.4.0" />
        <vers num="0.4.1" />
        <vers num="0.4.2" />
        <vers num="0.4.3" />
        <vers num="0.4.4" />
        <vers num="0.5.0" />
        <vers num="0.5.1" />
        <vers num="0.5.2" />
        <vers num="0.5.3" />
        <vers num="0.5.4" />
        <vers num="0.5.9" />
        <vers num="0.5.90" />
        <vers num="0.5.91" />
        <vers num="0.6.0" />
        <vers num="0.6.1" />
        <vers num="0.6.2" />
        <vers num="0.6.3" />
        <vers num="0.6.4" />
        <vers num="0.7.0" />
        <vers num="0.7.1" />
        <vers num="0.7.2" />
        <vers num="0.7.3" />
        <vers num="0.8.0" />
        <vers num="0.8.1" />
        <vers num="0.8.2" />
        <vers num="0.8.3" />
        <vers num="0.8.4" />
        <vers num="0.8.5" />
        <vers num="0.8.6" />
        <vers num="0.8.7" />
        <vers num="0.9.0" />
        <vers num="0.9.1" />
        <vers num="0.9.2" />
        <vers num="0.9.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1188" published="2009-04-23" name="CVE-2009-1188" modified="2012-01-18" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Integer overflow in the JBIG2 decoding feature in the SplashBitmap::SplashBitmap function in SplashBitmap.cc in Xpdf 3.x before 3.02pl4 and Poppler before 0.10.6, as used in GPdf and kdegraphics KPDF, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted PDF document.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/196617" source="CERT-VN">VU#196617</ref>
      <ref url="http://bugs.gentoo.org/show_bug.cgi?id=263028#c16" source="CONFIRM" patch="1">http://bugs.gentoo.org/show_bug.cgi?id=263028#c16</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-June/msg01291.html" source="FEDORA">FEDORA-2009-6982</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-June/msg01277.html" source="FEDORA">FEDORA-2009-6973</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-July/msg00567.html" source="FEDORA">FEDORA-2009-6972</ref>
      <ref url="https://rhn.redhat.com/errata/RHSA-2009-1512.html" source="REDHAT">RHSA-2009:1512</ref>
      <ref url="https://rhn.redhat.com/errata/RHSA-2009-1503.html" source="REDHAT">RHSA-2009:1503</ref>
      <ref url="https://rhn.redhat.com/errata/RHSA-2009-1502.html" source="REDHAT">RHSA-2009:1502</ref>
      <ref url="https://rhn.redhat.com/errata/RHSA-2009-1501.html" source="REDHAT">RHSA-2009:1501</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=526915" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=526915</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=495907" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=495907</ref>
      <ref url="https://bugs.launchpad.net/ubuntu/+source/poppler/+bug/361875" source="CONFIRM">https://bugs.launchpad.net/ubuntu/+source/poppler/+bug/361875</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/50185" source="XF">poppler-jbig2-splashbitmap-code-execution(50185)</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1220" source="VUPEN">ADV-2010-1220</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1040" source="VUPEN">ADV-2010-1040</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0802" source="VUPEN">ADV-2010-0802</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/2928" source="VUPEN">ADV-2009-2928</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1076" source="VUPEN">ADV-2009-1076</ref>
      <ref url="http://www.securityfocus.com/bid/34568" source="BID">34568</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/502761/100/0/threaded" source="BUGTRAQ">20090417 rPSA-2009-0059-1 poppler</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-0480.html" source="REDHAT">RHSA-2009:0480</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2011:175" source="MANDRIVA">MDVSA-2011:175</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2010:087" source="MANDRIVA">MDVSA-2010:087</ref>
      <ref url="http://www.debian.org/security/2010/dsa-2050" source="DEBIAN">DSA-2050</ref>
      <ref url="http://www.debian.org/security/2010/dsa-2028" source="DEBIAN">DSA-2028</ref>
      <ref url="http://wiki.rpath.com/Advisories:rPSA-2009-0059" source="CONFIRM">http://wiki.rpath.com/Advisories:rPSA-2009-0059</ref>
      <ref url="http://secunia.com/advisories/39938" source="SECUNIA">39938</ref>
      <ref url="http://secunia.com/advisories/39327" source="SECUNIA">39327</ref>
      <ref url="http://secunia.com/advisories/37079" source="SECUNIA">37079</ref>
      <ref url="http://secunia.com/advisories/37077" source="SECUNIA">37077</ref>
      <ref url="http://secunia.com/advisories/37053" source="SECUNIA">37053</ref>
      <ref url="http://secunia.com/advisories/37043" source="SECUNIA">37043</ref>
      <ref url="http://secunia.com/advisories/37037" source="SECUNIA">37037</ref>
      <ref url="http://secunia.com/advisories/37028" source="SECUNIA">37028</ref>
      <ref url="http://secunia.com/advisories/35618" source="SECUNIA">35618</ref>
      <ref url="http://secunia.com/advisories/35064" source="SECUNIA">35064</ref>
      <ref url="http://secunia.com/advisories/34746" source="SECUNIA">34746</ref>
      <ref url="http://poppler.freedesktop.org/releases.html" source="CONFIRM">http://poppler.freedesktop.org/releases.html</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9957" source="OVAL">oval:org.mitre.oval:def:9957</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2010-February/035408.html" source="FEDORA">FEDORA-2010-1377</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2010-February/035399.html" source="FEDORA">FEDORA-2010-1842</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2010-February/035340.html" source="FEDORA">FEDORA-2010-1805</ref>
    </refs>
    <vuln_soft>
      <prod vendor="poppler" name="poppler">
        <vers num="0.1" />
        <vers num="0.1.1" />
        <vers num="0.1.2" />
        <vers num="0.10.0" />
        <vers num="0.10.1" />
        <vers num="0.10.2" />
        <vers num="0.10.3" />
        <vers num="0.10.4" />
        <vers prev="1" num="0.10.5" />
        <vers num="0.2.0" />
        <vers num="0.3.0" />
        <vers num="0.3.1" />
        <vers num="0.3.2" />
        <vers num="0.3.3" />
        <vers num="0.4.0" />
        <vers num="0.4.1" />
        <vers num="0.4.2" />
        <vers num="0.4.3" />
        <vers num="0.4.4" />
        <vers num="0.5.0" />
        <vers num="0.5.1" />
        <vers num="0.5.2" />
        <vers num="0.5.3" />
        <vers num="0.5.4" />
        <vers num="0.5.9" />
        <vers num="0.5.90" />
        <vers num="0.5.91" />
        <vers num="0.6.0" />
        <vers num="0.6.1" />
        <vers num="0.6.2" />
        <vers num="0.6.3" />
        <vers num="0.6.4" />
        <vers num="0.7.0" />
        <vers num="0.7.1" />
        <vers num="0.7.2" />
        <vers num="0.7.3" />
        <vers num="0.8.0" />
        <vers num="0.8.1" />
        <vers num="0.8.2" />
        <vers num="0.8.3" />
        <vers num="0.8.4" />
        <vers num="0.8.5" />
        <vers num="0.8.6" />
        <vers num="0.8.7" />
        <vers num="0.9.0" />
        <vers num="0.9.1" />
        <vers num="0.9.2" />
        <vers num="0.9.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2009-1189" published="2009-04-27" name="CVE-2009-1189" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:P)" CVSS_score="3.6" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="3.9" CVSS_base_score="3.6">
    <desc>
      <descript source="cve">The _dbus_validate_signature_with_reason function (dbus-marshal-validate.c) in D-Bus (aka DBus) before 1.2.14 uses incorrect logic to validate a basic type, which allows remote attackers to spoof a signature via a crafted key.  NOTE: this is due to an incorrect fix for CVE-2008-3834.</descript>
    </desc>
    <loss_types>
      <avail />
      <int />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.freedesktop.org/wiki/Software/dbus#head-dad0dab297a44f1d7a3b1259cfc06b583fd6a88a" source="CONFIRM" patch="1" adv="1">http://www.freedesktop.org/wiki/Software/dbus#head-dad0dab297a44f1d7a3b1259cfc06b583fd6a88a</ref>
      <ref url="https://rhn.redhat.com/errata/RHSA-2010-0095.html" source="REDHAT">RHSA-2010:0095</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/50385" source="XF">dbus-dbusmarshalvalidate-spoofing(50385)</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0528" source="VUPEN" adv="1">ADV-2010-0528</ref>
      <ref url="http://www.securityfocus.com/bid/31602" source="BID">31602</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2009/04/16/13" source="MLIST">[oss-security] 20090416 CVE-2009-1189: invalid fix for CVE-2008-3834 (dbus)</ref>
      <ref url="http://secunia.com/advisories/38794" source="SECUNIA" adv="1">38794</ref>
      <ref url="http://secunia.com/advisories/35810" source="SECUNIA" adv="1">35810</ref>
      <ref url="http://secunia.com/advisories/32127" source="SECUNIA" adv="1">32127</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10308" source="OVAL">oval:org.mitre.oval:def:10308</ref>
      <ref url="http://lists.vmware.com/pipermail/security-announce/2010/000082.html" source="MLIST">[security-announce] 20100303 VMSA-2010-0004 ESX Service Console and vMA third party updates</ref>
      <ref url="http://bugs.freedesktop.org/show_bug.cgi?id=17803" source="CONFIRM">http://bugs.freedesktop.org/show_bug.cgi?id=17803</ref>
    </refs>
    <vuln_soft>
      <prod vendor="freedesktop" name="dbus">
        <vers num="0.1" />
        <vers num="0.10" />
        <vers num="0.11" />
        <vers num="0.12" />
        <vers num="0.13" />
        <vers num="0.2" />
        <vers num="0.20" />
        <vers num="0.21" />
        <vers num="0.22" />
        <vers num="0.23" />
        <vers num="0.23.1" />
        <vers num="0.23.2" />
        <vers num="0.23.3" />
        <vers num="0.3" />
        <vers num="0.31" />
        <vers num="0.32" />
        <vers num="0.33" />
        <vers num="0.34" />
        <vers num="0.35" />
        <vers num="0.35.1" />
        <vers num="0.35.2" />
        <vers num="0.36" />
        <vers num="0.36.1" />
        <vers num="0.36.2" />
        <vers num="0.4" />
        <vers num="0.5" />
        <vers num="0.50" />
        <vers num="0.6" />
        <vers num="0.60" />
        <vers num="0.61" />
        <vers num="0.62" />
        <vers num="0.7" />
        <vers num="0.8" />
        <vers num="0.9" />
        <vers num="0.90" />
        <vers num="0.91" />
        <vers num="0.92" />
        <vers num="1.0" edition="rc1" />
        <vers num="1.0" edition="rc2" />
        <vers num="1.0" edition="rc3" />
        <vers num="1.0.2" />
        <vers num="1.1.0" />
        <vers num="1.1.1" />
        <vers num="1.1.2" />
        <vers num="1.1.20" />
        <vers num="1.1.4" />
        <vers num="1.2.1" />
        <vers prev="1" num="1.2.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1190" published="2009-04-27" name="CVE-2009-1190" modified="2011-01-20" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Algorithmic complexity vulnerability in the java.util.regex.Pattern.compile method in Sun Java Development Kit (JDK) before 1.6, when used with spring.jar in SpringSource Spring Framework 1.1.0 through 2.5.6 and 3.0.0.M1 through 3.0.0.M2 and dm Server 1.0.0 through 1.0.2, allows remote attackers to cause a denial of service (CPU consumption) via serializable data with a long regex string containing multiple optional groups, a related issue to CVE-2004-2540.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=497161" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=497161</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/50083" source="XF">springframework-data-dos(50083)</ref>
      <ref url="http://www.springsource.com/securityadvisory" source="CONFIRM" adv="1">http://www.springsource.com/securityadvisory</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/502926/100/0/threaded" source="BUGTRAQ">20090424 CVE-2009-1190: Spring Framework Remote Denial of Service Vulnerability</ref>
      <ref url="http://www.packetstormsecurity.org/hitb06/DAY_1_-_Marc_Schoenefeld_-_Pentesting_Java_J2EE.pdf" source="MISC">http://www.packetstormsecurity.org/hitb06/DAY_1_-_Marc_Schoenefeld_-_Pentesting_Java_J2EE.pdf</ref>
      <ref url="http://secunia.com/advisories/34892" source="SECUNIA" adv="1">34892</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="jdk">
        <vers num="1.1.0" />
        <vers num="1.1.6" edition="update7" />
        <vers num="1.1.7b" edition="update5" />
        <vers num="1.1.8" edition="update10" />
        <vers num="1.1.8" edition="update13" />
        <vers num="1.1.8" edition="update14" />
        <vers num="1.1.8" edition="update2" />
        <vers num="1.1.8" edition="update7" />
        <vers num="1.1.8" edition="update8" />
        <vers num="1.2.0" />
        <vers num="1.2.1" edition="update3" />
        <vers num="1.2.2" edition="update4" />
        <vers num="1.2.2" edition="update5" />
        <vers num="1.3.0" />
        <vers num="1.3.0_01" />
        <vers num="1.3.0_02" />
        <vers num="1.3.0_03" />
        <vers num="1.3.0_04" />
        <vers num="1.3.0_05" />
        <vers num="1.3.1" edition="update19" />
        <vers num="1.3.1" edition="update20" />
        <vers num="1.3.1_01" />
        <vers num="1.3.1_01a" />
        <vers num="1.3.1_02" />
        <vers num="1.3.1_03" />
        <vers num="1.3.1_04" />
        <vers num="1.3.1_05" />
        <vers num="1.3.1_06" />
        <vers num="1.3.1_07" />
        <vers num="1.3.1_08" />
        <vers num="1.3.1_09" />
        <vers num="1.3.1_10" />
        <vers num="1.3.1_11" />
        <vers num="1.3.1_12" />
        <vers num="1.3.1_13" />
        <vers num="1.3.1_14" />
        <vers num="1.3.1_15" />
        <vers num="1.3.1_16" />
        <vers num="1.3.1_17" />
        <vers num="1.3.1_18" />
        <vers num="1.3.1_19" />
        <vers num="1.3.1_20" />
        <vers num="1.3.1_21" />
        <vers num="1.3.1_22" />
        <vers num="1.3.1_23" />
        <vers num="1.3.1_24" />
        <vers num="1.3.1_25" />
        <vers num="1.3.1_26" />
        <vers num="1.3.1_27" />
        <vers num="1.3.1_28" />
        <vers num="1.4.0" />
        <vers num="1.4.0_01" />
        <vers num="1.4.0_02" />
        <vers num="1.4.0_03" />
        <vers num="1.4.0_04" />
        <vers num="1.4.1" />
        <vers num="1.4.1_01" />
        <vers num="1.4.1_02" />
        <vers num="1.4.1_03" />
        <vers num="1.4.1_04" />
        <vers num="1.4.1_05" />
        <vers num="1.4.1_06" />
        <vers num="1.4.1_07" />
        <vers num="1.4.2" edition="update14" />
        <vers num="1.4.2_1" />
        <vers num="1.4.2_10" />
        <vers num="1.4.2_11" />
        <vers num="1.4.2_12" />
        <vers num="1.4.2_13" />
        <vers num="1.4.2_14" />
        <vers num="1.4.2_15" />
        <vers num="1.4.2_16" />
        <vers num="1.4.2_17" />
        <vers num="1.4.2_18" />
        <vers num="1.4.2_19" />
        <vers num="1.4.2_2" />
        <vers num="1.4.2_3" />
        <vers num="1.4.2_4" />
        <vers num="1.4.2_5" />
        <vers num="1.4.2_6" />
        <vers num="1.4.2_7" />
        <vers num="1.4.2_8" />
        <vers num="1.4.2_9" />
        <vers prev="1" num="1.5.0" edition="update1" />
        <vers prev="1" num="1.5.0" edition="update10" />
        <vers prev="1" num="1.5.0" edition="update11" />
        <vers prev="1" num="1.5.0" edition="update11_b03" />
        <vers prev="1" num="1.5.0" edition="update12" />
        <vers prev="1" num="1.5.0" edition="update13" />
        <vers prev="1" num="1.5.0" edition="update14" />
        <vers prev="1" num="1.5.0" edition="update15" />
        <vers prev="1" num="1.5.0" edition="update16" />
        <vers prev="1" num="1.5.0" edition="update17" />
        <vers prev="1" num="1.5.0" edition="update18" />
        <vers prev="1" num="1.5.0" edition="update19" />
        <vers prev="1" num="1.5.0" edition="update2" />
        <vers prev="1" num="1.5.0" edition="update20" />
        <vers prev="1" num="1.5.0" edition="update21" />
        <vers prev="1" num="1.5.0" edition="update22" />
        <vers prev="1" num="1.5.0" edition="update23" />
        <vers prev="1" num="1.5.0" edition="update24" />
        <vers prev="1" num="1.5.0" edition="update25" />
        <vers prev="1" num="1.5.0" edition="update3" />
        <vers prev="1" num="1.5.0" edition="update4" />
        <vers prev="1" num="1.5.0" edition="update5" />
        <vers prev="1" num="1.5.0" edition="update6" />
        <vers prev="1" num="1.5.0" edition="update7" />
        <vers prev="1" num="1.5.0" edition="update7_b03" />
        <vers prev="1" num="1.5.0" edition="update8" />
        <vers prev="1" num="1.5.0" edition="update9" />
        <vers prev="1" num="1.5.0" edition="update_1" />
        <vers prev="1" num="1.5.0" edition="update_10" />
        <vers prev="1" num="1.5.0" edition="update_11" />
        <vers prev="1" num="1.5.0" edition="update_12" />
        <vers prev="1" num="1.5.0" edition="update_13" />
        <vers prev="1" num="1.5.0" edition="update_14" />
        <vers prev="1" num="1.5.0" edition="update_15" />
        <vers prev="1" num="1.5.0" edition="update_16" />
        <vers prev="1" num="1.5.0" edition="update_17" />
        <vers prev="1" num="1.5.0" edition="update_18" />
        <vers prev="1" num="1.5.0" edition="update_19" />
        <vers prev="1" num="1.5.0" edition="update_2" />
        <vers prev="1" num="1.5.0" edition="update_20" />
        <vers prev="1" num="1.5.0" edition="update_21" />
        <vers prev="1" num="1.5.0" edition="update_22" />
        <vers prev="1" num="1.5.0" edition="update_3" />
        <vers prev="1" num="1.5.0" edition="update_4" />
        <vers prev="1" num="1.5.0" edition="update_5" />
        <vers prev="1" num="1.5.0" edition="update_6" />
        <vers prev="1" num="1.5.0" edition="update_7" />
        <vers prev="1" num="1.5.0" edition="update_8" />
        <vers prev="1" num="1.5.0" edition="update_9" />
        <vers num="1.5.0_03" edition="" />
        <vers num="1.5.0_03" edition=":solaris" />
        <vers num="1.5.0_03" edition=":windows" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1191" published="2009-04-23" name="CVE-2009-1191" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">mod_proxy_ajp.c in the mod_proxy_ajp module in the Apache HTTP Server 2.2.11 allows remote attackers to obtain sensitive response data, intended for a client that sent an earlier POST request with no request body, via an HTTP request.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/34663" source="BID" patch="1">34663</ref>
      <ref url="http://www.apache.org/dist/httpd/patches/apply_to_2.2.11/PR46949.diff" source="CONFIRM" patch="1" adv="1">http://www.apache.org/dist/httpd/patches/apply_to_2.2.11/PR46949.diff</ref>
      <ref url="http://svn.apache.org/viewvc/httpd/httpd/trunk/CHANGES?r1=766938&amp;r2=767089" source="CONFIRM" patch="1" adv="1">http://svn.apache.org/viewvc/httpd/httpd/trunk/CHANGES?r1=766938&amp;r2=767089</ref>
      <ref url="https://issues.apache.org/bugzilla/show_bug.cgi?id=46949" source="CONFIRM" adv="1">https://issues.apache.org/bugzilla/show_bug.cgi?id=46949</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/50059" source="XF">apache-modproxyajp-information-disclosure(50059)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/3184" source="VUPEN">ADV-2009-3184</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1147" source="VUPEN">ADV-2009-1147</ref>
      <ref url="http://www.ubuntu.com/usn/usn-787-1" source="UBUNTU">USN-787-1</ref>
      <ref url="http://www.securitytracker.com/id?1022264" source="SECTRACK">1022264</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:102" source="MANDRIVA">MDVSA-2009:102</ref>
      <ref url="http://support.apple.com/kb/HT3937" source="CONFIRM">http://support.apple.com/kb/HT3937</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200907-04.xml" source="GENTOO">GLSA-200907-04</ref>
      <ref url="http://secunia.com/advisories/35721" source="SECUNIA">35721</ref>
      <ref url="http://secunia.com/advisories/35395" source="SECUNIA">35395</ref>
      <ref url="http://secunia.com/advisories/34827" source="SECUNIA" adv="1">34827</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:8261" source="OVAL">oval:org.mitre.oval:def:8261</ref>
      <ref url="http://osvdb.org/53921" source="OSVDB">53921</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2009/Nov/msg00000.html" source="APPLE">APPLE-SA-2009-11-09-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apache" name="apache_http_server">
        <vers num="2.2.11" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1192" published="2009-04-24" name="CVE-2009-1192" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:N/A:N)" CVSS_score="4.9" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="3.9" CVSS_base_score="4.9">
    <desc>
      <descript source="cve">The (1) agp_generic_alloc_page and (2) agp_generic_alloc_pages functions in drivers/char/agp/generic.c in the agp subsystem in the Linux kernel before 2.6.30-rc3 do not zero out pages that may later be available to a user-space process, which allows local users to obtain sensitive information by reading these pages.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=497020" source="CONFIRM" patch="1">https://bugzilla.redhat.com/show_bug.cgi?id=497020</ref>
      <ref url="http://www.securityfocus.com/bid/34673" source="BID" patch="1">34673</ref>
      <ref url="http://www.kernel.org/pub/linux/kernel/v2.6/testing/ChangeLog-2.6.30-rc3" source="CONFIRM" patch="1" adv="1">http://www.kernel.org/pub/linux/kernel/v2.6/testing/ChangeLog-2.6.30-rc3</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/3316" source="VUPEN">ADV-2009-3316</ref>
      <ref url="http://www.vmware.com/security/advisories/VMSA-2009-0016.html" source="CONFIRM">http://www.vmware.com/security/advisories/VMSA-2009-0016.html</ref>
      <ref url="http://www.ubuntu.com/usn/usn-793-1" source="UBUNTU">USN-793-1</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/507985/100/0/threaded" source="BUGTRAQ">20091120 VMSA-2009-0016 VMware vCenter and ESX update release and vMA patch release address multiple security issue in third party components</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/503610/100/0/threaded" source="BUGTRAQ">20090516 rPSA-2009-0084-1 kernel</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-1081.html" source="REDHAT">RHSA-2009:1081</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:135" source="MANDRIVA">MDVSA-2009:135</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:119" source="MANDRIVA">MDVSA-2009:119</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1800" source="DEBIAN">DSA-1800</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1794" source="DEBIAN">DSA-1794</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1787" source="DEBIAN">DSA-1787</ref>
      <ref url="http://wiki.rpath.com/Advisories:rPSA-2009-0084" source="CONFIRM">http://wiki.rpath.com/Advisories:rPSA-2009-0084</ref>
      <ref url="http://secunia.com/advisories/37471" source="SECUNIA">37471</ref>
      <ref url="http://secunia.com/advisories/37351" source="SECUNIA">37351</ref>
      <ref url="http://secunia.com/advisories/35656" source="SECUNIA">35656</ref>
      <ref url="http://secunia.com/advisories/35387" source="SECUNIA">35387</ref>
      <ref url="http://secunia.com/advisories/35343" source="SECUNIA">35343</ref>
      <ref url="http://secunia.com/advisories/35121" source="SECUNIA">35121</ref>
      <ref url="http://secunia.com/advisories/35120" source="SECUNIA">35120</ref>
      <ref url="http://secunia.com/advisories/35011" source="SECUNIA">35011</ref>
      <ref url="http://secunia.com/advisories/34981" source="SECUNIA">34981</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:8003" source="OVAL">oval:org.mitre.oval:def:8003</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10567" source="OVAL">oval:org.mitre.oval:def:10567</ref>
      <ref url="http://openwall.com/lists/oss-security/2009/04/22/2" source="MLIST">[oss-security] 20090422 CVE-2009-1192 kernel: agp: zero pages before sending to userspace</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-11/msg00007.html" source="SUSE">SUSE-SA:2009:056</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-11/msg00005.html" source="SUSE">SUSE-SA:2009:054</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-06/msg00002.html" source="SUSE">SUSE-SA:2009:032</ref>
      <ref url="http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=59de2bebabc5027f93df999d59cc65df591c3e6e" source="CONFIRM" adv="1">http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=59de2bebabc5027f93df999d59cc65df591c3e6e</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="kernel">
        <vers num="2.2.27" />
        <vers num="2.4.36" />
        <vers num="2.4.36.1" />
        <vers num="2.4.36.2" />
        <vers num="2.4.36.3" />
        <vers num="2.4.36.4" />
        <vers num="2.4.36.5" />
        <vers num="2.4.36.6" />
        <vers num="2.6" />
        <vers num="2.6.0" />
        <vers num="2.6.1" />
        <vers num="2.6.10" />
        <vers num="2.6.11" />
        <vers num="2.6.11.1" />
        <vers num="2.6.11.10" />
        <vers num="2.6.11.11" />
        <vers num="2.6.11.12" />
        <vers num="2.6.11.2" />
        <vers num="2.6.11.3" />
        <vers num="2.6.11.4" />
        <vers num="2.6.11.5" />
        <vers num="2.6.11.6" />
        <vers num="2.6.11.7" />
        <vers num="2.6.11.8" />
        <vers num="2.6.11.9" />
        <vers num="2.6.12" />
        <vers num="2.6.12.1" />
        <vers num="2.6.12.2" />
        <vers num="2.6.12.3" />
        <vers num="2.6.12.4" />
        <vers num="2.6.12.5" />
        <vers num="2.6.12.6" />
        <vers num="2.6.13" />
        <vers num="2.6.13.1" />
        <vers num="2.6.13.2" />
        <vers num="2.6.13.3" />
        <vers num="2.6.13.4" />
        <vers num="2.6.13.5" />
        <vers num="2.6.14" />
        <vers num="2.6.14.1" />
        <vers num="2.6.14.2" />
        <vers num="2.6.14.3" />
        <vers num="2.6.14.4" />
        <vers num="2.6.14.5" />
        <vers num="2.6.14.6" />
        <vers num="2.6.14.7" />
        <vers num="2.6.15" />
        <vers num="2.6.15.1" />
        <vers num="2.6.15.2" />
        <vers num="2.6.15.3" />
        <vers num="2.6.15.4" />
        <vers num="2.6.15.5" />
        <vers num="2.6.15.6" />
        <vers num="2.6.15.7" />
        <vers num="2.6.16" />
        <vers num="2.6.16.1" />
        <vers num="2.6.16.10" />
        <vers num="2.6.16.11" />
        <vers num="2.6.16.12" />
        <vers num="2.6.16.13" />
        <vers num="2.6.16.14" />
        <vers num="2.6.16.15" />
        <vers num="2.6.16.16" />
        <vers num="2.6.16.17" />
        <vers num="2.6.16.18" />
        <vers num="2.6.16.19" />
        <vers num="2.6.16.2" />
        <vers num="2.6.16.20" />
        <vers num="2.6.16.21" />
        <vers num="2.6.16.22" />
        <vers num="2.6.16.23" />
        <vers num="2.6.16.24" />
        <vers num="2.6.16.25" />
        <vers num="2.6.16.26" />
        <vers num="2.6.16.27" />
        <vers num="2.6.16.28" />
        <vers num="2.6.16.29" />
        <vers num="2.6.16.3" />
        <vers num="2.6.16.30" />
        <vers num="2.6.16.31" />
        <vers num="2.6.16.32" />
        <vers num="2.6.16.33" />
        <vers num="2.6.16.34" />
        <vers num="2.6.16.35" />
        <vers num="2.6.16.36" />
        <vers num="2.6.16.37" />
        <vers num="2.6.16.38" />
        <vers num="2.6.16.39" />
        <vers num="2.6.16.4" />
        <vers num="2.6.16.40" />
        <vers num="2.6.16.41" />
        <vers num="2.6.16.42" />
        <vers num="2.6.16.43" />
        <vers num="2.6.16.44" />
        <vers num="2.6.16.45" />
        <vers num="2.6.16.46" />
        <vers num="2.6.16.47" />
        <vers num="2.6.16.48" />
        <vers num="2.6.16.49" />
        <vers num="2.6.16.5" />
        <vers num="2.6.16.50" />
        <vers num="2.6.16.51" />
        <vers num="2.6.16.52" />
        <vers num="2.6.16.53" />
        <vers num="2.6.16.54" />
        <vers num="2.6.16.55" />
        <vers num="2.6.16.56" />
        <vers num="2.6.16.57" />
        <vers num="2.6.16.58" />
        <vers num="2.6.16.59" />
        <vers num="2.6.16.6" />
        <vers num="2.6.16.60" />
        <vers num="2.6.16.61" />
        <vers num="2.6.16.62" />
        <vers num="2.6.16.7" />
        <vers num="2.6.16.8" />
        <vers num="2.6.16.9" />
        <vers num="2.6.17" />
        <vers num="2.6.17.1" />
        <vers num="2.6.17.10" />
        <vers num="2.6.17.11" />
        <vers num="2.6.17.12" />
        <vers num="2.6.17.13" />
        <vers num="2.6.17.14" />
        <vers num="2.6.17.2" />
        <vers num="2.6.17.3" />
        <vers num="2.6.17.4" />
        <vers num="2.6.17.5" />
        <vers num="2.6.17.6" />
        <vers num="2.6.17.7" />
        <vers num="2.6.17.8" />
        <vers num="2.6.17.9" />
        <vers num="2.6.18" edition="rc1" />
        <vers num="2.6.18" edition="rc2" />
        <vers num="2.6.18" edition="rc3" />
        <vers num="2.6.18" edition="rc4" />
        <vers num="2.6.18" edition="rc5" />
        <vers num="2.6.18" edition="rc6" />
        <vers num="2.6.18" edition="rc7" />
        <vers num="2.6.18.1" />
        <vers num="2.6.18.2" />
        <vers num="2.6.18.3" />
        <vers num="2.6.18.4" />
        <vers num="2.6.18.5" />
        <vers num="2.6.18.6" />
        <vers num="2.6.18.7" />
        <vers num="2.6.18.8" />
        <vers num="2.6.19" />
        <vers num="2.6.19.1" />
        <vers num="2.6.19.2" />
        <vers num="2.6.19.3" />
        <vers num="2.6.19.4" />
        <vers num="2.6.19.5" />
        <vers num="2.6.19.6" />
        <vers num="2.6.19.7" />
        <vers num="2.6.2" />
        <vers num="2.6.20" />
        <vers num="2.6.20.1" />
        <vers num="2.6.20.10" />
        <vers num="2.6.20.11" />
        <vers num="2.6.20.12" />
        <vers num="2.6.20.13" />
        <vers num="2.6.20.14" />
        <vers num="2.6.20.15" />
        <vers num="2.6.20.16" />
        <vers num="2.6.20.17" />
        <vers num="2.6.20.18" />
        <vers num="2.6.20.19" />
        <vers num="2.6.20.2" />
        <vers num="2.6.20.20" />
        <vers num="2.6.20.21" />
        <vers num="2.6.20.3" />
        <vers num="2.6.20.4" />
        <vers num="2.6.20.5" />
        <vers num="2.6.20.6" />
        <vers num="2.6.20.7" />
        <vers num="2.6.20.8" />
        <vers num="2.6.20.9" />
        <vers num="2.6.21" />
        <vers num="2.6.21.1" />
        <vers num="2.6.21.2" />
        <vers num="2.6.21.3" />
        <vers num="2.6.21.4" />
        <vers num="2.6.21.5" />
        <vers num="2.6.21.6" />
        <vers num="2.6.21.7" />
        <vers num="2.6.22" />
        <vers num="2.6.22.1" />
        <vers num="2.6.22.10" />
        <vers num="2.6.22.11" />
        <vers num="2.6.22.12" />
        <vers num="2.6.22.13" />
        <vers num="2.6.22.14" />
        <vers num="2.6.22.15" />
        <vers num="2.6.22.16" />
        <vers num="2.6.22.17" />
        <vers num="2.6.22.18" />
        <vers num="2.6.22.19" />
        <vers num="2.6.22.2" />
        <vers num="2.6.22.20" />
        <vers num="2.6.22.21" />
        <vers num="2.6.22.22" />
        <vers num="2.6.22.3" />
        <vers num="2.6.22.4" />
        <vers num="2.6.22.5" />
        <vers num="2.6.22.6" />
        <vers num="2.6.22.7" />
        <vers num="2.6.22.8" />
        <vers num="2.6.22.9" />
        <vers num="2.6.22_rc1" />
        <vers num="2.6.22_rc7" />
        <vers num="2.6.23" edition="rc1" />
        <vers num="2.6.23" edition="rc2" />
        <vers num="2.6.23.1" />
        <vers num="2.6.23.10" />
        <vers num="2.6.23.11" />
        <vers num="2.6.23.12" />
        <vers num="2.6.23.13" />
        <vers num="2.6.23.14" />
        <vers num="2.6.23.15" />
        <vers num="2.6.23.16" />
        <vers num="2.6.23.17" />
        <vers num="2.6.23.2" />
        <vers num="2.6.23.3" />
        <vers num="2.6.23.4" />
        <vers num="2.6.23.5" />
        <vers num="2.6.23.6" />
        <vers num="2.6.23.7" />
        <vers num="2.6.23.8" />
        <vers num="2.6.23.9" />
        <vers num="2.6.24" edition="rc1" />
        <vers num="2.6.24" edition="rc2" />
        <vers num="2.6.24" edition="rc3" />
        <vers num="2.6.24" edition="rc4" />
        <vers num="2.6.24" edition="rc5" />
        <vers num="2.6.24.1" />
        <vers num="2.6.24.2" />
        <vers num="2.6.24.3" />
        <vers num="2.6.24.4" />
        <vers num="2.6.24.5" />
        <vers num="2.6.24.6" />
        <vers num="2.6.24.7" />
        <vers num="2.6.25" edition="" />
        <vers num="2.6.25" edition=":x86_64" />
        <vers num="2.6.25.1" edition="" />
        <vers num="2.6.25.1" edition=":x86_64" />
        <vers num="2.6.25.10" edition="" />
        <vers num="2.6.25.10" edition=":x86_64" />
        <vers num="2.6.25.11" edition="" />
        <vers num="2.6.25.11" edition=":x86_64" />
        <vers num="2.6.25.12" edition="" />
        <vers num="2.6.25.12" edition=":x86_64" />
        <vers num="2.6.25.13" />
        <vers num="2.6.25.14" />
        <vers num="2.6.25.15" />
        <vers num="2.6.25.16" />
        <vers num="2.6.25.17" />
        <vers num="2.6.25.18" />
        <vers num="2.6.25.19" />
        <vers num="2.6.25.2" edition="" />
        <vers num="2.6.25.2" edition=":x86_64" />
        <vers num="2.6.25.20" />
        <vers num="2.6.25.3" edition="" />
        <vers num="2.6.25.3" edition=":x86_64" />
        <vers num="2.6.25.4" edition="" />
        <vers num="2.6.25.4" edition=":x86_64" />
        <vers num="2.6.25.5" edition="" />
        <vers num="2.6.25.5" edition=":x86_64" />
        <vers num="2.6.25.6" edition="" />
        <vers num="2.6.25.6" edition=":x86_64" />
        <vers num="2.6.25.7" edition="" />
        <vers num="2.6.25.7" edition=":x86_64" />
        <vers num="2.6.25.8" edition="" />
        <vers num="2.6.25.8" edition=":x86_64" />
        <vers num="2.6.25.9" edition="" />
        <vers num="2.6.25.9" edition=":x86_64" />
        <vers num="2.6.26" edition="rc4" />
        <vers num="2.6.26.1" />
        <vers num="2.6.26.2" />
        <vers num="2.6.26.3" />
        <vers num="2.6.26.4" />
        <vers num="2.6.26.5" />
        <vers num="2.6.26.6" />
        <vers num="2.6.26.7" />
        <vers num="2.6.26.8" />
        <vers num="2.6.27" edition="rc1" />
        <vers num="2.6.27" edition="rc2" />
        <vers num="2.6.27" edition="rc3" />
        <vers num="2.6.27" edition="rc4" />
        <vers num="2.6.27" edition="rc5" />
        <vers num="2.6.27" edition="rc6" />
        <vers num="2.6.27" edition="rc7" />
        <vers num="2.6.27" edition="rc8" />
        <vers num="2.6.27" edition="rc9" />
        <vers num="2.6.27.1" />
        <vers num="2.6.27.10" />
        <vers num="2.6.27.11" />
        <vers num="2.6.27.12" />
        <vers num="2.6.27.2" />
        <vers num="2.6.27.3" />
        <vers num="2.6.27.4" />
        <vers num="2.6.27.5" />
        <vers num="2.6.27.6" />
        <vers num="2.6.27.7" />
        <vers num="2.6.27.8" />
        <vers num="2.6.27.9" />
        <vers num="2.6.28" edition="rc1" />
        <vers num="2.6.28" edition="rc2" />
        <vers num="2.6.28" edition="rc3" />
        <vers num="2.6.28" edition="rc4" />
        <vers num="2.6.28" edition="rc5" />
        <vers num="2.6.28" edition="rc6" />
        <vers num="2.6.28" edition="rc7" />
        <vers num="2.6.28.1" />
        <vers num="2.6.28.2" />
        <vers num="2.6.28.3" />
        <vers num="2.6.28.4" />
        <vers num="2.6.29" edition="rc8-kk" />
        <vers num="2.6.29.rc1" />
        <vers num="2.6.29.rc2" />
        <vers num="2.6.29.rc2-git1" />
        <vers prev="1" num="2.6.30" edition="rc1" />
        <vers prev="1" num="2.6.30" edition="rc2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1194" published="2009-05-11" name="CVE-2009-1194" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Integer overflow in the pango_glyph_string_set_size function in pango/glyphstring.c in Pango before 1.24 allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a long glyph string that triggers a heap-based buffer overflow, as demonstrated by a long document.location value in Firefox.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.ocert.org/advisories/ocert-2009-001.html" source="MISC" patch="1">http://www.ocert.org/advisories/ocert-2009-001.html</ref>
      <ref url="https://launchpad.net/bugs/cve/2009-1194" source="CONFIRM">https://launchpad.net/bugs/cve/2009-1194</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=496887" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=496887</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=480134" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=480134</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/50397" source="XF">pango-pangoglyphstringsetsize-bo(50397)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1972" source="VUPEN">ADV-2009-1972</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1269" source="VUPEN">ADV-2009-1269</ref>
      <ref url="http://www.ubuntu.com/usn/USN-773-1" source="UBUNTU">USN-773-1</ref>
      <ref url="http://www.securitytracker.com/id?1022196" source="SECTRACK">1022196</ref>
      <ref url="http://www.securityfocus.com/bid/35758" source="BID">35758</ref>
      <ref url="http://www.securityfocus.com/bid/34870" source="BID">34870</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/503349/100/0/threaded" source="BUGTRAQ">20090507 [oCERT-2009-001] Pango integer overflow in heap allocation size calculations</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-0476.html" source="REDHAT">RHSA-2009:0476</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2009/05/07/1" source="MLIST">[oss-security] 20090507 [oCERT-2009-001] Pango integer overflow in heap allocation size calculations</ref>
      <ref url="http://www.mozilla.org/security/announce/2009/mfsa2009-36.html" source="CONFIRM">http://www.mozilla.org/security/announce/2009/mfsa2009-36.html</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1798" source="DEBIAN">DSA-1798</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-264308-1" source="SUNALERT">264308</ref>
      <ref url="http://secunia.com/advisories/36145" source="SECUNIA">36145</ref>
      <ref url="http://secunia.com/advisories/36005" source="SECUNIA">36005</ref>
      <ref url="http://secunia.com/advisories/35914" source="SECUNIA">35914</ref>
      <ref url="http://secunia.com/advisories/35685" source="SECUNIA">35685</ref>
      <ref url="http://secunia.com/advisories/35038" source="SECUNIA">35038</ref>
      <ref url="http://secunia.com/advisories/35027" source="SECUNIA">35027</ref>
      <ref url="http://secunia.com/advisories/35021" source="SECUNIA">35021</ref>
      <ref url="http://secunia.com/advisories/35018" source="SECUNIA">35018</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10137" source="OVAL">oval:org.mitre.oval:def:10137</ref>
      <ref url="http://osvdb.org/54279" source="OSVDB">54279</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-08/msg00002.html" source="SUSE">SUSE-SA:2009:042</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-07/msg00005.html" source="SUSE">SUSE-SA:2009:039</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-07/msg00002.html" source="SUSE">SUSE-SR:2009:012</ref>
      <ref url="http://github.com/bratsche/pango/commit/4de30e5500eaeb49f4bf0b7a07f718e149a2ed5e" source="CONFIRM">http://github.com/bratsche/pango/commit/4de30e5500eaeb49f4bf0b7a07f718e149a2ed5e</ref>
    </refs>
    <vuln_soft>
      <prod vendor="pango" name="pango">
        <vers num="1.10" />
        <vers num="1.12" />
        <vers num="1.14" />
        <vers num="1.16" />
        <vers num="1.18" />
        <vers num="1.2" />
        <vers num="1.20" />
        <vers prev="1" num="1.22" />
        <vers num="1.4" />
        <vers num="1.6" />
        <vers num="1.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1195" published="2009-05-28" name="CVE-2009-1195" modified="2011-07-18" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="4.9" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="3.9" CVSS_base_score="4.9">
    <desc>
      <descript source="cve">The Apache HTTP Server 2.2.11 and earlier 2.2 versions does not properly handle Options=IncludesNOEXEC in the AllowOverride directive, which allows local users to gain privileges by configuring (1) Options Includes, (2) Options +Includes, or (3) Options +IncludesNOEXEC in a .htaccess file, and then inserting an exec element in a .shtml file.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=489436" source="CONFIRM" patch="1">https://bugzilla.redhat.com/show_bug.cgi?id=489436</ref>
      <ref url="http://svn.apache.org/viewvc?view=rev&amp;revision=772997" source="CONFIRM" patch="1" adv="1">http://svn.apache.org/viewvc?view=rev&amp;revision=772997</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-August/msg01363.html" source="FEDORA">FEDORA-2009-8812</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/50808" source="XF">apache-allowoverrides-security-bypass(50808)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/3184" source="VUPEN">ADV-2009-3184</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1444" source="VUPEN">ADV-2009-1444</ref>
      <ref url="http://www.ubuntu.com/usn/usn-787-1" source="UBUNTU">USN-787-1</ref>
      <ref url="http://www.securitytracker.com/id?1022296" source="SECTRACK">1022296</ref>
      <ref url="http://www.securityfocus.com/bid/35115" source="BID">35115</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/507857/100/0/threaded" source="BUGTRAQ">20091113 rPSA-2009-0142-2 httpd mod_ssl</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/507852/100/0/threaded" source="BUGTRAQ">20091112 rPSA-2009-0142-1 httpd mod_ssl</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-1156.html" source="REDHAT">RHSA-2009:1156</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-1075.html" source="REDHAT">RHSA-2009:1075</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:124" source="MANDRIVA">MDVSA-2009:124</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1816" source="DEBIAN">DSA-1816</ref>
      <ref url="http://wiki.rpath.com/Advisories:rPSA-2009-0142" source="CONFIRM">http://wiki.rpath.com/Advisories:rPSA-2009-0142</ref>
      <ref url="http://support.apple.com/kb/HT3937" source="CONFIRM">http://support.apple.com/kb/HT3937</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200907-04.xml" source="GENTOO">GLSA-200907-04</ref>
      <ref url="http://secunia.com/advisories/37152" source="SECUNIA">37152</ref>
      <ref url="http://secunia.com/advisories/35721" source="SECUNIA">35721</ref>
      <ref url="http://secunia.com/advisories/35453" source="SECUNIA">35453</ref>
      <ref url="http://secunia.com/advisories/35395" source="SECUNIA">35395</ref>
      <ref url="http://secunia.com/advisories/35264" source="SECUNIA" adv="1">35264</ref>
      <ref url="http://secunia.com/advisories/35261" source="SECUNIA">35261</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:8704" source="OVAL">oval:org.mitre.oval:def:8704</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:12377" source="OVAL">oval:org.mitre.oval:def:12377</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11094" source="OVAL">oval:org.mitre.oval:def:11094</ref>
      <ref url="http://osvdb.org/54733" source="OSVDB">54733</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=129190899612998&amp;w=2" source="HP">SSRT100345</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=129190899612998&amp;w=2" source="HP">SSRT100345</ref>
      <ref url="http://marc.info/?l=apache-httpd-dev&amp;m=124048996106302&amp;w=2" source="MLIST">[apache-httpd-dev] 20090423 Includes vs IncludesNoExec security issue - help needed</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-10/msg00006.html" source="SUSE">SUSE-SA:2009:050</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2009/Nov/msg00000.html" source="APPLE">APPLE-SA-2009-11-09-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apache" name="http_server">
        <vers num="2.2" />
        <vers num="2.2.0" />
        <vers num="2.2.1" />
        <vers num="2.2.10" />
        <vers prev="1" num="2.2.11" />
        <vers num="2.2.2" edition="" />
        <vers num="2.2.2" edition=":windows" />
        <vers num="2.2.3" edition="" />
        <vers num="2.2.3" edition=":windows" />
        <vers num="2.2.4" />
        <vers num="2.2.5" />
        <vers num="2.2.6" />
        <vers num="2.2.7" />
        <vers num="2.2.8" />
        <vers num="2.2.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1196" published="2009-06-09" name="CVE-2009-1196" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The directory-services functionality in the scheduler in CUPS 1.1.17 and 1.1.22 allows remote attackers to cause a denial of service (cupsd daemon outage or crash) via manipulations of the timing of CUPS browse packets, related to a "pointer use-after-delete flaw."</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=497135" source="CONFIRM" patch="1">https://bugzilla.redhat.com/show_bug.cgi?id=497135</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/50944" source="XF">cups-directory-services-dos(50944)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1488" source="VUPEN" adv="1">ADV-2009-1488</ref>
      <ref url="http://www.securityfocus.com/bid/35194" source="BID">35194</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-1083.html" source="REDHAT">RHSA-2009:1083</ref>
      <ref url="http://securitytracker.com/id?1022327" source="SECTRACK">1022327</ref>
      <ref url="http://secunia.com/advisories/35340" source="SECUNIA" adv="1">35340</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11217" source="OVAL">oval:org.mitre.oval:def:11217</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="cups">
        <vers num="1.1.17" />
        <vers num="1.1.22" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1201" published="2009-06-25" name="CVE-2009-1201" modified="2010-05-04" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Eval injection vulnerability in the csco_wrap_js function in /+CSCOL+/cte.js in WebVPN on the Cisco Adaptive Security Appliances (ASA) device with software 8.0(4), 8.1.2, and 8.2.1 allows remote attackers to bypass a DOM wrapper and conduct cross-site scripting (XSS) attacks by setting CSCO_WebVPN['process'] to the name of a crafted function, aka Bug ID CSCsy80694.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="https://www.trustwave.com/spiderlabs/advisories/TWSL2009-002.txt" source="MISC">https://www.trustwave.com/spiderlabs/advisories/TWSL2009-002.txt</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1713" source="VUPEN">ADV-2009-1713</ref>
      <ref url="http://www.securitytracker.com/id?1022457" source="SECTRACK">1022457</ref>
      <ref url="http://www.securityfocus.com/bid/35476" source="BID">35476</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/504516/100/0/threaded" source="BUGTRAQ">20090624 Trustwave's SpiderLabs Security Advisory TWSL2009-002</ref>
      <ref url="http://secunia.com/advisories/35511" source="SECUNIA">35511</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="adaptive_security_appliance">
        <vers num="8.0(4)" />
        <vers num="8.1.2" />
        <vers num="8.2.1" />
      </prod>
      <prod vendor="cisco" name="adaptive_security_appliance">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1202" published="2009-06-25" name="CVE-2009-1202" modified="2010-05-04" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">WebVPN on the Cisco Adaptive Security Appliances (ASA) device with software 8.0(4), 8.1.2, and 8.2.1 allows remote attackers to bypass certain protection mechanisms involving URL rewriting and HTML rewriting, and conduct cross-site scripting (XSS) attacks, by modifying the first hex-encoded character in a /+CSCO+ URI, aka Bug ID CSCsy80705.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2009/1713" source="VUPEN">ADV-2009-1713</ref>
      <ref url="http://www.securitytracker.com/id?1022457" source="SECTRACK">1022457</ref>
      <ref url="http://www.securityfocus.com/bid/35480" source="BID">35480</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/504516/100/0/threaded" source="BUGTRAQ">20090624 Trustwave's SpiderLabs Security Advisory TWSL2009-002</ref>
      <ref url="http://secunia.com/advisories/35511" source="SECUNIA">35511</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="adaptive_security_appliance">
        <vers num="8.0(4)" />
        <vers num="8.1.2" />
        <vers num="8.2.1" />
      </prod>
      <prod vendor="cisco" name="adaptive_security_appliance">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1203" published="2009-06-25" name="CVE-2009-1203" modified="2010-05-04" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:S/C:P/I:P/A:P)" CVSS_score="6.0" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="6.8" CVSS_base_score="6.0">
    <desc>
      <descript source="cve">WebVPN on the Cisco Adaptive Security Appliances (ASA) device with software 8.0(4), 8.1.2, and 8.2.1 does not properly distinguish its own login screen from the login screens it produces for third-party (1) FTP and (2) CIFS servers, which makes it easier for remote attackers to trick a user into sending WebVPN credentials to an arbitrary server via a URL associated with that server, aka Bug ID CSCsy80709.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2009/1713" source="VUPEN">ADV-2009-1713</ref>
      <ref url="http://www.securitytracker.com/id?1022457" source="SECTRACK">1022457</ref>
      <ref url="http://www.securityfocus.com/bid/35475" source="BID">35475</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/504516/100/0/threaded" source="BUGTRAQ">20090624 Trustwave's SpiderLabs Security Advisory TWSL2009-002</ref>
      <ref url="http://secunia.com/advisories/35511" source="SECUNIA">35511</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="adaptive_security_appliance">
        <vers num="8.0(4)" />
        <vers num="8.1.2" />
        <vers num="8.2.1" />
      </prod>
      <prod vendor="cisco" name="adaptive_security_appliance">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1204" published="2009-03-31" name="CVE-2009-1204" modified="2009-04-01" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in TikiWiki (Tiki) CMS/Groupware 2.2 allows remote attackers to inject arbitrary web script or HTML via the PHP_SELF portion of a URI to (1) tiki-galleries.php, (2) tiki-list_file_gallery.php, (3) tiki-listpages.php, and (4) tiki-orphan_pages.php.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://tikiwiki.svn.sourceforge.net/viewvc/tikiwiki/branches/2.0/changelog.txt?view=markup" source="CONFIRM" patch="1">http://tikiwiki.svn.sourceforge.net/viewvc/tikiwiki/branches/2.0/changelog.txt?view=markup</ref>
      <ref url="http://info.tikiwiki.org/tiki-read_article.php?articleId=51" source="CONFIRM" patch="1">http://info.tikiwiki.org/tiki-read_article.php?articleId=51</ref>
      <ref url="http://www.securityfocus.com/bid/34108" source="BID">34108</ref>
      <ref url="http://www.securityfocus.com/bid/34107" source="BID">34107</ref>
      <ref url="http://www.securityfocus.com/bid/34106" source="BID">34106</ref>
      <ref url="http://www.securityfocus.com/bid/34105" source="BID">34105</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/501702/100/0/threaded" source="BUGTRAQ">20090312 TikiWiki 2.2 XSS Vulnerability in URI</ref>
      <ref url="http://secunia.com/advisories/34273" source="SECUNIA" adv="1">34273</ref>
      <ref url="http://dev.tikiwiki.org/tiki-view_tracker_item.php?itemId=2359&amp;trackerId=5&amp;show=view&amp;reloff=3&amp;cant=1229&amp;status=o&amp;trackerId=5&amp;sort_mode=created_desc" source="CONFIRM" adv="1">http://dev.tikiwiki.org/tiki-view_tracker_item.php?itemId=2359&amp;trackerId=5&amp;show=view&amp;reloff=3&amp;cant=1229&amp;status=o&amp;trackerId=5&amp;sort_mode=created_desc</ref>
    </refs>
    <vuln_soft>
      <prod vendor="tikiwiki" name="tikiwiki_cms/groupware">
        <vers num="2.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" seq="2009-1205" reject="1" published="2009-04-01" name="CVE-2009-1205" modified="2009-04-03">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2007-4475.  Reason: This candidate is a duplicate of CVE-2007-4475.  Notes: All CVE users should reference CVE-2007-4475 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript>
    </desc>
    <refs />
  </entry>
  <entry type="CVE" severity="High" seq="2009-1206" published="2009-04-01" name="CVE-2009-1206" modified="2009-04-16" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Unspecified vulnerability in futomi's CGI Cafe Access Analyzer CGI Professional Version 4.11.5 and earlier allows remote attackers to gain administrative privileges via unknown vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/49525" source="XF">cgicafe-unspecified-unauth-access(49525)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0888" source="VUPEN">ADV-2009-0888</ref>
      <ref url="http://www.securityfocus.com/bid/34315" source="BID">34315</ref>
      <ref url="http://www.futomi.com/library/info/2009/20090331.html" source="CONFIRM" adv="1">http://www.futomi.com/library/info/2009/20090331.html</ref>
      <ref url="http://secunia.com/advisories/34516" source="SECUNIA" adv="1">34516</ref>
      <ref url="http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-000016.html" source="JVNDB">JVNDB-2009-000016</ref>
      <ref url="http://jvn.jp/en/jp/JVN63511247/index.html" source="JVN">JVN#63511247</ref>
    </refs>
    <vuln_soft>
      <prod vendor="futomi" name="cgi_cafe_access_analyzer_cgi">
        <vers prev="1" num="4.10" edition="pro" />
        <vers prev="1" num="4.10.1" edition="pro" />
        <vers prev="1" num="4.10.2" edition="pro" />
        <vers prev="1" num="4.10.3" edition="pro" />
        <vers prev="1" num="4.10.4" edition="pro" />
        <vers prev="1" num="4.10.5" edition="pro" />
        <vers prev="1" num="4.11.0" edition="pro" />
        <vers prev="1" num="4.11.1" edition="pro" />
        <vers prev="1" num="4.11.2" edition="pro" />
        <vers prev="1" num="4.11.3" edition="pro" />
        <vers prev="1" num="4.11.4" edition="pro" />
        <vers prev="1" num="4.11.5" edition="pro" />
        <vers prev="1" num="4.9" edition="pro" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1207" published="2009-04-01" name="CVE-2009-1207" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="4.4" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.4" CVSS_base_score="4.4">
    <desc>
      <descript source="cve">Race condition in the dircmp script in Sun Solaris 8 through 10, and OpenSolaris snv_01 through snv_111, allows local users to overwrite arbitrary files, probably involving a symlink attack on temporary files.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/34316" source="BID" patch="1">34316</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-253468-1" source="SUNALERT" patch="1" adv="1">253468</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-21-138897-01-1" source="MISC" patch="1">http://sunsolve.sun.com/search/document.do?assetkey=1-21-138897-01-1</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/49526" source="XF">solaris-dircmp-file-overwrite(49526)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1105" source="VUPEN" adv="1">ADV-2009-1105</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2009-140.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2009-140.htm</ref>
      <ref url="http://secunia.com/advisories/34813" source="SECUNIA" adv="1">34813</ref>
      <ref url="http://secunia.com/advisories/34558" source="SECUNIA" adv="1">34558</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6183" source="OVAL">oval:org.mitre.oval:def:6183</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="opensolaris">
        <vers num="snv_01" edition="" />
        <vers num="snv_01" edition=":sparc" />
        <vers num="snv_01" edition=":x86" />
        <vers num="snv_02" edition="" />
        <vers num="snv_02" edition=":sparc" />
        <vers num="snv_02" edition=":x86" />
        <vers num="snv_03" edition="" />
        <vers num="snv_03" edition=":x86" />
        <vers num="snv_03" edition=":sparc" />
        <vers num="snv_04" edition="" />
        <vers num="snv_04" edition=":x86" />
        <vers num="snv_04" edition=":sparc" />
        <vers num="snv_05" edition="" />
        <vers num="snv_05" edition=":sparc" />
        <vers num="snv_05" edition=":x86" />
        <vers num="snv_06" edition="" />
        <vers num="snv_06" edition=":sparc" />
        <vers num="snv_06" edition=":x86" />
        <vers num="snv_07" edition="" />
        <vers num="snv_07" edition=":sparc" />
        <vers num="snv_07" edition=":x86" />
        <vers num="snv_08" edition="" />
        <vers num="snv_08" edition=":x86" />
        <vers num="snv_08" edition=":sparc" />
        <vers num="snv_09" edition="" />
        <vers num="snv_09" edition=":x86" />
        <vers num="snv_09" edition=":sparc" />
        <vers num="snv_10" edition="" />
        <vers num="snv_10" edition=":x86" />
        <vers num="snv_10" edition=":sparc" />
        <vers num="snv_100" edition="" />
        <vers num="snv_100" edition=":sparc" />
        <vers num="snv_100" edition=":x86" />
        <vers num="snv_101" edition="" />
        <vers num="snv_101" edition=":x86" />
        <vers num="snv_101" edition=":sparc" />
        <vers num="snv_102" edition="" />
        <vers num="snv_102" edition=":sparc" />
        <vers num="snv_102" edition=":x86" />
        <vers num="snv_103" edition="" />
        <vers num="snv_103" edition=":x86" />
        <vers num="snv_103" edition=":sparc" />
        <vers num="snv_104" edition="" />
        <vers num="snv_104" edition=":x86" />
        <vers num="snv_104" edition=":sparc" />
        <vers num="snv_105" edition="" />
        <vers num="snv_105" edition=":x86" />
        <vers num="snv_105" edition=":sparc" />
        <vers num="snv_106" edition="" />
        <vers num="snv_106" edition=":sparc" />
        <vers num="snv_106" edition=":x86" />
        <vers num="snv_107" edition="" />
        <vers num="snv_107" edition=":x86" />
        <vers num="snv_107" edition=":sparc" />
        <vers num="snv_108" edition="" />
        <vers num="snv_108" edition=":x86" />
        <vers num="snv_108" edition=":sparc" />
        <vers num="snv_109" edition="" />
        <vers num="snv_109" edition=":x86" />
        <vers num="snv_109" edition=":sparc" />
        <vers num="snv_11" edition="" />
        <vers num="snv_11" edition=":x86" />
        <vers num="snv_11" edition=":sparc" />
        <vers num="snv_110" edition="" />
        <vers num="snv_110" edition=":sparc" />
        <vers num="snv_110" edition=":x86" />
        <vers num="snv_111" edition="" />
        <vers num="snv_111" edition=":sparc" />
        <vers num="snv_12" edition="" />
        <vers num="snv_12" edition=":x86" />
        <vers num="snv_12" edition=":sparc" />
        <vers num="snv_13" edition="" />
        <vers num="snv_13" edition=":x86" />
        <vers num="snv_13" edition=":sparc" />
        <vers num="snv_14" edition="" />
        <vers num="snv_14" edition=":sparc" />
        <vers num="snv_14" edition=":x86" />
        <vers num="snv_15" edition="" />
        <vers num="snv_15" edition=":x86" />
        <vers num="snv_15" edition=":sparc" />
        <vers num="snv_16" edition="" />
        <vers num="snv_16" edition=":sparc" />
        <vers num="snv_16" edition=":x86" />
        <vers num="snv_17" edition="" />
        <vers num="snv_17" edition=":x86" />
        <vers num="snv_17" edition=":sparc" />
        <vers num="snv_18" edition="" />
        <vers num="snv_18" edition=":x86" />
        <vers num="snv_18" edition=":sparc" />
        <vers num="snv_19" edition="" />
        <vers num="snv_19" edition=":sparc" />
        <vers num="snv_19" edition=":x86" />
        <vers num="snv_20" edition="" />
        <vers num="snv_20" edition=":x86" />
        <vers num="snv_20" edition=":sparc" />
        <vers num="snv_21" edition="" />
        <vers num="snv_21" edition=":sparc" />
        <vers num="snv_21" edition=":x86" />
        <vers num="snv_22" edition="" />
        <vers num="snv_22" edition=":sparc" />
        <vers num="snv_22" edition=":x86" />
        <vers num="snv_23" edition="" />
        <vers num="snv_23" edition=":sparc" />
        <vers num="snv_23" edition=":x86" />
        <vers num="snv_24" edition="" />
        <vers num="snv_24" edition=":sparc" />
        <vers num="snv_24" edition=":x86" />
        <vers num="snv_25" edition="" />
        <vers num="snv_25" edition=":x86" />
        <vers num="snv_25" edition=":sparc" />
        <vers num="snv_26" edition="" />
        <vers num="snv_26" edition=":x86" />
        <vers num="snv_26" edition=":sparc" />
        <vers num="snv_27" edition="" />
        <vers num="snv_27" edition=":sparc" />
        <vers num="snv_27" edition=":x86" />
        <vers num="snv_28" edition="" />
        <vers num="snv_28" edition=":x86" />
        <vers num="snv_28" edition=":sparc" />
        <vers num="snv_29" edition="" />
        <vers num="snv_29" edition=":x86" />
        <vers num="snv_29" edition=":sparc" />
        <vers num="snv_30" edition="" />
        <vers num="snv_30" edition=":sparc" />
        <vers num="snv_30" edition=":x86" />
        <vers num="snv_31" edition="" />
        <vers num="snv_31" edition=":sparc" />
        <vers num="snv_31" edition=":x86" />
        <vers num="snv_32" edition="" />
        <vers num="snv_32" edition=":x86" />
        <vers num="snv_32" edition=":sparc" />
        <vers num="snv_33" edition="" />
        <vers num="snv_33" edition=":x86" />
        <vers num="snv_33" edition=":sparc" />
        <vers num="snv_34" edition="" />
        <vers num="snv_34" edition=":sparc" />
        <vers num="snv_34" edition=":x86" />
        <vers num="snv_35" edition="" />
        <vers num="snv_35" edition=":sparc" />
        <vers num="snv_35" edition=":x86" />
        <vers num="snv_36" edition="" />
        <vers num="snv_36" edition=":x86" />
        <vers num="snv_36" edition=":sparc" />
        <vers num="snv_37" edition="" />
        <vers num="snv_37" edition=":sparc" />
        <vers num="snv_37" edition=":x86" />
        <vers num="snv_38" edition="" />
        <vers num="snv_38" edition=":sparc" />
        <vers num="snv_38" edition=":x86" />
        <vers num="snv_39" edition="" />
        <vers num="snv_39" edition=":sparc" />
        <vers num="snv_39" edition=":x86" />
        <vers num="snv_40" edition="" />
        <vers num="snv_40" edition=":sparc" />
        <vers num="snv_40" edition=":x86" />
        <vers num="snv_41" edition="" />
        <vers num="snv_41" edition=":sparc" />
        <vers num="snv_41" edition=":x86" />
        <vers num="snv_42" edition="" />
        <vers num="snv_42" edition=":x86" />
        <vers num="snv_42" edition=":sparc" />
        <vers num="snv_43" edition="" />
        <vers num="snv_43" edition=":sparc" />
        <vers num="snv_43" edition=":x86" />
        <vers num="snv_44" edition="" />
        <vers num="snv_44" edition=":x86" />
        <vers num="snv_44" edition=":sparc" />
        <vers num="snv_45" edition="" />
        <vers num="snv_45" edition=":x86" />
        <vers num="snv_45" edition=":sparc" />
        <vers num="snv_46" edition="" />
        <vers num="snv_46" edition=":x86" />
        <vers num="snv_46" edition=":sparc" />
        <vers num="snv_47" edition="" />
        <vers num="snv_47" edition=":x86" />
        <vers num="snv_47" edition=":sparc" />
        <vers num="snv_48" edition="" />
        <vers num="snv_48" edition=":sparc" />
        <vers num="snv_48" edition=":x86" />
        <vers num="snv_49" edition="" />
        <vers num="snv_49" edition=":sparc" />
        <vers num="snv_49" edition=":x86" />
        <vers num="snv_50" edition="" />
        <vers num="snv_50" edition=":sparc" />
        <vers num="snv_50" edition=":x86" />
        <vers num="snv_51" edition="" />
        <vers num="snv_51" edition=":sparc" />
        <vers num="snv_51" edition=":x86" />
        <vers num="snv_52" edition="" />
        <vers num="snv_52" edition=":sparc" />
        <vers num="snv_52" edition=":x86" />
        <vers num="snv_53" edition="" />
        <vers num="snv_53" edition=":sparc" />
        <vers num="snv_53" edition=":x86" />
        <vers num="snv_54" edition="" />
        <vers num="snv_54" edition=":x86" />
        <vers num="snv_54" edition=":sparc" />
        <vers num="snv_55" edition="" />
        <vers num="snv_55" edition=":sparc" />
        <vers num="snv_55" edition=":x86" />
        <vers num="snv_56" edition="" />
        <vers num="snv_56" edition=":x86" />
        <vers num="snv_56" edition=":sparc" />
        <vers num="snv_57" edition="" />
        <vers num="snv_57" edition=":x86" />
        <vers num="snv_57" edition=":sparc" />
        <vers num="snv_58" edition="" />
        <vers num="snv_58" edition=":sparc" />
        <vers num="snv_58" edition=":x86" />
        <vers num="snv_59" edition="" />
        <vers num="snv_59" edition=":sparc" />
        <vers num="snv_59" edition=":x86" />
        <vers num="snv_60" edition="" />
        <vers num="snv_60" edition=":x86" />
        <vers num="snv_60" edition=":sparc" />
        <vers num="snv_61" edition="" />
        <vers num="snv_61" edition=":sparc" />
        <vers num="snv_61" edition=":x86" />
        <vers num="snv_62" edition="" />
        <vers num="snv_62" edition=":x86" />
        <vers num="snv_62" edition=":sparc" />
        <vers num="snv_63" edition="" />
        <vers num="snv_63" edition=":sparc" />
        <vers num="snv_63" edition=":x86" />
        <vers num="snv_64" edition="" />
        <vers num="snv_64" edition=":x86" />
        <vers num="snv_64" edition=":sparc" />
        <vers num="snv_65" edition="" />
        <vers num="snv_65" edition=":x86" />
        <vers num="snv_65" edition=":sparc" />
        <vers num="snv_66" edition="" />
        <vers num="snv_66" edition=":x86" />
        <vers num="snv_66" edition=":sparc" />
        <vers num="snv_67" edition="" />
        <vers num="snv_67" edition=":sparc" />
        <vers num="snv_67" edition=":x86" />
        <vers num="snv_68" edition="" />
        <vers num="snv_68" edition=":x86" />
        <vers num="snv_68" edition=":sparc" />
        <vers num="snv_69" edition="" />
        <vers num="snv_69" edition=":sparc" />
        <vers num="snv_69" edition=":x86" />
        <vers num="snv_70" edition="" />
        <vers num="snv_70" edition=":sparc" />
        <vers num="snv_70" edition=":x86" />
        <vers num="snv_71" edition="" />
        <vers num="snv_71" edition=":x86" />
        <vers num="snv_71" edition=":sparc" />
        <vers num="snv_72" edition="" />
        <vers num="snv_72" edition=":x86" />
        <vers num="snv_72" edition=":sparc" />
        <vers num="snv_73" edition="" />
        <vers num="snv_73" edition=":x86" />
        <vers num="snv_73" edition=":sparc" />
        <vers num="snv_74" edition="" />
        <vers num="snv_74" edition=":sparc" />
        <vers num="snv_74" edition=":x86" />
        <vers num="snv_75" edition="" />
        <vers num="snv_75" edition=":sparc" />
        <vers num="snv_75" edition=":x86" />
        <vers num="snv_76" edition="" />
        <vers num="snv_76" edition=":x86" />
        <vers num="snv_76" edition=":sparc" />
        <vers num="snv_77" edition="" />
        <vers num="snv_77" edition=":sparc" />
        <vers num="snv_77" edition=":x86" />
        <vers num="snv_78" edition="" />
        <vers num="snv_78" edition=":sparc" />
        <vers num="snv_78" edition=":x86" />
        <vers num="snv_79" edition="" />
        <vers num="snv_79" edition=":x86" />
        <vers num="snv_79" edition=":sparc" />
        <vers num="snv_80" edition="" />
        <vers num="snv_80" edition=":x86" />
        <vers num="snv_80" edition=":sparc" />
        <vers num="snv_81" edition="" />
        <vers num="snv_81" edition=":x86" />
        <vers num="snv_81" edition=":sparc" />
        <vers num="snv_82" edition="" />
        <vers num="snv_82" edition=":x86" />
        <vers num="snv_82" edition=":sparc" />
        <vers num="snv_83" edition="" />
        <vers num="snv_83" edition=":x86" />
        <vers num="snv_83" edition=":sparc" />
        <vers num="snv_84" edition="" />
        <vers num="snv_84" edition=":x86" />
        <vers num="snv_84" edition=":sparc" />
        <vers num="snv_85" edition="" />
        <vers num="snv_85" edition=":x86" />
        <vers num="snv_85" edition=":sparc" />
        <vers num="snv_86" edition="" />
        <vers num="snv_86" edition=":sparc" />
        <vers num="snv_86" edition=":x86" />
        <vers num="snv_87" edition="" />
        <vers num="snv_87" edition=":sparc" />
        <vers num="snv_87" edition=":x86" />
        <vers num="snv_88" edition="" />
        <vers num="snv_88" edition=":x86" />
        <vers num="snv_88" edition=":sparc" />
        <vers num="snv_89" edition="" />
        <vers num="snv_89" edition=":x86" />
        <vers num="snv_89" edition=":sparc" />
        <vers num="snv_90" edition="" />
        <vers num="snv_90" edition=":sparc" />
        <vers num="snv_90" edition=":x86" />
        <vers num="snv_91" edition="" />
        <vers num="snv_91" edition=":sparc" />
        <vers num="snv_91" edition=":x86" />
        <vers num="snv_92" edition="" />
        <vers num="snv_92" edition=":sparc" />
        <vers num="snv_92" edition=":x86" />
        <vers num="snv_93" edition="" />
        <vers num="snv_93" edition=":sparc" />
        <vers num="snv_93" edition=":x86" />
        <vers num="snv_94" edition="" />
        <vers num="snv_94" edition=":x86" />
        <vers num="snv_94" edition=":sparc" />
        <vers num="snv_95" edition="" />
        <vers num="snv_95" edition=":x86" />
        <vers num="snv_95" edition=":sparc" />
        <vers num="snv_96" edition="" />
        <vers num="snv_96" edition=":sparc" />
        <vers num="snv_96" edition=":x86" />
        <vers num="snv_97" edition="" />
        <vers num="snv_97" edition=":x86" />
        <vers num="snv_97" edition=":sparc" />
        <vers num="snv_98" edition="" />
        <vers num="snv_98" edition=":sparc" />
        <vers num="snv_98" edition=":x86" />
        <vers num="snv_99" edition="" />
        <vers num="snv_99" edition=":sparc" />
        <vers num="snv_99" edition=":x86" />
      </prod>
      <prod vendor="sun" name="solaris">
        <vers num="10" edition="" />
        <vers num="10" edition=":sparc" />
        <vers num="10" edition=":x86" />
        <vers num="8" edition="" />
        <vers num="8" edition=":sparc" />
        <vers num="8" edition=":x86" />
        <vers num="9" edition="" />
        <vers num="9" edition=":x86" />
        <vers num="9" edition=":sparc" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1208" published="2009-04-01" name="CVE-2009-1208" modified="2009-04-02" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in auth2db 0.2.5, and possibly other versions before 0.2.7, uses the addslashes function instead of the mysql_real_escape_string function, which allows remote attackers to conduct SQL injection attacks using multibyte character encodings.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2009/dsa-1757" source="DEBIAN" patch="1">DSA-1757</ref>
      <ref url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=521823" source="CONFIRM" patch="1">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=521823</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/49518" source="XF">auth2db-unspecified-sql-injection(49518)</ref>
      <ref url="http://www.securityfocus.com/bid/34287" source="BID">34287</ref>
      <ref url="http://www.auth2db.com.ar/?title=CHANGELOG" source="CONFIRM">http://www.auth2db.com.ar/?title=CHANGELOG</ref>
      <ref url="http://secunia.com/advisories/34488" source="SECUNIA" adv="1">34488</ref>
    </refs>
    <vuln_soft>
      <prod vendor="auth2db" name="auth2db">
        <vers num="0.1.0" />
        <vers num="0.1.2" />
        <vers num="0.1.3" />
        <vers num="0.1.4" />
        <vers num="0.1.5" />
        <vers num="0.1.6" />
        <vers num="0.1.7" />
        <vers num="0.1.8" />
        <vers num="0.1.9" />
        <vers num="0.2.0" />
        <vers num="0.2.1" />
        <vers num="0.2.2" />
        <vers num="0.2.3" />
        <vers num="0.2.4" />
        <vers num="0.2.5" />
        <vers num="0.2.6" />
      </prod>
      <prod vendor="auth2dbauth2db" name="0.1.1">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1209" published="2009-04-01" name="CVE-2009-1209" modified="2009-08-19" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Stack-based buffer overflow in W3C Amaya Web Browser 11.1 allows remote attackers to execute arbitrary code via a script tag with a long defer attribute.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/47399" source="XF">amaya-htmltag-bo(47399)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0889" source="VUPEN">ADV-2009-0889</ref>
      <ref url="http://www.securityfocus.com/bid/34295" source="BID">34295</ref>
      <ref url="http://www.milw0rm.com/exploits/8321" source="MILW0RM">8321</ref>
      <ref url="http://www.milw0rm.com/exploits/8314" source="MILW0RM">8314</ref>
      <ref url="http://secunia.com/advisories/34531" source="SECUNIA" adv="1">34531</ref>
    </refs>
    <vuln_soft>
      <prod vendor="w3" name="amaya">
        <vers num="11.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1210" published="2009-04-01" name="CVE-2009-1210" modified="2011-12-29" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Format string vulnerability in the PROFINET/DCP (PN-DCP) dissector in Wireshark 1.0.6 and earlier allows remote attackers to execute arbitrary code via a PN-DCP packet with format string specifiers in the station name.  NOTE: some of these details are obtained from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-May/msg01213.html" source="FEDORA">FEDORA-2009-5382</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-May/msg01167.html" source="FEDORA">FEDORA-2009-5339</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-May/msg00675.html" source="FEDORA">FEDORA-2009-3599</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/49512" source="XF">wireshark-pndcp-format-string(49512)</ref>
      <ref url="http://www.wireshark.org/security/wnpa-sec-2009-02.html" source="CONFIRM" adv="1">http://www.wireshark.org/security/wnpa-sec-2009-02.html</ref>
      <ref url="http://www.securityfocus.com/bid/34291" source="BID">34291</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/502745/100/0/threaded" source="BUGTRAQ">20090417 rPSA-2009-0062-1 tshark wireshark</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-1100.html" source="REDHAT">RHSA-2009:1100</ref>
      <ref url="http://www.milw0rm.com/exploits/8308" source="MILW0RM">8308</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:088" source="MANDRIVA">MDVSA-2009:088</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1785" source="DEBIAN">DSA-1785</ref>
      <ref url="http://wiki.rpath.com/Advisories:rPSA-2009-0062" source="CONFIRM">http://wiki.rpath.com/Advisories:rPSA-2009-0062</ref>
      <ref url="http://secunia.com/advisories/35464" source="SECUNIA" adv="1">35464</ref>
      <ref url="http://secunia.com/advisories/35416" source="SECUNIA" adv="1">35416</ref>
      <ref url="http://secunia.com/advisories/35224" source="SECUNIA" adv="1">35224</ref>
      <ref url="http://secunia.com/advisories/35133" source="SECUNIA" adv="1">35133</ref>
      <ref url="http://secunia.com/advisories/34970" source="SECUNIA" adv="1">34970</ref>
      <ref url="http://secunia.com/advisories/34778" source="SECUNIA" adv="1">34778</ref>
      <ref url="http://secunia.com/advisories/34542" source="SECUNIA" adv="1">34542</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9526" source="OVAL">oval:org.mitre.oval:def:9526</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5976" source="OVAL">oval:org.mitre.oval:def:5976</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-06/msg00003.html" source="SUSE">SUSE-SR:2009:011</ref>
    </refs>
    <vuln_soft>
      <prod vendor="wireshark" name="wireshark">
        <vers num="0.10" />
        <vers num="0.10.1" />
        <vers num="0.10.10" />
        <vers num="0.10.11" />
        <vers num="0.10.12" />
        <vers num="0.10.13" />
        <vers num="0.10.14" />
        <vers num="0.10.2" />
        <vers num="0.10.3" />
        <vers num="0.10.4" />
        <vers num="0.10.5" />
        <vers num="0.10.6" />
        <vers num="0.10.7" />
        <vers num="0.10.8" />
        <vers num="0.10.9" />
        <vers num="0.6" />
        <vers num="0.7.9" />
        <vers num="0.8.16" />
        <vers num="0.8.19" />
        <vers num="0.9.10" />
        <vers num="0.9.14" />
        <vers num="0.9.5" />
        <vers num="0.9.7" />
        <vers num="0.9.8" />
        <vers num="0.99" />
        <vers num="0.99.0" />
        <vers num="0.99.1" />
        <vers num="0.99.2" />
        <vers num="0.99.3" />
        <vers num="0.99.4" />
        <vers num="0.99.5" />
        <vers num="0.99.6" />
        <vers num="0.99.6a" />
        <vers num="0.99.7" />
        <vers num="0.99.8" />
        <vers num="1.0" />
        <vers num="1.0.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers prev="1" num="1.0.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1211" published="2009-04-01" name="CVE-2009-1211" modified="2009-04-01" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:P)" CVSS_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_base_score="5.8">
    <desc>
      <descript source="cve">Blue Coat ProxySG, when transparent interception mode is enabled, uses the HTTP Host header to determine the remote endpoint, which allows remote attackers to bypass access controls for Flash, Java, Silverlight, and probably other technologies, and possibly communicate with restricted intranet sites, via a crafted web page that causes a client to send HTTP requests with a modified Host header.</descript>
    </desc>
    <loss_types>
      <avail />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="https://hypersonic.bluecoat.com/support/securityadvisories/ProxySG_in_transparent_deployments" source="CONFIRM" adv="1">https://hypersonic.bluecoat.com/support/securityadvisories/ProxySG_in_transparent_deployments</ref>
      <ref url="http://www.securitytracker.com/id?1021781" source="SECTRACK">1021781</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bluecoat" name="proxysg">
        <vers num="3" />
        <vers num="3.2.8.6" />
        <vers num="4" />
        <vers num="4.1.2.1" />
        <vers num="4.2.6" />
        <vers num="4.3.2.3" />
        <vers num="5.1" />
        <vers num="5.1.6.1" />
        <vers num="5.2" />
        <vers num="5.2.2.4" />
        <vers num="5.2.5.2" />
        <vers num="5.3" />
        <vers num="5.3.2.1" />
        <vers num="5.4" />
        <vers num="5.4.1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1212" published="2009-04-01" name="CVE-2009-1212" modified="2009-04-16" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:C/A:N)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Multiple insecure method vulnerabilities in PRECIS~2.DLL in the PrecisionID Datamatrix ActiveX control (DMATRIXLib.Datamatrix) allow remote attackers to overwrite arbitrary files via the (1) SaveBarCode and (2) SaveEnhWMF methods.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/34322" source="BID">34322</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/502319/100/0/threaded" source="BUGTRAQ">20090331 [DSECRG-09-030] PrecisionID Datamatrix ActiveX control - Arbitrary File overwriting</ref>
      <ref url="http://www.milw0rm.com/exploits/8332" source="MILW0RM">8332</ref>
      <ref url="http://dsecrg.com/pages/vul/DSECRG-09-030.html" source="MISC">http://dsecrg.com/pages/vul/DSECRG-09-030.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="precisionid" name="data_matrix_barcode_activex_control">
        <vers num="-" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1213" published="2009-04-01" name="CVE-2009-1213" modified="2009-04-18" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site request forgery (CSRF) vulnerability in attachment.cgi in Bugzilla 3.2 before 3.2.3, 3.3 before 3.3.4, and earlier versions allows remote attackers to hijack the authentication of arbitrary users for requests that use attachment editing.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2009/0887" source="VUPEN" patch="1" adv="1">ADV-2009-0887</ref>
      <ref url="http://www.bugzilla.org/security/3.2.2/" source="CONFIRM" patch="1" adv="1">http://www.bugzilla.org/security/3.2.2/</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-April/msg00191.html" source="FEDORA">FEDORA-2009-3410</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-April/msg00188.html" source="FEDORA">FEDORA-2009-3405</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=476603" source="CONFIRM" adv="1">https://bugzilla.mozilla.org/show_bug.cgi?id=476603</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/49524" source="XF">bugzilla-attachment-csrf(49524)</ref>
      <ref url="http://www.securityfocus.com/bid/34308" source="BID">34308</ref>
      <ref url="http://secunia.com/advisories/34624" source="SECUNIA">34624</ref>
      <ref url="http://secunia.com/advisories/34547" source="SECUNIA" adv="1">34547</ref>
      <ref url="http://secunia.com/advisories/34545" source="SECUNIA" adv="1">34545</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="bugzilla">
        <vers num="3.2" edition="rc1" />
        <vers num="3.2" edition="rc2" />
        <vers num="3.2.1" />
        <vers num="3.2.2" />
        <vers num="3.3" />
        <vers num="3.3.1" />
        <vers num="3.3.2" />
        <vers num="3.3.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1214" published="2009-04-01" name="CVE-2009-1214" modified="2009-05-13" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:N/A:N)" CVSS_score="4.9" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="3.9" CVSS_base_score="4.9">
    <desc>
      <descript source="cve">GNU screen 4.0.3 creates the /tmp/screen-exchange temporary file with world-readable permissions, which might allow local users to obtain sensitive session information.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=492104" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=492104</ref>
      <ref url="https://bugs.launchpad.net/ubuntu/+source/screen/+bug/315993" source="CONFIRM">https://bugs.launchpad.net/ubuntu/+source/screen/+bug/315993</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/49886" source="XF">screen-screenexchange-info-disclosure(49886)</ref>
      <ref url="http://www.securityfocus.com/bid/34521" source="BID">34521</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2009/03/25/7" source="MLIST">[oss-security] 20090325 CVE request -- zsh, XFree86-xfs/xorg-x11-xfs, screen</ref>
      <ref url="http://savannah.gnu.org/bugs/?25296" source="MISC">http://savannah.gnu.org/bugs/?25296</ref>
      <ref url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=521123" source="CONFIRM">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=521123</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gnu" name="screen">
        <vers num="4.0.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2009-1215" published="2009-04-01" name="CVE-2009-1215" modified="2009-05-13" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="1.9" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.4" CVSS_base_score="1.9">
    <desc>
      <descript source="cve">Race condition in GNU screen 4.0.3 allows local users to create or overwrite arbitrary files via a symlink attack on the /tmp/screen-exchange temporary file.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=492104" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=492104</ref>
      <ref url="https://bugs.launchpad.net/ubuntu/+source/screen/+bug/315993" source="CONFIRM">https://bugs.launchpad.net/ubuntu/+source/screen/+bug/315993</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/49887" source="XF">screen-screenexchange-symlink(49887)</ref>
      <ref url="http://www.securityfocus.com/bid/34521" source="BID">34521</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2009/03/25/7" source="MLIST">[oss-security] 20090325 CVE request -- zsh, XFree86-xfs/xorg-x11-xfs, screen</ref>
      <ref url="http://savannah.gnu.org/bugs/?25296" source="MISC">http://savannah.gnu.org/bugs/?25296</ref>
      <ref url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=521123" source="CONFIRM">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=521123</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gnu" name="gnu_screen">
        <vers num="4.0.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1216" published="2009-04-01" name="CVE-2009-1216" modified="2009-04-16" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Multiple unspecified vulnerabilities in (1) unlzh.c and (2) unpack.c in the gzip libraries in Microsoft Windows Server 2008, Windows Services for UNIX 3.0 and 3.5, and the Subsystem for UNIX-based Applications (SUA); as used in gunzip, gzip, pack, pcat, and unpack 7.x before 7.0.1701.48, 8.x before 8.0.1969.62, and 9.x before 9.0.3790.2076; allow remote attackers to execute arbitrary code via unknown vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/49435" source="XF">win-unlzh-unpack-code-execution(49435)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0849" source="VUPEN" adv="1">ADV-2009-0849</ref>
      <ref url="http://www.securityfocus.com/bid/34258" source="BID">34258</ref>
      <ref url="http://support.microsoft.com/kb/953602" source="MSKB" adv="1">953602</ref>
      <ref url="http://securitytracker.com/id?1021937" source="SECTRACK">1021937</ref>
      <ref url="http://secunia.com/advisories/34428" source="SECUNIA" adv="1">34428</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="subsystem_for_unix-based_applications">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="windows_services_for_unix">
        <vers num="3.0" edition="-" />
        <vers num="3.0" edition="-:std" />
        <vers num="3.5" />
      </prod>
      <prod vendor="microsoft" name="windows_server_2008">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="windows_vista">
        <vers num="" edition=":x64-enterprise" />
        <vers num="" edition=":enterprise" />
        <vers num="" edition=":x64-ultimate" />
        <vers num="" edition=":ultimate" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1217" published="2009-04-01" name="CVE-2009-1217" modified="2009-04-16" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Off-by-one error in the GpFont::SetData function in gdiplus.dll in Microsoft GDI+ on Windows XP allows remote attackers to cause a denial of service (stack corruption and application termination) via a crafted EMF file that triggers an integer overflow, as demonstrated by voltage-exploit.emf, aka the "Microsoft GdiPlus EMF GpFont.SetData integer overflow."</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/49438" source="XF">win-gdi-emfplusfont-dos(49438)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0832" source="VUPEN" adv="1">ADV-2009-0832</ref>
      <ref url="http://www.securityfocus.com/bid/34250" source="BID">34250</ref>
      <ref url="http://blogs.technet.com/srd/archive/2009/03/26/new-emf-gdiplus-dll-crash-not-exploitable-for-code-execution.aspx" source="CONFIRM" adv="1">http://blogs.technet.com/srd/archive/2009/03/26/new-emf-gdiplus-dll-crash-not-exploitable-for-code-execution.aspx</ref>
      <ref url="http://bl4cksecurity.blogspot.com/2009/03/microsoft-gdiplus-emf-gpfontsetdata.html" source="MISC">http://bl4cksecurity.blogspot.com/2009/03/microsoft-gdiplus-emf-gpfontsetdata.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="gdiplus">
        <vers num="" />
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1218" published="2009-04-01" name="CVE-2009-1218" modified="2010-05-25" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Sun Calendar Express Web Server in Sun ONE Calendar Server 6.0 and Sun Java System Calendar Server 6 2004Q2 through 6.3-7.01 allow remote attackers to inject arbitrary web script or HTML via (1) the fmt-out parameter to login.wcap or (2) the date parameter to command.shtml.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-256228-1" source="SUNALERT" patch="1" adv="1">256228</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0905" source="VUPEN">ADV-2009-0905</ref>
      <ref url="http://www.securityfocus.com/bid/34153" source="BID">34153</ref>
      <ref url="http://www.securityfocus.com/bid/34152" source="BID">34152</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/502320/100/0/threaded" source="BUGTRAQ">20090331 CORE-2009-0108: Multiple vulnerabilities in Sun Calendar Express Web Server</ref>
      <ref url="http://www.coresecurity.com/content/sun-calendar-express" source="MISC">http://www.coresecurity.com/content/sun-calendar-express</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-77-1020321.1-1" source="SUNALERT">1020321</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="java_system_calendar_server">
        <vers num="6" edition="-" />
        <vers num="6" edition="-:linux" />
        <vers num="6" edition="-:sparc" />
        <vers num="6" edition="-:x86" />
        <vers num="6.3" edition="-" />
        <vers num="6.3" edition="-:sparc" />
        <vers num="6.3" edition="-:linux" />
        <vers num="6.3" edition="-:x86" />
      </prod>
      <prod vendor="sun" name="one_calendar_server">
        <vers num="6.0" edition="-" />
        <vers num="6.0" edition="-:x86" />
        <vers num="6.0" edition="-:linux" />
        <vers num="6.0" edition="-:sparc" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1219" published="2009-04-01" name="CVE-2009-1219" modified="2009-04-16" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Sun Calendar Express Web Server in Sun ONE Calendar Server 6.0 and Sun Java System Calendar Server 6 2004Q2 through 6.3-7.01 allows remote attackers to cause a denial of service (daemon crash) via multiple requests to the default URI with alphabetic characters in the tzid parameter.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-256228-1" source="SUNALERT" patch="1" adv="1">256228</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0905" source="VUPEN">ADV-2009-0905</ref>
      <ref url="http://www.securityfocus.com/bid/34150" source="BID">34150</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/502320/100/0/threaded" source="BUGTRAQ">20090331 CORE-2009-0108: Multiple vulnerabilities in Sun Calendar Express Web Server</ref>
      <ref url="http://www.coresecurity.com/content/sun-calendar-express" source="MISC">http://www.coresecurity.com/content/sun-calendar-express</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-255008-1" source="SUNALERT">255008</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="java_system_calendar_server">
        <vers num="6" edition="-" />
        <vers num="6" edition="-:linux" />
        <vers num="6" edition="-:sparc" />
        <vers num="6" edition="-:x86" />
        <vers num="6.3" edition="-" />
        <vers num="6.3" edition="-:sparc" />
        <vers num="6.3" edition="-:linux" />
        <vers num="6.3" edition="-:x86" />
      </prod>
      <prod vendor="sun" name="one_calendar_server">
        <vers num="6.0" edition="-" />
        <vers num="6.0" edition="-:x86" />
        <vers num="6.0" edition="-:linux" />
        <vers num="6.0" edition="-:sparc" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1220" published="2009-04-01" name="CVE-2009-1220" modified="2009-05-06" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in +webvpn+/index.html in WebVPN on the Cisco Adaptive Security Appliances (ASA) 5520 with software 7.2(4)30 and earlier 7.2 versions including 7.2(2)22, and 8.0(4)28 and earlier 8.0 versions, when clientless mode is enabled, allows remote attackers to inject arbitrary web script or HTML via the Host HTTP header.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/49528" source="XF">asa5520-webvpn-xss(49528)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1169" source="VUPEN">ADV-2009-1169</ref>
      <ref url="http://www.securitytracker.com/id?1022122" source="SECTRACK">1022122</ref>
      <ref url="http://www.securityfocus.com/bid/34307" source="BID">34307</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/502313/100/0/threaded" source="BUGTRAQ">20090331 Cisco ASA5520 Web VPN Host Header XSS</ref>
      <ref url="http://www.securityfocus.com/archive/1/502932" source="BUGTRAQ">20090424 RE: Cisco ASA5520 Web VPN Host Header XSS</ref>
      <ref url="http://tools.cisco.com/security/center/viewAlert.x?alertId=17950" source="CONFIRM">http://tools.cisco.com/security/center/viewAlert.x?alertId=17950</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2009-03/0478.html" source="FULLDISC">20090331 Cisco ASA5520 Web VPN Host Header XSS</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="adaptive_security_appliance">
        <vers num="5520" />
      </prod>
      <prod vendor="cisco" name="ios">
        <vers num="7.2(2)22" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1222" published="2009-04-02" name="CVE-2009-1222" modified="2009-06-16" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">Directory traversal vulnerability in index.php in webEdition 6.0.0.4 and earlier, when register_globals is enabled and magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary files via a .. (dot dot) in the WE_LANGUAGE parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/49530" source="XF">webedition-index-file-include(49530)</ref>
      <ref url="http://www.securityfocus.com/bid/34323" source="BID">34323</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/502315/100/0/threaded" source="BUGTRAQ">20090331 webEdition 6.0.0.4 Local File Inclusion</ref>
      <ref url="http://www.milw0rm.com/exploits/8328" source="MILW0RM">8328</ref>
      <ref url="http://secunia.com/advisories/34518" source="SECUNIA" adv="1">34518</ref>
    </refs>
    <vuln_soft>
      <prod vendor="webedition" name="webedition">
        <vers num="6.0.0.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1223" published="2009-04-02" name="CVE-2009-1223" modified="2009-04-18" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">aspWebCalendar Free Edition stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing user credentials via a direct request for calendar/calendar.mdb.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/49885" source="XF">aspwebcalendar-calendar-info-disclosure(49885)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/502311/100/0/threaded" source="BUGTRAQ">20090331 aspWebCalendar Free Edition bug</ref>
    </refs>
    <vuln_soft>
      <prod vendor="fullrevolution" name="aspwebcalendar">
        <vers num="-" edition="-" />
        <vers num="-" edition="-:free" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1224" published="2009-04-02" name="CVE-2009-1224" modified="2009-04-02" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in vsp-core/pub/themes/bismarck/gamestat.php in vsp stats processor 0.45 allows remote attackers to execute arbitrary SQL commands via the gameID parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.milw0rm.com/exploits/8331" source="MILW0RM">8331</ref>
    </refs>
    <vuln_soft>
      <prod vendor="scivox" name="vsp_stats_processor">
        <vers num="0.45" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1225" published="2009-04-02" name="CVE-2009-1225" modified="2009-04-02" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in index.php in Turnkey Ebook Store 1.1 allows remote attackers to inject arbitrary web script or HTML via the keywords parameter in a search action.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/34533" source="SECUNIA" adv="1">34533</ref>
      <ref url="http://packetstorm.linuxsecurity.com/0903-exploits/turnkeyebook-xss.txt" source="MISC">http://packetstorm.linuxsecurity.com/0903-exploits/turnkeyebook-xss.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="platinumprofitzone" name="turnkey_ebook_store">
        <vers num="1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1226" published="2009-04-02" name="CVE-2009-1226" modified="2009-04-10" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">core/admin/delete.php in Podcast Generator 1.1 and earlier does not properly restrict access to administrative functions, which allows remote attackers to delete arbitrary files via the file parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/34317" source="BID">34317</ref>
      <ref url="http://www.milw0rm.com/exploits/8324" source="MILW0RM">8324</ref>
      <ref url="http://secunia.com/advisories/34555" source="SECUNIA" adv="1">34555</ref>
    </refs>
    <vuln_soft>
      <prod vendor="podcast_generator" name="podcast_generator">
        <vers num="0.6" />
        <vers num="0.8" />
        <vers num="0.81" />
        <vers num="0.9" />
        <vers num="0.91" />
        <vers num="0.92" />
        <vers num="0.93" />
        <vers num="0.94" />
        <vers num="0.95" />
        <vers num="0.96" />
        <vers num="0.96.2" />
        <vers num="1.0" edition="beta_2" />
        <vers num="1.0_beta" />
        <vers num="1.0_beta2" />
        <vers num="1.0_beta3" />
        <vers num="1.0_beta4" />
        <vers num="1.0_beta4a" />
        <vers prev="1" num="1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1227" published="2009-04-02" name="CVE-2009-1227" modified="2009-04-08" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">** DISPUTED **  NOTE: this issue has been disputed by the vendor.  Buffer overflow in the PKI Web Service in Check Point Firewall-1 PKI Web Service allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long (1) Authorization or (2) Referer HTTP header to TCP port 18624.  NOTE: the vendor has disputed this issue, stating "Check Point Security Alert Team has analyzed this report. We've tried to reproduce the attack on all VPN-1 versions from NG FP2 and above with and without HFAs. The issue was not reproduced. We have conducted a thorough analysis of the relevant code and verified that we are secure against this attack. We consider this attack to pose no risk to Check Point customers."  In addition, the original researcher, whose reliability is unknown as of 20090407, also states that the issue "was discovered during a pen-test where the client would not allow further analysis."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securitytracker.com/id?1021948" source="SECTRACK">1021948</ref>
      <ref url="http://www.securityfocus.com/bid/34286" source="BID">34286</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/502256/100/0/threaded" source="BUGTRAQ">20090330 Check Point Firewall-1 PKI Web Service HTTP Header Remote Overflow</ref>
      <ref url="http://www.milw0rm.com/exploits/8313" source="MILW0RM">8313</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2009-03/0463.html" source="FULLDISC">20090330 Check Point Firewall-1 PKI Web Service HTTP Header Remote Overflow</ref>
    </refs>
    <vuln_soft>
      <prod vendor="checkpoint" name="firewall-1_pki_web_service">
        <vers num="-" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1228" published="2009-04-02" name="CVE-2009-1228" modified="2009-04-02" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in register.php in Arcadwy Arcade Script CMS allows remote attackers to inject arbitrary web script or HTML via the username field (user_name parameter).</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/49472" source="XF">arcadescript-register-xss(49472)</ref>
      <ref url="http://www.securityfocus.com/bid/34275" source="BID">34275</ref>
      <ref url="http://www.milw0rm.com/exploits/8296" source="MILW0RM">8296</ref>
      <ref url="http://secunia.com/advisories/34506" source="SECUNIA" adv="1">34506</ref>
    </refs>
    <vuln_soft>
      <prod vendor="arcadwy" name="arcadwy_arcade_script_cms">
        <vers num="-" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1229" published="2009-04-02" name="CVE-2009-1229" modified="2009-04-02" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in Arcadwy Arcade Script allows remote attackers to execute arbitrary SQL commands via the user cookie parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://z0rlu.blogspot.com/2009/03/arcadwy-arcade-script-auth-bypass.html" source="MISC">http://z0rlu.blogspot.com/2009/03/arcadwy-arcade-script-auth-bypass.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/49500" source="XF">arcadescript-user-sql-injection(49500)</ref>
      <ref url="http://www.securityfocus.com/bid/34284" source="BID">34284</ref>
      <ref url="http://www.milw0rm.com/exploits/8304" source="MILW0RM">8304</ref>
      <ref url="http://secunia.com/advisories/34506" source="SECUNIA" adv="1">34506</ref>
    </refs>
    <vuln_soft>
      <prod vendor="arcadwy" name="arcadwy_arcade_script">
        <vers num="-" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1230" published="2009-04-02" name="CVE-2009-1230" modified="2009-04-10" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)" CVSS_score="6.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.0" CVSS_base_score="6.5">
    <desc>
      <descript source="cve">Static code injection vulnerability in index.php in Podcast Generator 1.1 and earlier allows remote authenticated administrators to inject arbitrary PHP code into config.php via the recent parameter in a config change action.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.milw0rm.com/exploits/8324" source="MILW0RM">8324</ref>
    </refs>
    <vuln_soft>
      <prod vendor="podcast_generator" name="podcast_generator">
        <vers num="0.6" />
        <vers num="0.8" />
        <vers num="0.81" />
        <vers num="0.9" />
        <vers num="0.91" />
        <vers num="0.92" />
        <vers num="0.93" />
        <vers num="0.94" />
        <vers num="0.95" />
        <vers num="0.96" />
        <vers num="0.96.2" />
        <vers num="1.0" edition="beta_2" />
        <vers num="1.0_beta" />
        <vers num="1.0_beta2" />
        <vers num="1.0_beta3" />
        <vers num="1.0_beta4" />
        <vers num="1.0_beta4a" />
        <vers prev="1" num="1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1231" published="2009-04-02" name="CVE-2009-1231" modified="2009-04-16" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the eClient in IBM DB2 Content Manager 8.4.1 before 8.4.1.1 has unknown impact and attack vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg27015162" source="CONFIRM" patch="1">http://www-01.ibm.com/support/docview.wss?uid=swg27015162</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0910" source="VUPEN">ADV-2009-0910</ref>
      <ref url="http://www.securityfocus.com/bid/34326" source="BID">34326</ref>
      <ref url="http://secunia.com/advisories/34544" source="SECUNIA" adv="1">34544</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="db2_content_manager">
        <vers num="8.4.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1232" published="2009-04-02" name="CVE-2009-1232" modified="2009-08-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Mozilla Firefox 3.0.8 and earlier 3.0.x versions allows remote attackers to cause a denial of service (memory corruption) via an XML document composed of a long series of start-tags with no corresponding end-tags. NOTE: it was later reported that 3.0.10 and earlier are also affected.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=485941" source="MISC">https://bugzilla.mozilla.org/show_bug.cgi?id=485941</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/49521" source="XF">firefox-xml-dos(49521)</ref>
      <ref url="http://www.securityfocus.com/bid/34522" source="BID">34522</ref>
      <ref url="http://www.milw0rm.com/exploits/8306" source="MILW0RM">8306</ref>
      <ref url="http://websecurity.com.ua/3216/" source="MISC">http://websecurity.com.ua/3216/</ref>
      <ref url="http://milw0rm.com/sploits/2009-Firefox-XUL-0day-PoC.rar" source="MISC">http://milw0rm.com/sploits/2009-Firefox-XUL-0day-PoC.rar</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="3.0" edition="alpha" />
        <vers num="3.0" edition="beta2" />
        <vers num="3.0" edition="beta5" />
        <vers num="3.0.1" />
        <vers num="3.0.2" />
        <vers num="3.0.3" />
        <vers num="3.0.4" />
        <vers num="3.0.5" />
        <vers num="3.0.6" />
        <vers num="3.0.7" />
        <vers num="3.0.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1233" published="2009-04-02" name="CVE-2009-1233" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Apple Safari 3.2.2 and 4 Beta on Windows allows remote attackers to cause a denial of service (application crash) via an XML document containing many nested A elements.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/49527" source="XF">safari-xml-dos(49527)</ref>
      <ref url="http://www.securityfocus.com/bid/34318" source="BID">34318</ref>
      <ref url="http://www.milw0rm.com/exploits/8325" source="MILW0RM">8325</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5559" source="OVAL">oval:org.mitre.oval:def:5559</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="safari">
        <vers num="3.2.2" edition="-" />
        <vers num="3.2.2" edition="-:windows" />
        <vers num="4" edition="beta" />
        <vers num="4" edition="beta:windows" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1234" published="2009-04-02" name="CVE-2009-1234" modified="2011-01-06" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Opera 9.64 allows remote attackers to cause a denial of service (application crash) via an XML document containing a long series of start-tags with no corresponding end-tags.  NOTE: it was later reported that 9.52 is also affected.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/49522" source="XF">opera-xml-dos(49522)</ref>
      <ref url="http://www.securityfocus.com/bid/34298" source="BID">34298</ref>
      <ref url="http://www.milw0rm.com/exploits/8320" source="MILW0RM">8320</ref>
      <ref url="http://websecurity.com.ua/3216/" source="MISC">http://websecurity.com.ua/3216/</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5432" source="OVAL">oval:org.mitre.oval:def:5432</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-09/msg00001.html" source="SUSE">SUSE-SR:2009:015</ref>
    </refs>
    <vuln_soft>
      <prod vendor="opera" name="opera">
        <vers num="9.52" />
        <vers num="9.64" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1235" published="2009-04-02" name="CVE-2009-1235" modified="2009-08-13" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">XNU 1228.9.59 and earlier on Apple Mac OS X 10.5.6 and earlier does not properly restrict interaction between user space and the HFS IOCTL handler, which allows local users to overwrite kernel memory and gain privileges by attaching an HFS+ disk image and performing certain steps involving HFS_GET_BOOT_INFO fcntl calls.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-218A.html" source="CERT">TA09-218A</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/2172" source="VUPEN">ADV-2009-2172</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0822" source="VUPEN" adv="1">ADV-2009-0822</ref>
      <ref url="http://www.securitytracker.com/id?1022671" source="SECTRACK">1022671</ref>
      <ref url="http://www.securityfocus.com/bid/34203" source="BID">34203</ref>
      <ref url="http://www.milw0rm.com/exploits/8266" source="MILW0RM">8266</ref>
      <ref url="http://www.informationweek.com/news/hardware/mac/showArticle.jhtml?articleID=216401181" source="MISC">http://www.informationweek.com/news/hardware/mac/showArticle.jhtml?articleID=216401181</ref>
      <ref url="http://www.digit-labs.org/files/exploits/xnu-hfs-fcntl-v2.sh" source="MISC">http://www.digit-labs.org/files/exploits/xnu-hfs-fcntl-v2.sh</ref>
      <ref url="http://www.digit-labs.org/files/exploits/xnu-hfs-fcntl-v2.c" source="MISC">http://www.digit-labs.org/files/exploits/xnu-hfs-fcntl-v2.c</ref>
      <ref url="http://support.apple.com/kb/HT3757" source="CONFIRM">http://support.apple.com/kb/HT3757</ref>
      <ref url="http://secunia.com/advisories/36096" source="SECUNIA">36096</ref>
      <ref url="http://secunia.com/advisories/34424" source="SECUNIA">34424</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2009/Aug/msg00001.html" source="APPLE">APPLE-SA-2009-08-05-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.0" />
        <vers num="10.0.0" />
        <vers num="10.0.1" />
        <vers num="10.0.2" />
        <vers num="10.0.3" />
        <vers num="10.0.4" />
        <vers num="10.1" />
        <vers num="10.1.0" />
        <vers num="10.1.1" />
        <vers num="10.1.2" />
        <vers num="10.1.3" />
        <vers num="10.1.4" />
        <vers num="10.1.5" />
        <vers num="10.2" />
        <vers num="10.2.0" />
        <vers num="10.2.1" />
        <vers num="10.2.2" />
        <vers num="10.2.3" />
        <vers num="10.2.4" />
        <vers num="10.2.5" />
        <vers num="10.2.6" />
        <vers num="10.2.7" />
        <vers num="10.2.8" />
        <vers num="10.3" />
        <vers num="10.3.0" />
        <vers num="10.3.1" />
        <vers num="10.3.2" />
        <vers num="10.3.3" />
        <vers num="10.3.4" />
        <vers num="10.3.5" />
        <vers num="10.3.6" />
        <vers num="10.3.7" />
        <vers num="10.3.8" />
        <vers num="10.3.9" />
        <vers num="10.4" />
        <vers num="10.4.0" />
        <vers num="10.4.1" />
        <vers num="10.4.10" />
        <vers num="10.4.11" />
        <vers num="10.4.2" />
        <vers num="10.4.3" />
        <vers num="10.4.4" />
        <vers num="10.4.5" />
        <vers num="10.4.6" />
        <vers num="10.4.7" />
        <vers num="10.4.8" edition="" />
        <vers num="10.4.8" edition=":macbook" />
        <vers num="10.4.8" edition=":mac_mini" />
        <vers num="10.4.8" edition=":macbook_pro" />
        <vers num="10.4.9" />
        <vers num="10.5" />
        <vers num="10.5.0" />
        <vers num="10.5.1" />
        <vers num="10.5.2" edition="2008-002" />
        <vers num="10.5.3" />
        <vers num="10.5.4" />
        <vers num="10.5.5" />
        <vers prev="1" num="10.5.6" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.0" />
        <vers num="10.0.0" />
        <vers num="10.0.1" />
        <vers num="10.0.2" />
        <vers num="10.0.3" />
        <vers num="10.0.4" />
        <vers num="10.1" />
        <vers num="10.1.0" />
        <vers num="10.1.1" />
        <vers num="10.1.2" />
        <vers num="10.1.3" />
        <vers num="10.1.4" />
        <vers num="10.1.5" />
        <vers num="10.2" />
        <vers num="10.2.0" />
        <vers num="10.2.1" />
        <vers num="10.2.2" />
        <vers num="10.2.3" />
        <vers num="10.2.4" />
        <vers num="10.2.5" />
        <vers num="10.2.6" />
        <vers num="10.2.7" />
        <vers num="10.2.8" />
        <vers num="10.3" />
        <vers num="10.3.0" />
        <vers num="10.3.1" />
        <vers num="10.3.2" />
        <vers num="10.3.3" />
        <vers num="10.3.4" />
        <vers num="10.3.5" />
        <vers num="10.3.6" />
        <vers num="10.3.7" />
        <vers num="10.3.8" />
        <vers num="10.3.9" />
        <vers num="10.4" />
        <vers num="10.4.0" />
        <vers num="10.4.1" />
        <vers num="10.4.10" />
        <vers num="10.4.11" />
        <vers num="10.4.2" />
        <vers num="10.4.3" />
        <vers num="10.4.4" />
        <vers num="10.4.5" />
        <vers num="10.4.6" />
        <vers num="10.4.7" />
        <vers num="10.4.8" />
        <vers num="10.4.9" />
        <vers num="10.5" />
        <vers num="10.5.0" />
        <vers num="10.5.1" />
        <vers num="10.5.2" />
        <vers num="10.5.3" />
        <vers num="10.5.4" />
        <vers num="10.5.5" />
        <vers prev="1" num="10.5.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1236" published="2009-04-02" name="CVE-2009-1236" modified="2009-04-18" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Heap-based buffer overflow in the AppleTalk networking stack in XNU 1228.3.13 and earlier on Apple Mac OS X 10.5.6 and earlier allows remote attackers to cause a denial of service (system crash) via a ZIP NOTIFY (aka ZIPOP_NOTIFY) packet that overwrites a certain ifPort structure member.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/34201" source="BID">34201</ref>
      <ref url="http://www.milw0rm.com/exploits/8262" source="MILW0RM">8262</ref>
      <ref url="http://www.informationweek.com/news/hardware/mac/showArticle.jhtml?articleID=216401181" source="MISC">http://www.informationweek.com/news/hardware/mac/showArticle.jhtml?articleID=216401181</ref>
      <ref url="http://www.digit-labs.org/files/exploits/xnu-appletalk-zip.c" source="MISC">http://www.digit-labs.org/files/exploits/xnu-appletalk-zip.c</ref>
      <ref url="http://secunia.com/advisories/34424" source="SECUNIA">34424</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.0" />
        <vers num="10.0.0" />
        <vers num="10.0.1" />
        <vers num="10.0.2" />
        <vers num="10.0.3" />
        <vers num="10.0.4" />
        <vers num="10.1" />
        <vers num="10.1.0" />
        <vers num="10.1.1" />
        <vers num="10.1.2" />
        <vers num="10.1.3" />
        <vers num="10.1.4" />
        <vers num="10.1.5" />
        <vers num="10.2" />
        <vers num="10.2.0" />
        <vers num="10.2.1" />
        <vers num="10.2.2" />
        <vers num="10.2.3" />
        <vers num="10.2.4" />
        <vers num="10.2.5" />
        <vers num="10.2.6" />
        <vers num="10.2.7" />
        <vers num="10.2.8" />
        <vers num="10.3" />
        <vers num="10.3.0" />
        <vers num="10.3.1" />
        <vers num="10.3.2" />
        <vers num="10.3.3" />
        <vers num="10.3.4" />
        <vers num="10.3.5" />
        <vers num="10.3.6" />
        <vers num="10.3.7" />
        <vers num="10.3.8" />
        <vers num="10.3.9" />
        <vers num="10.4" />
        <vers num="10.4.0" />
        <vers num="10.4.1" />
        <vers num="10.4.10" />
        <vers num="10.4.11" />
        <vers num="10.4.2" />
        <vers num="10.4.3" />
        <vers num="10.4.4" />
        <vers num="10.4.5" />
        <vers num="10.4.6" />
        <vers num="10.4.7" />
        <vers num="10.4.8" edition="" />
        <vers num="10.4.8" edition=":macbook" />
        <vers num="10.4.8" edition=":mac_mini" />
        <vers num="10.4.8" edition=":macbook_pro" />
        <vers num="10.4.9" />
        <vers num="10.5" />
        <vers num="10.5.0" />
        <vers num="10.5.1" />
        <vers num="10.5.2" edition="2008-002" />
        <vers num="10.5.3" />
        <vers num="10.5.4" />
        <vers num="10.5.5" />
        <vers prev="1" num="10.5.6" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.0" />
        <vers num="10.0.0" />
        <vers num="10.0.1" />
        <vers num="10.0.2" />
        <vers num="10.0.3" />
        <vers num="10.0.4" />
        <vers num="10.1" />
        <vers num="10.1.0" />
        <vers num="10.1.1" />
        <vers num="10.1.2" />
        <vers num="10.1.3" />
        <vers num="10.1.4" />
        <vers num="10.1.5" />
        <vers num="10.2" />
        <vers num="10.2.0" />
        <vers num="10.2.1" />
        <vers num="10.2.2" />
        <vers num="10.2.3" />
        <vers num="10.2.4" />
        <vers num="10.2.5" />
        <vers num="10.2.6" />
        <vers num="10.2.7" />
        <vers num="10.2.8" />
        <vers num="10.3" />
        <vers num="10.3.0" />
        <vers num="10.3.1" />
        <vers num="10.3.2" />
        <vers num="10.3.3" />
        <vers num="10.3.4" />
        <vers num="10.3.5" />
        <vers num="10.3.6" />
        <vers num="10.3.7" />
        <vers num="10.3.8" />
        <vers num="10.3.9" />
        <vers num="10.4" />
        <vers num="10.4.0" />
        <vers num="10.4.1" />
        <vers num="10.4.10" />
        <vers num="10.4.11" />
        <vers num="10.4.2" />
        <vers num="10.4.3" />
        <vers num="10.4.4" />
        <vers num="10.4.5" />
        <vers num="10.4.6" />
        <vers num="10.4.7" />
        <vers num="10.4.8" />
        <vers num="10.4.9" />
        <vers num="10.5" />
        <vers num="10.5.0" />
        <vers num="10.5.1" />
        <vers num="10.5.2" />
        <vers num="10.5.3" />
        <vers num="10.5.4" />
        <vers num="10.5.5" />
        <vers prev="1" num="10.5.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1237" published="2009-04-02" name="CVE-2009-1237" modified="2009-04-18" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="4.9" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="3.9" CVSS_base_score="4.9">
    <desc>
      <descript source="cve">Multiple memory leaks in XNU 1228.3.13 and earlier on Apple Mac OS X 10.5.6 and earlier allow local users to cause a denial of service (kernel memory consumption) via a crafted (1) SYS_add_profil or (2) SYS___mac_getfsstat system call.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/34202" source="BID">34202</ref>
      <ref url="http://www.milw0rm.com/exploits/8264" source="MILW0RM">8264</ref>
      <ref url="http://www.milw0rm.com/exploits/8263" source="MILW0RM">8263</ref>
      <ref url="http://www.informationweek.com/news/hardware/mac/showArticle.jhtml?articleID=216401181" source="MISC">http://www.informationweek.com/news/hardware/mac/showArticle.jhtml?articleID=216401181</ref>
      <ref url="http://www.digit-labs.org/files/exploits/xnu-profil-leak.c" source="MISC">http://www.digit-labs.org/files/exploits/xnu-profil-leak.c</ref>
      <ref url="http://www.digit-labs.org/files/exploits/xnu-macfsstat-leak.c" source="MISC">http://www.digit-labs.org/files/exploits/xnu-macfsstat-leak.c</ref>
      <ref url="http://secunia.com/advisories/34424" source="SECUNIA">34424</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.0" />
        <vers num="10.0.0" />
        <vers num="10.0.1" />
        <vers num="10.0.2" />
        <vers num="10.0.3" />
        <vers num="10.0.4" />
        <vers num="10.1" />
        <vers num="10.1.0" />
        <vers num="10.1.1" />
        <vers num="10.1.2" />
        <vers num="10.1.3" />
        <vers num="10.1.4" />
        <vers num="10.1.5" />
        <vers num="10.2" />
        <vers num="10.2.0" />
        <vers num="10.2.1" />
        <vers num="10.2.2" />
        <vers num="10.2.3" />
        <vers num="10.2.4" />
        <vers num="10.2.5" />
        <vers num="10.2.6" />
        <vers num="10.2.7" />
        <vers num="10.2.8" />
        <vers num="10.3" />
        <vers num="10.3.0" />
        <vers num="10.3.1" />
        <vers num="10.3.2" />
        <vers num="10.3.3" />
        <vers num="10.3.4" />
        <vers num="10.3.5" />
        <vers num="10.3.6" />
        <vers num="10.3.7" />
        <vers num="10.3.8" />
        <vers num="10.3.9" />
        <vers num="10.4" />
        <vers num="10.4.0" />
        <vers num="10.4.1" />
        <vers num="10.4.10" />
        <vers num="10.4.11" />
        <vers num="10.4.2" />
        <vers num="10.4.3" />
        <vers num="10.4.4" />
        <vers num="10.4.5" />
        <vers num="10.4.6" />
        <vers num="10.4.7" />
        <vers num="10.4.8" edition="" />
        <vers num="10.4.8" edition=":macbook" />
        <vers num="10.4.8" edition=":mac_mini" />
        <vers num="10.4.8" edition=":macbook_pro" />
        <vers num="10.4.9" />
        <vers num="10.5" />
        <vers num="10.5.0" />
        <vers num="10.5.1" />
        <vers num="10.5.2" edition="2008-002" />
        <vers num="10.5.3" />
        <vers num="10.5.4" />
        <vers num="10.5.5" />
        <vers prev="1" num="10.5.6" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.0" />
        <vers num="10.0.0" />
        <vers num="10.0.1" />
        <vers num="10.0.2" />
        <vers num="10.0.3" />
        <vers num="10.0.4" />
        <vers num="10.1" />
        <vers num="10.1.0" />
        <vers num="10.1.1" />
        <vers num="10.1.2" />
        <vers num="10.1.3" />
        <vers num="10.1.4" />
        <vers num="10.1.5" />
        <vers num="10.2" />
        <vers num="10.2.0" />
        <vers num="10.2.1" />
        <vers num="10.2.2" />
        <vers num="10.2.3" />
        <vers num="10.2.4" />
        <vers num="10.2.5" />
        <vers num="10.2.6" />
        <vers num="10.2.7" />
        <vers num="10.2.8" />
        <vers num="10.3" />
        <vers num="10.3.0" />
        <vers num="10.3.1" />
        <vers num="10.3.2" />
        <vers num="10.3.3" />
        <vers num="10.3.4" />
        <vers num="10.3.5" />
        <vers num="10.3.6" />
        <vers num="10.3.7" />
        <vers num="10.3.8" />
        <vers num="10.3.9" />
        <vers num="10.4" />
        <vers num="10.4.0" />
        <vers num="10.4.1" />
        <vers num="10.4.10" />
        <vers num="10.4.11" />
        <vers num="10.4.2" />
        <vers num="10.4.3" />
        <vers num="10.4.4" />
        <vers num="10.4.5" />
        <vers num="10.4.6" />
        <vers num="10.4.7" />
        <vers num="10.4.8" />
        <vers num="10.4.9" />
        <vers num="10.5" />
        <vers num="10.5.0" />
        <vers num="10.5.1" />
        <vers num="10.5.2" />
        <vers num="10.5.3" />
        <vers num="10.5.4" />
        <vers num="10.5.5" />
        <vers prev="1" num="10.5.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1238" published="2009-04-02" name="CVE-2009-1238" modified="2009-04-18" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Race condition in the HFS vfs sysctl interface in XNU 1228.8.20 and earlier on Apple Mac OS X 10.5.6 and earlier allows local users to cause a denial of service (kernel memory corruption) by simultaneously executing the same HFS_SET_PKG_EXTENSIONS code path in multiple threads, which is problematic because of lack of mutex locking for an unspecified global variable.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/34202" source="BID">34202</ref>
      <ref url="http://www.milw0rm.com/exploits/8265" source="MILW0RM">8265</ref>
      <ref url="http://www.informationweek.com/news/hardware/mac/showArticle.jhtml?articleID=216401181" source="MISC">http://www.informationweek.com/news/hardware/mac/showArticle.jhtml?articleID=216401181</ref>
      <ref url="http://www.digit-labs.org/files/exploits/xnu-vfssysctl-dos.c" source="MISC">http://www.digit-labs.org/files/exploits/xnu-vfssysctl-dos.c</ref>
      <ref url="http://secunia.com/advisories/34424" source="SECUNIA">34424</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.0" />
        <vers num="10.0.0" />
        <vers num="10.0.1" />
        <vers num="10.0.2" />
        <vers num="10.0.3" />
        <vers num="10.0.4" />
        <vers num="10.1" />
        <vers num="10.1.0" />
        <vers num="10.1.1" />
        <vers num="10.1.2" />
        <vers num="10.1.3" />
        <vers num="10.1.4" />
        <vers num="10.1.5" />
        <vers num="10.2" />
        <vers num="10.2.0" />
        <vers num="10.2.1" />
        <vers num="10.2.2" />
        <vers num="10.2.3" />
        <vers num="10.2.4" />
        <vers num="10.2.5" />
        <vers num="10.2.6" />
        <vers num="10.2.7" />
        <vers num="10.2.8" />
        <vers num="10.3" />
        <vers num="10.3.0" />
        <vers num="10.3.1" />
        <vers num="10.3.2" />
        <vers num="10.3.3" />
        <vers num="10.3.4" />
        <vers num="10.3.5" />
        <vers num="10.3.6" />
        <vers num="10.3.7" />
        <vers num="10.3.8" />
        <vers num="10.3.9" />
        <vers num="10.4" />
        <vers num="10.4.0" />
        <vers num="10.4.1" />
        <vers num="10.4.10" />
        <vers num="10.4.11" />
        <vers num="10.4.2" />
        <vers num="10.4.3" />
        <vers num="10.4.4" />
        <vers num="10.4.5" />
        <vers num="10.4.6" />
        <vers num="10.4.7" />
        <vers num="10.4.8" edition="" />
        <vers num="10.4.8" edition=":macbook" />
        <vers num="10.4.8" edition=":mac_mini" />
        <vers num="10.4.8" edition=":macbook_pro" />
        <vers num="10.4.9" />
        <vers num="10.5" />
        <vers num="10.5.0" />
        <vers num="10.5.1" />
        <vers num="10.5.2" edition="2008-002" />
        <vers num="10.5.3" />
        <vers num="10.5.4" />
        <vers num="10.5.5" />
        <vers prev="1" num="10.5.6" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.0" />
        <vers num="10.0.0" />
        <vers num="10.0.1" />
        <vers num="10.0.2" />
        <vers num="10.0.3" />
        <vers num="10.0.4" />
        <vers num="10.1" />
        <vers num="10.1.0" />
        <vers num="10.1.1" />
        <vers num="10.1.2" />
        <vers num="10.1.3" />
        <vers num="10.1.4" />
        <vers num="10.1.5" />
        <vers num="10.2" />
        <vers num="10.2.0" />
        <vers num="10.2.1" />
        <vers num="10.2.2" />
        <vers num="10.2.3" />
        <vers num="10.2.4" />
        <vers num="10.2.5" />
        <vers num="10.2.6" />
        <vers num="10.2.7" />
        <vers num="10.2.8" />
        <vers num="10.3" />
        <vers num="10.3.0" />
        <vers num="10.3.1" />
        <vers num="10.3.2" />
        <vers num="10.3.3" />
        <vers num="10.3.4" />
        <vers num="10.3.5" />
        <vers num="10.3.6" />
        <vers num="10.3.7" />
        <vers num="10.3.8" />
        <vers num="10.3.9" />
        <vers num="10.4" />
        <vers num="10.4.0" />
        <vers num="10.4.1" />
        <vers num="10.4.10" />
        <vers num="10.4.11" />
        <vers num="10.4.2" />
        <vers num="10.4.3" />
        <vers num="10.4.4" />
        <vers num="10.4.5" />
        <vers num="10.4.6" />
        <vers num="10.4.7" />
        <vers num="10.4.8" />
        <vers num="10.4.9" />
        <vers num="10.5" />
        <vers num="10.5.0" />
        <vers num="10.5.1" />
        <vers num="10.5.2" />
        <vers num="10.5.3" />
        <vers num="10.5.4" />
        <vers num="10.5.5" />
        <vers prev="1" num="10.5.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1239" published="2009-04-03" name="CVE-2009-1239" modified="2009-04-18" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">IBM DB2 9.1 before FP7 returns incorrect query results in certain situations related to the order of application of an INNER JOIN predicate and an OUTER JOIN predicate, which might allow attackers to obtain sensitive information via a crafted query.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg21381257" source="CONFIRM" patch="1" adv="1">http://www-01.ibm.com/support/docview.wss?uid=swg21381257</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg1JR31886" source="AIXAPAR" patch="1">JR31886</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/49864" source="XF">db2-predicate-information-disclosure(49864)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0912" source="VUPEN" adv="1">ADV-2009-0912</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="db2">
        <vers prev="1" num="9.1" edition="" />
        <vers prev="1" num="9.1" edition=":personal" />
        <vers prev="1" num="9.1" edition=":enterprise_server" />
        <vers prev="1" num="9.1" edition=":express_server" />
        <vers prev="1" num="9.1" edition=":connect_server" />
        <vers prev="1" num="9.1" edition=":workgroup_server" />
        <vers prev="1" num="9.1" edition="fp1" />
        <vers prev="1" num="9.1" edition="fp1:windows" />
        <vers prev="1" num="9.1" edition="fp1:unix" />
        <vers prev="1" num="9.1" edition="fp2" />
        <vers prev="1" num="9.1" edition="fp3" />
        <vers prev="1" num="9.1" edition="fp3a" />
        <vers prev="1" num="9.1" edition="fp4" />
        <vers prev="1" num="9.1" edition="fp4a" />
        <vers prev="1" num="9.1" edition="fp5" />
        <vers prev="1" num="9.1" edition="fp6" />
        <vers prev="1" num="9.1" edition="fp6a" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1240" published="2009-04-03" name="CVE-2009-1240" modified="2009-09-11" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the IBM Proventia engine 4.9.0.0.44 20081231, as used in IBM Proventia Network Mail Security System, Network Mail Security System Virtual Appliance, Desktop Endpoint Security, Network Multi-Function Security (MFS), and possibly other products, allows remote attackers to bypass detection of malware via a modified RAR archive.</descript>
      <descript source="nvd">Per: http://iss.custhelp.com/cgi-bin/iss.cfg/php/enduser/std_adp.php?p_faqid=5417

Although the Virus Prevention System technology was, at one time, incorporated into the IBM Proventia Network MFS and the Proventia Network Mail appliances, this capability was removed in Jan 2008. For this reason, this vulnerability does not apply to these product lines.

The Virus Prevention System technology is currently incorporated into Proventia Desktop. However, the Proventia Desktop product is not affected by this evasion.

No other IBM ISS products currently incorporate the Virus Prevention System technology.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/34345" source="BID">34345</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/504995/100/0/threaded" source="BUGTRAQ">20090716 Re: Update: [TZO-06-2009] IBM Proventia - Generic bypass (Limited disclosure - see details)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/504992/100/0/threaded" source="BUGTRAQ">20090716 Re[2]: Update: [TZO-06-2009] IBM Proventia - Generic bypass (Limited disclosure - see details)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/504987/100/0/threaded" source="BUGTRAQ">20090715 Update: [TZO-06-2009] IBM Proventia - Generic bypass (Limited disclosure - see details)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/502369/100/0/threaded" source="BUGTRAQ">20090402 [TZO-06-2009] IBM Proventia - Generic bypass (Limited disclosure - see details)</ref>
      <ref url="http://iss.custhelp.com/cgi-bin/iss.cfg/php/enduser/std_adp.php?p_faqid=5417" source="MISC">http://iss.custhelp.com/cgi-bin/iss.cfg/php/enduser/std_adp.php?p_faqid=5417</ref>
      <ref url="http://blog.zoller.lu/2009/04/ibm-proventia-evasion-limited-details.html" source="MISC">http://blog.zoller.lu/2009/04/ibm-proventia-evasion-limited-details.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="proventia_desktop_endpoint_security">
        <vers num="" />
      </prod>
      <prod vendor="ibm" name="proventia_network_mail_security_system">
        <vers num="" />
      </prod>
      <prod vendor="ibm" name="network_multi-function_security">
        <vers num="" />
      </prod>
      <prod vendor="ibm" name="proventia_network_mail_security_system_virtual_appliance">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1241" published="2009-04-03" name="CVE-2009-1241" modified="2009-09-16" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Unspecified vulnerability in ClamAV before 0.95 allows remote attackers to bypass detection of malware via a modified RAR archive.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2009/0934" source="VUPEN">ADV-2009-0934</ref>
      <ref url="http://www.securityfocus.com/bid/34344" source="BID">34344</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/502366/100/0/threaded" source="BUGTRAQ">20090402 [TZO-05-2009] Clamav 0.94 and below - Evasion /bypass</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2009/04/07/6" source="MLIST">[oss-security] 20090407 Re: CVE request: clamav clamd and clamscan DoS and bypass by malformated archive</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:097" source="MANDRIVA">MDVSA-2009:097</ref>
      <ref url="http://support.apple.com/kb/HT3865" source="CONFIRM">http://support.apple.com/kb/HT3865</ref>
      <ref url="http://secunia.com/advisories/36701" source="SECUNIA">36701</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-04/msg00010.html" source="SUSE">SUSE-SR:2009:009</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2009/Sep/msg00004.html" source="APPLE">APPLE-SA-2009-09-10-2</ref>
      <ref url="http://blog.zoller.lu/2009/04/clamav-094-and-below-evasion-and-bypass.html" source="MISC">http://blog.zoller.lu/2009/04/clamav-094-and-below-evasion-and-bypass.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="clam_anti-virus" name="clamav">
        <vers num="0.01" />
        <vers num="0.02" />
        <vers num="0.03" />
        <vers num="0.04" />
        <vers num="0.05" />
        <vers num="0.06" />
        <vers num="0.10" />
        <vers num="0.11" />
        <vers num="0.12" />
        <vers num="0.13" />
        <vers num="0.14" edition="pre" />
        <vers num="0.15" />
        <vers num="0.20" />
        <vers num="0.21" />
        <vers num="0.22" />
        <vers num="0.23" />
        <vers num="0.24" />
        <vers num="0.51" />
        <vers num="0.52" />
        <vers num="0.53" />
        <vers num="0.54" />
        <vers num="0.60" />
        <vers num="0.60p" />
        <vers num="0.65" />
        <vers num="0.67" />
        <vers num="0.68" />
        <vers num="0.68.1" />
        <vers num="0.70" />
        <vers num="0.71" />
        <vers num="0.72" />
        <vers num="0.73" />
        <vers num="0.74" />
        <vers num="0.75" />
        <vers num="0.75.1" />
        <vers num="0.80" edition="rc" />
        <vers num="0.80" edition="rc2" />
        <vers num="0.80" edition="rc3" />
        <vers num="0.80" edition="rc4" />
        <vers num="0.80_rc1" />
        <vers num="0.80_rc2" />
        <vers num="0.80_rc3" />
        <vers num="0.80_rc4" />
        <vers num="0.81" edition="rc1" />
        <vers num="0.81_rc1" />
        <vers num="0.82" />
        <vers num="0.83" />
        <vers num="0.84" edition="rc1" />
        <vers num="0.84" edition="rc2" />
        <vers num="0.84_rc1" />
        <vers num="0.84_rc2" />
        <vers num="0.85" />
        <vers num="0.85.1" />
        <vers num="0.86" edition="rc1" />
        <vers num="0.86.1" />
        <vers num="0.86.2" />
        <vers num="0.86_rc1" />
        <vers num="0.87" />
        <vers num="0.87.1" />
        <vers num="0.88" />
        <vers num="0.88.1" />
        <vers num="0.88.2" />
        <vers num="0.88.3" />
        <vers num="0.88.4" />
        <vers num="0.88.5" />
        <vers num="0.88.6" />
        <vers num="0.88.7" edition="p0" />
        <vers num="0.88.7" edition="p1" />
        <vers num="0.90" />
        <vers num="0.90.1" edition="p0" />
        <vers num="0.90.2" edition="p0" />
        <vers num="0.90.3" edition="p0" />
        <vers num="0.90.3" edition="p1" />
        <vers num="0.90_rc1.1" />
        <vers num="0.90_rc2" />
        <vers num="0.90_rc3" />
        <vers num="0.90rc1" />
        <vers num="0.91" />
        <vers num="0.91.1" />
        <vers num="0.91.2" edition="p0" />
        <vers num="0.91rc1" />
        <vers num="0.91rc2" />
        <vers num="0.92" edition="p0" />
        <vers num="0.92.1" />
        <vers num="0.93" />
        <vers num="0.93.1" />
        <vers num="0.93.2" />
        <vers num="0.93.3" />
        <vers num="0.94" edition="rc1" />
        <vers num="0.94.1" />
      </prod>
      <prod vendor="clamav" name="clamav">
        <vers num="0.93.1" />
        <vers num="0.94" />
        <vers num="0.94.1" />
        <vers prev="1" num="0.94.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1242" published="2009-04-06" name="CVE-2009-1242" modified="2010-05-04" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="4.9" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="3.9" CVSS_base_score="4.9">
    <desc>
      <descript source="cve">The vmx_set_msr function in arch/x86/kvm/vmx.c in the VMX implementation in the KVM subsystem in the Linux kernel before 2.6.29.1 on the i386 platform allows guest OS users to cause a denial of service (OOPS) by setting the EFER_LME (aka "Long mode enable") bit in the Extended Feature Enable Register (EFER) model-specific register, which is specific to the x86_64 platform.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://patchwork.kernel.org/patch/15549/" source="CONFIRM" patch="1">http://patchwork.kernel.org/patch/15549/</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-May/msg01126.html" source="FEDORA">FEDORA-2009-5356</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=502109" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=502109</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/49594" source="XF">linux-kernel-eferlme-dos(49594)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0924" source="VUPEN">ADV-2009-0924</ref>
      <ref url="http://www.ubuntu.com/usn/usn-793-1" source="UBUNTU">USN-793-1</ref>
      <ref url="http://www.securityfocus.com/bid/34331" source="BID">34331</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/503610/100/0/threaded" source="BUGTRAQ">20090516 rPSA-2009-0084-1 kernel</ref>
      <ref url="http://www.kernel.org/pub/linux/kernel/v2.6/snapshots/patch-2.6.29-git1.log" source="CONFIRM">http://www.kernel.org/pub/linux/kernel/v2.6/snapshots/patch-2.6.29-git1.log</ref>
      <ref url="http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.29.1" source="CONFIRM">http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.29.1</ref>
      <ref url="http://www.globalsecuritymag.com/Vigil-nce-Linux-kernel-denial-of,20090402,8311" source="MISC">http://www.globalsecuritymag.com/Vigil-nce-Linux-kernel-denial-of,20090402,8311</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1800" source="DEBIAN">DSA-1800</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1787" source="DEBIAN">DSA-1787</ref>
      <ref url="http://wiki.rpath.com/Advisories:rPSA-2009-0084" source="CONFIRM">http://wiki.rpath.com/Advisories:rPSA-2009-0084</ref>
      <ref url="http://vigilance.fr/vulnerability/Linux-kernel-denial-of-service-via-EFER-8585" source="MISC">http://vigilance.fr/vulnerability/Linux-kernel-denial-of-service-via-EFER-8585</ref>
      <ref url="http://secunia.com/advisories/35656" source="SECUNIA">35656</ref>
      <ref url="http://secunia.com/advisories/35394" source="SECUNIA">35394</ref>
      <ref url="http://secunia.com/advisories/35387" source="SECUNIA">35387</ref>
      <ref url="http://secunia.com/advisories/35226" source="SECUNIA">35226</ref>
      <ref url="http://secunia.com/advisories/35121" source="SECUNIA">35121</ref>
      <ref url="http://secunia.com/advisories/35120" source="SECUNIA">35120</ref>
      <ref url="http://secunia.com/advisories/34981" source="SECUNIA">34981</ref>
      <ref url="http://secunia.com/advisories/34478" source="SECUNIA" adv="1">34478</ref>
      <ref url="http://openwall.com/lists/oss-security/2009/04/01/3" source="MLIST">[oss-security] 20090401 CVE request: kernel: KVM: VMX: Dont allow uninhibited access to EFER on i386</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-06/msg00002.html" source="SUSE">SUSE-SA:2009:032</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-06/msg00001.html" source="SUSE">SUSE-SA:2009:031</ref>
      <ref url="http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=16175a796d061833aacfbd9672235f2d2725df65" source="CONFIRM">http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=16175a796d061833aacfbd9672235f2d2725df65</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="kernel">
        <vers num="2.2.27" />
        <vers num="2.4.36" />
        <vers num="2.4.36.1" />
        <vers num="2.4.36.2" />
        <vers num="2.4.36.3" />
        <vers num="2.4.36.4" />
        <vers num="2.4.36.5" />
        <vers num="2.4.36.6" />
        <vers num="2.6" />
        <vers num="2.6.0" />
        <vers num="2.6.1" />
        <vers num="2.6.10" />
        <vers num="2.6.11" />
        <vers num="2.6.11.1" />
        <vers num="2.6.11.10" />
        <vers num="2.6.11.11" />
        <vers num="2.6.11.12" />
        <vers num="2.6.11.2" />
        <vers num="2.6.11.3" />
        <vers num="2.6.11.4" />
        <vers num="2.6.11.5" />
        <vers num="2.6.11.6" />
        <vers num="2.6.11.7" />
        <vers num="2.6.11.8" />
        <vers num="2.6.11.9" />
        <vers num="2.6.12" />
        <vers num="2.6.12.1" />
        <vers num="2.6.12.2" />
        <vers num="2.6.12.3" />
        <vers num="2.6.12.4" />
        <vers num="2.6.12.5" />
        <vers num="2.6.12.6" />
        <vers num="2.6.13" />
        <vers num="2.6.13.1" />
        <vers num="2.6.13.2" />
        <vers num="2.6.13.3" />
        <vers num="2.6.13.4" />
        <vers num="2.6.13.5" />
        <vers num="2.6.14" />
        <vers num="2.6.14.1" />
        <vers num="2.6.14.2" />
        <vers num="2.6.14.3" />
        <vers num="2.6.14.4" />
        <vers num="2.6.14.5" />
        <vers num="2.6.14.6" />
        <vers num="2.6.14.7" />
        <vers num="2.6.15" />
        <vers num="2.6.15.1" />
        <vers num="2.6.15.2" />
        <vers num="2.6.15.3" />
        <vers num="2.6.15.4" />
        <vers num="2.6.15.5" />
        <vers num="2.6.15.6" />
        <vers num="2.6.15.7" />
        <vers num="2.6.16" />
        <vers num="2.6.16.1" />
        <vers num="2.6.16.10" />
        <vers num="2.6.16.11" />
        <vers num="2.6.16.12" />
        <vers num="2.6.16.13" />
        <vers num="2.6.16.14" />
        <vers num="2.6.16.15" />
        <vers num="2.6.16.16" />
        <vers num="2.6.16.17" />
        <vers num="2.6.16.18" />
        <vers num="2.6.16.19" />
        <vers num="2.6.16.2" />
        <vers num="2.6.16.20" />
        <vers num="2.6.16.21" />
        <vers num="2.6.16.22" />
        <vers num="2.6.16.23" />
        <vers num="2.6.16.24" />
        <vers num="2.6.16.25" />
        <vers num="2.6.16.26" />
        <vers num="2.6.16.27" />
        <vers num="2.6.16.28" />
        <vers num="2.6.16.29" />
        <vers num="2.6.16.3" />
        <vers num="2.6.16.30" />
        <vers num="2.6.16.31" />
        <vers num="2.6.16.32" />
        <vers num="2.6.16.33" />
        <vers num="2.6.16.34" />
        <vers num="2.6.16.35" />
        <vers num="2.6.16.36" />
        <vers num="2.6.16.37" />
        <vers num="2.6.16.38" />
        <vers num="2.6.16.39" />
        <vers num="2.6.16.4" />
        <vers num="2.6.16.40" />
        <vers num="2.6.16.41" />
        <vers num="2.6.16.42" />
        <vers num="2.6.16.43" />
        <vers num="2.6.16.44" />
        <vers num="2.6.16.45" />
        <vers num="2.6.16.46" />
        <vers num="2.6.16.47" />
        <vers num="2.6.16.48" />
        <vers num="2.6.16.49" />
        <vers num="2.6.16.5" />
        <vers num="2.6.16.50" />
        <vers num="2.6.16.51" />
        <vers num="2.6.16.52" />
        <vers num="2.6.16.53" />
        <vers num="2.6.16.54" />
        <vers num="2.6.16.55" />
        <vers num="2.6.16.56" />
        <vers num="2.6.16.57" />
        <vers num="2.6.16.58" />
        <vers num="2.6.16.59" />
        <vers num="2.6.16.6" />
        <vers num="2.6.16.60" />
        <vers num="2.6.16.61" />
        <vers num="2.6.16.62" />
        <vers num="2.6.16.7" />
        <vers num="2.6.16.8" />
        <vers num="2.6.16.9" />
        <vers num="2.6.17" />
        <vers num="2.6.17.1" />
        <vers num="2.6.17.10" />
        <vers num="2.6.17.11" />
        <vers num="2.6.17.12" />
        <vers num="2.6.17.13" />
        <vers num="2.6.17.14" />
        <vers num="2.6.17.2" />
        <vers num="2.6.17.3" />
        <vers num="2.6.17.4" />
        <vers num="2.6.17.5" />
        <vers num="2.6.17.6" />
        <vers num="2.6.17.7" />
        <vers num="2.6.17.8" />
        <vers num="2.6.17.9" />
        <vers num="2.6.18" edition="rc1" />
        <vers num="2.6.18" edition="rc2" />
        <vers num="2.6.18" edition="rc3" />
        <vers num="2.6.18" edition="rc4" />
        <vers num="2.6.18" edition="rc5" />
        <vers num="2.6.18" edition="rc6" />
        <vers num="2.6.18" edition="rc7" />
        <vers num="2.6.18.1" />
        <vers num="2.6.18.2" />
        <vers num="2.6.18.3" />
        <vers num="2.6.18.4" />
        <vers num="2.6.18.5" />
        <vers num="2.6.18.6" />
        <vers num="2.6.18.7" />
        <vers num="2.6.18.8" />
        <vers num="2.6.19" />
        <vers num="2.6.19.1" />
        <vers num="2.6.19.2" />
        <vers num="2.6.19.3" />
        <vers num="2.6.19.4" />
        <vers num="2.6.19.5" />
        <vers num="2.6.19.6" />
        <vers num="2.6.19.7" />
        <vers num="2.6.2" />
        <vers num="2.6.2.27.13" />
        <vers num="2.6.20" />
        <vers num="2.6.20.1" />
        <vers num="2.6.20.10" />
        <vers num="2.6.20.11" />
        <vers num="2.6.20.12" />
        <vers num="2.6.20.13" />
        <vers num="2.6.20.14" />
        <vers num="2.6.20.15" />
        <vers num="2.6.20.16" />
        <vers num="2.6.20.17" />
        <vers num="2.6.20.18" />
        <vers num="2.6.20.19" />
        <vers num="2.6.20.2" />
        <vers num="2.6.20.20" />
        <vers num="2.6.20.21" />
        <vers num="2.6.20.3" />
        <vers num="2.6.20.4" />
        <vers num="2.6.20.5" />
        <vers num="2.6.20.6" />
        <vers num="2.6.20.7" />
        <vers num="2.6.20.8" />
        <vers num="2.6.20.9" />
        <vers num="2.6.21" />
        <vers num="2.6.21.1" />
        <vers num="2.6.21.2" />
        <vers num="2.6.21.3" />
        <vers num="2.6.21.4" />
        <vers num="2.6.21.5" />
        <vers num="2.6.21.6" />
        <vers num="2.6.21.7" />
        <vers num="2.6.22" />
        <vers num="2.6.22.1" />
        <vers num="2.6.22.10" />
        <vers num="2.6.22.11" />
        <vers num="2.6.22.12" />
        <vers num="2.6.22.13" />
        <vers num="2.6.22.14" />
        <vers num="2.6.22.15" />
        <vers num="2.6.22.16" />
        <vers num="2.6.22.17" />
        <vers num="2.6.22.18" />
        <vers num="2.6.22.19" />
        <vers num="2.6.22.2" />
        <vers num="2.6.22.20" />
        <vers num="2.6.22.21" />
        <vers num="2.6.22.22" />
        <vers num="2.6.22.3" />
        <vers num="2.6.22.4" />
        <vers num="2.6.22.5" />
        <vers num="2.6.22.6" />
        <vers num="2.6.22.7" />
        <vers num="2.6.22.8" />
        <vers num="2.6.22.9" />
        <vers num="2.6.22_rc1" />
        <vers num="2.6.22_rc7" />
        <vers num="2.6.23" edition="rc1" />
        <vers num="2.6.23" edition="rc2" />
        <vers num="2.6.23.1" />
        <vers num="2.6.23.10" />
        <vers num="2.6.23.11" />
        <vers num="2.6.23.12" />
        <vers num="2.6.23.13" />
        <vers num="2.6.23.14" />
        <vers num="2.6.23.15" />
        <vers num="2.6.23.16" />
        <vers num="2.6.23.17" />
        <vers num="2.6.23.2" />
        <vers num="2.6.23.3" />
        <vers num="2.6.23.4" />
        <vers num="2.6.23.5" />
        <vers num="2.6.23.6" />
        <vers num="2.6.23.7" />
        <vers num="2.6.23.8" />
        <vers num="2.6.23.9" />
        <vers num="2.6.23_rc1" />
        <vers num="2.6.24" edition="rc1" />
        <vers num="2.6.24" edition="rc2" />
        <vers num="2.6.24" edition="rc3" />
        <vers num="2.6.24" edition="rc4" />
        <vers num="2.6.24" edition="rc5" />
        <vers num="2.6.24.1" />
        <vers num="2.6.24.2" />
        <vers num="2.6.24.3" />
        <vers num="2.6.24.4" />
        <vers num="2.6.24.5" />
        <vers num="2.6.24.6" />
        <vers num="2.6.24.7" />
        <vers num="2.6.24_rc1" />
        <vers num="2.6.24_rc4" />
        <vers num="2.6.24_rc5" />
        <vers num="2.6.25" edition="" />
        <vers num="2.6.25" edition=":x86_64" />
        <vers num="2.6.25.1" edition="" />
        <vers num="2.6.25.1" edition=":x86_64" />
        <vers num="2.6.25.10" edition="" />
        <vers num="2.6.25.10" edition=":x86_64" />
        <vers num="2.6.25.11" edition="" />
        <vers num="2.6.25.11" edition=":x86_64" />
        <vers num="2.6.25.12" edition="" />
        <vers num="2.6.25.12" edition=":x86_64" />
        <vers num="2.6.25.13" />
        <vers num="2.6.25.14" />
        <vers num="2.6.25.15" />
        <vers num="2.6.25.16" />
        <vers num="2.6.25.17" />
        <vers num="2.6.25.18" />
        <vers num="2.6.25.19" />
        <vers num="2.6.25.2" edition="" />
        <vers num="2.6.25.2" edition=":x86_64" />
        <vers num="2.6.25.20" />
        <vers num="2.6.25.3" edition="" />
        <vers num="2.6.25.3" edition=":x86_64" />
        <vers num="2.6.25.4" edition="" />
        <vers num="2.6.25.4" edition=":x86_64" />
        <vers num="2.6.25.5" edition="" />
        <vers num="2.6.25.5" edition=":x86_64" />
        <vers num="2.6.25.6" edition="" />
        <vers num="2.6.25.6" edition=":x86_64" />
        <vers num="2.6.25.7" edition="" />
        <vers num="2.6.25.7" edition=":x86_64" />
        <vers num="2.6.25.8" edition="" />
        <vers num="2.6.25.8" edition=":x86_64" />
        <vers num="2.6.25.9" edition="" />
        <vers num="2.6.25.9" edition=":x86_64" />
        <vers num="2.6.26" edition="rc4" />
        <vers num="2.6.26.1" />
        <vers num="2.6.26.2" />
        <vers num="2.6.26.3" />
        <vers num="2.6.26.4" />
        <vers num="2.6.26.5" />
        <vers num="2.6.26.6" />
        <vers num="2.6.26.7" />
        <vers num="2.6.26.8" />
        <vers num="2.6.27" edition="rc1" />
        <vers num="2.6.27" edition="rc2" />
        <vers num="2.6.27" edition="rc3" />
        <vers num="2.6.27" edition="rc4" />
        <vers num="2.6.27" edition="rc5" />
        <vers num="2.6.27" edition="rc6" />
        <vers num="2.6.27" edition="rc7" />
        <vers num="2.6.27" edition="rc8" />
        <vers num="2.6.27" edition="rc9" />
        <vers num="2.6.27.1" />
        <vers num="2.6.27.10" />
        <vers num="2.6.27.11" />
        <vers num="2.6.27.12" />
        <vers num="2.6.27.13" />
        <vers num="2.6.27.14" />
        <vers num="2.6.27.15" />
        <vers num="2.6.27.16" />
        <vers num="2.6.27.17" />
        <vers num="2.6.27.18" />
        <vers num="2.6.27.19" />
        <vers num="2.6.27.2" />
        <vers num="2.6.27.20" />
        <vers num="2.6.27.3" />
        <vers num="2.6.27.4" />
        <vers num="2.6.27.5" />
        <vers num="2.6.27.6" />
        <vers num="2.6.27.7" />
        <vers num="2.6.27.8" />
        <vers num="2.6.27.9" />
        <vers num="2.6.28" edition="git7" />
        <vers num="2.6.28" edition="rc1" />
        <vers num="2.6.28" edition="rc2" />
        <vers num="2.6.28" edition="rc3" />
        <vers num="2.6.28" edition="rc4" />
        <vers num="2.6.28" edition="rc5" />
        <vers num="2.6.28" edition="rc6" />
        <vers num="2.6.28" edition="rc7" />
        <vers num="2.6.28.1" />
        <vers num="2.6.28.2" />
        <vers num="2.6.28.3" />
        <vers num="2.6.28.4" />
        <vers num="2.6.28.5" />
        <vers num="2.6.28.6" />
        <vers num="2.6.28.7" />
        <vers num="2.6.28.8" />
        <vers num="2.6.28.9" />
        <vers prev="1" num="2.6.29" edition="git1" />
        <vers prev="1" num="2.6.29" edition="rc1" />
        <vers prev="1" num="2.6.29" edition="rc2" />
        <vers prev="1" num="2.6.29" edition="rc2_git7" />
        <vers num="2.6.3" />
        <vers num="2.6.4" />
        <vers num="2.6.5" />
        <vers num="2.6.6" />
        <vers num="2.6.7" />
        <vers num="2.6.8" />
        <vers num="2.6.8.1" />
        <vers num="2.6.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1243" published="2009-04-06" name="CVE-2009-1243" modified="2009-04-16" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="4.9" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="3.9" CVSS_base_score="4.9">
    <desc>
      <descript source="cve">net/ipv4/udp.c in the Linux kernel before 2.6.29.1 performs an unlocking step in certain incorrect circumstances, which allows local users to cause a denial of service (panic) by reading zero bytes from the /proc/net/udp file and unspecified other files, related to the "udp seq_file infrastructure."</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/34329" source="BID" patch="1">34329</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/49595" source="XF">linux-kernel-procnetudp-dos(49595)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0924" source="VUPEN">ADV-2009-0924</ref>
      <ref url="http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.29.1" source="CONFIRM" adv="1">http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.29.1</ref>
      <ref url="http://vigilance.fr/vulnerability/Linux-kernel-denial-of-service-via-proc-net-udp-8586" source="MISC">http://vigilance.fr/vulnerability/Linux-kernel-denial-of-service-via-proc-net-udp-8586</ref>
      <ref url="http://secunia.com/advisories/34478" source="SECUNIA" adv="1">34478</ref>
      <ref url="http://openwall.com/lists/oss-security/2009/04/01/4" source="MLIST">[oss-security] 20090401 CVE request: kernel: udp: Wrong locking code in udp seq_file infrastructure</ref>
      <ref url="http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=30842f2989aacfaba3ccb39829b3417be9313dbe" source="CONFIRM" adv="1">http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=30842f2989aacfaba3ccb39829b3417be9313dbe</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="kernel">
        <vers num="2.2.27" />
        <vers num="2.4.36" />
        <vers num="2.4.36.1" />
        <vers num="2.4.36.2" />
        <vers num="2.4.36.3" />
        <vers num="2.4.36.4" />
        <vers num="2.4.36.5" />
        <vers num="2.4.36.6" />
        <vers num="2.6" />
        <vers num="2.6.0" />
        <vers num="2.6.1" />
        <vers num="2.6.10" />
        <vers num="2.6.11" />
        <vers num="2.6.11.1" />
        <vers num="2.6.11.10" />
        <vers num="2.6.11.11" />
        <vers num="2.6.11.12" />
        <vers num="2.6.11.2" />
        <vers num="2.6.11.3" />
        <vers num="2.6.11.4" />
        <vers num="2.6.11.5" />
        <vers num="2.6.11.6" />
        <vers num="2.6.11.7" />
        <vers num="2.6.11.8" />
        <vers num="2.6.11.9" />
        <vers num="2.6.12" />
        <vers num="2.6.12.1" />
        <vers num="2.6.12.2" />
        <vers num="2.6.12.3" />
        <vers num="2.6.12.4" />
        <vers num="2.6.12.5" />
        <vers num="2.6.12.6" />
        <vers num="2.6.13" />
        <vers num="2.6.13.1" />
        <vers num="2.6.13.2" />
        <vers num="2.6.13.3" />
        <vers num="2.6.13.4" />
        <vers num="2.6.13.5" />
        <vers num="2.6.14" />
        <vers num="2.6.14.1" />
        <vers num="2.6.14.2" />
        <vers num="2.6.14.3" />
        <vers num="2.6.14.4" />
        <vers num="2.6.14.5" />
        <vers num="2.6.14.6" />
        <vers num="2.6.14.7" />
        <vers num="2.6.15" />
        <vers num="2.6.15.1" />
        <vers num="2.6.15.2" />
        <vers num="2.6.15.3" />
        <vers num="2.6.15.4" />
        <vers num="2.6.15.5" />
        <vers num="2.6.15.6" />
        <vers num="2.6.15.7" />
        <vers num="2.6.16" />
        <vers num="2.6.16.1" />
        <vers num="2.6.16.10" />
        <vers num="2.6.16.11" />
        <vers num="2.6.16.12" />
        <vers num="2.6.16.13" />
        <vers num="2.6.16.14" />
        <vers num="2.6.16.15" />
        <vers num="2.6.16.16" />
        <vers num="2.6.16.17" />
        <vers num="2.6.16.18" />
        <vers num="2.6.16.19" />
        <vers num="2.6.16.2" />
        <vers num="2.6.16.20" />
        <vers num="2.6.16.21" />
        <vers num="2.6.16.22" />
        <vers num="2.6.16.23" />
        <vers num="2.6.16.24" />
        <vers num="2.6.16.25" />
        <vers num="2.6.16.26" />
        <vers num="2.6.16.27" />
        <vers num="2.6.16.28" />
        <vers num="2.6.16.29" />
        <vers num="2.6.16.3" />
        <vers num="2.6.16.30" />
        <vers num="2.6.16.31" />
        <vers num="2.6.16.32" />
        <vers num="2.6.16.33" />
        <vers num="2.6.16.34" />
        <vers num="2.6.16.35" />
        <vers num="2.6.16.36" />
        <vers num="2.6.16.37" />
        <vers num="2.6.16.38" />
        <vers num="2.6.16.39" />
        <vers num="2.6.16.4" />
        <vers num="2.6.16.40" />
        <vers num="2.6.16.41" />
        <vers num="2.6.16.42" />
        <vers num="2.6.16.43" />
        <vers num="2.6.16.44" />
        <vers num="2.6.16.45" />
        <vers num="2.6.16.46" />
        <vers num="2.6.16.47" />
        <vers num="2.6.16.48" />
        <vers num="2.6.16.49" />
        <vers num="2.6.16.5" />
        <vers num="2.6.16.50" />
        <vers num="2.6.16.51" />
        <vers num="2.6.16.52" />
        <vers num="2.6.16.53" />
        <vers num="2.6.16.54" />
        <vers num="2.6.16.55" />
        <vers num="2.6.16.56" />
        <vers num="2.6.16.57" />
        <vers num="2.6.16.58" />
        <vers num="2.6.16.59" />
        <vers num="2.6.16.6" />
        <vers num="2.6.16.60" />
        <vers num="2.6.16.61" />
        <vers num="2.6.16.62" />
        <vers num="2.6.16.7" />
        <vers num="2.6.16.8" />
        <vers num="2.6.16.9" />
        <vers num="2.6.17" />
        <vers num="2.6.17.1" />
        <vers num="2.6.17.10" />
        <vers num="2.6.17.11" />
        <vers num="2.6.17.12" />
        <vers num="2.6.17.13" />
        <vers num="2.6.17.14" />
        <vers num="2.6.17.2" />
        <vers num="2.6.17.3" />
        <vers num="2.6.17.4" />
        <vers num="2.6.17.5" />
        <vers num="2.6.17.6" />
        <vers num="2.6.17.7" />
        <vers num="2.6.17.8" />
        <vers num="2.6.17.9" />
        <vers num="2.6.18" edition="rc1" />
        <vers num="2.6.18" edition="rc2" />
        <vers num="2.6.18" edition="rc3" />
        <vers num="2.6.18" edition="rc4" />
        <vers num="2.6.18" edition="rc5" />
        <vers num="2.6.18" edition="rc6" />
        <vers num="2.6.18" edition="rc7" />
        <vers num="2.6.18.1" />
        <vers num="2.6.18.2" />
        <vers num="2.6.18.3" />
        <vers num="2.6.18.4" />
        <vers num="2.6.18.5" />
        <vers num="2.6.18.6" />
        <vers num="2.6.18.7" />
        <vers num="2.6.18.8" />
        <vers num="2.6.19" />
        <vers num="2.6.19.1" />
        <vers num="2.6.19.2" />
        <vers num="2.6.19.3" />
        <vers num="2.6.19.4" />
        <vers num="2.6.19.5" />
        <vers num="2.6.19.6" />
        <vers num="2.6.19.7" />
        <vers num="2.6.2" />
        <vers num="2.6.2.27.13" />
        <vers num="2.6.20" />
        <vers num="2.6.20.1" />
        <vers num="2.6.20.10" />
        <vers num="2.6.20.11" />
        <vers num="2.6.20.12" />
        <vers num="2.6.20.13" />
        <vers num="2.6.20.14" />
        <vers num="2.6.20.15" />
        <vers num="2.6.20.16" />
        <vers num="2.6.20.17" />
        <vers num="2.6.20.18" />
        <vers num="2.6.20.19" />
        <vers num="2.6.20.2" />
        <vers num="2.6.20.20" />
        <vers num="2.6.20.21" />
        <vers num="2.6.20.3" />
        <vers num="2.6.20.4" />
        <vers num="2.6.20.5" />
        <vers num="2.6.20.6" />
        <vers num="2.6.20.7" />
        <vers num="2.6.20.8" />
        <vers num="2.6.20.9" />
        <vers num="2.6.21" />
        <vers num="2.6.21.1" />
        <vers num="2.6.21.2" />
        <vers num="2.6.21.3" />
        <vers num="2.6.21.4" />
        <vers num="2.6.21.5" />
        <vers num="2.6.21.6" />
        <vers num="2.6.21.7" />
        <vers num="2.6.22" />
        <vers num="2.6.22.1" />
        <vers num="2.6.22.10" />
        <vers num="2.6.22.11" />
        <vers num="2.6.22.12" />
        <vers num="2.6.22.13" />
        <vers num="2.6.22.14" />
        <vers num="2.6.22.15" />
        <vers num="2.6.22.16" />
        <vers num="2.6.22.17" />
        <vers num="2.6.22.18" />
        <vers num="2.6.22.19" />
        <vers num="2.6.22.2" />
        <vers num="2.6.22.20" />
        <vers num="2.6.22.21" />
        <vers num="2.6.22.22" />
        <vers num="2.6.22.3" />
        <vers num="2.6.22.4" />
        <vers num="2.6.22.5" />
        <vers num="2.6.22.6" />
        <vers num="2.6.22.7" />
        <vers num="2.6.22.8" />
        <vers num="2.6.22.9" />
        <vers num="2.6.22_rc1" />
        <vers num="2.6.22_rc7" />
        <vers num="2.6.23" edition="rc1" />
        <vers num="2.6.23" edition="rc2" />
        <vers num="2.6.23.1" />
        <vers num="2.6.23.10" />
        <vers num="2.6.23.11" />
        <vers num="2.6.23.12" />
        <vers num="2.6.23.13" />
        <vers num="2.6.23.14" />
        <vers num="2.6.23.15" />
        <vers num="2.6.23.16" />
        <vers num="2.6.23.17" />
        <vers num="2.6.23.2" />
        <vers num="2.6.23.3" />
        <vers num="2.6.23.4" />
        <vers num="2.6.23.5" />
        <vers num="2.6.23.6" />
        <vers num="2.6.23.7" />
        <vers num="2.6.23.8" />
        <vers num="2.6.23.9" />
        <vers num="2.6.23_rc1" />
        <vers num="2.6.24" edition="rc1" />
        <vers num="2.6.24" edition="rc2" />
        <vers num="2.6.24" edition="rc3" />
        <vers num="2.6.24" edition="rc4" />
        <vers num="2.6.24" edition="rc5" />
        <vers num="2.6.24.1" />
        <vers num="2.6.24.2" />
        <vers num="2.6.24.3" />
        <vers num="2.6.24.4" />
        <vers num="2.6.24.5" />
        <vers num="2.6.24.6" />
        <vers num="2.6.24.7" />
        <vers num="2.6.24_rc1" />
        <vers num="2.6.24_rc4" />
        <vers num="2.6.24_rc5" />
        <vers num="2.6.25" edition="" />
        <vers num="2.6.25" edition=":x86_64" />
        <vers num="2.6.25.1" edition="" />
        <vers num="2.6.25.1" edition=":x86_64" />
        <vers num="2.6.25.10" edition="" />
        <vers num="2.6.25.10" edition=":x86_64" />
        <vers num="2.6.25.11" edition="" />
        <vers num="2.6.25.11" edition=":x86_64" />
        <vers num="2.6.25.12" edition="" />
        <vers num="2.6.25.12" edition=":x86_64" />
        <vers num="2.6.25.13" />
        <vers num="2.6.25.14" />
        <vers num="2.6.25.15" />
        <vers num="2.6.25.16" />
        <vers num="2.6.25.17" />
        <vers num="2.6.25.18" />
        <vers num="2.6.25.19" />
        <vers num="2.6.25.2" edition="" />
        <vers num="2.6.25.2" edition=":x86_64" />
        <vers num="2.6.25.20" />
        <vers num="2.6.25.3" edition="" />
        <vers num="2.6.25.3" edition=":x86_64" />
        <vers num="2.6.25.4" edition="" />
        <vers num="2.6.25.4" edition=":x86_64" />
        <vers num="2.6.25.5" edition="" />
        <vers num="2.6.25.5" edition=":x86_64" />
        <vers num="2.6.25.6" edition="" />
        <vers num="2.6.25.6" edition=":x86_64" />
        <vers num="2.6.25.7" edition="" />
        <vers num="2.6.25.7" edition=":x86_64" />
        <vers num="2.6.25.8" edition="" />
        <vers num="2.6.25.8" edition=":x86_64" />
        <vers num="2.6.25.9" edition="" />
        <vers num="2.6.25.9" edition=":x86_64" />
        <vers num="2.6.26" edition="rc4" />
        <vers num="2.6.26.1" />
        <vers num="2.6.26.2" />
        <vers num="2.6.26.3" />
        <vers num="2.6.26.4" />
        <vers num="2.6.26.5" />
        <vers num="2.6.26.6" />
        <vers num="2.6.26.7" />
        <vers num="2.6.26.8" />
        <vers num="2.6.27" edition="rc1" />
        <vers num="2.6.27" edition="rc2" />
        <vers num="2.6.27" edition="rc3" />
        <vers num="2.6.27" edition="rc4" />
        <vers num="2.6.27" edition="rc5" />
        <vers num="2.6.27" edition="rc6" />
        <vers num="2.6.27" edition="rc7" />
        <vers num="2.6.27" edition="rc8" />
        <vers num="2.6.27" edition="rc9" />
        <vers num="2.6.27.1" />
        <vers num="2.6.27.10" />
        <vers num="2.6.27.11" />
        <vers num="2.6.27.12" />
        <vers num="2.6.27.13" />
        <vers num="2.6.27.14" />
        <vers num="2.6.27.15" />
        <vers num="2.6.27.16" />
        <vers num="2.6.27.17" />
        <vers num="2.6.27.18" />
        <vers num="2.6.27.19" />
        <vers num="2.6.27.2" />
        <vers num="2.6.27.20" />
        <vers num="2.6.27.3" />
        <vers num="2.6.27.4" />
        <vers num="2.6.27.5" />
        <vers num="2.6.27.6" />
        <vers num="2.6.27.7" />
        <vers num="2.6.27.8" />
        <vers num="2.6.27.9" />
        <vers num="2.6.28" edition="git7" />
        <vers num="2.6.28" edition="rc1" />
        <vers num="2.6.28" edition="rc2" />
        <vers num="2.6.28" edition="rc3" />
        <vers num="2.6.28" edition="rc4" />
        <vers num="2.6.28" edition="rc5" />
        <vers num="2.6.28" edition="rc6" />
        <vers num="2.6.28" edition="rc7" />
        <vers num="2.6.28.1" />
        <vers num="2.6.28.2" />
        <vers num="2.6.28.3" />
        <vers num="2.6.28.4" />
        <vers num="2.6.28.5" />
        <vers num="2.6.28.6" />
        <vers num="2.6.28.7" />
        <vers num="2.6.28.8" />
        <vers num="2.6.28.9" />
        <vers prev="1" num="2.6.29" edition="git1" />
        <vers prev="1" num="2.6.29" edition="rc1" />
        <vers prev="1" num="2.6.29" edition="rc2" />
        <vers prev="1" num="2.6.29" edition="rc2_git7" />
        <vers num="2.6.3" />
        <vers num="2.6.4" />
        <vers num="2.6.5" />
        <vers num="2.6.6" />
        <vers num="2.6.7" />
        <vers num="2.6.8" />
        <vers num="2.6.8.1" />
        <vers num="2.6.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1244" published="2009-04-13" name="CVE-2009-1244" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:S/C:C/I:C/A:C)" CVSS_score="6.8" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.1" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Unspecified vulnerability in the virtual machine display function in VMware Workstation 6.5.1 and earlier; VMware Player 2.5.1 and earlier; VMware ACE 2.5.1 and earlier; VMware Server 1.x before 1.0.9 build 156507 and 2.x before 2.0.1 build 156745; VMware Fusion before 2.0.4 build 159196; VMware ESXi 3.5; and VMware ESX 3.0.2, 3.0.3, and 3.5 allows guest OS users to execute arbitrary code on the host OS via unknown vectors, a different vulnerability than CVE-2008-4916.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/34471" source="BID" patch="1">34471</ref>
      <ref url="http://lists.vmware.com/pipermail/security-announce/2009/000055.html" source="MLIST" patch="1" adv="1">[security-announce] 20090410 VMSA-2009-0006 VMware Hosted products and patches for ESX and ESXi resolve a critical security vulnerability</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/49834" source="XF">vmware-virtualmachine-code-execution(49834)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0944" source="VUPEN">ADV-2009-0944</ref>
      <ref url="http://www.vmware.com/security/advisories/VMSA-2009-0006.html" source="CONFIRM">http://www.vmware.com/security/advisories/VMSA-2009-0006.html</ref>
      <ref url="http://www.securitytracker.com/id?1022031" source="SECTRACK">1022031</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/502615/100/0/threaded" source="BUGTRAQ">20090410 VMSA-2009-0006 VMware Hosted products and patches for ESX and ESXi resolve a critical security vulnerability</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6065" source="OVAL">oval:org.mitre.oval:def:6065</ref>
      <ref url="http://osvdb.org/53634" source="OSVDB">53634</ref>
    </refs>
    <vuln_soft>
      <prod vendor="vmware" name="ace">
        <vers num="1.0" />
        <vers num="1.0.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.5" />
        <vers num="1.0.6" />
        <vers num="1.0.7" />
        <vers num="2.0" />
        <vers num="2.0.1" />
        <vers num="2.0.2" />
        <vers num="2.0.3" />
        <vers num="2.0.4" />
        <vers num="2.0.5" />
        <vers num="2.5.0" />
        <vers prev="1" num="2.5.1" />
      </prod>
      <prod vendor="vmware" name="esx">
        <vers num="3.0.2" />
        <vers num="3.0.3" />
        <vers num="3.5" />
      </prod>
      <prod vendor="vmware" name="esxi">
        <vers num="3.5" />
      </prod>
      <prod vendor="vmware" name="fusion">
        <vers num="1.0" />
        <vers num="1.1" />
        <vers num="1.1.1" />
        <vers num="1.1.2" />
        <vers num="1.1.3" />
        <vers num="2.0" />
        <vers num="2.0.1" />
        <vers num="2.0.2" />
        <vers prev="1" num="2.0.3" />
      </prod>
      <prod vendor="vmware" name="player">
        <vers num="1.0" />
        <vers num="1.0.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.5" />
        <vers num="1.0.6" />
        <vers num="1.0.7" />
        <vers num="1.0.8" />
        <vers num="2.0" />
        <vers num="2.0.1" />
        <vers num="2.0.2" />
        <vers num="2.0.3" />
        <vers num="2.0.4" />
        <vers num="2.0.5" />
        <vers num="2.5" />
        <vers prev="1" num="2.5.1" />
      </prod>
      <prod vendor="vmware" name="server">
        <vers num="1.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.5" />
        <vers num="1.0.6" />
        <vers num="1.0.7" />
        <vers num="1.0.8" />
        <vers num="1.0.9" />
        <vers num="2.0" />
      </prod>
      <prod vendor="vmware" name="workstation">
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.4" />
        <vers num="1.0.5" />
        <vers num="1.1" />
        <vers num="1.1.1" />
        <vers num="1.1.2" />
        <vers num="2.0" />
        <vers num="2.0.1" />
        <vers num="3.2.1" edition="patch1" />
        <vers num="3.4" />
        <vers num="4.0" />
        <vers num="4.0.1" />
        <vers num="4.0.2" />
        <vers num="4.5.2" />
        <vers num="5" />
        <vers num="5.0.0" />
        <vers num="5.5" />
        <vers num="5.5.0" />
        <vers num="5.5.1" />
        <vers num="5.5.2" />
        <vers num="5.5.3" />
        <vers num="5.5.4" />
        <vers num="5.5.5" />
        <vers num="5.5.6" />
        <vers num="5.5.7" />
        <vers num="5.5.8" />
        <vers num="6.0" />
        <vers num="6.0.1" />
        <vers num="6.0.2" />
        <vers num="6.0.3" />
        <vers num="6.0.4" />
        <vers num="6.0.5" />
        <vers num="6.5" />
        <vers prev="1" num="6.5.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1245" published="2009-04-06" name="CVE-2009-1245" modified="2009-04-06" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in the insert_to_pastebin function in php/cccp-admin/inc/functions.php in CCCP Community Clan Portal Pastebin before 2.80 allow remote attackers to execute arbitrary SQL commands via the (1) subject, (2) language, and (3) nickname parameters to php/cccp-pages/submit.php.  NOTE: some of these details are obtained from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://jcsfog.cvs.sourceforge.net/viewvc/jcsfog/CCCP-Pastebin/php/cccp-admin/inc/functions.php?r1=1.10&amp;r2=1.11" source="CONFIRM" patch="1">http://jcsfog.cvs.sourceforge.net/viewvc/jcsfog/CCCP-Pastebin/php/cccp-admin/inc/functions.php?r1=1.10&amp;r2=1.11</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/49426" source="XF">communitycode-submit-sql-injection(49426)</ref>
      <ref url="http://www.securityfocus.com/bid/34264" source="BID">34264</ref>
      <ref url="http://sourceforge.net/project/shownotes.php?release_id=670960" source="CONFIRM">http://sourceforge.net/project/shownotes.php?release_id=670960</ref>
      <ref url="http://secunia.com/advisories/34474" source="SECUNIA" adv="1">34474</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cccp-common-clan-portal-pasterbin" name="cccp_pastebin">
        <vers num="2.10" />
        <vers num="2.20" />
        <vers num="2.30" />
        <vers num="2.40" />
        <vers num="2.50" />
        <vers num="2.60" />
        <vers prev="1" num="2.70" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1246" published="2009-04-06" name="CVE-2009-1246" modified="2009-04-06" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple directory traversal vulnerabilities in Blogplus 1.0 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the (1) row_mysql_blocks_center_down[file] parameter to includes/block_center_down.php; (2) row_mysql_blocks_center_top[file] includes/parameter to block_center_top.php; (3) row_mysql_blocks_left[file] parameter to includes/block_left.php; (4) row_mysql_blocks_right[file] parameter to includes/block_right.php; and row_mysql_bloginfo[theme] parameter to (5) includes/window_down.php and (6) includes/window_top.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/49446" source="XF">blogplus-file-theme-file-include(49446)</ref>
      <ref url="http://www.securityfocus.com/bid/34261" source="BID">34261</ref>
      <ref url="http://www.milw0rm.com/exploits/8290" source="MILW0RM">8290</ref>
    </refs>
    <vuln_soft>
      <prod vendor="blogplus" name="blogplus">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1247" published="2009-04-06" name="CVE-2009-1247" modified="2009-04-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in login.php in Acute Control Panel 1.0.0 allows remote attackers to execute arbitrary SQL commands via the username parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/49444" source="XF">acutecontrol-login-sql-injection(49444)</ref>
      <ref url="http://www.securityfocus.com/bid/34265" source="BID">34265</ref>
      <ref url="http://www.milw0rm.com/exploits/8291" source="MILW0RM">8291</ref>
      <ref url="http://secunia.com/advisories/34485" source="SECUNIA" adv="1">34485</ref>
    </refs>
    <vuln_soft>
      <prod vendor="acutecp.rediscussed" name="acutecp">
        <vers num="1.0.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1248" published="2009-04-06" name="CVE-2009-1248" modified="2009-04-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple PHP remote file inclusion vulnerabilities in Acute Control Panel 1.0.0 allow remote attackers to execute arbitrary PHP code via a URL in the theme_directory parameter to (1) container.php and (2) header.php in themes/.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/49443" source="XF">acutecontrol-themedirectory-file-include(49443)</ref>
      <ref url="http://www.securityfocus.com/bid/34265" source="BID">34265</ref>
      <ref url="http://www.milw0rm.com/exploits/8291" source="MILW0RM">8291</ref>
      <ref url="http://secunia.com/advisories/34485" source="SECUNIA" adv="1">34485</ref>
    </refs>
    <vuln_soft>
      <prod vendor="acutecp" name="acute_control_panel">
        <vers num="1.0.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1249" published="2009-04-06" name="CVE-2009-1249" modified="2009-04-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Feed element mapper 5.x before 5.x-1.1, a module for Drupal, allows remote attackers to inject arbitrary web script or HTML via the content title in admin/content/node-type/nodetype/map.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://drupal.org/node/414702" source="CONFIRM" patch="1" adv="1">http://drupal.org/node/414702</ref>
      <ref url="http://drupal.org/node/414644" source="CONFIRM" patch="1">http://drupal.org/node/414644</ref>
      <ref url="http://www.securityfocus.com/bid/34266" source="BID">34266</ref>
      <ref url="http://secunia.com/advisories/34497" source="SECUNIA" adv="1">34497</ref>
    </refs>
    <vuln_soft>
      <prod vendor="drupal" name="feedapi_mapper">
        <vers num="5.x-1.0" edition="beta1" />
        <vers num="5.x-1.0" edition="beta2" />
        <vers num="5.x-1.0" edition="beta3" />
        <vers num="5.x-1.0" edition="beta4" />
        <vers num="5.x-1.0" edition="beta5" />
        <vers num="5.x-1.0" edition="beta6" />
        <vers num="5.x-1.0" edition="beta7" />
        <vers num="5.x-1.x" edition="dev" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1250" published="2009-04-08" name="CVE-2009-1250" modified="2011-01-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">The cache manager in the client in OpenAFS 1.0 through 1.4.8 and 1.5.0 through 1.5.58, and IBM AFS 3.6 before Patch 19, on Linux allows remote attackers to cause a denial of service (system crash) via an RX response with a large error-code value that is interpreted as a pointer and dereferenced, related to use of the ERR_PTR macro.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2011/0117" source="VUPEN">ADV-2011-0117</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0984" source="VUPEN">ADV-2009-0984</ref>
      <ref url="http://www.securityfocus.com/bid/34404" source="BID">34404</ref>
      <ref url="http://www.openafs.org/security/OPENAFS-SA-2009-002.txt" source="CONFIRM">http://www.openafs.org/security/OPENAFS-SA-2009-002.txt</ref>
      <ref url="http://www.openafs.org/security/openafs-sa-2009-002.patch" source="CONFIRM">http://www.openafs.org/security/openafs-sa-2009-002.patch</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:099" source="MANDRIVA">MDVSA-2009:099</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1768" source="DEBIAN">DSA-1768</ref>
      <ref url="http://www-1.ibm.com/support/docview.wss?uid=swg1ID71123" source="AIXAPAR">ID71123</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg21396389" source="CONFIRM">http://www-01.ibm.com/support/docview.wss?uid=swg21396389</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-201101-05.xml" source="GENTOO">GLSA-201101-05</ref>
      <ref url="http://secunia.com/advisories/42896" source="SECUNIA">42896</ref>
      <ref url="http://secunia.com/advisories/36310" source="SECUNIA">36310</ref>
      <ref url="http://secunia.com/advisories/34684" source="SECUNIA">34684</ref>
      <ref url="http://secunia.com/advisories/34655" source="SECUNIA">34655</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="afs">
        <vers prev="1" num="3.6" edition="patch12" />
        <vers prev="1" num="3.6" edition="patch13" />
        <vers prev="1" num="3.6" edition="patch14" />
        <vers prev="1" num="3.6" edition="patch15" />
        <vers prev="1" num="3.6" edition="patch16" />
        <vers prev="1" num="3.6" edition="patch18" />
      </prod>
      <prod vendor="openafs" name="openafs">
        <vers num="1.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.4a" />
        <vers num="1.1" />
        <vers num="1.1.0" />
        <vers num="1.1.1" />
        <vers num="1.1.1a" />
        <vers num="1.2" />
        <vers num="1.2.1" />
        <vers num="1.2.10" />
        <vers num="1.2.11" />
        <vers num="1.2.13" />
        <vers num="1.2.2" />
        <vers num="1.2.2a" />
        <vers num="1.2.2b" />
        <vers num="1.2.3" />
        <vers num="1.2.4" />
        <vers num="1.2.5" />
        <vers num="1.2.6" />
        <vers num="1.2.7" />
        <vers num="1.2.8" />
        <vers num="1.2.9" />
        <vers num="1.3" />
        <vers num="1.3.1" />
        <vers num="1.3.2" />
        <vers num="1.3.5" />
        <vers num="1.3.70" />
        <vers num="1.3.74" />
        <vers num="1.3.77" />
        <vers num="1.3.81" />
        <vers num="1.4" />
        <vers num="1.4.0" />
        <vers num="1.4.3" />
        <vers num="1.4.4" />
        <vers num="1.4.5" />
        <vers num="1.4.6" />
        <vers num="1.4.7" />
        <vers num="1.4.7_pre1" />
        <vers num="1.4.7_pre2" />
        <vers num="1.4.7_pre3" />
        <vers num="1.4.7_pre4" />
        <vers num="1.4.7_pre5" />
        <vers num="1.4.8" />
        <vers num="1.4.8_pre1" />
        <vers num="1.4.8_pre2" />
        <vers num="1.4.8_pre3" />
        <vers num="1.5" />
        <vers num="1.5.16" />
        <vers num="1.5.17" />
        <vers num="1.5.26" />
        <vers num="1.5.27" />
        <vers num="1.5.30" />
        <vers num="1.5.31" />
        <vers num="1.5.32" />
        <vers num="1.5.33" />
        <vers num="1.5.34" />
        <vers num="1.5.35" />
        <vers num="1.5.36" />
        <vers num="1.5.38" />
        <vers num="1.5.39" />
        <vers num="1.5.50" />
        <vers num="1.5.52" />
        <vers num="1.5.53" />
        <vers num="1.5.54" />
        <vers num="1.5.55" />
        <vers num="1.5.56" />
        <vers num="1.5.57" />
        <vers num="1.5.58" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1251" published="2009-04-08" name="CVE-2009-1251" modified="2011-01-26" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Heap-based buffer overflow in the cache manager in the client in OpenAFS 1.0 through 1.4.8 and 1.5.0 through 1.5.58 on Unix platforms allows remote attackers to cause a denial of service (system crash) or possibly execute arbitrary code via an RX response containing more data than specified in a request, related to use of XDR arrays.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.openafs.org/security/openafs-sa-2009-001.patch" source="CONFIRM" patch="1">http://www.openafs.org/security/openafs-sa-2009-001.patch</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0117" source="VUPEN">ADV-2011-0117</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0984" source="VUPEN">ADV-2009-0984</ref>
      <ref url="http://www.securityfocus.com/bid/34407" source="BID">34407</ref>
      <ref url="http://www.openafs.org/security/OPENAFS-SA-2009-001.txt" source="CONFIRM" adv="1">http://www.openafs.org/security/OPENAFS-SA-2009-001.txt</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:099" source="MANDRIVA">MDVSA-2009:099</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1768" source="DEBIAN">DSA-1768</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-201101-05.xml" source="GENTOO">GLSA-201101-05</ref>
      <ref url="http://secunia.com/advisories/42896" source="SECUNIA">42896</ref>
      <ref url="http://secunia.com/advisories/34684" source="SECUNIA">34684</ref>
      <ref url="http://secunia.com/advisories/34655" source="SECUNIA">34655</ref>
    </refs>
    <vuln_soft>
      <prod vendor="openafs" name="openafs">
        <vers num="1.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.4a" />
        <vers num="1.1" />
        <vers num="1.1.0" />
        <vers num="1.1.1" />
        <vers num="1.1.1a" />
        <vers num="1.2" />
        <vers num="1.2.1" />
        <vers num="1.2.10" />
        <vers num="1.2.11" />
        <vers num="1.2.13" />
        <vers num="1.2.2" />
        <vers num="1.2.2a" />
        <vers num="1.2.2b" />
        <vers num="1.2.3" />
        <vers num="1.2.4" />
        <vers num="1.2.5" />
        <vers num="1.2.6" />
        <vers num="1.2.7" />
        <vers num="1.2.8" />
        <vers num="1.2.9" />
        <vers num="1.3" />
        <vers num="1.3.1" />
        <vers num="1.3.2" />
        <vers num="1.3.5" />
        <vers num="1.3.70" />
        <vers num="1.3.74" />
        <vers num="1.3.77" />
        <vers num="1.3.81" />
        <vers num="1.4" />
        <vers num="1.4.0" />
        <vers num="1.4.3" />
        <vers num="1.4.4" />
        <vers num="1.4.5" />
        <vers num="1.4.6" />
        <vers num="1.4.7" />
        <vers num="1.4.7_pre1" />
        <vers num="1.4.7_pre2" />
        <vers num="1.4.7_pre3" />
        <vers num="1.4.7_pre4" />
        <vers num="1.4.7_pre5" />
        <vers num="1.4.8" />
        <vers num="1.4.8_pre1" />
        <vers num="1.4.8_pre2" />
        <vers num="1.4.8_pre3" />
        <vers num="1.5" />
        <vers num="1.5.16" />
        <vers num="1.5.17" />
        <vers num="1.5.26" />
        <vers num="1.5.27" />
        <vers num="1.5.30" />
        <vers num="1.5.31" />
        <vers num="1.5.32" />
        <vers num="1.5.33" />
        <vers num="1.5.34" />
        <vers num="1.5.35" />
        <vers num="1.5.36" />
        <vers num="1.5.38" />
        <vers num="1.5.39" />
        <vers num="1.5.50" />
        <vers num="1.5.52" />
        <vers num="1.5.53" />
        <vers num="1.5.54" />
        <vers num="1.5.55" />
        <vers num="1.5.56" />
        <vers num="1.5.57" />
        <vers num="1.5.58" />
      </prod>
      <prod vendor="unix" name="unix">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1252" published="2009-05-19" name="CVE-2009-1252" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Stack-based buffer overflow in the crypto_recv function in ntp_crypto.c in ntpd in NTP before 4.2.4p7 and 4.2.5 before 4.2.5p74, when OpenSSL and autokey are enabled, allows remote attackers to execute arbitrary code via a crafted packet containing an extension field.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/853097" source="CERT-VN">VU#853097</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=499694" source="CONFIRM" patch="1">https://bugzilla.redhat.com/show_bug.cgi?id=499694</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2009-1040.html" source="REDHAT" patch="1">RHSA-2009:1040</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2009-1039.html" source="REDHAT" patch="1">RHSA-2009:1039</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-May/msg01449.html" source="FEDORA">FEDORA-2009-5275</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-May/msg01414.html" source="FEDORA">FEDORA-2009-5273</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-June/msg00293.html" source="FEDORA">FEDORA-2009-5674</ref>
      <ref url="https://support.ntp.org/bugs/show_bug.cgi?id=1151" source="CONFIRM">https://support.ntp.org/bugs/show_bug.cgi?id=1151</ref>
      <ref url="https://launchpad.net/bugs/cve/2009-1252" source="MISC">https://launchpad.net/bugs/cve/2009-1252</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/3316" source="VUPEN">ADV-2009-3316</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1361" source="VUPEN">ADV-2009-1361</ref>
      <ref url="http://www.vmware.com/security/advisories/VMSA-2009-0016.html" source="CONFIRM">http://www.vmware.com/security/advisories/VMSA-2009-0016.html</ref>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-777-1" source="UBUNTU">USN-777-1</ref>
      <ref url="http://www.securitytracker.com/id?1022243" source="SECTRACK">1022243</ref>
      <ref url="http://www.securityfocus.com/bid/35017" source="BID">35017</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/507985/100/0/threaded" source="BUGTRAQ">20091120 VMSA-2009-0016 VMware vCenter and ESX update release and vMA patch release address multiple security issue in third party components</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:117" source="MANDRIVA">MDVSA-2009:117</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200905-08.xml" source="GENTOO">GLSA-200905-08</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1801" source="DEBIAN">DSA-1801</ref>
      <ref url="http://wiki.rpath.com/wiki/Advisories:rPSA-2009-0092" source="CONFIRM">http://wiki.rpath.com/wiki/Advisories:rPSA-2009-0092</ref>
      <ref url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2009&amp;m=slackware-security.566238" source="SLACKWARE">SSA:2009-154-01</ref>
      <ref url="http://security.freebsd.org/advisories/FreeBSD-SA-09:11.ntpd.asc" source="FREEBSD">FreeBSD-SA-09:11</ref>
      <ref url="http://secunia.com/advisories/37471" source="SECUNIA">37471</ref>
      <ref url="http://secunia.com/advisories/37470" source="SECUNIA">37470</ref>
      <ref url="http://secunia.com/advisories/35630" source="SECUNIA">35630</ref>
      <ref url="http://secunia.com/advisories/35416" source="SECUNIA">35416</ref>
      <ref url="http://secunia.com/advisories/35388" source="SECUNIA">35388</ref>
      <ref url="http://secunia.com/advisories/35336" source="SECUNIA">35336</ref>
      <ref url="http://secunia.com/advisories/35308" source="SECUNIA">35308</ref>
      <ref url="http://secunia.com/advisories/35253" source="SECUNIA">35253</ref>
      <ref url="http://secunia.com/advisories/35243" source="SECUNIA">35243</ref>
      <ref url="http://secunia.com/advisories/35169" source="SECUNIA">35169</ref>
      <ref url="http://secunia.com/advisories/35166" source="SECUNIA">35166</ref>
      <ref url="http://secunia.com/advisories/35138" source="SECUNIA">35138</ref>
      <ref url="http://secunia.com/advisories/35137" source="SECUNIA">35137</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6307" source="OVAL">oval:org.mitre.oval:def:6307</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11231" source="OVAL">oval:org.mitre.oval:def:11231</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-06/msg00003.html" source="SUSE">SUSE-SR:2009:011</ref>
      <ref url="ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2009-006.txt.asc" source="NETBSD">NetBSD-SA2009-006</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ntp" name="ntp">
        <vers num="4.2.4p0" />
        <vers num="4.2.4p1" />
        <vers num="4.2.4p2" />
        <vers num="4.2.4p3" />
        <vers num="4.2.4p4" />
        <vers num="4.2.4p5" />
        <vers num="4.2.4p6" />
        <vers num="4.2.5p0" />
        <vers num="4.2.5p1" />
        <vers num="4.2.5p10" />
        <vers num="4.2.5p11" />
        <vers num="4.2.5p12" />
        <vers num="4.2.5p13" />
        <vers num="4.2.5p14" />
        <vers num="4.2.5p15" />
        <vers num="4.2.5p16" />
        <vers num="4.2.5p17" />
        <vers num="4.2.5p18" />
        <vers num="4.2.5p19" />
        <vers num="4.2.5p2" />
        <vers num="4.2.5p20" />
        <vers num="4.2.5p21" />
        <vers num="4.2.5p23" />
        <vers num="4.2.5p24" />
        <vers num="4.2.5p25" />
        <vers num="4.2.5p26" />
        <vers num="4.2.5p27" />
        <vers num="4.2.5p28" />
        <vers num="4.2.5p29" />
        <vers num="4.2.5p3" />
        <vers num="4.2.5p30" />
        <vers num="4.2.5p31" />
        <vers num="4.2.5p32" />
        <vers num="4.2.5p33" />
        <vers num="4.2.5p35" />
        <vers num="4.2.5p36" />
        <vers num="4.2.5p37" />
        <vers num="4.2.5p38" />
        <vers num="4.2.5p39" />
        <vers num="4.2.5p4" />
        <vers num="4.2.5p40" />
        <vers num="4.2.5p41" />
        <vers num="4.2.5p42" />
        <vers num="4.2.5p43" />
        <vers num="4.2.5p44" />
        <vers num="4.2.5p45" />
        <vers num="4.2.5p46" />
        <vers num="4.2.5p47" />
        <vers num="4.2.5p48" />
        <vers num="4.2.5p49" />
        <vers num="4.2.5p5" />
        <vers num="4.2.5p50" />
        <vers num="4.2.5p51" />
        <vers num="4.2.5p52" />
        <vers num="4.2.5p53" />
        <vers num="4.2.5p54" />
        <vers num="4.2.5p55" />
        <vers num="4.2.5p56" />
        <vers num="4.2.5p57" />
        <vers num="4.2.5p58" />
        <vers num="4.2.5p59" />
        <vers num="4.2.5p6" />
        <vers num="4.2.5p60" />
        <vers num="4.2.5p61" />
        <vers num="4.2.5p62" />
        <vers num="4.2.5p63" />
        <vers num="4.2.5p64" />
        <vers num="4.2.5p65" />
        <vers num="4.2.5p66" />
        <vers num="4.2.5p67" />
        <vers num="4.2.5p68" />
        <vers num="4.2.5p69" />
        <vers num="4.2.5p7" />
        <vers num="4.2.5p70" />
        <vers num="4.2.5p71" />
        <vers num="4.2.5p73" />
        <vers num="4.2.5p8" />
        <vers num="4.2.5p9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1253" published="2009-04-08" name="CVE-2009-1253" modified="2009-04-16" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="4.4" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.4" CVSS_base_score="4.4">
    <desc>
      <descript source="cve">James Stone Tunapie 2.1 allows local users to overwrite arbitrary files via a symlink attack on an unspecified temporary file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="https://launchpad.net/bugs/cve/2009-1253" source="CONFIRM">https://launchpad.net/bugs/cve/2009-1253</ref>
      <ref url="https://launchpad.net/bugs/314591" source="CONFIRM">https://launchpad.net/bugs/314591</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0972" source="VUPEN">ADV-2009-0972</ref>
      <ref url="http://www.securityfocus.com/bid/34417" source="BID">34417</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1764" source="DEBIAN">DSA-1764</ref>
      <ref url="http://secunia.com/advisories/34643" source="SECUNIA">34643</ref>
      <ref url="http://osvdb.org/53426" source="OSVDB">53426</ref>
    </refs>
    <vuln_soft>
      <prod vendor="james_stone" name="tunapie">
        <vers num="2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1254" published="2009-04-08" name="CVE-2009-1254" modified="2009-04-16" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">James Stone Tunapie 2.1 allows remote attackers to execute arbitrary commands via shell metacharacters in a stream URL.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="https://launchpad.net/bugs/cve/2009-1254" source="CONFIRM">https://launchpad.net/bugs/cve/2009-1254</ref>
      <ref url="https://launchpad.net/bugs/314591" source="CONFIRM">https://launchpad.net/bugs/314591</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0972" source="VUPEN">ADV-2009-0972</ref>
      <ref url="http://www.securityfocus.com/bid/34418" source="BID">34418</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1764" source="DEBIAN">DSA-1764</ref>
      <ref url="http://secunia.com/advisories/34643" source="SECUNIA">34643</ref>
      <ref url="http://osvdb.org/53427" source="OSVDB">53427</ref>
    </refs>
    <vuln_soft>
      <prod vendor="james_stone" name="tunapie">
        <vers num="2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1255" published="2009-04-30" name="CVE-2009-1255" modified="2009-06-09" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The process_stat function in (1) Memcached before 1.2.8 and (2) MemcacheDB 1.2.0 discloses (a) the contents of /proc/self/maps in response to a stats maps command and (b) memory-allocation statistics in response to a stats malloc command, which allows remote attackers to obtain sensitive information such as the locations of memory regions, and defeat ASLR protection, by sending a command to the daemon's TCP port.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://code.google.com/p/memcachedb/source/diff?spec=svn98&amp;r=98&amp;format=side&amp;path=/trunk/memcachedb.c" source="CONFIRM" patch="1">http://code.google.com/p/memcachedb/source/diff?spec=svn98&amp;r=98&amp;format=side&amp;path=/trunk/memcachedb.c</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-May/msg01256.html" source="FEDORA">FEDORA-2009-4542</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-May/msg00851.html" source="FEDORA">FEDORA-2009-4199</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/50221" source="XF">memcachedb-procselfmaps-info-disclosure(50221)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1197" source="VUPEN" adv="1">ADV-2009-1197</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1196" source="VUPEN" adv="1">ADV-2009-1196</ref>
      <ref url="http://www.securitytracker.com/id?1022140" source="SECTRACK">1022140</ref>
      <ref url="http://www.securityfocus.com/bid/34756" source="BID">34756</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/503064/100/0/threaded" source="BUGTRAQ">20090428 Positron Security Advisory #2009-001: Memcached and MemcacheDB ASLR Bypass Weakness</ref>
      <ref url="http://www.positronsecurity.com/advisories/2009-001.html" source="MISC">http://www.positronsecurity.com/advisories/2009-001.html</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:105" source="MANDRIVA">MDVSA-2009:105</ref>
      <ref url="http://secunia.com/advisories/35175" source="SECUNIA">35175</ref>
      <ref url="http://secunia.com/advisories/34932" source="SECUNIA" adv="1">34932</ref>
      <ref url="http://secunia.com/advisories/34915" source="SECUNIA" adv="1">34915</ref>
      <ref url="http://osvdb.org/54127" source="OSVDB">54127</ref>
      <ref url="http://groups.google.com/group/memcached/browse_thread/thread/ff96a9b88fb5d40e" source="CONFIRM">http://groups.google.com/group/memcached/browse_thread/thread/ff96a9b88fb5d40e</ref>
      <ref url="http://code.google.com/p/memcachedb/source/detail?r=98" source="CONFIRM">http://code.google.com/p/memcachedb/source/detail?r=98</ref>
      <ref url="http://code.google.com/p/memcachedb/source/browse/trunk/ChangeLog?spec=svn98&amp;r=98" source="CONFIRM">http://code.google.com/p/memcachedb/source/browse/trunk/ChangeLog?spec=svn98&amp;r=98</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2009-04/0282.html" source="FULLDISC">20090428 Positron Security Advisory #2009-001: Memcached and MemcacheDB ASLR Bypass Weakness</ref>
    </refs>
    <vuln_soft>
      <prod vendor="memcachedb" name="memcached">
        <vers num="0.0.1" />
        <vers num="0.0.2" />
        <vers num="0.0.3" />
        <vers num="0.0.4" />
        <vers num="0.1.0" />
        <vers num="0.1.1" />
        <vers num="1.0.0" edition="beta" />
        <vers num="1.0.1" edition="beta" />
        <vers num="1.0.2" edition="beta" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.1.0" edition="beta" />
        <vers prev="1" num="1.2.0" edition="beta" />
        <vers num="1.2.1" edition="beta" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1256" published="2009-04-07" name="CVE-2009-1256" modified="2009-04-08" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in FlexCMS 2.5 allows remote attackers to execute arbitrary SQL commands via the ItemId parameter.  NOTE: some of these details are obtained from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/49680" source="XF">flexcms-itemid-sql-injection(49680)</ref>
      <ref url="http://www.securityfocus.com/bid/34394" source="BID">34394</ref>
      <ref url="http://www.milw0rm.com/exploits/8355" source="MILW0RM">8355</ref>
    </refs>
    <vuln_soft>
      <prod vendor="flexcms" name="flexcms">
        <vers num="2.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1257" published="2009-04-07" name="CVE-2009-1257" modified="2009-04-28" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:C)" CVSS_score="9.0" CVSS_impact_subscore="8.5" CVSS_exploit_subscore="10.0" CVSS_base_score="9.0">
    <desc>
      <descript source="cve">Heap-based buffer overflow in Magic ISO Maker 5.5 build 0274 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a crafted CCD file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/49673" source="XF">magiciso-ccd-bo(49673)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0940" source="VUPEN">ADV-2009-0940</ref>
      <ref url="http://www.securityfocus.com/bid/34574" source="BID">34574</ref>
      <ref url="http://www.milw0rm.com/exploits/8343" source="MILW0RM">8343</ref>
      <ref url="http://secunia.com/advisories/34595" source="SECUNIA" adv="1">34595</ref>
      <ref url="http://osvdb.org/53262" source="OSVDB">53262</ref>
    </refs>
    <vuln_soft>
      <prod vendor="magic_iso_maker" name="magic_iso_maker">
        <vers num="5.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1258" published="2009-04-07" name="CVE-2009-1258" modified="2009-04-08" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in the RD-Autos (com_rdautos) component 1.5.7 for Joomla! allows remote attackers to execute arbitrary SQL commands via the makeid parameter in index.php.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/49671" source="XF">rdautos-makeid-sql-injection(49671)</ref>
      <ref url="http://www.securityfocus.com/bid/34364" source="BID">34364</ref>
      <ref url="http://secunia.com/advisories/34578" source="SECUNIA" adv="1">34578</ref>
      <ref url="http://osvdb.org/53138" source="OSVDB">53138</ref>
    </refs>
    <vuln_soft>
      <prod vendor="rd-media" name="com_rdautos">
        <vers num="1.5.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1259" published="2009-04-07" name="CVE-2009-1259" modified="2009-04-08" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">SQL injection vulnerability in inc/bb/topic.php in Insane Visions AdaptBB 1.0, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the topic_id parameter in a topic action to index.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/49681" source="XF">adaptbb-topic-sql-injection(49681)</ref>
      <ref url="http://www.securityfocus.com/bid/34371" source="BID">34371</ref>
      <ref url="http://www.milw0rm.com/exploits/8351" source="MILW0RM">8351</ref>
    </refs>
    <vuln_soft>
      <prod vendor="insanevisions" name="adaptbb">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1260" published="2009-04-07" name="CVE-2009-1260" modified="2010-04-01" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Multiple stack-based buffer overflows in UltraISO 9.3.3.2685 and earlier allow remote attackers to cause a denial of service (crash) or execute arbitrary code via a crafted (1) CCD or (2) IMG file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/49672" source="XF">ultraiso-ccd-img-bo(49672)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0935" source="VUPEN" adv="1">ADV-2009-0935</ref>
      <ref url="http://www.securityfocus.com/bid/34363" source="BID">34363</ref>
      <ref url="http://www.milw0rm.com/exploits/8343" source="MILW0RM">8343</ref>
      <ref url="http://secunia.com/advisories/34581" source="SECUNIA" adv="1">34581</ref>
      <ref url="http://osvdb.org/53275" source="OSVDB">53275</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ezbsystems" name="ultraiso">
        <vers num="3.1" />
        <vers num="3.1_sr1" />
        <vers num="3.1_sr2" />
        <vers num="4.0" />
        <vers num="4.1" />
        <vers num="4.5" />
        <vers num="5.0" />
        <vers num="5.1" />
        <vers num="5.55" />
        <vers num="5.55_sr-1" />
        <vers num="5.55_sr-2" />
        <vers num="6.0" />
        <vers num="6.1" />
        <vers num="6.5" />
        <vers num="6.51" />
        <vers num="6.52" />
        <vers num="6.52_sr-1" />
        <vers num="6.52_sr-2" />
        <vers num="6.56_sr-1" />
        <vers num="6.56_sr-2" />
        <vers num="7.0" edition="-" />
        <vers num="7.0" edition="-:me" />
        <vers num="7.1" edition="-" />
        <vers num="7.1" edition="-:me" />
        <vers num="7.21_sr-1" />
        <vers num="7.21_sr-2" />
        <vers num="7.22_me" />
        <vers num="7.23" edition="-" />
        <vers num="7.23" edition="-:me" />
        <vers num="7.25" edition="-" />
        <vers num="7.25" edition="-:me" />
        <vers num="7.5" edition="-" />
        <vers num="7.5" edition="-:me" />
        <vers num="7.51" edition="-" />
        <vers num="7.51" edition="-:me" />
        <vers num="7.52" edition="-" />
        <vers num="7.52" edition="-:me" />
        <vers num="7.55" edition="-" />
        <vers num="7.55" edition="-:me" />
        <vers num="7.56" edition="-" />
        <vers num="7.56" edition="-:me" />
        <vers num="7.6" edition="-" />
        <vers num="7.6" edition="-:me" />
        <vers num="7.62" edition="-" />
        <vers num="7.62" edition="-:me" />
        <vers num="7.65" edition="-" />
        <vers num="7.65" edition="-:me" />
        <vers num="7.65_sr-2" />
        <vers num="7.66" edition="-" />
        <vers num="7.66" edition="-:me" />
        <vers num="8" edition="-" />
        <vers num="8" edition="-:pe" />
        <vers num="8.12" edition="-" />
        <vers num="8.12" edition="-:pe" />
        <vers num="8.2" edition="-" />
        <vers num="8.2" edition="-:pe" />
        <vers num="8.51" edition="-" />
        <vers num="8.51" edition="-:pe" />
        <vers num="8.6" edition="-" />
        <vers num="8.6" edition="-:pe" />
        <vers num="8.61" edition="-" />
        <vers num="8.61" edition="-:pe" />
        <vers num="8.62" edition="-" />
        <vers num="8.62" edition="-:pe" />
        <vers num="8.63" edition="-" />
        <vers num="8.63" edition="-:pe" />
        <vers num="8.65" edition="-" />
        <vers num="8.65" edition="-:pe" />
        <vers num="8.66" edition="-" />
        <vers num="8.66" edition="-:pe" />
        <vers num="9.0" edition="-" />
        <vers num="9.0" edition="-:pe" />
        <vers num="9.1.2" edition="-" />
        <vers num="9.1.2" edition="-:pe" />
        <vers num="9.2" edition="-" />
        <vers num="9.2" edition="-:pe" />
        <vers num="9.3" edition="-" />
        <vers num="9.3" edition="-:pe" />
        <vers num="9.3.1" edition="-" />
        <vers num="9.3.1" edition="-:pe" />
        <vers num="9.3.2" edition="-" />
        <vers num="9.3.2" edition="-:pe" />
        <vers prev="1" num="9.3.3" edition="-" />
        <vers prev="1" num="9.3.3" edition="-:pe" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1261" published="2009-04-07" name="CVE-2009-1261" modified="2009-04-16" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Web Help Desk 9.1.22 (evaluation version) allow remote attackers to inject arbitrary web script or HTML via the (1) Report Name, (2) Asset No., and (3) Full Name fields in a Models action.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/49683" source="XF">webhelpdesk-multiple-form-xss(49683)</ref>
      <ref url="http://www.securityfocus.com/bid/34391" source="BID">34391</ref>
      <ref url="http://secunia.com/advisories/34596" source="SECUNIA" adv="1">34596</ref>
      <ref url="http://osvdb.org/53424" source="OSVDB">53424</ref>
      <ref url="http://osvdb.org/53423" source="OSVDB">53423</ref>
      <ref url="http://osvdb.org/53422" source="OSVDB">53422</ref>
    </refs>
    <vuln_soft>
      <prod vendor="webhelpdesk" name="web_help_desk">
        <vers num="9.1.22" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1262" published="2009-04-07" name="CVE-2009-1262" modified="2009-04-18" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Format string vulnerability in Fortinet FortiClient 3.0.614, and possibly earlier, allows local users to execute arbitrary code via format string specifiers in the VPN connection name.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/49633" source="XF">forticlient-vpn-format-string(49633)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0941" source="VUPEN" adv="1">ADV-2009-0941</ref>
      <ref url="http://www.securitytracker.com/id?1021966" source="SECTRACK">1021966</ref>
      <ref url="http://www.securityfocus.com/bid/34343" source="BID">34343</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/502602/100/0/threaded" source="BUGTRAQ">20090410 Re: Layered Defense Research Advisory: Format String Vulnerability: FortiClient Version 3</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/502354/100/0/threaded" source="BUGTRAQ">20090402 Layered Defense Research Advisory: Format String Vulnerability: FortiClient Version 3</ref>
      <ref url="http://www.layereddefense.com/FortiClient02Apr.html" source="MISC">http://www.layereddefense.com/FortiClient02Apr.html</ref>
      <ref url="http://secunia.com/advisories/34524" source="SECUNIA" adv="1">34524</ref>
      <ref url="http://osvdb.org/53266" source="OSVDB">53266</ref>
      <ref url="http://lists.grok.org.uk/pipermail/full-disclosure/2009-April/068583.html" source="FULLDISC">20090402 Layered Defense Research Advisory: Format String Vulnerability: FortiClient Version 3</ref>
    </refs>
    <vuln_soft>
      <prod vendor="fortinet" name="forticlient">
        <vers num="3.0.614" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1263" published="2009-04-07" name="CVE-2009-1263" modified="2009-08-24" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in sub_commententry.php in the BookJoomlas (com_bookjoomlas) component 0.1 for Joomla! allows remote attackers to execute arbitrary SQL commands via the gbid parameter in a comment action to index.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/49682" source="XF">bookjoomlas-index-sql-injection(49682)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0952" source="VUPEN" adv="1">ADV-2009-0952</ref>
      <ref url="http://www.securityfocus.com/bid/34392" source="BID">34392</ref>
      <ref url="http://www.milw0rm.com/exploits/8353" source="MILW0RM">8353</ref>
      <ref url="http://osvdb.org/53421" source="OSVDB">53421</ref>
    </refs>
    <vuln_soft>
      <prod vendor="alikonweb" name="com_bookjoomlas">
        <vers num="0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1264" published="2009-04-07" name="CVE-2009-1264" modified="2009-04-08" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:N/A:N)" CVSS_score="4.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.0" CVSS_base_score="4.0">
    <desc>
      <descript source="cve">Frontend User Registration (sr_feuser_register) extension 2.5.20 and earlier for TYPO3 does not properly verify access rights, which allows remote authenticated users to obtain sensitive information such as passwords via unknown attack vectors.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2009/0938" source="VUPEN" patch="1" adv="1">ADV-2009-0938</ref>
      <ref url="http://www.securityfocus.com/bid/34374" source="BID" patch="1">34374</ref>
      <ref url="http://typo3.org/teams/security/security-bulletins/typo3-sa-2009-004/" source="CONFIRM" patch="1" adv="1">http://typo3.org/teams/security/security-bulletins/typo3-sa-2009-004/</ref>
      <ref url="http://typo3.org/extensions/repository/view/sr_feuser_register/2.5.21/" source="CONFIRM" patch="1" adv="1">http://typo3.org/extensions/repository/view/sr_feuser_register/2.5.21/</ref>
      <ref url="http://secunia.com/advisories/34586" source="SECUNIA" adv="1">34586</ref>
      <ref url="http://osvdb.org/53278" source="OSVDB">53278</ref>
    </refs>
    <vuln_soft>
      <prod vendor="stanislas_rolland" name="sr_feuser_register">
        <vers num="1.4" />
        <vers num="1.6" />
        <vers num="2.2.1" />
        <vers num="2.2.7" />
        <vers num="2.2.8" />
        <vers num="2.3" />
        <vers num="2.3.6" />
        <vers num="2.4" />
        <vers num="2.5" />
        <vers num="2.5.10" />
        <vers prev="1" num="2.5.20" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1265" published="2009-04-07" name="CVE-2009-1265" modified="2010-05-04" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Integer overflow in rose_sendmsg (sys/net/af_rose.c) in the Linux kernel 2.6.24.4, and other versions before 2.6.30-rc1, might allow remote attackers to obtain sensitive information via a large length value, which causes "garbage" memory to be sent.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.ubuntu.com/usn/usn-793-1" source="UBUNTU">USN-793-1</ref>
      <ref url="http://www.securityfocus.com/bid/34654" source="BID">34654</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2009/04/08/2" source="MLIST">[oss-security] 20090408 CVE-2009-1265 kernel: af_rose/x25: Sanity check the maximum user frame size</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:135" source="MANDRIVA">MDVSA-2009:135</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:119" source="MANDRIVA">MDVSA-2009:119</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1800" source="DEBIAN">DSA-1800</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1794" source="DEBIAN">DSA-1794</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1787" source="DEBIAN">DSA-1787</ref>
      <ref url="http://secunia.com/advisories/35656" source="SECUNIA">35656</ref>
      <ref url="http://secunia.com/advisories/35394" source="SECUNIA">35394</ref>
      <ref url="http://secunia.com/advisories/35390" source="SECUNIA">35390</ref>
      <ref url="http://secunia.com/advisories/35387" source="SECUNIA">35387</ref>
      <ref url="http://secunia.com/advisories/35185" source="SECUNIA">35185</ref>
      <ref url="http://secunia.com/advisories/35121" source="SECUNIA">35121</ref>
      <ref url="http://secunia.com/advisories/35011" source="SECUNIA">35011</ref>
      <ref url="http://secunia.com/advisories/34981" source="SECUNIA">34981</ref>
      <ref url="http://osvdb.org/53631" source="OSVDB">53631</ref>
      <ref url="http://osvdb.org/53630" source="OSVDB">53630</ref>
      <ref url="http://osvdb.org/53571" source="OSVDB">53571</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-06/msg00002.html" source="SUSE">SUSE-SA:2009:032</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-06/msg00001.html" source="SUSE">SUSE-SA:2009:031</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-06/msg00000.html" source="SUSE">SUSE-SA:2009:030</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-05/msg00002.html" source="SUSE">SUSE-SA:2009:028</ref>
      <ref url="http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commitdiff;h=83e0bbcbe2145f160fbaa109b0439dae7f4a38a9" source="CONFIRM">http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commitdiff;h=83e0bbcbe2145f160fbaa109b0439dae7f4a38a9</ref>
      <ref url="http://bugzilla.kernel.org/show_bug.cgi?id=10423" source="MISC">http://bugzilla.kernel.org/show_bug.cgi?id=10423</ref>
    </refs>
    <vuln_soft>
      <prod vendor="kernel" name="linux">
        <vers num="2.6.24" />
        <vers num="2.6.24.1" />
        <vers num="2.6.24.2" />
        <vers num="2.6.24.3" />
        <vers num="2.6.24.4" />
        <vers num="2.6.24.5" />
        <vers num="2.6.24.6" />
        <vers num="2.6.24.7" />
        <vers num="2.6.25" edition="rc7" />
        <vers num="2.6.25" edition="rc8" />
        <vers num="2.6.25" edition="rc9" />
        <vers num="2.6.25.1" />
        <vers num="2.6.25.10" />
        <vers num="2.6.25.11" />
        <vers num="2.6.25.12" />
        <vers num="2.6.25.13" />
        <vers num="2.6.25.14" />
        <vers num="2.6.25.15" />
        <vers num="2.6.25.16" />
        <vers num="2.6.25.17" />
        <vers num="2.6.25.18" />
        <vers num="2.6.25.19" />
        <vers num="2.6.25.2" />
        <vers num="2.6.25.20" />
        <vers num="2.6.25.3" />
        <vers num="2.6.25.4" />
        <vers num="2.6.25.5" />
        <vers num="2.6.25.6" />
        <vers num="2.6.25.7" />
        <vers num="2.6.25.8" />
        <vers num="2.6.25.9" />
        <vers num="2.6.26" edition="rc1" />
        <vers num="2.6.26" edition="rc2" />
        <vers num="2.6.26" edition="rc3" />
        <vers num="2.6.26" edition="rc4" />
        <vers num="2.6.26" edition="rc5" />
        <vers num="2.6.26" edition="rc6" />
        <vers num="2.6.26" edition="rc7" />
        <vers num="2.6.26" edition="rc8" />
        <vers num="2.6.26" edition="rc9" />
        <vers num="2.6.26-rc8-mm1" />
        <vers num="2.6.26-rc9" />
        <vers num="2.6.26-rc9-git5" />
        <vers num="2.6.26.1" />
        <vers num="2.6.26.2" />
        <vers num="2.6.26.3" />
        <vers num="2.6.26.4" />
        <vers num="2.6.26.5" />
        <vers num="2.6.26.6" />
        <vers num="2.6.26.7" />
        <vers num="2.6.26.8" />
        <vers num="2.6.27" />
        <vers num="2.6.27.1" />
        <vers num="2.6.27.10" />
        <vers num="2.6.27.11" />
        <vers num="2.6.27.12" />
        <vers num="2.6.27.13" />
        <vers num="2.6.27.14" />
        <vers num="2.6.27.15" />
        <vers num="2.6.27.16" />
        <vers num="2.6.27.17" />
        <vers num="2.6.27.18" />
        <vers num="2.6.27.19" />
        <vers num="2.6.27.2" />
        <vers num="2.6.27.3" />
        <vers num="2.6.27.4" />
        <vers num="2.6.27.5" />
        <vers num="2.6.27.6" />
        <vers num="2.6.27.7" />
        <vers num="2.6.27.8" />
        <vers num="2.6.27.9" />
        <vers num="2.6.28" />
        <vers num="2.6.28.1" />
        <vers num="2.6.28.2" />
        <vers num="2.6.28.3" />
        <vers num="2.6.28.4" />
        <vers num="2.6.28.5" />
        <vers num="2.6.28.6" />
        <vers num="2.6.28.7" />
        <vers num="2.6.28.8" />
        <vers num="2.6.29" />
        <vers prev="1" num="2.6.29.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1266" published="2009-04-21" name="CVE-2009-1266" modified="2009-06-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in Wireshark before 1.0.7-0.1-1 has unknown impact and attack vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/50334" source="XF">wireshark-unspecified(50334)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/502745/100/0/threaded" source="BUGTRAQ">20090417 rPSA-2009-0062-1 tshark wireshark</ref>
      <ref url="http://wiki.rpath.com/Advisories:rPSA-2009-0062" source="CONFIRM">http://wiki.rpath.com/Advisories:rPSA-2009-0062</ref>
      <ref url="http://secunia.com/advisories/35416" source="SECUNIA">35416</ref>
      <ref url="http://secunia.com/advisories/34778" source="SECUNIA" adv="1">34778</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-06/msg00003.html" source="SUSE">SUSE-SR:2009:011</ref>
    </refs>
    <vuln_soft>
      <prod vendor="wireshark" name="wireshark">
        <vers num="0.10" />
        <vers num="0.10.1" />
        <vers num="0.10.10" />
        <vers num="0.10.11" />
        <vers num="0.10.12" />
        <vers num="0.10.13" />
        <vers num="0.10.14" />
        <vers num="0.10.2" />
        <vers num="0.10.3" />
        <vers num="0.10.4" />
        <vers num="0.10.5" />
        <vers num="0.10.6" />
        <vers num="0.10.7" />
        <vers num="0.10.8" />
        <vers num="0.10.9" />
        <vers num="0.6" />
        <vers num="0.7.9" />
        <vers num="0.8.16" />
        <vers num="0.8.19" />
        <vers num="0.9.10" />
        <vers num="0.9.14" />
        <vers num="0.9.5" />
        <vers num="0.9.6" />
        <vers num="0.9.7" />
        <vers num="0.9.8" />
        <vers num="0.99" />
        <vers num="0.99.0" />
        <vers num="0.99.1" />
        <vers num="0.99.2" />
        <vers num="0.99.3" />
        <vers num="0.99.4" />
        <vers num="0.99.5" />
        <vers num="0.99.6" />
        <vers num="0.99.6a" />
        <vers num="0.99.7" />
        <vers num="0.99.8" />
        <vers num="1.0" />
        <vers num="1.0.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.5" />
        <vers num="1.0.6" />
        <vers prev="1" num="1.0.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1267" published="2009-04-13" name="CVE-2009-1267" modified="2011-01-20" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the LDAP dissector in Wireshark 0.99.2 through 1.0.6, when running on Windows, allows remote attackers to cause a denial of service (crash) via unknown attack vectors.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.wireshark.org/security/wnpa-sec-2009-02.html" source="CONFIRM" patch="1" adv="1">http://www.wireshark.org/security/wnpa-sec-2009-02.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/49814" source="XF">wireshark-ldap-home-dos(49814)</ref>
      <ref url="http://www.securitytracker.com/id?1022027" source="SECTRACK">1022027</ref>
      <ref url="http://www.securityfocus.com/bid/34457" source="BID">34457</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/502745/100/0/threaded" source="BUGTRAQ">20090417 rPSA-2009-0062-1 tshark wireshark</ref>
      <ref url="http://wiki.rpath.com/Advisories:rPSA-2009-0062" source="CONFIRM">http://wiki.rpath.com/Advisories:rPSA-2009-0062</ref>
      <ref url="http://secunia.com/advisories/35416" source="SECUNIA" adv="1">35416</ref>
      <ref url="http://secunia.com/advisories/34778" source="SECUNIA">34778</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6099" source="OVAL">oval:org.mitre.oval:def:6099</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-06/msg00003.html" source="SUSE">SUSE-SR:2009:011</ref>
    </refs>
    <vuln_soft>
      <prod vendor="wireshark" name="wireshark">
        <vers num="0.99.2" />
        <vers num="0.99.3" />
        <vers num="0.99.4" />
        <vers num="0.99.5" />
        <vers num="0.99.6" />
        <vers num="0.99.6a" />
        <vers num="0.99.7" />
        <vers num="0.99.8" />
        <vers num="1.0" />
        <vers num="1.0.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.5" />
        <vers num="1.0.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1268" published="2009-04-13" name="CVE-2009-1268" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">The Check Point High-Availability Protocol (CPHAP) dissector in Wireshark 0.9.6 through 1.0.6 allows remote attackers to cause a denial of service (crash) via a crafted FWHA_MY_STATE packet.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-May/msg01213.html" source="FEDORA">FEDORA-2009-5382</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-May/msg01167.html" source="FEDORA">FEDORA-2009-5339</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-May/msg00675.html" source="FEDORA">FEDORA-2009-3599</ref>
      <ref url="https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=3269" source="MISC" adv="1">https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=3269</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/49815" source="XF">wireshark-cphap-dos(49815)</ref>
      <ref url="http://www.wireshark.org/security/wnpa-sec-2009-02.html" source="CONFIRM" adv="1">http://www.wireshark.org/security/wnpa-sec-2009-02.html</ref>
      <ref url="http://www.securitytracker.com/id?1022027" source="SECTRACK">1022027</ref>
      <ref url="http://www.securityfocus.com/bid/34457" source="BID">34457</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/502745/100/0/threaded" source="BUGTRAQ">20090417 rPSA-2009-0062-1 tshark wireshark</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-1100.html" source="REDHAT">RHSA-2009:1100</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:088" source="MANDRIVA" adv="1">MDVSA-2009:088</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1942" source="DEBIAN">DSA-1942</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1785" source="DEBIAN">DSA-1785</ref>
      <ref url="http://wiki.rpath.com/Advisories:rPSA-2009-0062" source="CONFIRM">http://wiki.rpath.com/Advisories:rPSA-2009-0062</ref>
      <ref url="http://secunia.com/advisories/37477" source="SECUNIA">37477</ref>
      <ref url="http://secunia.com/advisories/35464" source="SECUNIA">35464</ref>
      <ref url="http://secunia.com/advisories/35416" source="SECUNIA">35416</ref>
      <ref url="http://secunia.com/advisories/35224" source="SECUNIA">35224</ref>
      <ref url="http://secunia.com/advisories/35133" source="SECUNIA">35133</ref>
      <ref url="http://secunia.com/advisories/34970" source="SECUNIA">34970</ref>
      <ref url="http://secunia.com/advisories/34778" source="SECUNIA">34778</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5335" source="OVAL">oval:org.mitre.oval:def:5335</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10876" source="OVAL">oval:org.mitre.oval:def:10876</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-06/msg00003.html" source="SUSE">SUSE-SR:2009:011</ref>
    </refs>
    <vuln_soft>
      <prod vendor="wireshark" name="wireshark">
        <vers num="0.9.6" />
        <vers num="0.9.7" />
        <vers num="0.9.8" />
        <vers num="0.99" />
        <vers num="0.99.0" />
        <vers num="0.99.1" />
        <vers num="0.99.2" />
        <vers num="0.99.3" />
        <vers num="0.99.4" />
        <vers num="0.99.5" />
        <vers num="0.99.6" />
        <vers num="0.99.6a" />
        <vers num="0.99.7" />
        <vers num="0.99.8" />
        <vers num="1.0" />
        <vers num="1.0.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.5" />
        <vers num="1.0.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1269" published="2009-04-13" name="CVE-2009-1269" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in Wireshark 0.99.6 through 1.0.6 allows remote attackers to cause a denial of service (crash) via a crafted Tektronix .rf5 file.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-May/msg01213.html" source="FEDORA">FEDORA-2009-5382</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-May/msg01167.html" source="FEDORA">FEDORA-2009-5339</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-May/msg00675.html" source="FEDORA">FEDORA-2009-3599</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/49816" source="XF">wireshark-rf5file-dos(49816)</ref>
      <ref url="http://www.wireshark.org/security/wnpa-sec-2009-02.html" source="CONFIRM" adv="1">http://www.wireshark.org/security/wnpa-sec-2009-02.html</ref>
      <ref url="http://www.securitytracker.com/id?1022027" source="SECTRACK">1022027</ref>
      <ref url="http://www.securityfocus.com/bid/34457" source="BID">34457</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/502745/100/0/threaded" source="BUGTRAQ">20090417 rPSA-2009-0062-1 tshark wireshark</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-1100.html" source="REDHAT">RHSA-2009:1100</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:088" source="MANDRIVA">MDVSA-2009:088</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1785" source="DEBIAN">DSA-1785</ref>
      <ref url="http://wiki.rpath.com/Advisories:rPSA-2009-0062" source="CONFIRM">http://wiki.rpath.com/Advisories:rPSA-2009-0062</ref>
      <ref url="http://secunia.com/advisories/35464" source="SECUNIA">35464</ref>
      <ref url="http://secunia.com/advisories/35416" source="SECUNIA">35416</ref>
      <ref url="http://secunia.com/advisories/35224" source="SECUNIA">35224</ref>
      <ref url="http://secunia.com/advisories/35133" source="SECUNIA">35133</ref>
      <ref url="http://secunia.com/advisories/34970" source="SECUNIA">34970</ref>
      <ref url="http://secunia.com/advisories/34778" source="SECUNIA">34778</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5748" source="OVAL">oval:org.mitre.oval:def:5748</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10642" source="OVAL">oval:org.mitre.oval:def:10642</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-06/msg00003.html" source="SUSE">SUSE-SR:2009:011</ref>
    </refs>
    <vuln_soft>
      <prod vendor="wireshark" name="wireshark">
        <vers num="0.9.6" />
        <vers num="0.9.7" />
        <vers num="0.9.8" />
        <vers num="0.99" />
        <vers num="0.99.0" />
        <vers num="0.99.1" />
        <vers num="0.99.2" />
        <vers num="0.99.3" />
        <vers num="0.99.4" />
        <vers num="0.99.5" />
        <vers num="0.99.6" />
        <vers num="0.99.6a" />
        <vers num="0.99.7" />
        <vers num="0.99.8" />
        <vers num="1.0" />
        <vers num="1.0.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.5" />
        <vers num="1.0.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1270" published="2009-04-08" name="CVE-2009-1270" modified="2009-09-16" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">libclamav/untar.c in ClamAV before 0.95 allows remote attackers to cause a denial of service (infinite loop) via a crafted TAR file that causes (1) clamd and (2) clamscan to hang.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="https://wwws.clamav.net/bugzilla/show_bug.cgi?id=1462" source="CONFIRM">https://wwws.clamav.net/bugzilla/show_bug.cgi?id=1462</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/49846" source="XF">clamav-untar-dos(49846)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0934" source="VUPEN">ADV-2009-0934</ref>
      <ref url="http://www.ubuntu.com/usn/usn-754-1" source="UBUNTU">USN-754-1</ref>
      <ref url="http://www.securityfocus.com/bid/34357" source="BID">34357</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2009/04/07/6" source="MLIST">[oss-security] 20090407 Re: CVE request: clamav clamd and clamscan DoS and bypass by malformated archive</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:097" source="MANDRIVA">MDVSA-2009:097</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1771" source="DEBIAN">DSA-1771</ref>
      <ref url="http://support.apple.com/kb/HT3865" source="CONFIRM">http://support.apple.com/kb/HT3865</ref>
      <ref url="http://secunia.com/advisories/36701" source="SECUNIA">36701</ref>
      <ref url="http://secunia.com/advisories/34716" source="SECUNIA">34716</ref>
      <ref url="http://osvdb.org/53461" source="OSVDB">53461</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2009/Sep/msg00004.html" source="APPLE">APPLE-SA-2009-09-10-2</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cclamav" name="clamav">
        <vers num="0.14" />
      </prod>
      <prod vendor="clamav" name="clamav">
        <vers num="0.01" />
        <vers num="0.02" />
        <vers num="0.03" />
        <vers num="0.05" />
        <vers num="0.10" />
        <vers num="0.12" />
        <vers num="0.13" />
        <vers num="0.14" edition="pre" />
        <vers num="0.15" />
        <vers num="0.20" />
        <vers num="0.21" />
        <vers num="0.22" />
        <vers num="0.23" />
        <vers num="0.24" />
        <vers num="0.51" />
        <vers num="0.52" />
        <vers num="0.53" />
        <vers num="0.54" />
        <vers num="0.60" />
        <vers num="0.60p" />
        <vers num="0.65" />
        <vers num="0.67" />
        <vers num="0.68" />
        <vers num="0.68.1" />
        <vers num="0.70" />
        <vers num="0.71" />
        <vers num="0.72" />
        <vers num="0.73" />
        <vers num="0.74" />
        <vers num="0.75" />
        <vers num="0.75.1" />
        <vers num="0.80" />
        <vers num="0.80_rc" />
        <vers num="0.80_rc1" />
        <vers num="0.80_rc2" />
        <vers num="0.80_rc3" />
        <vers num="0.81" />
        <vers num="0.81_rc1" />
        <vers num="0.82" />
        <vers num="0.83" />
        <vers num="0.84" />
        <vers num="0.84_rc1" />
        <vers num="0.84_rc2" />
        <vers num="0.85" />
        <vers num="0.85.1" />
        <vers num="0.86" />
        <vers num="0.86.1" />
        <vers num="0.86.2" />
        <vers num="0.86_rc1" />
        <vers num="0.87" />
        <vers num="0.87.1" />
        <vers num="0.88" />
        <vers num="0.88.1" />
        <vers num="0.88.2" />
        <vers num="0.88.3" />
        <vers num="0.88.4" />
        <vers num="0.88.5" />
        <vers num="0.88.6" />
        <vers num="0.88.7" />
        <vers num="0.88.7_p0" />
        <vers num="0.88.7_p1" />
        <vers num="0.8_" edition="rc3" />
        <vers num="0.90" />
        <vers num="0.90.1" />
        <vers num="0.90.1_p0" />
        <vers num="0.90.2" />
        <vers num="0.90.2_p0" />
        <vers num="0.90.3" />
        <vers num="0.90.3_p0" />
        <vers num="0.90.3_p1" />
        <vers num="0.90_rc1" />
        <vers num="0.90_rc1.1" />
        <vers num="0.90_rc2" />
        <vers num="0.90_rc3" />
        <vers num="0.91" />
        <vers num="0.91.1" />
        <vers num="0.91.2" />
        <vers num="0.91.2_p0" />
        <vers num="0.91_rc1" />
        <vers num="0.91_rc2" />
        <vers num="0.92" />
        <vers num="0.92.1" />
        <vers num="0.92_p0" />
        <vers num="0.93" />
        <vers num="0.93.1" />
        <vers num="0.93.2" />
        <vers num="0.93.3" />
        <vers num="0.94" />
        <vers num="0.94.1" />
        <vers num="0.9_rc1" />
      </prod>
      <prod vendor="clamavclamav" name="0.11">
        <vers num="" />
      </prod>
      <prod vendor="clamavclamav" name="0.80_rc4">
        <vers num="" />
      </prod>
      <prod vendor="clamavs" name="clamav">
        <vers num="0.04" />
        <vers num="0.06" />
        <vers num="0.24" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1271" published="2009-04-08" name="CVE-2009-1271" modified="2009-09-16" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The JSON_parser function (ext/json/JSON_parser.c) in PHP 5.2.x before 5.2.9 allows remote attackers to cause a denial of service (segmentation fault) via a malformed string to the json_decode API function.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-May/msg01465.html" source="FEDORA">FEDORA-2009-3848</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-May/msg01451.html" source="FEDORA">FEDORA-2009-3768</ref>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-761-1" source="UBUNTU">USN-761-1</ref>
      <ref url="http://www.ubuntu.com/usn/USN-761-2" source="UBUNTU">USN-761-2</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-0350.html" source="REDHAT">RHSA-2009:0350</ref>
      <ref url="http://www.php.net/releases/5_2_9.php" source="CONFIRM" adv="1">http://www.php.net/releases/5_2_9.php</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2009/04/01/9" source="MLIST">[oss-security] 20090401 CVE request: PHP 5.2.9</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:090" source="MANDRIVA">MDVSA-2009:090</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1789" source="DEBIAN">DSA-1789</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1775" source="DEBIAN">DSA-1775</ref>
      <ref url="http://support.apple.com/kb/HT3865" source="CONFIRM">http://support.apple.com/kb/HT3865</ref>
      <ref url="http://secunia.com/advisories/36701" source="SECUNIA">36701</ref>
      <ref url="http://secunia.com/advisories/35685" source="SECUNIA">35685</ref>
      <ref url="http://secunia.com/advisories/35306" source="SECUNIA">35306</ref>
      <ref url="http://secunia.com/advisories/35007" source="SECUNIA">35007</ref>
      <ref url="http://secunia.com/advisories/35003" source="SECUNIA">35003</ref>
      <ref url="http://secunia.com/advisories/34933" source="SECUNIA">34933</ref>
      <ref url="http://secunia.com/advisories/34830" source="SECUNIA">34830</ref>
      <ref url="http://secunia.com/advisories/34770" source="SECUNIA">34770</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-07/msg00002.html" source="SUSE">SUSE-SR:2009:012</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2009/Sep/msg00004.html" source="APPLE">APPLE-SA-2009-09-10-2</ref>
      <ref url="http://cvs.php.net/viewvc.cgi/php-src/ext/json/JSON_parser.c?r1=1.1.2.14&amp;r2=1.1.2.15" source="MISC">http://cvs.php.net/viewvc.cgi/php-src/ext/json/JSON_parser.c?r1=1.1.2.14&amp;r2=1.1.2.15</ref>
    </refs>
    <vuln_soft>
      <prod vendor="php" name="php">
        <vers num="5.2.0" />
        <vers num="5.2.1" />
        <vers num="5.2.2" />
        <vers num="5.2.3" />
        <vers num="5.2.4" edition="" />
        <vers num="5.2.4" edition=":windows" />
        <vers num="5.2.5" />
        <vers num="5.2.6" />
        <vers num="5.2.7" />
        <vers num="5.2.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1272" published="2009-04-08" name="CVE-2009-1272" modified="2009-09-16" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The php_zip_make_relative_path function in php_zip.c in PHP 5.2.x before 5.2.9 allows context-dependent attackers to cause a denial of service (crash) via a ZIP file that contains filenames with relative paths, which is not properly handled during extraction.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.php.net/releases/5_2_9.php" source="CONFIRM" adv="1">http://www.php.net/releases/5_2_9.php</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2009/04/09/1" source="MLIST">[oss-security] 20090409 Re: CVE request: PHP 5.2.9</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2009/04/01/9" source="MLIST">[oss-security] 20090401 CVE request: PHP 5.2.9</ref>
      <ref url="http://support.apple.com/kb/HT3865" source="CONFIRM">http://support.apple.com/kb/HT3865</ref>
      <ref url="http://secunia.com/advisories/36701" source="SECUNIA">36701</ref>
      <ref url="http://secunia.com/advisories/35685" source="SECUNIA">35685</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=125017764422557&amp;w=2" source="HP">SSRT090062</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=125017764422557&amp;w=2" source="HP">SSRT090062</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-07/msg00002.html" source="SUSE">SUSE-SR:2009:012</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2009/Sep/msg00004.html" source="APPLE">APPLE-SA-2009-09-10-2</ref>
      <ref url="http://cvs.php.net/viewvc.cgi/php-src/ext/zip/php_zip.c?r1=1.1.2.48&amp;r2=1.1.2.49" source="MISC">http://cvs.php.net/viewvc.cgi/php-src/ext/zip/php_zip.c?r1=1.1.2.48&amp;r2=1.1.2.49</ref>
    </refs>
    <vuln_soft>
      <prod vendor="php" name="php">
        <vers num="5.2.0" />
        <vers num="5.2.1" />
        <vers num="5.2.2" />
        <vers num="5.2.3" />
        <vers num="5.2.4" edition="" />
        <vers num="5.2.4" edition=":windows" />
        <vers num="5.2.5" />
        <vers num="5.2.6" />
        <vers num="5.2.7" />
        <vers num="5.2.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1273" published="2009-04-08" name="CVE-2009-1273" modified="2009-05-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">pam_ssh 1.92 and possibly other versions, as used when PAM is compiled with USE=ssh, generates different error messages depending on whether the username is valid or invalid, which makes it easier for remote attackers to enumerate usernames.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-May/msg00145.html" source="FEDORA">FEDORA-2009-3627</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-May/msg00116.html" source="FEDORA">FEDORA-2009-3500</ref>
      <ref url="http://secunia.com/advisories/34986" source="SECUNIA">34986</ref>
      <ref url="http://secunia.com/advisories/34536" source="SECUNIA" adv="1">34536</ref>
      <ref url="http://bugs.gentoo.org/show_bug.cgi?id=263579" source="CONFIRM">http://bugs.gentoo.org/show_bug.cgi?id=263579</ref>
    </refs>
    <vuln_soft>
      <prod vendor="andrew_j.korty" name="pam_ssh">
        <vers num="1.92" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1274" published="2009-04-08" name="CVE-2009-1274" modified="2009-11-24" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Integer overflow in the qt_error parse_trak_atom function in demuxers/demux_qt.c in xine-lib 1.1.16.2 and earlier allows remote attackers to execute arbitrary code via a Quicktime movie file with a large count value in an STTS atom, which triggers a heap-based buffer overflow.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-April/msg00215.html" source="FEDORA">FEDORA-2009-3433</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-April/msg00210.html" source="FEDORA">FEDORA-2009-3428</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/49714" source="XF">xinelib-demuxqt-bo(49714)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0937" source="VUPEN" adv="1">ADV-2009-0937</ref>
      <ref url="http://www.trapkit.de/advisories/TKADV2009-005.txt" source="MISC">http://www.trapkit.de/advisories/TKADV2009-005.txt</ref>
      <ref url="http://www.securitytracker.com/id?1021989" source="SECTRACK">1021989</ref>
      <ref url="http://www.securityfocus.com/bid/34384" source="BID">34384</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/502481/100/0/threaded" source="BUGTRAQ">20090404 [TKADV2009-005] xine-lib Quicktime STTS Atom Integer Overflow</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:299" source="MANDRIVA">MDVSA-2009:299</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:298" source="MANDRIVA">MDVSA-2009:298</ref>
      <ref url="http://sourceforge.net/project/shownotes.php?group_id=9655&amp;release_id=673233" source="CONFIRM">http://sourceforge.net/project/shownotes.php?group_id=9655&amp;release_id=673233</ref>
      <ref url="http://secunia.com/advisories/35416" source="SECUNIA">35416</ref>
      <ref url="http://secunia.com/advisories/34712" source="SECUNIA">34712</ref>
      <ref url="http://secunia.com/advisories/34593" source="SECUNIA" adv="1">34593</ref>
      <ref url="http://osvdb.org/53288" source="OSVDB">53288</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-06/msg00003.html" source="SUSE">SUSE-SR:2009:011</ref>
      <ref url="http://bugs.xine-project.org/show_bug.cgi?id=224" source="CONFIRM">http://bugs.xine-project.org/show_bug.cgi?id=224</ref>
    </refs>
    <vuln_soft>
      <prod vendor="xine" name="xine-lib">
        <vers num="1.1.0" />
        <vers num="1.1.1" />
        <vers num="1.1.10" />
        <vers num="1.1.10.1" />
        <vers num="1.1.11" />
        <vers num="1.1.11.1" />
        <vers num="1.1.12" />
        <vers num="1.1.13" />
        <vers num="1.1.14" />
        <vers num="1.1.15" />
        <vers num="1.1.16.1" />
        <vers num="1.1.16.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1275" published="2009-04-09" name="CVE-2009-1275" modified="2009-04-29" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Apache Tiles 2.1 before 2.1.2, as used in Apache Struts and other products, evaluates Expression Language (EL) expressions twice in certain circumstances, which allows remote attackers to conduct cross-site scripting (XSS) attacks or obtain sensitive information via unspecified vectors, related to the (1) tiles:putAttribute and (2) tiles:insertTemplate JSP tags.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="https://issues.apache.org/struts/browse/TILES-351" source="CONFIRM" adv="1">https://issues.apache.org/struts/browse/TILES-351</ref>
      <ref url="http://www.securityfocus.com/bid/34657" source="BID">34657</ref>
      <ref url="http://svn.apache.org/viewvc/tiles/framework/trunk/src/site/apt/security/security-bulletin-1.apt?revision=741913" source="CONFIRM" adv="1">http://svn.apache.org/viewvc/tiles/framework/trunk/src/site/apt/security/security-bulletin-1.apt?revision=741913</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apache" name="tiles">
        <vers num="2.1.0" />
        <vers num="2.1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2009-1276" published="2009-04-09" name="CVE-2009-1276" modified="2009-08-11" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">XScreenSaver in Sun Solaris 10 and OpenSolaris before snv_109, and Solaris 8 and 9 with GNOME 2.0 or 2.0.2, allows physically proximate attackers to obtain sensitive information by reading popup windows, which are displayed even when the screen is locked, as demonstrated by Thunderbird new-mail notifications.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-255308-1" source="SUNALERT" patch="1" adv="1">255308</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-21-120094-22-1" source="CONFIRM" patch="1" adv="1">http://sunsolve.sun.com/search/document.do?assetkey=1-21-120094-22-1</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0978" source="VUPEN">ADV-2009-0978</ref>
      <ref url="http://www.securityfocus.com/bid/34421" source="BID">34421</ref>
      <ref url="http://securitytracker.com/id?1022009" source="SECTRACK">1022009</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="opensolaris">
        <vers num="snv_01" edition="" />
        <vers num="snv_01" edition=":sparc" />
        <vers num="snv_01" edition=":x86" />
        <vers num="snv_02" edition="" />
        <vers num="snv_02" edition=":sparc" />
        <vers num="snv_02" edition=":x86" />
        <vers num="snv_03" edition="" />
        <vers num="snv_03" edition=":x86" />
        <vers num="snv_03" edition=":sparc" />
        <vers num="snv_04" edition="" />
        <vers num="snv_04" edition=":x86" />
        <vers num="snv_04" edition=":sparc" />
        <vers num="snv_05" edition="" />
        <vers num="snv_05" edition=":sparc" />
        <vers num="snv_05" edition=":x86" />
        <vers num="snv_06" edition="" />
        <vers num="snv_06" edition=":sparc" />
        <vers num="snv_06" edition=":x86" />
        <vers num="snv_07" edition="" />
        <vers num="snv_07" edition=":sparc" />
        <vers num="snv_07" edition=":x86" />
        <vers num="snv_08" edition="" />
        <vers num="snv_08" edition=":x86" />
        <vers num="snv_08" edition=":sparc" />
        <vers num="snv_09" edition="" />
        <vers num="snv_09" edition=":x86" />
        <vers num="snv_09" edition=":sparc" />
        <vers num="snv_10" edition="" />
        <vers num="snv_10" edition=":x86" />
        <vers num="snv_10" edition=":sparc" />
        <vers num="snv_100" edition="" />
        <vers num="snv_100" edition=":sparc" />
        <vers num="snv_100" edition=":x86" />
        <vers num="snv_101" edition="" />
        <vers num="snv_101" edition=":x86" />
        <vers num="snv_101" edition=":sparc" />
        <vers num="snv_102" edition="" />
        <vers num="snv_102" edition=":sparc" />
        <vers num="snv_102" edition=":x86" />
        <vers num="snv_103" edition="" />
        <vers num="snv_103" edition=":x86" />
        <vers num="snv_103" edition=":sparc" />
        <vers num="snv_104" edition="" />
        <vers num="snv_104" edition=":x86" />
        <vers num="snv_104" edition=":sparc" />
        <vers num="snv_105" edition="" />
        <vers num="snv_105" edition=":x86" />
        <vers num="snv_105" edition=":sparc" />
        <vers num="snv_106" edition="" />
        <vers num="snv_106" edition=":sparc" />
        <vers num="snv_106" edition=":x86" />
        <vers num="snv_107" edition="" />
        <vers num="snv_107" edition=":x86" />
        <vers num="snv_107" edition=":sparc" />
        <vers prev="1" num="snv_108" edition="" />
        <vers prev="1" num="snv_108" edition=":x86" />
        <vers prev="1" num="snv_108" edition=":sparc" />
        <vers num="snv_11" edition="" />
        <vers num="snv_11" edition=":x86" />
        <vers num="snv_11" edition=":sparc" />
        <vers num="snv_12" edition="" />
        <vers num="snv_12" edition=":x86" />
        <vers num="snv_12" edition=":sparc" />
        <vers num="snv_13" edition="" />
        <vers num="snv_13" edition=":x86" />
        <vers num="snv_13" edition=":sparc" />
        <vers num="snv_14" edition="" />
        <vers num="snv_14" edition=":sparc" />
        <vers num="snv_14" edition=":x86" />
        <vers num="snv_15" edition="" />
        <vers num="snv_15" edition=":x86" />
        <vers num="snv_15" edition=":sparc" />
        <vers num="snv_16" edition="" />
        <vers num="snv_16" edition=":sparc" />
        <vers num="snv_16" edition=":x86" />
        <vers num="snv_17" edition="" />
        <vers num="snv_17" edition=":x86" />
        <vers num="snv_17" edition=":sparc" />
        <vers num="snv_18" edition="" />
        <vers num="snv_18" edition=":x86" />
        <vers num="snv_18" edition=":sparc" />
        <vers num="snv_19" edition="" />
        <vers num="snv_19" edition=":sparc" />
        <vers num="snv_19" edition=":x86" />
        <vers num="snv_20" edition="" />
        <vers num="snv_20" edition=":x86" />
        <vers num="snv_20" edition=":sparc" />
        <vers num="snv_21" edition="" />
        <vers num="snv_21" edition=":sparc" />
        <vers num="snv_21" edition=":x86" />
        <vers num="snv_22" edition="" />
        <vers num="snv_22" edition=":sparc" />
        <vers num="snv_22" edition=":x86" />
        <vers num="snv_23" edition="" />
        <vers num="snv_23" edition=":sparc" />
        <vers num="snv_23" edition=":x86" />
        <vers num="snv_24" edition="" />
        <vers num="snv_24" edition=":sparc" />
        <vers num="snv_24" edition=":x86" />
        <vers num="snv_25" edition="" />
        <vers num="snv_25" edition=":x86" />
        <vers num="snv_25" edition=":sparc" />
        <vers num="snv_26" edition="" />
        <vers num="snv_26" edition=":x86" />
        <vers num="snv_26" edition=":sparc" />
        <vers num="snv_27" edition="" />
        <vers num="snv_27" edition=":sparc" />
        <vers num="snv_27" edition=":x86" />
        <vers num="snv_28" edition="" />
        <vers num="snv_28" edition=":x86" />
        <vers num="snv_28" edition=":sparc" />
        <vers num="snv_29" edition="" />
        <vers num="snv_29" edition=":x86" />
        <vers num="snv_29" edition=":sparc" />
        <vers num="snv_30" edition="" />
        <vers num="snv_30" edition=":sparc" />
        <vers num="snv_30" edition=":x86" />
        <vers num="snv_31" edition="" />
        <vers num="snv_31" edition=":sparc" />
        <vers num="snv_31" edition=":x86" />
        <vers num="snv_32" edition="" />
        <vers num="snv_32" edition=":x86" />
        <vers num="snv_32" edition=":sparc" />
        <vers num="snv_33" edition="" />
        <vers num="snv_33" edition=":x86" />
        <vers num="snv_33" edition=":sparc" />
        <vers num="snv_34" edition="" />
        <vers num="snv_34" edition=":sparc" />
        <vers num="snv_34" edition=":x86" />
        <vers num="snv_35" edition="" />
        <vers num="snv_35" edition=":sparc" />
        <vers num="snv_35" edition=":x86" />
        <vers num="snv_36" edition="" />
        <vers num="snv_36" edition=":x86" />
        <vers num="snv_36" edition=":sparc" />
        <vers num="snv_37" edition="" />
        <vers num="snv_37" edition=":sparc" />
        <vers num="snv_37" edition=":x86" />
        <vers num="snv_38" edition="" />
        <vers num="snv_38" edition=":sparc" />
        <vers num="snv_38" edition=":x86" />
        <vers num="snv_39" edition="" />
        <vers num="snv_39" edition=":sparc" />
        <vers num="snv_39" edition=":x86" />
        <vers num="snv_40" edition="" />
        <vers num="snv_40" edition=":sparc" />
        <vers num="snv_40" edition=":x86" />
        <vers num="snv_41" edition="" />
        <vers num="snv_41" edition=":sparc" />
        <vers num="snv_41" edition=":x86" />
        <vers num="snv_42" edition="" />
        <vers num="snv_42" edition=":x86" />
        <vers num="snv_42" edition=":sparc" />
        <vers num="snv_43" edition="" />
        <vers num="snv_43" edition=":sparc" />
        <vers num="snv_43" edition=":x86" />
        <vers num="snv_44" edition="" />
        <vers num="snv_44" edition=":x86" />
        <vers num="snv_44" edition=":sparc" />
        <vers num="snv_45" edition="" />
        <vers num="snv_45" edition=":x86" />
        <vers num="snv_45" edition=":sparc" />
        <vers num="snv_46" edition="" />
        <vers num="snv_46" edition=":x86" />
        <vers num="snv_46" edition=":sparc" />
        <vers num="snv_47" edition="" />
        <vers num="snv_47" edition=":x86" />
        <vers num="snv_47" edition=":sparc" />
        <vers num="snv_48" edition="" />
        <vers num="snv_48" edition=":sparc" />
        <vers num="snv_48" edition=":x86" />
        <vers num="snv_49" edition="" />
        <vers num="snv_49" edition=":sparc" />
        <vers num="snv_49" edition=":x86" />
        <vers num="snv_50" edition="" />
        <vers num="snv_50" edition=":sparc" />
        <vers num="snv_50" edition=":x86" />
        <vers num="snv_51" edition="" />
        <vers num="snv_51" edition=":sparc" />
        <vers num="snv_51" edition=":x86" />
        <vers num="snv_52" edition="" />
        <vers num="snv_52" edition=":sparc" />
        <vers num="snv_52" edition=":x86" />
        <vers num="snv_53" edition="" />
        <vers num="snv_53" edition=":sparc" />
        <vers num="snv_53" edition=":x86" />
        <vers num="snv_54" edition="" />
        <vers num="snv_54" edition=":x86" />
        <vers num="snv_54" edition=":sparc" />
        <vers num="snv_55" edition="" />
        <vers num="snv_55" edition=":sparc" />
        <vers num="snv_55" edition=":x86" />
        <vers num="snv_56" edition="" />
        <vers num="snv_56" edition=":x86" />
        <vers num="snv_56" edition=":sparc" />
        <vers num="snv_57" edition="" />
        <vers num="snv_57" edition=":x86" />
        <vers num="snv_57" edition=":sparc" />
        <vers num="snv_58" edition="" />
        <vers num="snv_58" edition=":sparc" />
        <vers num="snv_58" edition=":x86" />
        <vers num="snv_59" edition="" />
        <vers num="snv_59" edition=":sparc" />
        <vers num="snv_59" edition=":x86" />
        <vers num="snv_60" edition="" />
        <vers num="snv_60" edition=":x86" />
        <vers num="snv_60" edition=":sparc" />
        <vers num="snv_61" edition="" />
        <vers num="snv_61" edition=":sparc" />
        <vers num="snv_61" edition=":x86" />
        <vers num="snv_62" edition="" />
        <vers num="snv_62" edition=":x86" />
        <vers num="snv_62" edition=":sparc" />
        <vers num="snv_63" edition="" />
        <vers num="snv_63" edition=":sparc" />
        <vers num="snv_63" edition=":x86" />
        <vers num="snv_64" edition="" />
        <vers num="snv_64" edition=":x86" />
        <vers num="snv_64" edition=":sparc" />
        <vers num="snv_65" edition="" />
        <vers num="snv_65" edition=":x86" />
        <vers num="snv_65" edition=":sparc" />
        <vers num="snv_66" edition="" />
        <vers num="snv_66" edition=":x86" />
        <vers num="snv_66" edition=":sparc" />
        <vers num="snv_67" edition="" />
        <vers num="snv_67" edition=":sparc" />
        <vers num="snv_67" edition=":x86" />
        <vers num="snv_68" edition="" />
        <vers num="snv_68" edition=":x86" />
        <vers num="snv_68" edition=":sparc" />
        <vers num="snv_69" edition="" />
        <vers num="snv_69" edition=":sparc" />
        <vers num="snv_69" edition=":x86" />
        <vers num="snv_70" edition="" />
        <vers num="snv_70" edition=":sparc" />
        <vers num="snv_70" edition=":x86" />
        <vers num="snv_71" edition="" />
        <vers num="snv_71" edition=":x86" />
        <vers num="snv_71" edition=":sparc" />
        <vers num="snv_72" edition="" />
        <vers num="snv_72" edition=":x86" />
        <vers num="snv_72" edition=":sparc" />
        <vers num="snv_73" edition="" />
        <vers num="snv_73" edition=":x86" />
        <vers num="snv_73" edition=":sparc" />
        <vers num="snv_74" edition="" />
        <vers num="snv_74" edition=":sparc" />
        <vers num="snv_74" edition=":x86" />
        <vers num="snv_75" edition="" />
        <vers num="snv_75" edition=":sparc" />
        <vers num="snv_75" edition=":x86" />
        <vers num="snv_76" edition="" />
        <vers num="snv_76" edition=":x86" />
        <vers num="snv_76" edition=":sparc" />
        <vers num="snv_77" edition="" />
        <vers num="snv_77" edition=":sparc" />
        <vers num="snv_77" edition=":x86" />
        <vers num="snv_78" edition="" />
        <vers num="snv_78" edition=":sparc" />
        <vers num="snv_78" edition=":x86" />
        <vers num="snv_79" edition="" />
        <vers num="snv_79" edition=":x86" />
        <vers num="snv_79" edition=":sparc" />
        <vers num="snv_80" edition="" />
        <vers num="snv_80" edition=":x86" />
        <vers num="snv_80" edition=":sparc" />
        <vers num="snv_81" edition="" />
        <vers num="snv_81" edition=":x86" />
        <vers num="snv_81" edition=":sparc" />
        <vers num="snv_82" edition="" />
        <vers num="snv_82" edition=":x86" />
        <vers num="snv_82" edition=":sparc" />
        <vers num="snv_83" edition="" />
        <vers num="snv_83" edition=":x86" />
        <vers num="snv_83" edition=":sparc" />
        <vers num="snv_84" edition="" />
        <vers num="snv_84" edition=":x86" />
        <vers num="snv_84" edition=":sparc" />
        <vers num="snv_85" edition="" />
        <vers num="snv_85" edition=":x86" />
        <vers num="snv_85" edition=":sparc" />
        <vers num="snv_86" edition="" />
        <vers num="snv_86" edition=":sparc" />
        <vers num="snv_86" edition=":x86" />
        <vers num="snv_87" edition="" />
        <vers num="snv_87" edition=":sparc" />
        <vers num="snv_87" edition=":x86" />
        <vers num="snv_88" edition="" />
        <vers num="snv_88" edition=":x86" />
        <vers num="snv_88" edition=":sparc" />
        <vers num="snv_89" edition="" />
        <vers num="snv_89" edition=":x86" />
        <vers num="snv_89" edition=":sparc" />
        <vers num="snv_90" edition="" />
        <vers num="snv_90" edition=":sparc" />
        <vers num="snv_90" edition=":x86" />
        <vers num="snv_91" edition="" />
        <vers num="snv_91" edition=":sparc" />
        <vers num="snv_91" edition=":x86" />
        <vers num="snv_92" edition="" />
        <vers num="snv_92" edition=":sparc" />
        <vers num="snv_92" edition=":x86" />
        <vers num="snv_93" edition="" />
        <vers num="snv_93" edition=":sparc" />
        <vers num="snv_93" edition=":x86" />
        <vers num="snv_94" edition="" />
        <vers num="snv_94" edition=":x86" />
        <vers num="snv_94" edition=":sparc" />
        <vers num="snv_95" edition="" />
        <vers num="snv_95" edition=":x86" />
        <vers num="snv_95" edition=":sparc" />
        <vers num="snv_96" edition="" />
        <vers num="snv_96" edition=":sparc" />
        <vers num="snv_96" edition=":x86" />
        <vers num="snv_97" edition="" />
        <vers num="snv_97" edition=":x86" />
        <vers num="snv_97" edition=":sparc" />
        <vers num="snv_98" edition="" />
        <vers num="snv_98" edition=":sparc" />
        <vers num="snv_98" edition=":x86" />
        <vers num="snv_99" edition="" />
        <vers num="snv_99" edition=":sparc" />
        <vers num="snv_99" edition=":x86" />
      </prod>
      <prod vendor="sun" name="solaris">
        <vers num="10" edition="" />
        <vers num="10" edition=":sparc" />
        <vers num="10" edition=":x86" />
        <vers num="8" edition="" />
        <vers num="8" edition=":sparc" />
        <vers num="8" edition=":x86" />
        <vers num="9" edition="" />
        <vers num="9" edition=":x86" />
        <vers num="9" edition=":sparc" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1277" published="2009-04-09" name="CVE-2009-1277" modified="2009-04-09" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in index.php in Gravity Board X (GBX) 2.0 BETA allows remote attackers to execute arbitrary SQL commands via the member_id parameter in a viewprofile action.  NOTE: the board_id issue is already covered by CVE-2008-2996.2.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/49678" source="XF">gravityboardx-index-sql-injection(49678)</ref>
      <ref url="http://www.securityfocus.com/bid/34370" source="BID">34370</ref>
      <ref url="http://www.milw0rm.com/exploits/8350" source="MILW0RM">8350</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gravityboardx" name="gravity_board_x">
        <vers num="2.0" edition="beta" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1278" published="2009-04-09" name="CVE-2009-1278" modified="2009-04-09" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Static code injection vulnerability in forms/ajax/configure.php in Gravity Board X (GBX) 2.0 BETA allows remote attackers to inject arbitrary PHP code into config.php via the configure action to index.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/49679" source="XF">gravityboardx-index-code-execution(49679)</ref>
      <ref url="http://www.securityfocus.com/bid/34370" source="BID">34370</ref>
      <ref url="http://www.milw0rm.com/exploits/8350" source="MILW0RM">8350</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gravityboardx" name="gravity_board_x">
        <vers num="2.0" edition="beta" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2009-1279" published="2009-04-09" name="CVE-2009-1279" modified="2009-04-09" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Joomla! 1.5 through 1.5.9 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors to the (1) com_admin component, (2) com_search component when "Gather Search Statistics" is enabled, and (3) the category view in the com_content component.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/34360" source="BID" patch="1">34360</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/49655" source="XF">admin-search-unspecified-xss(49655)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/49654" source="XF">content-categoryview-xss(49654)</ref>
      <ref url="http://secunia.com/advisories/34551" source="SECUNIA" adv="1">34551</ref>
      <ref url="http://developer.joomla.org/security/news/294-20090302-core-comcontent-xss.html" source="CONFIRM" adv="1">http://developer.joomla.org/security/news/294-20090302-core-comcontent-xss.html</ref>
      <ref url="http://developer.joomla.org/security/news/293-20090301-core-multiple-xsscsrf.html" source="CONFIRM" adv="1">http://developer.joomla.org/security/news/293-20090301-core-multiple-xsscsrf.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="joomla" name="joomla">
        <vers num="1.5" />
        <vers num="1.5.0" edition="beta" />
        <vers num="1.5.0" edition="beta1" />
        <vers num="1.5.0" edition="beta2" />
        <vers num="1.5.0" edition="rc1" />
        <vers num="1.5.1" />
        <vers num="1.5.2" />
        <vers num="1.5.3" />
        <vers num="1.5.4" />
        <vers num="1.5.5" />
        <vers num="1.5.6" />
        <vers num="1.5.7" />
        <vers num="1.5.8" />
        <vers num="1.5.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1280" published="2009-04-09" name="CVE-2009-1280" modified="2009-04-09" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple cross-site request forgery (CSRF) vulnerabilities in the com_media component for Joomla! 1.5.x through 1.5.9 allow remote attackers to hijack the authentication of unspecified victims via unknown vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/49656" source="XF">media-unspecified-csrf(49656)</ref>
      <ref url="http://secunia.com/advisories/34551" source="SECUNIA" adv="1">34551</ref>
      <ref url="http://developer.joomla.org/security/news/293-20090301-core-multiple-xsscsrf.html" source="CONFIRM" adv="1">http://developer.joomla.org/security/news/293-20090301-core-multiple-xsscsrf.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="joomla" name="joomla">
        <vers num="1.5" />
        <vers num="1.5.0" edition="beta" />
        <vers num="1.5.0" edition="beta1" />
        <vers num="1.5.0" edition="beta2" />
        <vers num="1.5.0" edition="rc1" />
        <vers num="1.5.1" />
        <vers num="1.5.2" />
        <vers num="1.5.3" />
        <vers num="1.5.4" />
        <vers num="1.5.5" />
        <vers num="1.5.6" />
        <vers num="1.5.7" />
        <vers num="1.5.8" />
        <vers num="1.5.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1281" published="2009-04-09" name="CVE-2009-1281" modified="2009-04-10" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in glFusion before 1.1.3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.glfusion.org/article.php/glfusion113" source="CONFIRM" patch="1" adv="1">http://www.glfusion.org/article.php/glfusion113</ref>
      <ref url="http://www.securityfocus.com/bid/34377" source="BID">34377</ref>
      <ref url="http://secunia.com/advisories/34575" source="SECUNIA" adv="1">34575</ref>
      <ref url="http://osvdb.org/53287" source="OSVDB">53287</ref>
    </refs>
    <vuln_soft>
      <prod vendor="glfusion" name="glfusion">
        <vers num="1.0.0" />
        <vers num="1.0.1" />
        <vers num="1.1.0" />
        <vers num="1.1.1" />
        <vers prev="1" num="1.1.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1282" published="2009-04-09" name="CVE-2009-1282" modified="2009-04-09" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in private/system/lib-session.php in glFusion 1.1.2 and earlier allows remote attackers to execute arbitrary SQL commands via the glf_session cookie parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/34361" source="BID" patch="1">34361</ref>
      <ref url="http://www.glfusion.org/wiki/doku.php?id=glfusion:whatsnew" source="CONFIRM" patch="1" adv="1">http://www.glfusion.org/wiki/doku.php?id=glfusion:whatsnew</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/49652" source="XF">glfusion-libsession-sql-injection(49652)</ref>
      <ref url="http://www.milw0rm.com/exploits/8347" source="MILW0RM">8347</ref>
      <ref url="http://secunia.com/advisories/34575" source="SECUNIA" adv="1">34575</ref>
      <ref url="http://retrogod.altervista.org/9sg_glfuso_sql_cookies.html" source="MISC">http://retrogod.altervista.org/9sg_glfuso_sql_cookies.html</ref>
      <ref url="http://osvdb.org/53286" source="OSVDB">53286</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=123877379105028&amp;w=2" source="BUGTRAQ">20090403 glFusion &lt;= 1.1.2 COM_applyFilter()/cookies remote blind sql</ref>
    </refs>
    <vuln_soft>
      <prod vendor="glfusion" name="glfusion">
        <vers num="1.0.0" edition="rc1" />
        <vers num="1.0.0" edition="rc2" />
        <vers num="1.0.1" />
        <vers num="1.1.0" edition="rc1" />
        <vers num="1.1.1" />
        <vers prev="1" num="1.1.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1283" published="2009-04-09" name="CVE-2009-1283" modified="2009-04-10" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">glFusion before 1.1.3 performs authentication with a user-provided password hash instead of a password, which allows remote attackers to gain privileges by obtaining the hash and using it in the glf_password cookie, aka "User Masquerading." NOTE: this can be leveraged with a separate SQL injection vulnerability to steal hashes.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.glfusion.org/article.php/glfusion113" source="CONFIRM" patch="1" adv="1">http://www.glfusion.org/article.php/glfusion113</ref>
      <ref url="http://www.milw0rm.com/exploits/8347" source="MILW0RM">8347</ref>
      <ref url="http://www.glfusion.org/wiki/doku.php?id=glfusion:whatsnew" source="CONFIRM" adv="1">http://www.glfusion.org/wiki/doku.php?id=glfusion:whatsnew</ref>
      <ref url="http://secunia.com/advisories/34575" source="SECUNIA" adv="1">34575</ref>
      <ref url="http://retrogod.altervista.org/9sg_glfuso_sql_cookies.html" source="MISC">http://retrogod.altervista.org/9sg_glfuso_sql_cookies.html</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=123877379105028&amp;w=2" source="BUGTRAQ">20090403 glFusion &lt;= 1.1.2 COM_applyFilter()/cookies remote blind sql</ref>
    </refs>
    <vuln_soft>
      <prod vendor="glfusion" name="glfusion">
        <vers num="1.0.0" edition="rc1" />
        <vers num="1.0.0" edition="rc2" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.1.0" edition="rc1" />
        <vers num="1.1.1" />
        <vers prev="1" num="1.1.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1284" published="2009-04-09" name="CVE-2009-1284" modified="2010-05-12" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Buffer overflow in BibTeX 0.99 allows context-dependent attackers to cause a denial of service (memory corruption and crash) via a long .bib bibliography file.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-November/msg00507.html" source="FEDORA">FEDORA-2009-10857</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-November/msg00505.html" source="FEDORA">FEDORA-2009-10730</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=492136" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=492136</ref>
      <ref url="http://www.ubuntu.com/usn/USN-937-1" source="UBUNTU">USN-937-1</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2009/04/01/8" source="MLIST">[oss-security] 20090401 CVE request -- bibtex, pam_ssh</ref>
      <ref url="http://secunia.com/advisories/34445" source="SECUNIA">34445</ref>
      <ref url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=520920" source="CONFIRM">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=520920</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bibtex" name="bibtex">
        <vers num="0.99" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1285" published="2009-04-16" name="CVE-2009-1285" modified="2009-04-28" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Static code injection vulnerability in the getConfigFile function in setup/lib/ConfigFile.class.php in phpMyAdmin 3.x before 3.1.3.2 allows remote attackers to inject arbitrary PHP code into configuration files.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/34526" source="BID" patch="1">34526</ref>
      <ref url="http://www.phpmyadmin.net/home_page/security/PMASA-2009-4.php" source="CONFIRM" patch="1" adv="1">http://www.phpmyadmin.net/home_page/security/PMASA-2009-4.php</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-April/msg00452.html" source="FEDORA">FEDORA-2009-3700</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-April/msg00442.html" source="FEDORA">FEDORA-2009-3692</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1045" source="VUPEN">ADV-2009-1045</ref>
      <ref url="http://secunia.com/advisories/34741" source="SECUNIA">34741</ref>
      <ref url="http://secunia.com/advisories/34727" source="SECUNIA">34727</ref>
      <ref url="http://phpmyadmin.svn.sourceforge.net/viewvc/phpmyadmin/branches/MAINT_3_1_3/phpMyAdmin/setup/lib/ConfigFile.class.php?r1=12248&amp;r2=12301&amp;pathrev=12342" source="CONFIRM">http://phpmyadmin.svn.sourceforge.net/viewvc/phpmyadmin/branches/MAINT_3_1_3/phpMyAdmin/setup/lib/ConfigFile.class.php?r1=12248&amp;r2=12301&amp;pathrev=12342</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpmyadmin" name="phpmyadmin">
        <vers num="3.0.0" />
        <vers num="3.0.1" />
        <vers num="3.1.0" />
        <vers num="3.1.0.0" />
        <vers num="3.1.1" edition="rc1" />
        <vers num="3.1.2" edition="rc1" />
        <vers num="3.1.3" edition="1" />
        <vers num="3.1.3" edition="rc1" />
        <vers num="3.1.3.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1286" published="2009-04-13" name="CVE-2009-1286" modified="2009-04-14" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The IMAP task in the server in IBM Lotus Domino 8.0.2 before FP1 IF1 and 8.5 before IF3 allows remote attackers to cause a denial of service (daemon crash) via a MIME e-mail message with RFC822 attachments (aka blobs) containing malformed root entities.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg21381562" source="CONFIRM" patch="1">http://www-01.ibm.com/support/docview.wss?uid=swg21381562</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg21379915" source="CONFIRM" patch="1" adv="1">http://www-01.ibm.com/support/docview.wss?uid=swg21379915</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0986" source="VUPEN" adv="1">ADV-2009-0986</ref>
      <ref url="http://www.securityfocus.com/bid/34441" source="BID">34441</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg21381566" source="CONFIRM">http://www-01.ibm.com/support/docview.wss?uid=swg21381566</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg21379894" source="CONFIRM">http://www-01.ibm.com/support/docview.wss?uid=swg21379894</ref>
      <ref url="http://securitytracker.com/id?1022024" source="SECTRACK">1022024</ref>
      <ref url="http://secunia.com/advisories/34657" source="SECUNIA" adv="1">34657</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="lotus_domino">
        <vers num="8.0" />
        <vers num="8.0.1" />
        <vers num="8.0.2" />
        <vers num="8.0.2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1287" published="2009-04-13" name="CVE-2009-1287" modified="2009-05-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Cisco Subscriber Edge Services Manager (SESM) allows remote attackers to inject arbitrary web script or HTML via the URI.  NOTE: some of these details are obtained from third party information.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/50349" source="XF">sesm-unspecified-xss(50349)</ref>
      <ref url="http://www.xc0re.net/index.php?p=1_17_Cisco-Subscriber-Edge-Services-Manager-Multiple-Vulnerabilities" source="MISC">http://www.xc0re.net/index.php?p=1_17_Cisco-Subscriber-Edge-Services-Manager-Multiple-Vulnerabilities</ref>
      <ref url="http://www.securityfocus.com/bid/34454" source="BID">34454</ref>
      <ref url="http://securitytracker.com/id?1022030" source="SECTRACK">1022030</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="subscriber_edge_services_manager">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1288" published="2009-04-13" name="CVE-2009-1288" modified="2009-04-18" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in the Advanced Management Module (AMM) on the IBM BladeCenter, including the BladeCenter H with BPET36H 54, allow remote attackers to inject arbitrary web script or HTML via (1) the username in a login action or (2) the PATH parameter to private/file_management.ssi in the File manager.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/34447" source="BID">34447</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/502582/100/0/threaded" source="BUGTRAQ">20090409 IBM BladeCenter Advanced Management Module Multiple vulnerabilities</ref>
      <ref url="http://www.louhinetworks.fi/advisory/ibm_090409.txt" source="MISC">http://www.louhinetworks.fi/advisory/ibm_090409.txt</ref>
      <ref url="http://securitytracker.com/id?1022025" source="SECTRACK">1022025</ref>
      <ref url="http://osvdb.org/53658" source="OSVDB">53658</ref>
      <ref url="http://osvdb.org/53657" source="OSVDB">53657</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="advanced_management_module">
        <vers num="1.36h" />
      </prod>
      <prod vendor="ibm" name="bladecenter">
        <vers num="e" edition="" />
        <vers num="e" edition=":8677" />
        <vers num="e" edition=":7967" />
        <vers num="e" edition=":1881" />
        <vers num="h" edition="" />
        <vers num="h" edition=":8852" />
        <vers num="h" edition=":7989" />
        <vers num="hc10" edition="" />
        <vers num="hc10" edition=":7996" />
        <vers num="hs12" edition="" />
        <vers num="hs12" edition=":1916" />
        <vers num="hs12" edition=":8014" />
        <vers num="hs12" edition=":8028" />
        <vers num="hs20" edition="" />
        <vers num="hs20" edition=":1883" />
        <vers num="hs21" edition="" />
        <vers num="hs21" edition=":1885" />
        <vers num="hs21" edition=":8853" />
        <vers num="hs21_xm" edition="" />
        <vers num="hs21_xm" edition=":7995" />
        <vers num="hs21_xm" edition=":1915" />
        <vers num="ht" edition="" />
        <vers num="ht" edition=":8740" />
        <vers num="ht" edition=":8750" />
        <vers num="js12" edition="" />
        <vers num="js12" edition=":7998" />
        <vers num="js21" edition="" />
        <vers num="js21" edition=":8844" />
        <vers num="js21" edition=":7988" />
        <vers num="js22" edition="" />
        <vers num="js22" edition=":7998" />
        <vers num="ls20" edition="" />
        <vers num="ls20" edition=":8850" />
        <vers num="ls21" edition="" />
        <vers num="ls21" edition=":7971" />
        <vers num="ls41" edition="" />
        <vers num="ls41" edition=":7972" />
        <vers num="qs21" edition="" />
        <vers num="qs21" edition=":0792" />
        <vers num="qs22" edition="" />
        <vers num="qs22" edition=":0793" />
        <vers num="s" edition="" />
        <vers num="s" edition=":8886" />
        <vers num="s" edition=":1948" />
        <vers num="t" edition="" />
        <vers num="t" edition=":8720" />
        <vers num="t" edition=":8730" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1289" published="2009-04-13" name="CVE-2009-1289" modified="2009-04-18" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:N/A:N)" CVSS_score="4.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.0" CVSS_base_score="4.0">
    <desc>
      <descript source="cve">private/login.ssi in the Advanced Management Module (AMM) on the IBM BladeCenter, including the BladeCenter H with BPET36H 54, allows remote attackers to discover the access roles and scopes of arbitrary user accounts via a modified WEBINDEX parameter.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/34447" source="BID">34447</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/502582/100/0/threaded" source="BUGTRAQ">20090409 IBM BladeCenter Advanced Management Module Multiple vulnerabilities</ref>
      <ref url="http://www.louhinetworks.fi/advisory/ibm_090409.txt" source="MISC">http://www.louhinetworks.fi/advisory/ibm_090409.txt</ref>
      <ref url="http://securitytracker.com/id?1022025" source="SECTRACK">1022025</ref>
      <ref url="http://osvdb.org/53659" source="OSVDB">53659</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="advanced_management_module">
        <vers num="1.36h" />
      </prod>
      <prod vendor="ibm" name="bladecenter">
        <vers num="e" edition="" />
        <vers num="e" edition=":8677" />
        <vers num="e" edition=":7967" />
        <vers num="e" edition=":1881" />
        <vers num="h" edition="" />
        <vers num="h" edition=":8852" />
        <vers num="h" edition=":7989" />
        <vers num="hc10" edition="" />
        <vers num="hc10" edition=":7996" />
        <vers num="hs12" edition="" />
        <vers num="hs12" edition=":1916" />
        <vers num="hs12" edition=":8014" />
        <vers num="hs12" edition=":8028" />
        <vers num="hs20" edition="" />
        <vers num="hs20" edition=":1883" />
        <vers num="hs21" edition="" />
        <vers num="hs21" edition=":1885" />
        <vers num="hs21" edition=":8853" />
        <vers num="hs21_xm" edition="" />
        <vers num="hs21_xm" edition=":7995" />
        <vers num="hs21_xm" edition=":1915" />
        <vers num="ht" edition="" />
        <vers num="ht" edition=":8740" />
        <vers num="ht" edition=":8750" />
        <vers num="js12" edition="" />
        <vers num="js12" edition=":7998" />
        <vers num="js21" edition="" />
        <vers num="js21" edition=":8844" />
        <vers num="js21" edition=":7988" />
        <vers num="js22" edition="" />
        <vers num="js22" edition=":7998" />
        <vers num="ls20" edition="" />
        <vers num="ls20" edition=":8850" />
        <vers num="ls21" edition="" />
        <vers num="ls21" edition=":7971" />
        <vers num="ls41" edition="" />
        <vers num="ls41" edition=":7972" />
        <vers num="qs21" edition="" />
        <vers num="qs21" edition=":0792" />
        <vers num="qs22" edition="" />
        <vers num="qs22" edition=":0793" />
        <vers num="s" edition="" />
        <vers num="s" edition=":8886" />
        <vers num="s" edition=":1948" />
        <vers num="t" edition="" />
        <vers num="t" edition=":8720" />
        <vers num="t" edition=":8730" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1290" published="2009-04-13" name="CVE-2009-1290" modified="2009-04-18" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple cross-site request forgery (CSRF) vulnerabilities in the web administration interface in the Advanced Management Module (AMM) on the IBM BladeCenter, including the BladeCenter H with BPET36H 54, allow remote attackers to hijack the authentication of administrators, as demonstrated by a power-off request to the private/blade_power_action script.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/34447" source="BID">34447</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/502582/100/0/threaded" source="BUGTRAQ">20090409 IBM BladeCenter Advanced Management Module Multiple vulnerabilities</ref>
      <ref url="http://www.louhinetworks.fi/advisory/ibm_090409.txt" source="MISC">http://www.louhinetworks.fi/advisory/ibm_090409.txt</ref>
      <ref url="http://securitytracker.com/id?1022025" source="SECTRACK">1022025</ref>
      <ref url="http://osvdb.org/53660" source="OSVDB">53660</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="advanced_management_module">
        <vers num="1.36h" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1291" published="2009-04-30" name="CVE-2009-1291" modified="2009-05-14" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Stack-based buffer overflow in TIBCO SmartSockets before 6.8.2, SmartSockets Product Family (aka RTworks) before 4.0.5, and Enterprise Message Service (EMS) 4.0.0 through 5.1.1, as used in SmartSockets Server and RTworks Server (aka RTserver), SmartSockets client libraries and add-on products, RTworks libraries and components, EMS Server (aka tibemsd), SmartMQ, iProcess Engine, ActiveMatrix products, and CA Enterprise Communicator, allows remote attackers to execute arbitrary code via "inbound data," as demonstrated by requests to the UDP interface of the RTserver component, and data injection into the TCP stream to tibemsd.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.tibco.com/services/support/advisories/default.jsp" source="CONFIRM" patch="1" adv="1">http://www.tibco.com/services/support/advisories/default.jsp</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/50214" source="XF">smartsockets-udp-bo(50214)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1198" source="VUPEN" adv="1">ADV-2009-1198</ref>
      <ref url="http://www.tibco.com/services/support/advisories/smartsockets-sspfm-ems_advisory_20090428.jsp" source="CONFIRM" adv="1">http://www.tibco.com/services/support/advisories/smartsockets-sspfm-ems_advisory_20090428.jsp</ref>
      <ref url="http://www.tibco.com/multimedia/security_advisory_smartsockets_tcm8-7560.txt" source="CONFIRM" adv="1">http://www.tibco.com/multimedia/security_advisory_smartsockets_tcm8-7560.txt</ref>
      <ref url="http://www.tibco.com/multimedia/security_advisory_rtworks_tcm8-7559.txt" source="CONFIRM" adv="1">http://www.tibco.com/multimedia/security_advisory_rtworks_tcm8-7559.txt</ref>
      <ref url="http://www.tibco.com/multimedia/security_advisory_ems_tcm8-7558.txt" source="CONFIRM" adv="1">http://www.tibco.com/multimedia/security_advisory_ems_tcm8-7558.txt</ref>
      <ref url="http://www.securityfocus.com/bid/34754" source="BID">34754</ref>
      <ref url="http://www.harmonysecurity.com/blog/2009/04/tibco-smartsockets-stack-buffer.html" source="MISC">http://www.harmonysecurity.com/blog/2009/04/tibco-smartsockets-stack-buffer.html</ref>
      <ref url="http://securitytracker.com/id?1022129" source="SECTRACK">1022129</ref>
      <ref url="http://secunia.com/advisories/34911" source="SECUNIA" adv="1">34911</ref>
      <ref url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=785" source="IDEFENSE">20090428 TIBCO SmartSockets Stack Buffer Overflow Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="tibco" name="enterprise_message_service">
        <vers num="4.0.0" />
        <vers num="4.1.0" />
        <vers num="4.2.0" />
        <vers num="4.3.0" />
        <vers num="4.4.1" />
        <vers num="4.4.2" />
        <vers prev="1" num="5.1.1" />
      </prod>
      <prod vendor="tibco" name="rtworks">
        <vers num="4.0.3" />
        <vers num="4.0.4" />
      </prod>
      <prod vendor="tibco" name="smartsockets">
        <vers num="6.8.0" />
        <vers num="6.8.1" />
      </prod>
      <prod vendor="tibco" name="smartsockets_rtserver">
        <vers num="6.8.0" />
        <vers prev="1" num="6.8.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2009-1292" published="2009-04-14" name="CVE-2009-1292" modified="2009-04-23" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">UCM-CQ in IBM Rational ClearCase 7.0.0.x before 7.0.0.5, 7.0.1.x before 7.0.1.4, and 7.1.x before 7.1.0.1 on Linux and AIX places a username and password on the command line, which allows local users to obtain credentials by listing the process.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg1PK75832" source="AIXAPAR" patch="1" adv="1">PK75832</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/49836" source="XF">clearcase-ucmcq-information-disclosure(49836)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1017" source="VUPEN">ADV-2009-1017</ref>
      <ref url="http://www.securitytracker.com/id?1022035" source="SECTRACK">1022035</ref>
      <ref url="http://www.securityfocus.com/bid/34483" source="BID">34483</ref>
      <ref url="http://secunia.com/advisories/34689" source="SECUNIA" adv="1">34689</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="rational_clearcase">
        <vers num="7.0" />
        <vers num="7.0.0.1" />
        <vers num="7.0.0.2" />
        <vers num="7.0.0.3" />
        <vers num="7.0.0.4" />
        <vers num="7.0.1" />
        <vers num="7.0.1.1" />
        <vers num="7.0.1.2" />
        <vers num="7.0.1.3" />
        <vers num="7.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1293" published="2009-04-16" name="CVE-2009-1293" modified="2009-04-23" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The web login functionality (c/portal/login) in Novell Teaming 1.0 through SP3 (1.0.3) generates different error messages depending on whether the username is valid or invalid, which makes it easier for remote attackers to enumerate usernames.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.novell.com/support/php/search.do?cmd=displayKC&amp;docType=kc&amp;externalId=7002997&amp;sliceId=1&amp;docTypeID=DT_TID_1_1&amp;dialogID=33090060&amp;stateId=1%200%2033084737" source="CONFIRM" patch="1" adv="1">http://www.novell.com/support/php/search.do?cmd=displayKC&amp;docType=kc&amp;externalId=7002997&amp;sliceId=1&amp;docTypeID=DT_TID_1_1&amp;dialogID=33090060&amp;stateId=1%200%2033084737</ref>
      <ref url="https://www.sec-consult.com/files/20090415-0-novell-teaming.txt" source="MISC">https://www.sec-consult.com/files/20090415-0-novell-teaming.txt</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1048" source="VUPEN">ADV-2009-1048</ref>
      <ref url="http://www.securitytracker.com/id?1022063" source="SECTRACK">1022063</ref>
      <ref url="http://www.securityfocus.com/bid/34531" source="BID">34531</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/502704/100/0/threaded" source="BUGTRAQ">20090415 SEC Consult SA-20090415-0 :: Multiple Vulnerabilities in Novell Teaming</ref>
      <ref url="http://secunia.com/advisories/34714" source="SECUNIA">34714</ref>
    </refs>
    <vuln_soft>
      <prod vendor="novell" name="teaming">
        <vers num="1.0" edition="sp1" />
        <vers num="1.0" edition="sp2" />
        <vers num="1.0" edition="sp3" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1294" published="2009-04-16" name="CVE-2009-1294" modified="2009-04-23" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in web/guest/home in the Liferay 4.3.0 portal in Novell Teaming 1.0 through SP3 (1.0.3) allow remote attackers to inject arbitrary web script or HTML via the (1) p_p_state or (2) p_p_mode parameters.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.novell.com/support/php/search.do?cmd=displayKC&amp;docType=kc&amp;externalId=7002999&amp;sliceId=1&amp;docTypeID=DT_TID_1_1&amp;dialogID=33090060&amp;stateId=1%200%2033084737" source="CONFIRM" patch="1" adv="1">http://www.novell.com/support/php/search.do?cmd=displayKC&amp;docType=kc&amp;externalId=7002999&amp;sliceId=1&amp;docTypeID=DT_TID_1_1&amp;dialogID=33090060&amp;stateId=1%200%2033084737</ref>
      <ref url="https://www.sec-consult.com/files/20090415-0-novell-teaming.txt" source="MISC">https://www.sec-consult.com/files/20090415-0-novell-teaming.txt</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1048" source="VUPEN">ADV-2009-1048</ref>
      <ref url="http://www.securitytracker.com/id?1022063" source="SECTRACK">1022063</ref>
      <ref url="http://www.securityfocus.com/bid/34531" source="BID">34531</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/502704/100/0/threaded" source="BUGTRAQ">20090415 SEC Consult SA-20090415-0 :: Multiple Vulnerabilities in Novell Teaming</ref>
      <ref url="http://secunia.com/advisories/34714" source="SECUNIA">34714</ref>
    </refs>
    <vuln_soft>
      <prod vendor="liferay" name="liferay_enterprise_portal">
        <vers num="4.3.0" />
      </prod>
      <prod vendor="novell" name="teaming">
        <vers num="1.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2009-1295" published="2009-04-30" name="CVE-2009-1295" modified="2009-05-15" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="1.9" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.4" CVSS_base_score="1.9">
    <desc>
      <descript source="cve">Apport before 0.108.4 on Ubuntu 8.04 LTS, before 0.119.2 on Ubuntu 8.10, and before 1.0-0ubuntu5.2 on Ubuntu 9.04 does not properly remove files from the application's crash-report directory, which allows local users to delete arbitrary files via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="https://launchpad.net/bugs/cve/2009-1295" source="CONFIRM">https://launchpad.net/bugs/cve/2009-1295</ref>
      <ref url="https://bugs.launchpad.net/bugs/357024" source="MISC">https://bugs.launchpad.net/bugs/357024</ref>
      <ref url="http://www.ubuntu.com/usn/usn-768-1" source="UBUNTU" adv="1">USN-768-1</ref>
      <ref url="http://www.securityfocus.com/bid/34776" source="BID">34776</ref>
      <ref url="http://secunia.com/advisories/35065" source="SECUNIA">35065</ref>
      <ref url="http://secunia.com/advisories/34952" source="SECUNIA">34952</ref>
      <ref url="http://secunia.com/advisories/34947" source="SECUNIA">34947</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-05/msg00000.html" source="SUSE">SUSE-SR:2009:010</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apport" name="apport">
        <vers prev="1" num="0.1.0.8.1" />
      </prod>
      <prod vendor="ubuntu" name="ubuntu">
        <vers num="8.0.4_lts" />
        <vers num="8.1.0" />
        <vers num="9.0.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2009-1296" published="2009-06-09" name="CVE-2009-1296" modified="2009-06-23" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:P/I:N/A:N)" CVSS_score="1.9" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.4" CVSS_base_score="1.9">
    <desc>
      <descript source="cve">The eCryptfs support utilities (ecryptfs-utils) 73-0ubuntu6.1 on Ubuntu 9.04 stores the mount passphrase in installation logs, which might allow local users to obtain access to the filesystem by reading the log files from disk.  NOTE: the log files are only readable by root.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/51191" source="XF">ecryptfs-passphrase-info-disclosure(51191)</ref>
      <ref url="http://www.ubuntu.com/usn/usn-783-1" source="UBUNTU" adv="1">USN-783-1</ref>
      <ref url="http://www.securitytracker.com/id?1022347" source="SECTRACK">1022347</ref>
      <ref url="http://secunia.com/advisories/35383" source="SECUNIA" adv="1">35383</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ubuntu" name="73-oubuntu">
        <vers num="6.1" />
      </prod>
      <prod vendor="ubuntu" name="ubuntu">
        <vers num="9.0.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1297" published="2009-10-23" name="CVE-2009-1297" modified="2009-10-29" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="4.4" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.4" CVSS_base_score="4.4">
    <desc>
      <descript source="cve">iscsi_discovery in open-iscsi in SUSE openSUSE 10.3 through 11.1 and SUSE Linux Enterprise (SLE) 10 SP2 and 11 allows local users to overwrite arbitrary files via a symlink attack on an unspecified temporary file that has a predictable name.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-10/msg00001.html" source="SUSE" adv="1">SUSE-SR:2009:016</ref>
    </refs>
    <vuln_soft>
      <prod vendor="novell" name="opensuse">
        <vers num="10.3" />
        <vers num="11.1" />
      </prod>
      <prod vendor="novell" name="suse_linux">
        <vers num="10" edition="sp2" />
        <vers num="10" edition="sp2:enterprise" />
        <vers num="11" edition="-" />
        <vers num="11" edition="-:enterprise" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1298" published="2009-12-08" name="CVE-2009-1298" modified="2010-01-14" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">The ip_frag_reasm function in net/ipv4/ip_fragment.c in the Linux kernel 2.6.32-rc8, and 2.6.29 and later versions before 2.6.32, calls IP_INC_STATS_BH with an incorrect argument, which allows remote attackers to cause a denial of service (NULL pointer dereference and hang) via long IP packets, possibly related to the ip_defrag function.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-December/msg00496.html" source="FEDORA">FEDORA-2009-12825</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-December/msg00453.html" source="FEDORA">FEDORA-2009-12786</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=544144" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=544144</ref>
      <ref url="http://www.ubuntu.com/usn/USN-869-1" source="UBUNTU">USN-869-1</ref>
      <ref url="http://www.theregister.co.uk/2009/12/11/linux_kernel_bugs_patched/" source="MISC">http://www.theregister.co.uk/2009/12/11/linux_kernel_bugs_patched/</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/508517/100/0/threaded" source="BUGTRAQ">20091216 rPSA-2009-0161-1 hwdata kernel</ref>
      <ref url="http://www.osvdb.org/60788" source="OSVDB">60788</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:329" source="MANDRIVA">MDVSA-2009:329</ref>
      <ref url="http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.32" source="CONFIRM">http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.32</ref>
      <ref url="http://wiki.rpath.com/Advisories:rPSA-2009-0161" source="CONFIRM">http://wiki.rpath.com/Advisories:rPSA-2009-0161</ref>
      <ref url="http://twitter.com/spendergrsec/statuses/6339560349" source="MISC">http://twitter.com/spendergrsec/statuses/6339560349</ref>
      <ref url="http://secunia.com/advisories/38017" source="SECUNIA">38017</ref>
      <ref url="http://secunia.com/advisories/37624" source="SECUNIA" adv="1">37624</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-01/msg00000.html" source="SUSE">SUSE-SA:2010:001</ref>
      <ref url="http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commitdiff;h=bbf31bf18d34caa87dd01f08bf713635593697f2" source="CONFIRM">http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commitdiff;h=bbf31bf18d34caa87dd01f08bf713635593697f2</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="kernel">
        <vers num="2.6.28" edition="rc1" />
        <vers num="2.6.28" edition="rc2" />
        <vers num="2.6.28" edition="rc3" />
        <vers num="2.6.28" edition="rc4" />
        <vers num="2.6.28" edition="rc5" />
        <vers num="2.6.28" edition="rc6" />
        <vers num="2.6.28" edition="rc7" />
        <vers num="2.6.28.1" />
        <vers num="2.6.28.10" />
        <vers num="2.6.28.2" />
        <vers num="2.6.28.3" />
        <vers num="2.6.28.4" />
        <vers num="2.6.28.5" />
        <vers num="2.6.28.6" />
        <vers num="2.6.28.7" />
        <vers num="2.6.28.8" />
        <vers num="2.6.28.9" />
        <vers num="2.6.29" edition="rc2" />
        <vers num="2.6.29" edition="rc2_git7" />
        <vers num="2.6.29" edition="rc8-kk" />
        <vers num="2.6.29.1" />
        <vers num="2.6.29.2" />
        <vers num="2.6.29.3" />
        <vers num="2.6.29.4" />
        <vers num="2.6.29.5" />
        <vers num="2.6.29.6" />
        <vers num="2.6.30" edition="rc1" />
        <vers num="2.6.30" edition="rc2" />
        <vers num="2.6.30" edition="rc3" />
        <vers num="2.6.30" edition="rc4" />
        <vers num="2.6.30" edition="rc4:x86_32" />
        <vers num="2.6.30" edition="rc5" />
        <vers num="2.6.30" edition="rc6" />
        <vers num="2.6.30" edition="rc7-git6" />
        <vers num="2.6.30.1" />
        <vers num="2.6.30.2" />
        <vers num="2.6.30.3" />
        <vers num="2.6.30.4" />
        <vers num="2.6.30.5" />
        <vers num="2.6.30.6" />
        <vers num="2.6.30.7" />
        <vers num="2.6.30.8" />
        <vers num="2.6.30.9" />
        <vers num="2.6.31" edition="rc1" />
        <vers num="2.6.31" edition="rc2" />
        <vers num="2.6.31" edition="rc3" />
        <vers num="2.6.31" edition="rc4" />
        <vers num="2.6.31" edition="rc5" />
        <vers num="2.6.31" edition="rc6" />
        <vers num="2.6.31" edition="rc7" />
        <vers num="2.6.31" edition="rc8" />
        <vers num="2.6.31.1" />
        <vers num="2.6.31.2" />
        <vers num="2.6.31.3" />
        <vers num="2.6.31.4" />
        <vers num="2.6.31.5" />
        <vers num="2.6.31.6" />
        <vers prev="1" num="2.6.32" edition="rc1" />
        <vers prev="1" num="2.6.32" edition="rc3" />
        <vers prev="1" num="2.6.32" edition="rc4" />
        <vers prev="1" num="2.6.32" edition="rc5" />
        <vers prev="1" num="2.6.32" edition="rc6" />
        <vers prev="1" num="2.6.32" edition="rc7" />
        <vers prev="1" num="2.6.32" edition="rc8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1299" published="2010-03-18" name="CVE-2009-1299" modified="2010-06-29" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="6.9" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.4" CVSS_base_score="6.9">
    <desc>
      <descript source="cve">The pa_make_secure_dir function in core-util.c in PulseAudio 0.9.10 and 0.9.19 allows local users to change the ownership and permissions of arbitrary files via a symlink attack on a /tmp/.esd-##### temporary file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="https://bugs.edge.launchpad.net/ubuntu/+source/pulseaudio/+bug/509008" source="CONFIRM">https://bugs.edge.launchpad.net/ubuntu/+source/pulseaudio/+bug/509008</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1570" source="VUPEN">ADV-2010-1570</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2010:124" source="MANDRIVA">MDVSA-2010:124</ref>
      <ref url="http://www.debian.org/security/2010/dsa-2017" source="DEBIAN">DSA-2017</ref>
      <ref url="http://git.0pointer.de/?p=pulseaudio.git;a=patch;h=d3efa43d85ac132c6a5a416a2b6f2115f5d577ee" source="CONFIRM">http://git.0pointer.de/?p=pulseaudio.git;a=patch;h=d3efa43d85ac132c6a5a416a2b6f2115f5d577ee</ref>
      <ref url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=573615" source="MISC">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=573615</ref>
    </refs>
    <vuln_soft>
      <prod vendor="pulseaudio" name="pulseaudio">
        <vers num="0.9.10" />
        <vers num="0.9.19" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1300" published="2009-04-16" name="CVE-2009-1300" modified="2009-05-19" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">apt 0.7.20 does not check when the date command returns an "invalid date" error, which can prevent apt from loading security updates in time zones for which DST occurs at midnight.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="https://bugs.launchpad.net/ubuntu/+source/coreutils/+bug/354793" source="CONFIRM">https://bugs.launchpad.net/ubuntu/+source/coreutils/+bug/354793</ref>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-762-1" source="UBUNTU">USN-762-1</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2009/04/08/11" source="MLIST">[oss-security] 20090408 CVE request: apt</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1779" source="DEBIAN">DSA-1779</ref>
      <ref url="http://secunia.com/advisories/34874" source="SECUNIA">34874</ref>
      <ref url="http://secunia.com/advisories/34832" source="SECUNIA">34832</ref>
      <ref url="http://secunia.com/advisories/34829" source="SECUNIA">34829</ref>
      <ref url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=523213" source="CONFIRM">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=523213</ref>
    </refs>
    <vuln_soft>
      <prod vendor="debian" name="apt">
        <vers num="0.7.20" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1301" published="2009-04-16" name="CVE-2009-1301" modified="2009-04-29" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Integer signedness error in the store_id3_text function in the ID3v2 code in mpg123 before 1.7.2 allows remote attackers to cause a denial of service (out-of-bounds memory access) and possibly execute arbitrary code via an ID3 tag with a negative encoding value.  NOTE: some of these details are obtained from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2009/0936" source="VUPEN" patch="1" adv="1">ADV-2009-0936</ref>
      <ref url="http://www.securityfocus.com/bid/34381" source="BID">34381</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:093" source="MANDRIVA">MDVSA-2009:093</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200904-15.xml" source="GENTOO">GLSA-200904-15</ref>
      <ref url="http://sourceforge.net/project/shownotes.php?release_id=673696" source="CONFIRM">http://sourceforge.net/project/shownotes.php?release_id=673696</ref>
      <ref url="http://sourceforge.net/mailarchive/message.php?msg_name=20090405211856.41696433%40sunscreen.local" source="MLIST">[mpg123-devel] 20090405 mpg123 1.7.2 is out -- important security fix!</ref>
      <ref url="http://secunia.com/advisories/34748" source="SECUNIA">34748</ref>
      <ref url="http://secunia.com/advisories/34587" source="SECUNIA" adv="1">34587</ref>
      <ref url="http://bugs.gentoo.org/show_bug.cgi?id=265342" source="CONFIRM">http://bugs.gentoo.org/show_bug.cgi?id=265342</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mpg123" name="mpg123">
        <vers num="0.59m" />
        <vers num="0.59n" />
        <vers num="0.59o" />
        <vers num="0.59p" />
        <vers num="0.59q" />
        <vers num="0.59r" />
        <vers num="0.59s" />
        <vers num="0.62" />
        <vers num="1.6.3" />
        <vers num="1.6.4" />
        <vers num="1.7.0" />
        <vers prev="1" num="1.7.1" />
        <vers num="pre0.59s" />
        <vers num="pre0.59s_r11" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1302" published="2009-04-22" name="CVE-2009-1302" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The browser engine in Mozilla Firefox 3.x before 3.0.9, Thunderbird before 2.0.0.22, and SeaMonkey before 1.1.16 allows remote attackers to cause a denial of service (application crash) and possibly trigger memory corruption via vectors related to (1) nsAsyncInstantiateEvent::Run, (2) nsStyleContext::Destroy, (3) nsComputedDOMStyle::GetWidth, (4) the xslt_attributeset_ImportSameName.html test case for the XSLT stylesheet compiler, (5) nsXULDocument::SynchronizeBroadcastListener, (6) IsBindingAncestor, (7) PL_DHashTableOperate and nsEditor::EndUpdateViewBatch, and (8) gfxSkipCharsIterator::SetOffsets, and other vectors.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-April/msg00683.html" source="FEDORA">FEDORA-2009-3875</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=483444" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=483444</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=477775" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=477775</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=467881" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=467881</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=462517" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=462517</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=461053" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=461053</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=454276" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=454276</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=432114" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=432114</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=431260" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=431260</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=428113" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=428113</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1125" source="VUPEN">ADV-2009-1125</ref>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-764-1" source="UBUNTU">USN-764-1</ref>
      <ref url="http://www.slackware.com/security/viewer.php?l=slackware-security&amp;y=2009&amp;m=slackware-security.454275" source="SLACKWARE">SSA:2009-178-01</ref>
      <ref url="http://www.securitytracker.com/id?1022090" source="SECTRACK">1022090</ref>
      <ref url="http://www.securityfocus.com/bid/34656" source="BID">34656</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-0436.html" source="REDHAT">RHSA-2009:0436</ref>
      <ref url="http://www.mozilla.org/security/announce/2009/mfsa2009-14.html" source="CONFIRM" adv="1">http://www.mozilla.org/security/announce/2009/mfsa2009-14.html</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:141" source="MANDRIVA">MDVSA-2009:141</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:111" source="MANDRIVA">MDVSA-2009:111</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1830" source="DEBIAN">DSA-1830</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1797" source="DEBIAN">DSA-1797</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-264308-1" source="SUNALERT">264308</ref>
      <ref url="http://secunia.com/advisories/35602" source="SECUNIA">35602</ref>
      <ref url="http://secunia.com/advisories/35065" source="SECUNIA">35065</ref>
      <ref url="http://secunia.com/advisories/35042" source="SECUNIA">35042</ref>
      <ref url="http://secunia.com/advisories/34894" source="SECUNIA">34894</ref>
      <ref url="http://secunia.com/advisories/34843" source="SECUNIA">34843</ref>
      <ref url="http://secunia.com/advisories/34780" source="SECUNIA">34780</ref>
      <ref url="http://secunia.com/advisories/34758" source="SECUNIA">34758</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7030" source="OVAL">oval:org.mitre.oval:def:7030</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6170" source="OVAL">oval:org.mitre.oval:def:6170</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6070" source="OVAL">oval:org.mitre.oval:def:6070</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5527" source="OVAL">oval:org.mitre.oval:def:5527</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10106" source="OVAL">oval:org.mitre.oval:def:10106</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-05/msg00000.html" source="SUSE">SUSE-SR:2009:010</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="3.0" />
        <vers num="3.0.1" />
        <vers num="3.0.2" />
        <vers num="3.0.3" />
        <vers num="3.0.4" />
        <vers num="3.0.5" />
        <vers num="3.0.6" />
        <vers num="3.0.7" />
        <vers num="3.0.8" />
      </prod>
      <prod vendor="mozilla" name="seamonkey">
        <vers num="1.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.5" />
        <vers num="1.0.6" />
        <vers num="1.0.7" />
        <vers num="1.0.8" />
        <vers num="1.0.9" />
        <vers num="1.1" edition="alpha" />
        <vers num="1.1" edition="beta" />
        <vers num="1.1.1" />
        <vers num="1.1.10" />
        <vers num="1.1.11" />
        <vers num="1.1.12" />
        <vers prev="1" num="1.1.13" />
        <vers num="1.1.14" />
        <vers num="1.1.15" />
        <vers num="1.1.2" />
        <vers num="1.1.3" />
        <vers num="1.1.4" />
        <vers num="1.1.5" />
        <vers num="1.1.6" />
        <vers num="1.1.7" />
        <vers num="1.1.8" />
        <vers num="1.1.9" />
      </prod>
      <prod vendor="mozilla" name="thunderbird">
        <vers num="1.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.5" edition="beta" />
        <vers num="1.0.6" />
        <vers num="1.0.7" />
        <vers num="1.0.8" />
        <vers num="1.5" edition="beta2" />
        <vers num="1.5.0.1" />
        <vers num="1.5.0.10" />
        <vers num="1.5.0.11" />
        <vers num="1.5.0.12" />
        <vers num="1.5.0.13" />
        <vers num="1.5.0.14" />
        <vers num="1.5.0.2" />
        <vers num="1.5.0.3" />
        <vers num="1.5.0.4" />
        <vers num="1.5.0.5" />
        <vers num="1.5.0.6" />
        <vers num="1.5.0.7" />
        <vers num="1.5.0.8" />
        <vers num="1.5.0.9" />
        <vers num="1.5.1" />
        <vers num="1.5.2" />
        <vers num="2.0.0.0" />
        <vers num="2.0.0.12" />
        <vers num="2.0.0.14" />
        <vers num="2.0.0.16" />
        <vers num="2.0.0.17" />
        <vers num="2.0.0.18" />
        <vers prev="1" num="2.0.0.19" />
        <vers num="2.0.0.20" />
        <vers num="2.0.0.21" />
        <vers num="2.0.0.4" />
        <vers num="2.0.0.5" />
        <vers num="2.0.0.6" />
        <vers num="2.0.0.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1303" published="2009-04-22" name="CVE-2009-1303" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The browser engine in Mozilla Firefox before 3.0.9, Thunderbird before 2.0.0.22, and SeaMonkey before 1.1.16 allows remote attackers to cause a denial of service (application crash) and possibly trigger memory corruption via vectors related to nsSVGElement::BindToTree.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-April/msg00683.html" source="FEDORA">FEDORA-2009-3875</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=453736" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=453736</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1125" source="VUPEN">ADV-2009-1125</ref>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-764-1" source="UBUNTU">USN-764-1</ref>
      <ref url="http://www.ubuntu.com/usn/usn-782-1" source="UBUNTU">USN-782-1</ref>
      <ref url="http://www.slackware.com/security/viewer.php?l=slackware-security&amp;y=2009&amp;m=slackware-security.454275" source="SLACKWARE">SSA:2009-178-01</ref>
      <ref url="http://www.securitytracker.com/id?1022090" source="SECTRACK">1022090</ref>
      <ref url="http://www.securityfocus.com/bid/34656" source="BID">34656</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-1126.html" source="REDHAT">RHSA-2009:1126</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-1125.html" source="REDHAT">RHSA-2009:1125</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-0436.html" source="REDHAT">RHSA-2009:0436</ref>
      <ref url="http://www.mozilla.org/security/announce/2009/mfsa2009-14.html" source="CONFIRM" adv="1">http://www.mozilla.org/security/announce/2009/mfsa2009-14.html</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:141" source="MANDRIVA">MDVSA-2009:141</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:111" source="MANDRIVA">MDVSA-2009:111</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1830" source="DEBIAN">DSA-1830</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1797" source="DEBIAN">DSA-1797</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-264308-1" source="SUNALERT">264308</ref>
      <ref url="http://secunia.com/advisories/35602" source="SECUNIA">35602</ref>
      <ref url="http://secunia.com/advisories/35536" source="SECUNIA">35536</ref>
      <ref url="http://secunia.com/advisories/35065" source="SECUNIA">35065</ref>
      <ref url="http://secunia.com/advisories/35042" source="SECUNIA">35042</ref>
      <ref url="http://secunia.com/advisories/34894" source="SECUNIA">34894</ref>
      <ref url="http://secunia.com/advisories/34844" source="SECUNIA">34844</ref>
      <ref url="http://secunia.com/advisories/34843" source="SECUNIA">34843</ref>
      <ref url="http://secunia.com/advisories/34780" source="SECUNIA">34780</ref>
      <ref url="http://secunia.com/advisories/34758" source="SECUNIA">34758</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2009-0437.html" source="REDHAT">RHSA-2009:0437</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9455" source="OVAL">oval:org.mitre.oval:def:9455</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6646" source="OVAL">oval:org.mitre.oval:def:6646</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6151" source="OVAL">oval:org.mitre.oval:def:6151</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5992" source="OVAL">oval:org.mitre.oval:def:5992</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5810" source="OVAL">oval:org.mitre.oval:def:5810</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-05/msg00000.html" source="SUSE">SUSE-SR:2009:010</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="0.1" />
        <vers num="0.10" />
        <vers num="0.10.1" />
        <vers num="0.2" />
        <vers num="0.3" />
        <vers num="0.4" />
        <vers num="0.5" />
        <vers num="0.6" />
        <vers num="0.6.1" />
        <vers num="0.7" />
        <vers num="0.7.1" />
        <vers num="0.8" />
        <vers num="0.9" edition="rc" />
        <vers num="0.9.1" />
        <vers num="0.9.2" />
        <vers num="0.9.3" />
        <vers num="0.9_rc" />
        <vers num="1.0" edition="preview_release" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.5" />
        <vers num="1.0.6" edition="" />
        <vers num="1.0.6" edition=":linux" />
        <vers num="1.0.7" />
        <vers num="1.0.8" />
        <vers num="1.5" edition="beta1" />
        <vers num="1.5" edition="beta2" />
        <vers num="1.5.0.1" />
        <vers num="1.5.0.10" />
        <vers num="1.5.0.11" />
        <vers num="1.5.0.12" />
        <vers num="1.5.0.2" />
        <vers num="1.5.0.3" />
        <vers num="1.5.0.4" />
        <vers num="1.5.0.5" />
        <vers num="1.5.0.6" />
        <vers num="1.5.0.7" />
        <vers num="1.5.0.8" />
        <vers num="1.5.0.9" />
        <vers num="1.5.1" />
        <vers num="1.5.2" />
        <vers num="1.5.3" />
        <vers num="1.5.4" />
        <vers num="1.5.5" />
        <vers num="1.5.6" />
        <vers num="1.5.7" />
        <vers num="1.5.8" />
        <vers num="1.8" />
        <vers num="2.0" edition="beta1" />
        <vers num="2.0" edition="beta_1" />
        <vers num="2.0" edition="rc2" />
        <vers num="2.0" edition="rc3" />
        <vers num="2.0.0.1" />
        <vers num="2.0.0.10" />
        <vers num="2.0.0.11" />
        <vers num="2.0.0.12" />
        <vers num="2.0.0.13" />
        <vers num="2.0.0.14" />
        <vers num="2.0.0.15" />
        <vers num="2.0.0.16" />
        <vers num="2.0.0.17" />
        <vers num="2.0.0.18" />
        <vers num="2.0.0.19" />
        <vers num="2.0.0.2" />
        <vers num="2.0.0.20" />
        <vers num="2.0.0.21" />
        <vers num="2.0.0.3" />
        <vers num="2.0.0.4" />
        <vers num="2.0.0.5" />
        <vers num="2.0.0.6" />
        <vers num="2.0.0.7" />
        <vers num="2.0.0.8" />
        <vers num="2.0.0.9" />
        <vers num="3.0" edition="alpha" />
        <vers num="3.0" edition="beta2" />
        <vers num="3.0" edition="beta5" />
        <vers num="3.0.1" />
        <vers num="3.0.2" />
        <vers num="3.0.3" />
        <vers num="3.0.4" />
        <vers num="3.0.5" />
        <vers num="3.0.6" />
        <vers num="3.0.7" />
        <vers prev="1" num="3.0.8" />
      </prod>
      <prod vendor="mozilla" name="seamonkey">
        <vers num="1.0" edition="" />
        <vers num="1.0" edition=":dev" />
        <vers num="1.0" edition="alpha" />
        <vers num="1.0" edition="beta" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.5" />
        <vers num="1.0.6" />
        <vers num="1.0.7" />
        <vers num="1.0.8" />
        <vers num="1.0.9" />
        <vers num="1.0.99" />
        <vers num="1.1" edition="alpha" />
        <vers num="1.1" edition="beta" />
        <vers num="1.1.1" />
        <vers num="1.1.10" />
        <vers num="1.1.11" />
        <vers num="1.1.12" />
        <vers num="1.1.13" />
        <vers num="1.1.14" />
        <vers prev="1" num="1.1.15" />
        <vers num="1.1.2" />
        <vers num="1.1.3" />
        <vers num="1.1.4" />
        <vers num="1.1.5" edition="1.1.10" />
        <vers num="1.1.6" />
        <vers num="1.1.7" />
        <vers num="1.1.8" />
        <vers num="1.1.9" />
        <vers num="1.5.0.10" />
        <vers num="1.5.0.8" />
        <vers num="1.5.0.9" />
      </prod>
      <prod vendor="mozilla" name="thunderbird">
        <vers num="0.1" />
        <vers num="0.2" />
        <vers num="0.3" />
        <vers num="0.4" />
        <vers num="0.5" />
        <vers num="0.6" />
        <vers num="0.7" />
        <vers num="0.7.1" />
        <vers num="0.7.2" />
        <vers num="0.7.3" />
        <vers num="0.8" />
        <vers num="0.9" />
        <vers num="1.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.5" edition="beta" />
        <vers num="1.0.6" />
        <vers num="1.0.7" />
        <vers num="1.0.8" />
        <vers num="1.5" edition="beta2" />
        <vers num="1.5.0.1" />
        <vers num="1.5.0.10" />
        <vers num="1.5.0.11" />
        <vers num="1.5.0.12" />
        <vers num="1.5.0.13" />
        <vers num="1.5.0.14" />
        <vers num="1.5.0.2" />
        <vers num="1.5.0.3" />
        <vers num="1.5.0.4" />
        <vers num="1.5.0.5" />
        <vers num="1.5.0.6" />
        <vers num="1.5.0.7" />
        <vers num="1.5.0.8" />
        <vers num="1.5.0.9" />
        <vers num="1.5.1" />
        <vers num="1.5.2" />
        <vers num="1.7.1" />
        <vers num="1.7.3" />
        <vers num="2.0.0.0" />
        <vers num="2.0.0.1" />
        <vers num="2.0.0.11" />
        <vers num="2.0.0.12" />
        <vers num="2.0.0.13" />
        <vers num="2.0.0.14" />
        <vers num="2.0.0.15" />
        <vers num="2.0.0.16" />
        <vers num="2.0.0.17" />
        <vers num="2.0.0.18" />
        <vers num="2.0.0.19" />
        <vers num="2.0.0.2" />
        <vers num="2.0.0.20" />
        <vers prev="1" num="2.0.0.21" />
        <vers num="2.0.0.3" />
        <vers num="2.0.0.4" />
        <vers num="2.0.0.5" />
        <vers num="2.0.0.6" />
        <vers num="2.0.0.7" />
        <vers num="2.0.0.8" />
        <vers num="2.0.0.9" />
        <vers num="2.0.14" />
        <vers num="2.0_.12" />
        <vers num="2.0_.13" />
        <vers num="2.0_.14" />
        <vers num="2.0_.4" />
        <vers num="2.0_.5" />
        <vers num="2.0_.6" />
        <vers num="2.0_.9" />
        <vers num="2.0_8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1304" published="2009-04-22" name="CVE-2009-1304" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The JavaScript engine in Mozilla Firefox 3.x before 3.0.9, Thunderbird before 2.0.0.22, and SeaMonkey before 1.1.16 allows remote attackers to cause a denial of service (application crash) and possibly trigger memory corruption via vectors involving (1) js_FindPropertyHelper, related to the definitions of Math and Date; and (2) js_CheckRedeclaration.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-April/msg00683.html" source="FEDORA">FEDORA-2009-3875</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=475971" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=475971</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=461158" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=461158</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1125" source="VUPEN">ADV-2009-1125</ref>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-764-1" source="UBUNTU">USN-764-1</ref>
      <ref url="http://www.slackware.com/security/viewer.php?l=slackware-security&amp;y=2009&amp;m=slackware-security.454275" source="SLACKWARE">SSA:2009-178-01</ref>
      <ref url="http://www.securitytracker.com/id?1022090" source="SECTRACK">1022090</ref>
      <ref url="http://www.securityfocus.com/bid/34656" source="BID">34656</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-0436.html" source="REDHAT">RHSA-2009:0436</ref>
      <ref url="http://www.mozilla.org/security/announce/2009/mfsa2009-14.html" source="CONFIRM" adv="1">http://www.mozilla.org/security/announce/2009/mfsa2009-14.html</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:141" source="MANDRIVA">MDVSA-2009:141</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:111" source="MANDRIVA">MDVSA-2009:111</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1797" source="DEBIAN">DSA-1797</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-264308-1" source="SUNALERT">264308</ref>
      <ref url="http://secunia.com/advisories/35602" source="SECUNIA">35602</ref>
      <ref url="http://secunia.com/advisories/35065" source="SECUNIA">35065</ref>
      <ref url="http://secunia.com/advisories/35042" source="SECUNIA">35042</ref>
      <ref url="http://secunia.com/advisories/34894" source="SECUNIA">34894</ref>
      <ref url="http://secunia.com/advisories/34843" source="SECUNIA">34843</ref>
      <ref url="http://secunia.com/advisories/34780" source="SECUNIA">34780</ref>
      <ref url="http://secunia.com/advisories/34758" source="SECUNIA">34758</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9535" source="OVAL">oval:org.mitre.oval:def:9535</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7516" source="OVAL">oval:org.mitre.oval:def:7516</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6015" source="OVAL">oval:org.mitre.oval:def:6015</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5480" source="OVAL">oval:org.mitre.oval:def:5480</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5319" source="OVAL">oval:org.mitre.oval:def:5319</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-05/msg00000.html" source="SUSE">SUSE-SR:2009:010</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="3.0" />
        <vers num="3.0.1" />
        <vers num="3.0.2" />
        <vers num="3.0.3" />
        <vers num="3.0.4" />
        <vers num="3.0.5" />
        <vers num="3.0.6" />
        <vers num="3.0.7" />
        <vers num="3.0.8" />
      </prod>
      <prod vendor="mozilla" name="seamonkey">
        <vers num="1.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.5" />
        <vers num="1.0.6" />
        <vers num="1.0.7" />
        <vers num="1.0.8" />
        <vers num="1.0.9" />
        <vers num="1.1" edition="alpha" />
        <vers num="1.1" edition="beta" />
        <vers num="1.1.1" />
        <vers num="1.1.10" />
        <vers num="1.1.11" />
        <vers num="1.1.12" />
        <vers prev="1" num="1.1.13" />
        <vers num="1.1.14" />
        <vers num="1.1.15" />
        <vers num="1.1.2" />
        <vers num="1.1.3" />
        <vers num="1.1.4" />
        <vers num="1.1.5" />
        <vers num="1.1.6" />
        <vers num="1.1.7" />
        <vers num="1.1.8" />
        <vers num="1.1.9" />
      </prod>
      <prod vendor="mozilla" name="thunderbird">
        <vers num="1.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.5" edition="beta" />
        <vers num="1.0.6" />
        <vers num="1.0.7" />
        <vers num="1.0.8" />
        <vers num="1.5" edition="beta2" />
        <vers num="1.5.0.1" />
        <vers num="1.5.0.10" />
        <vers num="1.5.0.11" />
        <vers num="1.5.0.12" />
        <vers num="1.5.0.13" />
        <vers num="1.5.0.14" />
        <vers num="1.5.0.2" />
        <vers num="1.5.0.3" />
        <vers num="1.5.0.4" />
        <vers num="1.5.0.5" />
        <vers num="1.5.0.6" />
        <vers num="1.5.0.7" />
        <vers num="1.5.0.8" />
        <vers num="1.5.0.9" />
        <vers num="1.5.1" />
        <vers num="1.5.2" />
        <vers num="2.0.0.0" />
        <vers num="2.0.0.12" />
        <vers num="2.0.0.14" />
        <vers num="2.0.0.16" />
        <vers num="2.0.0.17" />
        <vers num="2.0.0.18" />
        <vers prev="1" num="2.0.0.19" />
        <vers num="2.0.0.20" />
        <vers num="2.0.0.21" />
        <vers num="2.0.0.4" />
        <vers num="2.0.0.5" />
        <vers num="2.0.0.6" />
        <vers num="2.0.0.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1305" published="2009-04-22" name="CVE-2009-1305" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The JavaScript engine in Mozilla Firefox before 3.0.9, Thunderbird before 2.0.0.22, and SeaMonkey before 1.1.16 allows remote attackers to cause a denial of service (application crash) and possibly trigger memory corruption via vectors involving JSOP_DEFVAR and properties that lack the JSPROP_PERMANENT attribute.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-April/msg00683.html" source="FEDORA">FEDORA-2009-3875</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=476049" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=476049</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1125" source="VUPEN">ADV-2009-1125</ref>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-764-1" source="UBUNTU">USN-764-1</ref>
      <ref url="http://www.ubuntu.com/usn/usn-782-1" source="UBUNTU">USN-782-1</ref>
      <ref url="http://www.slackware.com/security/viewer.php?l=slackware-security&amp;y=2009&amp;m=slackware-security.454275" source="SLACKWARE">SSA:2009-178-01</ref>
      <ref url="http://www.securitytracker.com/id?1022090" source="SECTRACK">1022090</ref>
      <ref url="http://www.securityfocus.com/bid/34656" source="BID">34656</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-1126.html" source="REDHAT">RHSA-2009:1126</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-1125.html" source="REDHAT">RHSA-2009:1125</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-0436.html" source="REDHAT">RHSA-2009:0436</ref>
      <ref url="http://www.mozilla.org/security/announce/2009/mfsa2009-14.html" source="CONFIRM" adv="1">http://www.mozilla.org/security/announce/2009/mfsa2009-14.html</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:141" source="MANDRIVA">MDVSA-2009:141</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:111" source="MANDRIVA">MDVSA-2009:111</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1797" source="DEBIAN">DSA-1797</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-264308-1" source="SUNALERT">264308</ref>
      <ref url="http://secunia.com/advisories/35602" source="SECUNIA">35602</ref>
      <ref url="http://secunia.com/advisories/35536" source="SECUNIA">35536</ref>
      <ref url="http://secunia.com/advisories/35065" source="SECUNIA">35065</ref>
      <ref url="http://secunia.com/advisories/35042" source="SECUNIA">35042</ref>
      <ref url="http://secunia.com/advisories/34894" source="SECUNIA">34894</ref>
      <ref url="http://secunia.com/advisories/34844" source="SECUNIA">34844</ref>
      <ref url="http://secunia.com/advisories/34843" source="SECUNIA">34843</ref>
      <ref url="http://secunia.com/advisories/34780" source="SECUNIA">34780</ref>
      <ref url="http://secunia.com/advisories/34758" source="SECUNIA">34758</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2009-0437.html" source="REDHAT">RHSA-2009:0437</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6921" source="OVAL">oval:org.mitre.oval:def:6921</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6248" source="OVAL">oval:org.mitre.oval:def:6248</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6232" source="OVAL">oval:org.mitre.oval:def:6232</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6090" source="OVAL">oval:org.mitre.oval:def:6090</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10110" source="OVAL">oval:org.mitre.oval:def:10110</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-05/msg00000.html" source="SUSE">SUSE-SR:2009:010</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="3.0" />
        <vers num="3.0.1" />
        <vers num="3.0.2" />
        <vers num="3.0.3" />
        <vers num="3.0.4" />
        <vers num="3.0.5" />
        <vers num="3.0.6" />
        <vers num="3.0.7" />
        <vers num="3.0.8" />
      </prod>
      <prod vendor="mozilla" name="seamonkey">
        <vers num="1.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.5" />
        <vers num="1.0.6" />
        <vers num="1.0.7" />
        <vers num="1.0.8" />
        <vers num="1.0.9" />
        <vers num="1.1" edition="alpha" />
        <vers num="1.1" edition="beta" />
        <vers num="1.1.1" />
        <vers num="1.1.10" />
        <vers num="1.1.11" />
        <vers num="1.1.12" />
        <vers prev="1" num="1.1.13" />
        <vers num="1.1.14" />
        <vers num="1.1.15" />
        <vers num="1.1.2" />
        <vers num="1.1.3" />
        <vers num="1.1.4" />
        <vers num="1.1.5" />
        <vers num="1.1.6" />
        <vers num="1.1.7" />
        <vers num="1.1.8" />
        <vers num="1.1.9" />
      </prod>
      <prod vendor="mozilla" name="thunderbird">
        <vers num="1.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.5" edition="beta" />
        <vers num="1.0.6" />
        <vers num="1.0.7" />
        <vers num="1.0.8" />
        <vers num="1.5" edition="beta2" />
        <vers num="1.5.0.1" />
        <vers num="1.5.0.10" />
        <vers num="1.5.0.11" />
        <vers num="1.5.0.12" />
        <vers num="1.5.0.13" />
        <vers num="1.5.0.14" />
        <vers num="1.5.0.2" />
        <vers num="1.5.0.3" />
        <vers num="1.5.0.4" />
        <vers num="1.5.0.5" />
        <vers num="1.5.0.6" />
        <vers num="1.5.0.7" />
        <vers num="1.5.0.8" />
        <vers num="1.5.0.9" />
        <vers num="1.5.1" />
        <vers num="1.5.2" />
        <vers num="2.0.0.0" />
        <vers num="2.0.0.12" />
        <vers num="2.0.0.14" />
        <vers num="2.0.0.16" />
        <vers num="2.0.0.17" />
        <vers num="2.0.0.18" />
        <vers prev="1" num="2.0.0.19" />
        <vers num="2.0.0.20" />
        <vers num="2.0.0.21" />
        <vers num="2.0.0.4" />
        <vers num="2.0.0.5" />
        <vers num="2.0.0.6" />
        <vers num="2.0.0.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1306" published="2009-04-22" name="CVE-2009-1306" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">The jar: URI implementation in Mozilla Firefox before 3.0.9, Thunderbird, and SeaMonkey does not follow the Content-Disposition header of the inner URI, which allows remote attackers to conduct cross-site scripting (XSS) attacks and possibly other attacks via an uploaded .jar file with a "Content-Disposition: attachment" designation.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-April/msg00683.html" source="FEDORA">FEDORA-2009-3875</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=474536" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=474536</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1125" source="VUPEN">ADV-2009-1125</ref>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-764-1" source="UBUNTU">USN-764-1</ref>
      <ref url="http://www.ubuntu.com/usn/usn-782-1" source="UBUNTU">USN-782-1</ref>
      <ref url="http://www.securitytracker.com/id?1022095" source="SECTRACK">1022095</ref>
      <ref url="http://www.securityfocus.com/bid/34656" source="BID">34656</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-1126.html" source="REDHAT">RHSA-2009:1126</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-1125.html" source="REDHAT">RHSA-2009:1125</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-0436.html" source="REDHAT">RHSA-2009:0436</ref>
      <ref url="http://www.mozilla.org/security/announce/2009/mfsa2009-16.html" source="CONFIRM" adv="1">http://www.mozilla.org/security/announce/2009/mfsa2009-16.html</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:141" source="MANDRIVA">MDVSA-2009:141</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:111" source="MANDRIVA">MDVSA-2009:111</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1797" source="DEBIAN">DSA-1797</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-264308-1" source="SUNALERT">264308</ref>
      <ref url="http://secunia.com/advisories/35536" source="SECUNIA">35536</ref>
      <ref url="http://secunia.com/advisories/35065" source="SECUNIA">35065</ref>
      <ref url="http://secunia.com/advisories/35042" source="SECUNIA">35042</ref>
      <ref url="http://secunia.com/advisories/34894" source="SECUNIA">34894</ref>
      <ref url="http://secunia.com/advisories/34844" source="SECUNIA">34844</ref>
      <ref url="http://secunia.com/advisories/34843" source="SECUNIA">34843</ref>
      <ref url="http://secunia.com/advisories/34780" source="SECUNIA">34780</ref>
      <ref url="http://secunia.com/advisories/34758" source="SECUNIA">34758</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2009-0437.html" source="REDHAT">RHSA-2009:0437</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6710" source="OVAL">oval:org.mitre.oval:def:6710</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6312" source="OVAL">oval:org.mitre.oval:def:6312</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6194" source="OVAL">oval:org.mitre.oval:def:6194</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6021" source="OVAL">oval:org.mitre.oval:def:6021</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10150" source="OVAL">oval:org.mitre.oval:def:10150</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-05/msg00000.html" source="SUSE">SUSE-SR:2009:010</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="0.1" />
        <vers num="0.10" />
        <vers num="0.10.1" />
        <vers num="0.2" />
        <vers num="0.3" />
        <vers num="0.4" />
        <vers num="0.5" />
        <vers num="0.6" />
        <vers num="0.6.1" />
        <vers num="0.7" />
        <vers num="0.7.1" />
        <vers num="0.8" />
        <vers num="0.9" edition="rc" />
        <vers num="0.9.1" />
        <vers num="0.9.2" />
        <vers num="0.9.3" />
        <vers num="0.9_rc" />
        <vers num="1.0" edition="preview_release" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.5" />
        <vers num="1.0.6" edition="" />
        <vers num="1.0.6" edition=":linux" />
        <vers num="1.0.7" />
        <vers num="1.0.8" />
        <vers num="1.5" edition="beta1" />
        <vers num="1.5" edition="beta2" />
        <vers num="1.5.0.1" />
        <vers num="1.5.0.10" />
        <vers num="1.5.0.11" />
        <vers num="1.5.0.12" />
        <vers num="1.5.0.2" />
        <vers num="1.5.0.3" />
        <vers num="1.5.0.4" />
        <vers num="1.5.0.5" />
        <vers num="1.5.0.6" />
        <vers num="1.5.0.7" />
        <vers num="1.5.0.8" />
        <vers num="1.5.0.9" />
        <vers num="1.5.1" />
        <vers num="1.5.2" />
        <vers num="1.5.3" />
        <vers num="1.5.4" />
        <vers num="1.5.5" />
        <vers num="1.5.6" />
        <vers num="1.5.7" />
        <vers num="1.5.8" />
        <vers num="1.8" />
        <vers num="2.0" edition="beta1" />
        <vers num="2.0" edition="beta_1" />
        <vers num="2.0" edition="rc2" />
        <vers num="2.0" edition="rc3" />
        <vers num="2.0.0.1" />
        <vers num="2.0.0.10" />
        <vers num="2.0.0.11" />
        <vers num="2.0.0.12" />
        <vers num="2.0.0.13" />
        <vers num="2.0.0.14" />
        <vers num="2.0.0.15" />
        <vers num="2.0.0.16" />
        <vers num="2.0.0.17" />
        <vers num="2.0.0.18" />
        <vers num="2.0.0.19" />
        <vers num="2.0.0.2" />
        <vers num="2.0.0.20" />
        <vers num="2.0.0.21" />
        <vers num="2.0.0.3" />
        <vers num="2.0.0.4" />
        <vers num="2.0.0.5" />
        <vers num="2.0.0.6" />
        <vers num="2.0.0.7" />
        <vers num="2.0.0.8" />
        <vers num="2.0.0.9" />
        <vers num="2.0_.1" />
        <vers num="2.0_.10" />
        <vers num="2.0_.4" />
        <vers num="2.0_.5" />
        <vers num="2.0_.6" />
        <vers num="2.0_.7" />
        <vers num="2.0_.9" />
        <vers num="2.0_8" />
        <vers num="3.0" edition="alpha" />
        <vers num="3.0" edition="beta2" />
        <vers num="3.0" edition="beta5" />
        <vers num="3.0.1" />
        <vers num="3.0.2" />
        <vers num="3.0.3" />
        <vers num="3.0.4" />
        <vers num="3.0.5" />
        <vers num="3.0.6" />
        <vers num="3.0.7" />
        <vers prev="1" num="3.0.8" />
        <vers num="3.0beta5" />
      </prod>
      <prod vendor="mozilla" name="seamonkey">
        <vers num="" />
      </prod>
      <prod vendor="mozilla" name="thunderbird">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1307" published="2009-04-22" name="CVE-2009-1307" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">The view-source: URI implementation in Mozilla Firefox before 3.0.9, Thunderbird, and SeaMonkey does not properly implement the Same Origin Policy, which allows remote attackers to (1) bypass crossdomain.xml restrictions and connect to arbitrary web sites via a Flash file; (2) read, create, or modify Local Shared Objects via a Flash file; or (3) bypass unspecified restrictions and render content via vectors involving a jar: URI.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=481342" source="CONFIRM" patch="1">https://bugzilla.mozilla.org/show_bug.cgi?id=481342</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-July/msg00504.html" source="FEDORA">FEDORA-2009-7614</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-July/msg00444.html" source="FEDORA">FEDORA-2009-7567</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-April/msg00683.html" source="FEDORA">FEDORA-2009-3875</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1125" source="VUPEN">ADV-2009-1125</ref>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-764-1" source="UBUNTU">USN-764-1</ref>
      <ref url="http://www.ubuntu.com/usn/usn-782-1" source="UBUNTU">USN-782-1</ref>
      <ref url="http://www.slackware.com/security/viewer.php?l=slackware-security&amp;y=2009&amp;m=slackware-security.454275" source="SLACKWARE">SSA:2009-178-01</ref>
      <ref url="http://www.securitytracker.com/id?1022093" source="SECTRACK">1022093</ref>
      <ref url="http://www.securityfocus.com/bid/34656" source="BID">34656</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-1126.html" source="REDHAT">RHSA-2009:1126</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-1125.html" source="REDHAT">RHSA-2009:1125</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-0436.html" source="REDHAT">RHSA-2009:0436</ref>
      <ref url="http://www.mozilla.org/security/announce/2009/mfsa2009-17.html" source="CONFIRM" adv="1">http://www.mozilla.org/security/announce/2009/mfsa2009-17.html</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:141" source="MANDRIVA">MDVSA-2009:141</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:111" source="MANDRIVA">MDVSA-2009:111</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1830" source="DEBIAN">DSA-1830</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1797" source="DEBIAN">DSA-1797</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-264308-1" source="SUNALERT">264308</ref>
      <ref url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2009&amp;m=slackware-security.425408" source="SLACKWARE">SSA:2009-176-01</ref>
      <ref url="http://secunia.com/advisories/35882" source="SECUNIA">35882</ref>
      <ref url="http://secunia.com/advisories/35602" source="SECUNIA">35602</ref>
      <ref url="http://secunia.com/advisories/35561" source="SECUNIA">35561</ref>
      <ref url="http://secunia.com/advisories/35536" source="SECUNIA">35536</ref>
      <ref url="http://secunia.com/advisories/35065" source="SECUNIA">35065</ref>
      <ref url="http://secunia.com/advisories/35042" source="SECUNIA">35042</ref>
      <ref url="http://secunia.com/advisories/34894" source="SECUNIA">34894</ref>
      <ref url="http://secunia.com/advisories/34844" source="SECUNIA">34844</ref>
      <ref url="http://secunia.com/advisories/34843" source="SECUNIA">34843</ref>
      <ref url="http://secunia.com/advisories/34780" source="SECUNIA">34780</ref>
      <ref url="http://secunia.com/advisories/34758" source="SECUNIA">34758</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2009-0437.html" source="REDHAT">RHSA-2009:0437</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7008" source="OVAL">oval:org.mitre.oval:def:7008</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6266" source="OVAL">oval:org.mitre.oval:def:6266</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6154" source="OVAL">oval:org.mitre.oval:def:6154</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5933" source="OVAL">oval:org.mitre.oval:def:5933</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10972" source="OVAL">oval:org.mitre.oval:def:10972</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-05/msg00000.html" source="SUSE">SUSE-SR:2009:010</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="0.1" />
        <vers num="0.10" />
        <vers num="0.10.1" />
        <vers num="0.2" />
        <vers num="0.3" />
        <vers num="0.4" />
        <vers num="0.5" />
        <vers num="0.6" />
        <vers num="0.6.1" />
        <vers num="0.7" />
        <vers num="0.7.1" />
        <vers num="0.8" />
        <vers num="0.9" edition="rc" />
        <vers num="0.9.1" />
        <vers num="0.9.2" />
        <vers num="0.9.3" />
        <vers num="0.9_rc" />
        <vers num="1.0" edition="preview_release" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.5" />
        <vers num="1.0.6" edition="" />
        <vers num="1.0.6" edition=":linux" />
        <vers num="1.0.7" />
        <vers num="1.0.8" />
        <vers num="1.5" edition="beta1" />
        <vers num="1.5" edition="beta2" />
        <vers num="1.5.0.1" />
        <vers num="1.5.0.10" />
        <vers num="1.5.0.11" />
        <vers num="1.5.0.12" />
        <vers num="1.5.0.2" />
        <vers num="1.5.0.3" />
        <vers num="1.5.0.4" />
        <vers num="1.5.0.5" />
        <vers num="1.5.0.6" />
        <vers num="1.5.0.7" />
        <vers num="1.5.0.8" />
        <vers num="1.5.0.9" />
        <vers num="1.5.1" />
        <vers num="1.5.2" />
        <vers num="1.5.3" />
        <vers num="1.5.4" />
        <vers num="1.5.5" />
        <vers num="1.5.6" />
        <vers num="1.5.7" />
        <vers num="1.5.8" />
        <vers num="1.8" />
        <vers num="2.0" edition="beta1" />
        <vers num="2.0" edition="beta_1" />
        <vers num="2.0" edition="rc2" />
        <vers num="2.0" edition="rc3" />
        <vers num="2.0.0.1" />
        <vers num="2.0.0.10" />
        <vers num="2.0.0.11" />
        <vers num="2.0.0.12" />
        <vers num="2.0.0.13" />
        <vers num="2.0.0.14" />
        <vers num="2.0.0.15" />
        <vers num="2.0.0.16" />
        <vers num="2.0.0.17" />
        <vers num="2.0.0.18" />
        <vers num="2.0.0.19" />
        <vers num="2.0.0.2" />
        <vers num="2.0.0.20" />
        <vers num="2.0.0.21" />
        <vers num="2.0.0.3" />
        <vers num="2.0.0.4" />
        <vers num="2.0.0.5" />
        <vers num="2.0.0.6" />
        <vers num="2.0.0.7" />
        <vers num="2.0.0.8" />
        <vers num="2.0.0.9" />
        <vers num="3.0" edition="alpha" />
        <vers num="3.0" edition="beta2" />
        <vers num="3.0" edition="beta5" />
        <vers num="3.0.1" />
        <vers num="3.0.2" />
        <vers num="3.0.3" />
        <vers num="3.0.4" />
        <vers num="3.0.5" />
        <vers num="3.0.6" />
        <vers num="3.0.7" />
        <vers prev="1" num="3.0.8" />
        <vers num="3.0beta5" />
      </prod>
      <prod vendor="mozilla" name="seamonkey">
        <vers num="" />
      </prod>
      <prod vendor="mozilla" name="thunderbird">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1308" published="2009-04-22" name="CVE-2009-1308" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Mozilla Firefox before 3.0.9, Thunderbird, and SeaMonkey allows remote attackers to inject arbitrary web script or HTML via vectors involving XBL JavaScript bindings and remote stylesheets, as exploited in the wild by a March 2009 eBay listing.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-April/msg00683.html" source="FEDORA">FEDORA-2009-3875</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=481558" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=481558</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1125" source="VUPEN">ADV-2009-1125</ref>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-764-1" source="UBUNTU">USN-764-1</ref>
      <ref url="http://www.ubuntu.com/usn/usn-782-1" source="UBUNTU">USN-782-1</ref>
      <ref url="http://www.theregister.co.uk/2009/03/08/ebay_scam_wizardy/" source="MISC">http://www.theregister.co.uk/2009/03/08/ebay_scam_wizardy/</ref>
      <ref url="http://www.securitytracker.com/id?1022097" source="SECTRACK">1022097</ref>
      <ref url="http://www.securityfocus.com/bid/34656" source="BID">34656</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-1126.html" source="REDHAT">RHSA-2009:1126</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-0436.html" source="REDHAT">RHSA-2009:0436</ref>
      <ref url="http://www.mozilla.org/security/announce/2009/mfsa2009-18.html" source="CONFIRM" adv="1">http://www.mozilla.org/security/announce/2009/mfsa2009-18.html</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:141" source="MANDRIVA">MDVSA-2009:141</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:111" source="MANDRIVA">MDVSA-2009:111</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1797" source="DEBIAN">DSA-1797</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-264308-1" source="SUNALERT">264308</ref>
      <ref url="http://secunia.com/advisories/35536" source="SECUNIA">35536</ref>
      <ref url="http://secunia.com/advisories/35065" source="SECUNIA">35065</ref>
      <ref url="http://secunia.com/advisories/35042" source="SECUNIA">35042</ref>
      <ref url="http://secunia.com/advisories/34894" source="SECUNIA">34894</ref>
      <ref url="http://secunia.com/advisories/34843" source="SECUNIA">34843</ref>
      <ref url="http://secunia.com/advisories/34780" source="SECUNIA">34780</ref>
      <ref url="http://secunia.com/advisories/34758" source="SECUNIA">34758</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7285" source="OVAL">oval:org.mitre.oval:def:7285</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6296" source="OVAL">oval:org.mitre.oval:def:6296</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6185" source="OVAL">oval:org.mitre.oval:def:6185</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6173" source="OVAL">oval:org.mitre.oval:def:6173</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10428" source="OVAL">oval:org.mitre.oval:def:10428</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-05/msg00000.html" source="SUSE">SUSE-SR:2009:010</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="0.1" />
        <vers num="0.10" />
        <vers num="0.10.1" />
        <vers num="0.2" />
        <vers num="0.3" />
        <vers num="0.4" />
        <vers num="0.5" />
        <vers num="0.6" />
        <vers num="0.6.1" />
        <vers num="0.7" />
        <vers num="0.7.1" />
        <vers num="0.8" />
        <vers num="0.9" edition="rc" />
        <vers num="0.9.1" />
        <vers num="0.9.2" />
        <vers num="0.9.3" />
        <vers num="0.9_rc" />
        <vers num="1.0" edition="preview_release" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.5" />
        <vers num="1.0.6" edition="" />
        <vers num="1.0.6" edition=":linux" />
        <vers num="1.0.7" />
        <vers num="1.0.8" />
        <vers num="1.5" edition="beta1" />
        <vers num="1.5" edition="beta2" />
        <vers num="1.5.0.1" />
        <vers num="1.5.0.10" />
        <vers num="1.5.0.11" />
        <vers num="1.5.0.12" />
        <vers num="1.5.0.2" />
        <vers num="1.5.0.3" />
        <vers num="1.5.0.4" />
        <vers num="1.5.0.5" />
        <vers num="1.5.0.6" />
        <vers num="1.5.0.7" />
        <vers num="1.5.0.8" />
        <vers num="1.5.0.9" />
        <vers num="1.5.1" />
        <vers num="1.5.2" />
        <vers num="1.5.3" />
        <vers num="1.5.4" />
        <vers num="1.5.5" />
        <vers num="1.5.6" />
        <vers num="1.5.7" />
        <vers num="1.5.8" />
        <vers num="1.8" />
        <vers num="2.0" edition="beta1" />
        <vers num="2.0" edition="beta_1" />
        <vers num="2.0" edition="rc2" />
        <vers num="2.0" edition="rc3" />
        <vers num="2.0.0.1" />
        <vers num="2.0.0.10" />
        <vers num="2.0.0.11" />
        <vers num="2.0.0.12" />
        <vers num="2.0.0.13" />
        <vers num="2.0.0.14" />
        <vers num="2.0.0.15" />
        <vers num="2.0.0.16" />
        <vers num="2.0.0.17" />
        <vers num="2.0.0.18" />
        <vers num="2.0.0.19" />
        <vers num="2.0.0.2" />
        <vers num="2.0.0.20" />
        <vers num="2.0.0.21" />
        <vers num="2.0.0.3" />
        <vers num="2.0.0.4" />
        <vers num="2.0.0.5" />
        <vers num="2.0.0.6" />
        <vers num="2.0.0.7" />
        <vers num="2.0.0.8" />
        <vers num="2.0.0.9" />
        <vers num="2.0_.1" />
        <vers num="2.0_.10" />
        <vers num="2.0_.4" />
        <vers num="2.0_.5" />
        <vers num="2.0_.6" />
        <vers num="2.0_.7" />
        <vers num="2.0_.9" />
        <vers num="2.0_8" />
        <vers num="3.0" edition="alpha" />
        <vers num="3.0" edition="beta2" />
        <vers num="3.0" edition="beta5" />
        <vers num="3.0.1" />
        <vers num="3.0.2" />
        <vers num="3.0.3" />
        <vers num="3.0.4" />
        <vers num="3.0.5" />
        <vers num="3.0.6" />
        <vers num="3.0.7" />
        <vers prev="1" num="3.0.8" />
        <vers num="3.0beta5" />
      </prod>
      <prod vendor="mozilla" name="seamonkey">
        <vers num="" />
      </prod>
      <prod vendor="mozilla" name="thunderbird">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1309" published="2009-04-22" name="CVE-2009-1309" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Mozilla Firefox before 3.0.9, Thunderbird, and SeaMonkey do not properly implement the Same Origin Policy for (1) XMLHttpRequest, involving a mismatch for a document's principal, and (2) XPCNativeWrapper.toString, involving an incorrect __proto__ scope, which allows remote attackers to conduct cross-site scripting (XSS) attacks and possibly other attacks via a crafted document.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-April/msg00683.html" source="FEDORA">FEDORA-2009-3875</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=482206" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=482206</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=478433" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=478433</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1125" source="VUPEN">ADV-2009-1125</ref>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-764-1" source="UBUNTU">USN-764-1</ref>
      <ref url="http://www.ubuntu.com/usn/usn-782-1" source="UBUNTU">USN-782-1</ref>
      <ref url="http://www.securitytracker.com/id?1022094" source="SECTRACK">1022094</ref>
      <ref url="http://www.securityfocus.com/bid/34656" source="BID">34656</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-1126.html" source="REDHAT">RHSA-2009:1126</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-1125.html" source="REDHAT">RHSA-2009:1125</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-0436.html" source="REDHAT">RHSA-2009:0436</ref>
      <ref url="http://www.mozilla.org/security/announce/2009/mfsa2009-19.html" source="CONFIRM" adv="1">http://www.mozilla.org/security/announce/2009/mfsa2009-19.html</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:141" source="MANDRIVA">MDVSA-2009:141</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:111" source="MANDRIVA">MDVSA-2009:111</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1797" source="DEBIAN">DSA-1797</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-264308-1" source="SUNALERT">264308</ref>
      <ref url="http://secunia.com/advisories/35536" source="SECUNIA">35536</ref>
      <ref url="http://secunia.com/advisories/35065" source="SECUNIA">35065</ref>
      <ref url="http://secunia.com/advisories/35042" source="SECUNIA">35042</ref>
      <ref url="http://secunia.com/advisories/34894" source="SECUNIA">34894</ref>
      <ref url="http://secunia.com/advisories/34844" source="SECUNIA">34844</ref>
      <ref url="http://secunia.com/advisories/34843" source="SECUNIA">34843</ref>
      <ref url="http://secunia.com/advisories/34780" source="SECUNIA">34780</ref>
      <ref url="http://secunia.com/advisories/34758" source="SECUNIA">34758</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2009-0437.html" source="REDHAT">RHSA-2009:0437</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9494" source="OVAL">oval:org.mitre.oval:def:9494</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6831" source="OVAL">oval:org.mitre.oval:def:6831</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6139" source="OVAL">oval:org.mitre.oval:def:6139</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5591" source="OVAL">oval:org.mitre.oval:def:5591</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5265" source="OVAL">oval:org.mitre.oval:def:5265</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-05/msg00000.html" source="SUSE">SUSE-SR:2009:010</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="0.1" />
        <vers num="0.10" />
        <vers num="0.10.1" />
        <vers num="0.2" />
        <vers num="0.3" />
        <vers num="0.4" />
        <vers num="0.5" />
        <vers num="0.6" />
        <vers num="0.6.1" />
        <vers num="0.7" />
        <vers num="0.7.1" />
        <vers num="0.8" />
        <vers num="0.9" edition="rc" />
        <vers num="0.9.1" />
        <vers num="0.9.2" />
        <vers num="0.9.3" />
        <vers num="0.9_rc" />
        <vers num="1.0" edition="preview_release" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.5" />
        <vers num="1.0.6" edition="" />
        <vers num="1.0.6" edition=":linux" />
        <vers num="1.0.7" />
        <vers num="1.0.8" />
        <vers num="1.5" edition="beta1" />
        <vers num="1.5" edition="beta2" />
        <vers num="1.5.0.1" />
        <vers num="1.5.0.10" />
        <vers num="1.5.0.11" />
        <vers num="1.5.0.12" />
        <vers num="1.5.0.2" />
        <vers num="1.5.0.3" />
        <vers num="1.5.0.4" />
        <vers num="1.5.0.5" />
        <vers num="1.5.0.6" />
        <vers num="1.5.0.7" />
        <vers num="1.5.0.8" />
        <vers num="1.5.0.9" />
        <vers num="1.5.1" />
        <vers num="1.5.2" />
        <vers num="1.5.3" />
        <vers num="1.5.4" />
        <vers num="1.5.5" />
        <vers num="1.5.6" />
        <vers num="1.5.7" />
        <vers num="1.5.8" />
        <vers num="1.8" />
        <vers num="2.0" edition="beta1" />
        <vers num="2.0" edition="beta_1" />
        <vers num="2.0" edition="rc2" />
        <vers num="2.0" edition="rc3" />
        <vers num="2.0.0.1" />
        <vers num="2.0.0.10" />
        <vers num="2.0.0.11" />
        <vers num="2.0.0.12" />
        <vers num="2.0.0.13" />
        <vers num="2.0.0.14" />
        <vers num="2.0.0.15" />
        <vers num="2.0.0.16" />
        <vers num="2.0.0.17" />
        <vers num="2.0.0.18" />
        <vers num="2.0.0.19" />
        <vers num="2.0.0.2" />
        <vers num="2.0.0.20" />
        <vers num="2.0.0.21" />
        <vers num="2.0.0.3" />
        <vers num="2.0.0.4" />
        <vers num="2.0.0.5" />
        <vers num="2.0.0.6" />
        <vers num="2.0.0.7" />
        <vers num="2.0.0.8" />
        <vers num="2.0.0.9" />
        <vers num="2.0_.1" />
        <vers num="2.0_.10" />
        <vers num="2.0_.4" />
        <vers num="2.0_.5" />
        <vers num="2.0_.6" />
        <vers num="2.0_.7" />
        <vers num="2.0_.9" />
        <vers num="2.0_8" />
        <vers num="3.0" edition="alpha" />
        <vers num="3.0" edition="beta2" />
        <vers num="3.0" edition="beta5" />
        <vers num="3.0.1" />
        <vers num="3.0.2" />
        <vers num="3.0.3" />
        <vers num="3.0.4" />
        <vers num="3.0.5" />
        <vers num="3.0.6" />
        <vers num="3.0.7" />
        <vers prev="1" num="3.0.8" />
        <vers num="3.0beta5" />
      </prod>
      <prod vendor="mozilla" name="seamonkey">
        <vers num="" />
      </prod>
      <prod vendor="mozilla" name="thunderbird">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1310" published="2009-04-22" name="CVE-2009-1310" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the MozSearch plugin implementation in Mozilla Firefox before 3.0.9 allows user-assisted remote attackers to inject arbitrary web script or HTML via a javascript: URI in the SearchForm element.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=483086" source="CONFIRM" patch="1">https://bugzilla.mozilla.org/show_bug.cgi?id=483086</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-April/msg00683.html" source="FEDORA">FEDORA-2009-3875</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1125" source="VUPEN">ADV-2009-1125</ref>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-764-1" source="UBUNTU">USN-764-1</ref>
      <ref url="http://www.securitytracker.com/id?1022097" source="SECTRACK">1022097</ref>
      <ref url="http://www.securityfocus.com/bid/34656" source="BID">34656</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-0436.html" source="REDHAT">RHSA-2009:0436</ref>
      <ref url="http://www.mozilla.org/security/announce/2009/mfsa2009-20.html" source="CONFIRM" adv="1">http://www.mozilla.org/security/announce/2009/mfsa2009-20.html</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:111" source="MANDRIVA">MDVSA-2009:111</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-264308-1" source="SUNALERT">264308</ref>
      <ref url="http://secunia.com/advisories/35065" source="SECUNIA">35065</ref>
      <ref url="http://secunia.com/advisories/34894" source="SECUNIA">34894</ref>
      <ref url="http://secunia.com/advisories/34843" source="SECUNIA">34843</ref>
      <ref url="http://secunia.com/advisories/34758" source="SECUNIA">34758</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6242" source="OVAL">oval:org.mitre.oval:def:6242</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11520" source="OVAL">oval:org.mitre.oval:def:11520</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-05/msg00000.html" source="SUSE">SUSE-SR:2009:010</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="0.1" />
        <vers num="0.10" />
        <vers num="0.10.1" />
        <vers num="0.2" />
        <vers num="0.3" />
        <vers num="0.4" />
        <vers num="0.5" />
        <vers num="0.6" />
        <vers num="0.6.1" />
        <vers num="0.7" />
        <vers num="0.7.1" />
        <vers num="0.8" />
        <vers num="0.9" edition="rc" />
        <vers num="0.9.1" />
        <vers num="0.9.2" />
        <vers num="0.9.3" />
        <vers num="0.9_rc" />
        <vers num="1.0" edition="preview_release" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.5" />
        <vers num="1.0.6" edition="" />
        <vers num="1.0.6" edition=":linux" />
        <vers num="1.0.7" />
        <vers num="1.0.8" />
        <vers num="1.5" edition="beta1" />
        <vers num="1.5" edition="beta2" />
        <vers num="1.5.0.1" />
        <vers num="1.5.0.10" />
        <vers num="1.5.0.11" />
        <vers num="1.5.0.12" />
        <vers num="1.5.0.2" />
        <vers num="1.5.0.3" />
        <vers num="1.5.0.4" />
        <vers num="1.5.0.5" />
        <vers num="1.5.0.6" />
        <vers num="1.5.0.7" />
        <vers num="1.5.0.8" />
        <vers num="1.5.0.9" />
        <vers num="1.5.1" />
        <vers num="1.5.2" />
        <vers num="1.5.3" />
        <vers num="1.5.4" />
        <vers num="1.5.5" />
        <vers num="1.5.6" />
        <vers num="1.5.7" />
        <vers num="1.5.8" />
        <vers num="1.8" />
        <vers num="2.0" edition="beta1" />
        <vers num="2.0" edition="beta_1" />
        <vers num="2.0" edition="rc2" />
        <vers num="2.0" edition="rc3" />
        <vers num="2.0.0.1" />
        <vers num="2.0.0.10" />
        <vers num="2.0.0.11" />
        <vers num="2.0.0.12" />
        <vers num="2.0.0.13" />
        <vers num="2.0.0.14" />
        <vers num="2.0.0.15" />
        <vers num="2.0.0.16" />
        <vers num="2.0.0.17" />
        <vers num="2.0.0.18" />
        <vers num="2.0.0.19" />
        <vers num="2.0.0.2" />
        <vers num="2.0.0.20" />
        <vers num="2.0.0.21" />
        <vers num="2.0.0.3" />
        <vers num="2.0.0.4" />
        <vers num="2.0.0.5" />
        <vers num="2.0.0.6" />
        <vers num="2.0.0.7" />
        <vers num="2.0.0.8" />
        <vers num="2.0.0.9" />
        <vers num="2.0_8" />
        <vers num="3.0" edition="alpha" />
        <vers num="3.0" edition="beta2" />
        <vers num="3.0" edition="beta5" />
        <vers num="3.0.1" />
        <vers num="3.0.2" />
        <vers num="3.0.3" />
        <vers num="3.0.4" />
        <vers num="3.0.5" />
        <vers num="3.0.6" />
        <vers num="3.0.7" />
        <vers prev="1" num="3.0.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1311" published="2009-04-22" name="CVE-2009-1311" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Mozilla Firefox before 3.0.9 and SeaMonkey before 1.1.17 allow user-assisted remote attackers to obtain sensitive information via a web page with an embedded frame, which causes POST data from an outer page to be sent to the inner frame's URL during a SAVEMODE_FILEONLY save of the inner frame.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-July/msg00504.html" source="FEDORA">FEDORA-2009-7614</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-July/msg00444.html" source="FEDORA">FEDORA-2009-7567</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-April/msg00683.html" source="FEDORA">FEDORA-2009-3875</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=471962" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=471962</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1125" source="VUPEN">ADV-2009-1125</ref>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-764-1" source="UBUNTU">USN-764-1</ref>
      <ref url="http://www.securitytracker.com/id?1022097" source="SECTRACK">1022097</ref>
      <ref url="http://www.securityfocus.com/bid/34656" source="BID">34656</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-0436.html" source="REDHAT">RHSA-2009:0436</ref>
      <ref url="http://www.mozilla.org/security/announce/2009/mfsa2009-21.html" source="CONFIRM" adv="1">http://www.mozilla.org/security/announce/2009/mfsa2009-21.html</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:111" source="MANDRIVA">MDVSA-2009:111</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1797" source="DEBIAN">DSA-1797</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-264308-1" source="SUNALERT">264308</ref>
      <ref url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2009&amp;m=slackware-security.425408" source="SLACKWARE">SSA:2009-176-01</ref>
      <ref url="http://secunia.com/advisories/35882" source="SECUNIA">35882</ref>
      <ref url="http://secunia.com/advisories/35561" source="SECUNIA">35561</ref>
      <ref url="http://secunia.com/advisories/35065" source="SECUNIA">35065</ref>
      <ref url="http://secunia.com/advisories/35042" source="SECUNIA">35042</ref>
      <ref url="http://secunia.com/advisories/34894" source="SECUNIA">34894</ref>
      <ref url="http://secunia.com/advisories/34844" source="SECUNIA">34844</ref>
      <ref url="http://secunia.com/advisories/34843" source="SECUNIA">34843</ref>
      <ref url="http://secunia.com/advisories/34758" source="SECUNIA">34758</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2009-0437.html" source="REDHAT">RHSA-2009:0437</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7235" source="OVAL">oval:org.mitre.oval:def:7235</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6222" source="OVAL">oval:org.mitre.oval:def:6222</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6200" source="OVAL">oval:org.mitre.oval:def:6200</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10939" source="OVAL">oval:org.mitre.oval:def:10939</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-05/msg00000.html" source="SUSE">SUSE-SR:2009:010</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="0.1" />
        <vers num="0.10" />
        <vers num="0.10.1" />
        <vers num="0.2" />
        <vers num="0.3" />
        <vers num="0.4" />
        <vers num="0.5" />
        <vers num="0.6" />
        <vers num="0.6.1" />
        <vers num="0.7" />
        <vers num="0.7.1" />
        <vers num="0.8" />
        <vers num="0.9" edition="rc" />
        <vers num="0.9.1" />
        <vers num="0.9.2" />
        <vers num="0.9.3" />
        <vers num="0.9_rc" />
        <vers num="1.0" edition="preview_release" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.5" />
        <vers num="1.0.6" edition="" />
        <vers num="1.0.6" edition=":linux" />
        <vers num="1.0.7" />
        <vers num="1.0.8" />
        <vers num="1.5" edition="beta1" />
        <vers num="1.5" edition="beta2" />
        <vers num="1.5.0.1" />
        <vers num="1.5.0.10" />
        <vers num="1.5.0.11" />
        <vers num="1.5.0.3" />
        <vers num="1.5.0.6" />
        <vers num="1.5.0.7" />
        <vers num="1.5.0.8" />
        <vers num="1.5.0.9" />
        <vers num="1.5.1" />
        <vers num="1.5.2" />
        <vers num="1.5.3" />
        <vers num="1.5.4" />
        <vers num="1.5.5" />
        <vers num="1.5.6" />
        <vers num="1.5.7" />
        <vers num="1.5.8" />
        <vers num="1.8" />
        <vers num="2.0" edition="beta1" />
        <vers num="2.0" edition="beta_1" />
        <vers num="2.0" edition="rc2" />
        <vers num="2.0" edition="rc3" />
        <vers num="2.0.0.1" />
        <vers num="2.0.0.10" />
        <vers num="2.0.0.11" />
        <vers num="2.0.0.12" />
        <vers num="2.0.0.13" />
        <vers num="2.0.0.14" />
        <vers num="2.0.0.15" />
        <vers num="2.0.0.16" />
        <vers num="2.0.0.17" />
        <vers num="2.0.0.18" />
        <vers num="2.0.0.19" />
        <vers num="2.0.0.2" />
        <vers num="2.0.0.20" />
        <vers num="2.0.0.21" />
        <vers num="2.0.0.3" />
        <vers num="2.0.0.4" />
        <vers num="2.0.0.5" />
        <vers num="2.0.0.6" />
        <vers num="2.0.0.7" />
        <vers num="2.0.0.8" />
        <vers num="2.0.0.9" />
        <vers num="2.0_.1" />
        <vers num="2.0_.10" />
        <vers num="2.0_.4" />
        <vers num="2.0_.5" />
        <vers num="2.0_.6" />
        <vers num="2.0_.7" />
        <vers num="2.0_.9" />
        <vers num="2.0_8" />
        <vers num="3.0" edition="alpha" />
        <vers num="3.0" edition="beta2" />
        <vers num="3.0" edition="beta5" />
        <vers num="3.0.1" />
        <vers num="3.0.2" />
        <vers num="3.0.3" />
        <vers num="3.0.4" />
        <vers num="3.0.5" />
        <vers num="3.0.6" />
        <vers num="3.0.7" />
        <vers prev="1" num="3.0.8" />
      </prod>
      <prod vendor="mozilla" name="seamonkey">
        <vers num="1.0" edition="" />
        <vers num="1.0" edition=":dev" />
        <vers num="1.0" edition=":alpha" />
        <vers num="1.0" edition=":beta" />
        <vers num="1.0" edition="alpha" />
        <vers num="1.0" edition="beta" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.5" />
        <vers num="1.0.6" />
        <vers num="1.0.7" />
        <vers num="1.0.8" />
        <vers num="1.0.9" />
        <vers num="1.0.99" />
        <vers num="1.1" edition="" />
        <vers num="1.1" edition=":alpha" />
        <vers num="1.1" edition=":beta" />
        <vers num="1.1" edition="alpha" />
        <vers num="1.1" edition="beta" />
        <vers num="1.1.1" />
        <vers num="1.1.10" />
        <vers num="1.1.11" />
        <vers num="1.1.12" />
        <vers num="1.1.13" />
        <vers num="1.1.14" />
        <vers num="1.1.15" />
        <vers prev="1" num="1.1.16" />
        <vers num="1.1.2" />
        <vers num="1.1.3" />
        <vers num="1.1.4" />
        <vers num="1.1.5" edition="1.1.10" />
        <vers num="1.1.6" />
        <vers num="1.1.7" />
        <vers num="1.1.8" />
        <vers num="1.1.9" />
        <vers num="1.5.0.10" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1312" published="2009-04-22" name="CVE-2009-1312" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Mozilla Firefox before 3.0.9 and SeaMonkey 1.1.17 do not block javascript: URIs in Refresh headers in HTTP responses, which allows remote attackers to conduct cross-site scripting (XSS) attacks via vectors related to (1) injecting a Refresh header or (2) specifying the content of a Refresh header. NOTE: it was later reported that Firefox 3.6 a1 pre and Mozilla 1.7.x and earlier are also affected.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=475636" source="CONFIRM" patch="1" adv="1">https://bugzilla.mozilla.org/show_bug.cgi?id=475636</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-April/msg00683.html" source="FEDORA">FEDORA-2009-3875</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1125" source="VUPEN">ADV-2009-1125</ref>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-764-1" source="UBUNTU">USN-764-1</ref>
      <ref url="http://www.securitytracker.com/id?1022096" source="SECTRACK">1022096</ref>
      <ref url="http://www.securityfocus.com/bid/34656" source="BID">34656</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/504723/100/0/threaded" source="BUGTRAQ">20090703 Re: Cross-Site Scripting vulnerabilities in Mozilla, Internet Explorer, Opera and Chrome</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/504718/100/0/threaded" source="BUGTRAQ">20090702 Cross-Site Scripting vulnerabilities in Mozilla, Internet Explorer, Opera and Chrome</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-0436.html" source="REDHAT">RHSA-2009:0436</ref>
      <ref url="http://www.mozilla.org/security/announce/2009/mfsa2009-22.html" source="CONFIRM" adv="1">http://www.mozilla.org/security/announce/2009/mfsa2009-22.html</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:111" source="MANDRIVA">MDVSA-2009:111</ref>
      <ref url="http://websecurity.com.ua/3386/" source="MISC">http://websecurity.com.ua/3386/</ref>
      <ref url="http://websecurity.com.ua/3275/" source="MISC">http://websecurity.com.ua/3275/</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-264308-1" source="SUNALERT">264308</ref>
      <ref url="http://secunia.com/advisories/35065" source="SECUNIA">35065</ref>
      <ref url="http://secunia.com/advisories/34894" source="SECUNIA">34894</ref>
      <ref url="http://secunia.com/advisories/34844" source="SECUNIA">34844</ref>
      <ref url="http://secunia.com/advisories/34843" source="SECUNIA">34843</ref>
      <ref url="http://secunia.com/advisories/34758" source="SECUNIA">34758</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2009-0437.html" source="REDHAT">RHSA-2009:0437</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9818" source="OVAL">oval:org.mitre.oval:def:9818</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6731" source="OVAL">oval:org.mitre.oval:def:6731</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6131" source="OVAL">oval:org.mitre.oval:def:6131</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6064" source="OVAL">oval:org.mitre.oval:def:6064</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-05/msg00000.html" source="SUSE">SUSE-SR:2009:010</ref>
      <ref url="http://ha.ckers.org/blog/20070309/firefox-header-redirection-javascript-execution/" source="MISC">http://ha.ckers.org/blog/20070309/firefox-header-redirection-javascript-execution/</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="0.1" />
        <vers num="0.10" />
        <vers num="0.10.1" />
        <vers num="0.2" />
        <vers num="0.3" />
        <vers num="0.4" />
        <vers num="0.5" />
        <vers num="0.6" />
        <vers num="0.6.1" />
        <vers num="0.7" />
        <vers num="0.7.1" />
        <vers num="0.8" />
        <vers num="0.9" edition="rc" />
        <vers num="0.9.1" />
        <vers num="0.9.2" />
        <vers num="0.9.3" />
        <vers num="0.9_rc" />
        <vers num="1.0" edition="preview_release" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.5" />
        <vers num="1.0.6" edition="" />
        <vers num="1.0.6" edition=":linux" />
        <vers num="1.0.7" />
        <vers num="1.0.8" />
        <vers num="1.5" edition="beta1" />
        <vers num="1.5" edition="beta2" />
        <vers num="1.5.0.1" />
        <vers num="1.5.0.10" />
        <vers num="1.5.0.11" />
        <vers num="1.5.0.12" />
        <vers num="1.5.0.2" />
        <vers num="1.5.0.3" />
        <vers num="1.5.0.4" />
        <vers num="1.5.0.5" />
        <vers num="1.5.0.6" />
        <vers num="1.5.0.7" />
        <vers num="1.5.0.8" />
        <vers num="1.5.0.9" />
        <vers num="1.5.1" />
        <vers num="1.5.2" />
        <vers num="1.5.3" />
        <vers num="1.5.4" />
        <vers num="1.5.5" />
        <vers num="1.5.6" />
        <vers num="1.5.7" />
        <vers num="1.5.8" />
        <vers num="1.8" />
        <vers num="2.0" edition="beta1" />
        <vers num="2.0" edition="beta_1" />
        <vers num="2.0" edition="rc2" />
        <vers num="2.0" edition="rc3" />
        <vers num="2.0.0.1" />
        <vers num="2.0.0.10" />
        <vers num="2.0.0.11" />
        <vers num="2.0.0.12" />
        <vers num="2.0.0.13" />
        <vers num="2.0.0.14" />
        <vers num="2.0.0.15" />
        <vers num="2.0.0.16" />
        <vers num="2.0.0.17" />
        <vers num="2.0.0.18" />
        <vers num="2.0.0.19" />
        <vers num="2.0.0.2" />
        <vers num="2.0.0.20" />
        <vers num="2.0.0.21" />
        <vers num="2.0.0.3" />
        <vers num="2.0.0.4" />
        <vers num="2.0.0.5" />
        <vers num="2.0.0.6" />
        <vers num="2.0.0.7" />
        <vers num="2.0.0.8" />
        <vers num="2.0.0.9" />
        <vers num="2.0_8" />
        <vers num="3.0" edition="alpha" />
        <vers num="3.0" edition="beta2" />
        <vers num="3.0" edition="beta5" />
        <vers num="3.0.1" />
        <vers num="3.0.2" />
        <vers num="3.0.3" />
        <vers num="3.0.4" />
        <vers num="3.0.5" />
        <vers num="3.0.6" />
        <vers num="3.0.7" />
        <vers prev="1" num="3.0.8" />
        <vers num="3.0beta5" />
      </prod>
      <prod vendor="mozilla" name="seamonkey">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1313" published="2009-04-30" name="CVE-2009-1313" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">The nsTextFrame::ClearTextRun function in layout/generic/nsTextFrameThebes.cpp in Mozilla Firefox 3.0.9 allows remote attackers to cause a denial of service (memory corruption) and probably execute arbitrary code via unspecified vectors.  NOTE: this vulnerability reportedly exists because of an incorrect fix for CVE-2009-1302.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="https://rhn.redhat.com/errata/RHSA-2009-0449.html" source="REDHAT">RHSA-2009:0449</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=497447" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=497447</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=490233" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=490233</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=489676" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=489676</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=489647" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=489647</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1180" source="VUPEN">ADV-2009-1180</ref>
      <ref url="http://www.ubuntu.com/usn/USN-765-1" source="UBUNTU">USN-765-1</ref>
      <ref url="http://www.securityfocus.com/bid/34743" source="BID">34743</ref>
      <ref url="http://www.mozilla.org/security/announce/2009/mfsa2009-23.html" source="CONFIRM">http://www.mozilla.org/security/announce/2009/mfsa2009-23.html</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:111" source="MANDRIVA">MDVSA-2009:111</ref>
      <ref url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2009&amp;m=slackware-security.350967" source="SLACKWARE">SSA:2009-118-01</ref>
      <ref url="http://securitytracker.com/id?1022127" source="SECTRACK">1022127</ref>
      <ref url="http://securitytracker.com/id?1022126" source="SECTRACK">1022126</ref>
      <ref url="http://secunia.com/advisories/34919" source="SECUNIA">34919</ref>
      <ref url="http://secunia.com/advisories/34910" source="SECUNIA">34910</ref>
      <ref url="http://secunia.com/advisories/34866" source="SECUNIA">34866</ref>
      <ref url="http://secunia.com/advisories/34851" source="SECUNIA">34851</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10446" source="OVAL">oval:org.mitre.oval:def:10446</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="3.0.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1314" published="2009-04-16" name="CVE-2009-1314" modified="2009-05-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">body.asp in Web File Explorer 3.1 allows remote attackers to create arbitrary files and execute arbitrary code via the savefile action with a file parameter containing a filename that has an executable extension.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/50389" source="XF">webfileexplorer-body-code-execution(50389)</ref>
      <ref url="http://www.milw0rm.com/exploits/8382" source="MILW0RM">8382</ref>
    </refs>
    <vuln_soft>
      <prod vendor="webfileexplorer" name="web_file_explorer">
        <vers num="3.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1315" published="2009-04-17" name="CVE-2009-1315" modified="2009-08-19" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in AbleSpace 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) gid parameter to groups_profile.php, (2) cat_id and (3) razd_id parameters to adv_cat.php, and the (4) URL to blogs_full.php.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/44847" source="XF">ablespace-advcat-xss(44847)</ref>
      <ref url="http://www.securityfocus.com/bid/34512" source="BID">34512</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/502670/100/0/threaded" source="BUGTRAQ">20090414 [DSECRG-09-037] abk-soft AbleSpace CMS 1.0 - Multiple security vulnerabilities</ref>
      <ref url="http://www.milw0rm.com/exploits/8424" source="MILW0RM">8424</ref>
      <ref url="http://secunia.com/advisories/34663" source="SECUNIA">34663</ref>
      <ref url="http://dsecrg.com/pages/vul/show.php?id=137" source="MISC">http://dsecrg.com/pages/vul/show.php?id=137</ref>
    </refs>
    <vuln_soft>
      <prod vendor="abk-soft" name="ablespace">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1316" published="2009-04-17" name="CVE-2009-1316" modified="2009-04-28" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in AbleSpace 1.0 allow remote attackers to execute arbitrary SQL commands via the (1) eid parameter to events_view.php and the (2) id parameter to events_clndr_view.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/34512" source="BID">34512</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/502670/100/0/threaded" source="BUGTRAQ">20090414 [DSECRG-09-037] abk-soft AbleSpace CMS 1.0 - Multiple security vulnerabilities</ref>
      <ref url="http://www.milw0rm.com/exploits/8424" source="MILW0RM">8424</ref>
      <ref url="http://secunia.com/advisories/34663" source="SECUNIA">34663</ref>
      <ref url="http://dsecrg.com/pages/vul/show.php?id=137" source="MISC">http://dsecrg.com/pages/vul/show.php?id=137</ref>
    </refs>
    <vuln_soft>
      <prod vendor="abk-soft" name="ablespace">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1317" published="2009-04-17" name="CVE-2009-1317" modified="2009-04-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in Aqua CMS 1.1, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) userSID cookie parameter to droplets/functions/base.php and the (2) username parameter to admin/index.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/34516" source="BID">34516</ref>
      <ref url="http://www.milw0rm.com/exploits/8432" source="MILW0RM">8432</ref>
      <ref url="http://secunia.com/advisories/34720" source="SECUNIA" adv="1">34720</ref>
    </refs>
    <vuln_soft>
      <prod vendor="aquacms" name="aqua_cms">
        <vers num="1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1318" published="2009-04-17" name="CVE-2009-1318" modified="2009-04-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)" CVSS_score="6.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.0" CVSS_base_score="6.5">
    <desc>
      <descript source="cve">Directory traversal vulnerability in index.php in Jamroom 3.1.2, 3.2.3 through 3.2.6, 4.0.2, and possibly other versions before 3.4.0 allows remote attackers to include arbitrary files via directory traversal sequences in the t parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/49869" source="XF">jamroom-index-file-include(49869)</ref>
      <ref url="http://www.securityfocus.com/bid/34511" source="BID">34511</ref>
      <ref url="http://www.milw0rm.com/exploits/8423" source="MILW0RM">8423</ref>
      <ref url="http://www.jamroom.net/index.php?m=td_tracker&amp;o=view&amp;id=1470" source="CONFIRM" adv="1">http://www.jamroom.net/index.php?m=td_tracker&amp;o=view&amp;id=1470</ref>
    </refs>
    <vuln_soft>
      <prod vendor="jamroom" name="jamroom">
        <vers num="1.0" edition="b1" />
        <vers num="1.0" edition="b2" />
        <vers num="1.0" edition="b3" />
        <vers num="1.0" edition="b4" />
        <vers num="1.0" edition="b5" />
        <vers num="2.0.9" edition="a" />
        <vers num="2.6.10" />
        <vers num="2.6.11" />
        <vers num="2.6.12" />
        <vers num="2.60" edition="rc2" />
        <vers num="2.60" edition="rc3" />
        <vers num="2.61" />
        <vers num="2.62" />
        <vers num="2.63" />
        <vers num="2.64" />
        <vers num="2.65" />
        <vers num="2.66" />
        <vers num="2.67" />
        <vers num="2.68" />
        <vers num="2.69" />
        <vers num="3.0" edition="b1" />
        <vers num="3.0" edition="b2" />
        <vers num="3.0" edition="b3" />
        <vers num="3.0" edition="b4" />
        <vers num="3.0" edition="b5" />
        <vers num="3.0" edition="b6" />
        <vers num="3.0" edition="b7" />
        <vers num="3.0" edition="b8" />
        <vers num="3.0.1" />
        <vers num="3.0.10" />
        <vers num="3.0.11" />
        <vers num="3.0.12" />
        <vers num="3.0.13" />
        <vers num="3.0.14" />
        <vers num="3.0.15" />
        <vers num="3.0.16" />
        <vers num="3.0.17" />
        <vers num="3.0.18" />
        <vers num="3.0.19" />
        <vers num="3.0.2" />
        <vers num="3.0.20" />
        <vers num="3.0.21" />
        <vers num="3.0.22" />
        <vers num="3.0.23" />
        <vers num="3.0.24" />
        <vers num="3.0.25" />
        <vers num="3.0.26" />
        <vers num="3.0.27" />
        <vers num="3.0.28" />
        <vers num="3.0.29" />
        <vers num="3.0.3" />
        <vers num="3.0.30" />
        <vers num="3.0.4" />
        <vers num="3.0.5" />
        <vers num="3.0.6" />
        <vers num="3.0.7" />
        <vers num="3.0.8" />
        <vers num="3.0.9" />
        <vers num="3.1.0" edition="b1" />
        <vers num="3.1.0" edition="b2" />
        <vers num="3.1.0" edition="b3" />
        <vers num="3.1.1" />
        <vers num="3.1.2" />
        <vers num="3.1.3" />
        <vers num="3.1.4" />
        <vers num="3.1.5" />
        <vers num="3.2.0" />
        <vers num="3.2.1" />
        <vers num="3.2.2" />
        <vers num="3.2.3" />
        <vers num="3.2.4" />
        <vers num="3.2.5" />
        <vers num="3.2.6" />
        <vers num="3.3.0" />
        <vers num="3.3.1" />
        <vers num="3.3.2" />
        <vers num="3.3.3" />
        <vers num="3.3.4" />
        <vers num="3.3.5" />
        <vers num="3.3.6" />
        <vers num="3.3.7" />
        <vers num="3.3.8" />
        <vers num="4.0.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1319" published="2009-04-17" name="CVE-2009-1319" modified="2009-04-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Directory traversal vulnerability in includes/ini.inc.php in GuestCal 2.1 allows remote attackers to include and execute arbitrary files via a .. (dot dot) in the lang parameter to index.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/34519" source="BID">34519</ref>
      <ref url="http://www.milw0rm.com/exploits/8431" source="MILW0RM">8431</ref>
      <ref url="http://secunia.com/advisories/34721" source="SECUNIA" adv="1">34721</ref>
    </refs>
    <vuln_soft>
      <prod vendor="guestcal" name="guest_cal">
        <vers num="2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1320" published="2009-04-17" name="CVE-2009-1320" modified="2009-04-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in include/zstore.php in Zazzle Store Builder 1.0.2 allow remote attackers to inject arbitrary web script or HTML via the (1) gridPage and (2) gridSort parameters.  NOTE: some of these details are obtained from third party information.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/34525" source="BID">34525</ref>
      <ref url="http://secunia.com/advisories/34009" source="SECUNIA" adv="1">34009</ref>
      <ref url="http://holisticinfosec.org/content/view/102/45/" source="MISC">http://holisticinfosec.org/content/view/102/45/</ref>
    </refs>
    <vuln_soft>
      <prod vendor="zazzle" name="store_builder">
        <vers num="1.0.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1321" published="2009-04-17" name="CVE-2009-1321" modified="2009-04-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in search.asp in ASP Product Catalog 1.0 allows remote attackers to inject arbitrary web script or HTML via the keywords parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/49858" source="XF">aspproduct-search-xss(49858)</ref>
      <ref url="http://www.securityfocus.com/bid/34504" source="BID">34504</ref>
      <ref url="http://www.milw0rm.com/exploits/8418" source="MILW0RM">8418</ref>
    </refs>
    <vuln_soft>
      <prod vendor="humayun_shabbir_bhutta" name="asp_product_catalog">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1322" published="2009-04-17" name="CVE-2009-1322" modified="2009-04-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">ASP Product Catalog 1.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing user credentials via a direct request for database/aspProductCatalog.mdb.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/49859" source="XF">aspproduct-aspproductcatalog-info-disc(49859)</ref>
      <ref url="http://www.milw0rm.com/exploits/8418" source="MILW0RM">8418</ref>
    </refs>
    <vuln_soft>
      <prod vendor="humayun_shabbir_bhutta" name="asp_product_catalog">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1323" published="2009-04-17" name="CVE-2009-1323" modified="2009-04-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in body.asp in Web File Explorer 3.1 allows remote attackers to execute arbitrary SQL commands via the id parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/49801" source="XF">webfileexplorer-body-sql-injection(49801)</ref>
      <ref url="http://www.securityfocus.com/bid/34462" source="BID">34462</ref>
      <ref url="http://www.milw0rm.com/exploits/8382" source="MILW0RM">8382</ref>
      <ref url="http://secunia.com/advisories/34648" source="SECUNIA" adv="1">34648</ref>
    </refs>
    <vuln_soft>
      <prod vendor="webfileexplorer" name="web_file_explorer">
        <vers num="3.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1324" published="2009-04-17" name="CVE-2009-1324" modified="2009-04-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Stack-based buffer overflow in Mini-stream ASX to MP3 Converter 3.0.0.7 allows remote attackers to execute arbitrary code via a long URI in a playlist (.m3u) file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/49840" source="XF" adv="1">asxmp3-m3u-bo(49840)</ref>
      <ref url="http://www.securityfocus.com/bid/34494" source="BID">34494</ref>
      <ref url="http://www.milw0rm.com/exploits/8412" source="MILW0RM">8412</ref>
      <ref url="http://www.milw0rm.com/exploits/8407" source="MILW0RM">8407</ref>
      <ref url="http://secunia.com/advisories/34681" source="SECUNIA" adv="1">34681</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mini-stream" name="asx_to_mp3_converter">
        <vers num="3.0.0.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1325" published="2009-04-17" name="CVE-2009-1325" modified="2009-04-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Stack-based buffer overflow in Mini-stream Ripper 3.0.1.1 allows remote attackers to execute arbitrary code via a long URI in a playlist (.m3u) file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/49844" source="XF">ripper-m3u-bo(49844)</ref>
      <ref url="http://www.securityfocus.com/bid/34494" source="BID">34494</ref>
      <ref url="http://www.milw0rm.com/exploits/8416" source="MILW0RM">8416</ref>
      <ref url="http://www.milw0rm.com/exploits/8402" source="MILW0RM">8402</ref>
      <ref url="http://secunia.com/advisories/34692" source="SECUNIA" adv="1">34692</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mini-stream" name="ripper">
        <vers num="3.0.1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1326" published="2009-04-17" name="CVE-2009-1326" modified="2009-04-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Stack-based buffer overflow in Mini-stream RM Downloader 3.0.0.9 allows remote attackers to execute arbitrary code via a long URI in a playlist (.m3u) file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/49843" source="XF">rmdownloader-m3u-bo(49843)</ref>
      <ref url="http://www.securityfocus.com/bid/34494" source="BID">34494</ref>
      <ref url="http://www.milw0rm.com/exploits/8410" source="MILW0RM">8410</ref>
      <ref url="http://www.milw0rm.com/exploits/8404" source="MILW0RM">8404</ref>
      <ref url="http://secunia.com/advisories/34647" source="SECUNIA" adv="1">34647</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mini-stream" name="rm_downloader">
        <vers num="3.0.0.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1327" published="2009-04-17" name="CVE-2009-1327" modified="2009-04-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Stack-based buffer overflow in Mini-stream WM Downloader 3.0.0.9 allows remote attackers to execute arbitrary code via a long URI in a playlist (.m3u) file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/49842" source="XF">wmdownloader-m3u-bo(49842)</ref>
      <ref url="http://www.securityfocus.com/bid/34494" source="BID">34494</ref>
      <ref url="http://www.milw0rm.com/exploits/8411" source="MILW0RM">8411</ref>
      <ref url="http://www.milw0rm.com/exploits/8403" source="MILW0RM">8403</ref>
      <ref url="http://secunia.com/advisories/34674" source="SECUNIA" adv="1">34674</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mini-stream" name="wm_downloader">
        <vers num="3.0.0.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1328" published="2009-04-17" name="CVE-2009-1328" modified="2009-04-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Stack-based buffer overflow in Mini-stream RM-MP3 Converter 3.0.0.7 allows remote attackers to execute arbitrary code via a long URI in a playlist (.m3u) file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/49841" source="XF">rmmp3-m3u-bo(49841)</ref>
      <ref url="http://www.securityfocus.com/bid/34494" source="BID">34494</ref>
      <ref url="http://www.milw0rm.com/exploits/8413" source="MILW0RM">8413</ref>
      <ref url="http://www.milw0rm.com/exploits/8405" source="MILW0RM">8405</ref>
      <ref url="http://secunia.com/advisories/34653" source="SECUNIA" adv="1">34653</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mini-stream" name="rm-mp3_converter">
        <vers num="3.0.0.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1329" published="2009-04-17" name="CVE-2009-1329" modified="2009-04-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Stack-based buffer overflow in Mini-stream Shadow Stream Recorder 3.0.1.7 allows remote attackers to execute arbitrary code via a long URI in a playlist (.m3u) file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/34494" source="BID">34494</ref>
      <ref url="http://www.milw0rm.com/exploits/8426" source="MILW0RM">8426</ref>
      <ref url="http://secunia.com/advisories/34719" source="SECUNIA" adv="1">34719</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mini-stream" name="shadow_stream_recorder">
        <vers num="3.0.1.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1330" published="2009-04-17" name="CVE-2009-1330" modified="2009-05-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Stack-based buffer overflow in Easy RM to MP3 Converter allows remote attackers to execute arbitrary code via a long filename in a playlist (.pls) file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/50326" source="XF">easyrmmp3-pls-bo(50326)</ref>
      <ref url="http://www.securityfocus.com/bid/34514" source="BID">34514</ref>
      <ref url="http://www.milw0rm.com/exploits/8427" source="MILW0RM">8427</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mini-stream" name="easy_rm_to_mp3_converter">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1331" published="2009-04-17" name="CVE-2009-1331" modified="2009-04-28" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Integer overflow in Microsoft Windows Media Player (WMP) 11.0.5721.5260 allows remote attackers to cause a denial of service (application crash) via a crafted .mid file, as demonstrated by crash.mid.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/34534" source="BID">34534</ref>
      <ref url="http://www.milw0rm.com/exploits/8445" source="MILW0RM">8445</ref>
      <ref url="http://osvdb.org/53804" source="OSVDB">53804</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_media_player">
        <vers num="11.0.5721.5260" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1332" published="2009-04-17" name="CVE-2009-1332" modified="2009-04-28" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The Online Help feature in Sun Java System Directory Server 5.2 and Enterprise Edition 5 allows remote attackers to determine the existence of files and directories, and possibly obtain partial contents of files, via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2009/1059" source="VUPEN">ADV-2009-1059</ref>
      <ref url="http://www.securityfocus.com/bid/34548" source="BID">34548</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-255848-1" source="SUNALERT" adv="1">255848</ref>
      <ref url="http://secunia.com/advisories/34751" source="SECUNIA" adv="1">34751</ref>
      <ref url="http://osvdb.org/53800" source="OSVDB">53800</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="java_system_directory_server">
        <vers num="5.0" edition="-" />
        <vers num="5.0" edition="-:enterprise" />
        <vers num="5.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1333" published="2009-04-17" name="CVE-2009-1333" modified="2009-04-28" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in refresh_rate.htm in the web interface on the HP Deskjet 6840 printer with firmware XF1M131A allows remote attackers to inject arbitrary web script or HTML via the POST request body.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/49850" source="XF">deskjet-refreshrate-xss(49850)</ref>
      <ref url="http://www.securityfocus.com/bid/34480" source="BID">34480</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/502620/100/0/threaded" source="BUGTRAQ">20090411 HP Deskjet 6800 XSS in Web Interface</ref>
      <ref url="http://secunia.com/advisories/34702" source="SECUNIA">34702</ref>
      <ref url="http://osvdb.org/53769" source="OSVDB">53769</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="deskjet_6840">
        <vers num="xf1m131a" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1334" published="2009-04-17" name="CVE-2009-1334" modified="2009-04-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in login/FilepathLogin.html in IBM Tivoli Continuous Data Protection (CDP) for Files 3.1.4.0 allows remote attackers to inject arbitrary web script or HTML via the reason parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/49872" source="XF">tivoli-cdpf-reason-xss(49872)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1021" source="VUPEN" adv="1">ADV-2009-1021</ref>
      <ref url="http://www.securityfocus.com/bid/34513" source="BID">34513</ref>
      <ref url="http://www.osvdb.org/53651" source="OSVDB">53651</ref>
      <ref url="http://www.insight-tech.org/index.php?p=IBM-Tivoli-Continuous-Data-Protection-for-Files-version-3-1-4-0---XSS" source="MISC">http://www.insight-tech.org/index.php?p=IBM-Tivoli-Continuous-Data-Protection-for-Files-version-3-1-4-0---XSS</ref>
      <ref url="http://securitytracker.com/id?1022060" source="SECTRACK">1022060</ref>
      <ref url="http://secunia.com/advisories/34646" source="SECUNIA" adv="1">34646</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="tivoli_continuous_data_protection_for_files">
        <vers num="3.1.4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1335" published="2009-04-17" name="CVE-2009-1335" modified="2009-05-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Microsoft Internet Explorer 7 and 8 on Windows XP and Vista allows remote attackers to cause a denial of service (application hang) via a large document composed of unprintable characters, aka MSRC 9011jr.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/50350" source="XF">ie-unprintable-dos(50350)</ref>
      <ref url="http://www.securityfocus.com/bid/34478" source="BID">34478</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/502617/100/0/threaded" source="BUGTRAQ">20090411 [BMSA 2009-04] Remote DoS in Internet Explorer</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2009-04/0111.html" source="FULLDISC">20090411 [BMSA 2009-04] Remote DoS in Internet Explorer</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="7" />
        <vers num="8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1336" published="2009-04-22" name="CVE-2009-1336" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="4.9" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="3.9" CVSS_base_score="4.9">
    <desc>
      <descript source="cve">fs/nfs/client.c in the Linux kernel before 2.6.23 does not properly initialize a certain structure member that stores the maximum NFS filename length, which allows local users to cause a denial of service (OOPS) via a long filename, related to the encode_lookup function.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=494074" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=494074</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/3316" source="VUPEN">ADV-2009-3316</ref>
      <ref url="http://www.vmware.com/security/advisories/VMSA-2009-0016.html" source="CONFIRM">http://www.vmware.com/security/advisories/VMSA-2009-0016.html</ref>
      <ref url="http://www.ubuntu.com/usn/usn-793-1" source="UBUNTU">USN-793-1</ref>
      <ref url="http://www.securitytracker.com/id?1022176" source="SECTRACK">1022176</ref>
      <ref url="http://www.securityfocus.com/bid/34390" source="BID">34390</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/507985/100/0/threaded" source="BUGTRAQ">20091120 VMSA-2009-0016 VMware vCenter and ESX update release and vMA patch release address multiple security issue in third party components</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-1077.html" source="REDHAT">RHSA-2009:1077</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-1024.html" source="REDHAT">RHSA-2009:1024</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2009/04/17/2" source="MLIST">[oss-security] 20090417 Re: CVE request: kernel: NFS: Fix an Oops in encode_lookup()</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2009/04/06/1" source="MLIST">[oss-security] 20090406 CVE request: kernel: NFS: Fix an Oops in encode_lookup()</ref>
      <ref url="http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.23" source="CONFIRM" adv="1">http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.23</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1794" source="DEBIAN">DSA-1794</ref>
      <ref url="http://secunia.com/advisories/37471" source="SECUNIA">37471</ref>
      <ref url="http://secunia.com/advisories/35656" source="SECUNIA">35656</ref>
      <ref url="http://secunia.com/advisories/35324" source="SECUNIA">35324</ref>
      <ref url="http://secunia.com/advisories/35160" source="SECUNIA">35160</ref>
      <ref url="http://secunia.com/advisories/35015" source="SECUNIA">35015</ref>
      <ref url="http://secunia.com/advisories/35011" source="SECUNIA">35011</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2009-0473.html" source="REDHAT">RHSA-2009:0473</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:8495" source="OVAL">oval:org.mitre.oval:def:8495</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10859" source="OVAL">oval:org.mitre.oval:def:10859</ref>
      <ref url="http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=54af3bb543c071769141387a42deaaab5074da55" source="CONFIRM">http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=54af3bb543c071769141387a42deaaab5074da55</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="kernel">
        <vers num="2.6" />
        <vers num="2.6.0" />
        <vers num="2.6.1" />
        <vers num="2.6.10" />
        <vers num="2.6.11" />
        <vers num="2.6.11.1" />
        <vers num="2.6.11.10" />
        <vers num="2.6.11.11" />
        <vers num="2.6.11.12" />
        <vers num="2.6.11.2" />
        <vers num="2.6.11.3" />
        <vers num="2.6.11.4" />
        <vers num="2.6.11.5" />
        <vers num="2.6.11.6" />
        <vers num="2.6.11.7" />
        <vers num="2.6.11.8" />
        <vers num="2.6.11.9" />
        <vers num="2.6.12" />
        <vers num="2.6.12.1" />
        <vers num="2.6.12.2" />
        <vers num="2.6.12.3" />
        <vers num="2.6.12.4" />
        <vers num="2.6.12.5" />
        <vers num="2.6.12.6" />
        <vers num="2.6.13" />
        <vers num="2.6.13.1" />
        <vers num="2.6.13.2" />
        <vers num="2.6.13.3" />
        <vers num="2.6.13.4" />
        <vers num="2.6.13.5" />
        <vers num="2.6.14" />
        <vers num="2.6.14.1" />
        <vers num="2.6.14.2" />
        <vers num="2.6.14.3" />
        <vers num="2.6.14.4" />
        <vers num="2.6.14.5" />
        <vers num="2.6.14.6" />
        <vers num="2.6.14.7" />
        <vers num="2.6.15" />
        <vers num="2.6.15.1" />
        <vers num="2.6.15.2" />
        <vers num="2.6.15.3" />
        <vers num="2.6.15.4" />
        <vers num="2.6.15.5" />
        <vers num="2.6.15.6" />
        <vers num="2.6.15.7" />
        <vers num="2.6.16" />
        <vers num="2.6.16.1" />
        <vers num="2.6.16.10" />
        <vers num="2.6.16.11" />
        <vers num="2.6.16.12" />
        <vers num="2.6.16.13" />
        <vers num="2.6.16.14" />
        <vers num="2.6.16.15" />
        <vers num="2.6.16.16" />
        <vers num="2.6.16.17" />
        <vers num="2.6.16.18" />
        <vers num="2.6.16.19" />
        <vers num="2.6.16.2" />
        <vers num="2.6.16.20" />
        <vers num="2.6.16.21" />
        <vers num="2.6.16.22" />
        <vers num="2.6.16.23" />
        <vers num="2.6.16.24" />
        <vers num="2.6.16.25" />
        <vers num="2.6.16.26" />
        <vers num="2.6.16.27" />
        <vers num="2.6.16.28" />
        <vers num="2.6.16.29" />
        <vers num="2.6.16.3" />
        <vers num="2.6.16.30" />
        <vers num="2.6.16.31" />
        <vers num="2.6.16.32" />
        <vers num="2.6.16.33" />
        <vers num="2.6.16.34" />
        <vers num="2.6.16.35" />
        <vers num="2.6.16.36" />
        <vers num="2.6.16.37" />
        <vers num="2.6.16.38" />
        <vers num="2.6.16.39" />
        <vers num="2.6.16.4" />
        <vers num="2.6.16.40" />
        <vers num="2.6.16.41" />
        <vers num="2.6.16.42" />
        <vers num="2.6.16.43" />
        <vers num="2.6.16.44" />
        <vers num="2.6.16.45" />
        <vers num="2.6.16.46" />
        <vers num="2.6.16.47" />
        <vers num="2.6.16.48" />
        <vers num="2.6.16.49" />
        <vers num="2.6.16.5" />
        <vers num="2.6.16.50" />
        <vers num="2.6.16.51" />
        <vers num="2.6.16.52" />
        <vers num="2.6.16.53" />
        <vers num="2.6.16.54" />
        <vers num="2.6.16.55" />
        <vers num="2.6.16.56" />
        <vers num="2.6.16.57" />
        <vers num="2.6.16.58" />
        <vers num="2.6.16.59" />
        <vers num="2.6.16.6" />
        <vers num="2.6.16.60" />
        <vers num="2.6.16.61" />
        <vers num="2.6.16.62" />
        <vers num="2.6.16.7" />
        <vers num="2.6.16.8" />
        <vers num="2.6.16.9" />
        <vers num="2.6.17" />
        <vers num="2.6.17.1" />
        <vers num="2.6.17.10" />
        <vers num="2.6.17.11" />
        <vers num="2.6.17.12" />
        <vers num="2.6.17.13" />
        <vers num="2.6.17.14" />
        <vers num="2.6.17.2" />
        <vers num="2.6.17.3" />
        <vers num="2.6.17.4" />
        <vers num="2.6.17.5" />
        <vers num="2.6.17.6" />
        <vers num="2.6.17.7" />
        <vers num="2.6.17.8" />
        <vers num="2.6.17.9" />
        <vers num="2.6.18" edition="rc1" />
        <vers num="2.6.18" edition="rc2" />
        <vers num="2.6.18" edition="rc3" />
        <vers num="2.6.18" edition="rc4" />
        <vers num="2.6.18" edition="rc5" />
        <vers num="2.6.18" edition="rc6" />
        <vers num="2.6.18" edition="rc7" />
        <vers num="2.6.18.1" />
        <vers num="2.6.18.2" />
        <vers num="2.6.18.3" />
        <vers num="2.6.18.4" />
        <vers num="2.6.18.5" />
        <vers num="2.6.18.6" />
        <vers num="2.6.18.7" />
        <vers num="2.6.18.8" />
        <vers num="2.6.19" />
        <vers num="2.6.19.1" />
        <vers num="2.6.19.2" />
        <vers num="2.6.19.3" />
        <vers num="2.6.19.4" />
        <vers num="2.6.19.5" />
        <vers num="2.6.19.6" />
        <vers num="2.6.19.7" />
        <vers num="2.6.2" />
        <vers num="2.6.20" />
        <vers num="2.6.20.1" />
        <vers num="2.6.20.10" />
        <vers num="2.6.20.11" />
        <vers num="2.6.20.12" />
        <vers num="2.6.20.13" />
        <vers num="2.6.20.14" />
        <vers num="2.6.20.15" />
        <vers num="2.6.20.16" />
        <vers num="2.6.20.17" />
        <vers num="2.6.20.18" />
        <vers num="2.6.20.19" />
        <vers num="2.6.20.2" />
        <vers num="2.6.20.20" />
        <vers num="2.6.20.21" />
        <vers num="2.6.20.3" />
        <vers num="2.6.20.4" />
        <vers num="2.6.20.5" />
        <vers num="2.6.20.6" />
        <vers num="2.6.20.7" />
        <vers num="2.6.20.8" />
        <vers num="2.6.20.9" />
        <vers num="2.6.21" />
        <vers num="2.6.21.1" />
        <vers num="2.6.21.2" />
        <vers num="2.6.21.3" />
        <vers num="2.6.21.4" />
        <vers num="2.6.21.5" />
        <vers num="2.6.21.6" />
        <vers num="2.6.21.7" />
        <vers num="2.6.22" />
        <vers num="2.6.22.1" />
        <vers num="2.6.22.10" />
        <vers num="2.6.22.11" />
        <vers num="2.6.22.12" />
        <vers num="2.6.22.13" />
        <vers num="2.6.22.14" />
        <vers num="2.6.22.15" />
        <vers num="2.6.22.16" />
        <vers num="2.6.22.17" />
        <vers num="2.6.22.18" />
        <vers prev="1" num="2.6.22.19" />
        <vers num="2.6.22.2" />
        <vers num="2.6.22.3" />
        <vers num="2.6.22.4" />
        <vers num="2.6.22.5" />
        <vers num="2.6.22.6" />
        <vers num="2.6.22.7" />
        <vers num="2.6.22.8" />
        <vers num="2.6.22.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1337" published="2009-04-22" name="CVE-2009-1337" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="4.4" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.4" CVSS_base_score="4.4">
    <desc>
      <descript source="cve">The exit_notify function in kernel/exit.c in the Linux kernel before 2.6.30-rc1 does not restrict exit signals when the CAP_KILL capability is held, which allows local users to send an arbitrary signal to a process by running a program that modifies the exit_signal field and then uses an exec system call to launch a setuid application.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://patchwork.kernel.org/patch/16544/" source="CONFIRM" patch="1">http://patchwork.kernel.org/patch/16544/</ref>
      <ref url="http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=432870dab85a2f69dc417022646cb9a70acf7f94" source="CONFIRM" patch="1" adv="1">http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=432870dab85a2f69dc417022646cb9a70acf7f94</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-May/msg01126.html" source="FEDORA">FEDORA-2009-5356</ref>
      <ref url="https://rhn.redhat.com/errata/RHSA-2009-1550.html" source="REDHAT">RHSA-2009:1550</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=493771" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=493771</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/3316" source="VUPEN">ADV-2009-3316</ref>
      <ref url="http://www.vmware.com/security/advisories/VMSA-2009-0016.html" source="CONFIRM">http://www.vmware.com/security/advisories/VMSA-2009-0016.html</ref>
      <ref url="http://www.ubuntu.com/usn/usn-793-1" source="UBUNTU">USN-793-1</ref>
      <ref url="http://www.securitytracker.com/id?1022141" source="SECTRACK">1022141</ref>
      <ref url="http://www.securityfocus.com/bid/34405" source="BID">34405</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/512019/100/0/threaded" source="BUGTRAQ">20100625 VMSA-2010-0010 ESX 3.5 third party update for Service Console kernel</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/507985/100/0/threaded" source="BUGTRAQ">20091120 VMSA-2009-0016 VMware vCenter and ESX update release and vMA patch release address multiple security issue in third party components</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/503610/100/0/threaded" source="BUGTRAQ">20090516 rPSA-2009-0084-1 kernel</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-1077.html" source="REDHAT">RHSA-2009:1077</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-1024.html" source="REDHAT">RHSA-2009:1024</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-0451.html" source="REDHAT">RHSA-2009:0451</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2009/04/17/3" source="MLIST">[oss-security] 20090417 Re: CVE request: kernel: exit_notify: kill the wrong capable(CAP_KILL) check</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2009/04/07/1" source="MLIST">[oss-security] 20090407 CVE request: kernel: exit_notify: kill the wrong capable(CAP_KILL) check</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:135" source="MANDRIVA">MDVSA-2009:135</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:119" source="MANDRIVA">MDVSA-2009:119</ref>
      <ref url="http://www.kernel.org/pub/linux/kernel/v2.6/testing/ChangeLog-2.6.30-rc1" source="CONFIRM" adv="1">http://www.kernel.org/pub/linux/kernel/v2.6/testing/ChangeLog-2.6.30-rc1</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1800" source="DEBIAN">DSA-1800</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1794" source="DEBIAN">DSA-1794</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1787" source="DEBIAN">DSA-1787</ref>
      <ref url="http://wiki.rpath.com/Advisories:rPSA-2009-0084" source="CONFIRM">http://wiki.rpath.com/Advisories:rPSA-2009-0084</ref>
      <ref url="http://secunia.com/advisories/37471" source="SECUNIA">37471</ref>
      <ref url="http://secunia.com/advisories/35656" source="SECUNIA">35656</ref>
      <ref url="http://secunia.com/advisories/35394" source="SECUNIA">35394</ref>
      <ref url="http://secunia.com/advisories/35390" source="SECUNIA">35390</ref>
      <ref url="http://secunia.com/advisories/35387" source="SECUNIA">35387</ref>
      <ref url="http://secunia.com/advisories/35324" source="SECUNIA">35324</ref>
      <ref url="http://secunia.com/advisories/35226" source="SECUNIA">35226</ref>
      <ref url="http://secunia.com/advisories/35185" source="SECUNIA">35185</ref>
      <ref url="http://secunia.com/advisories/35160" source="SECUNIA">35160</ref>
      <ref url="http://secunia.com/advisories/35121" source="SECUNIA">35121</ref>
      <ref url="http://secunia.com/advisories/35120" source="SECUNIA">35120</ref>
      <ref url="http://secunia.com/advisories/35015" source="SECUNIA">35015</ref>
      <ref url="http://secunia.com/advisories/35011" source="SECUNIA">35011</ref>
      <ref url="http://secunia.com/advisories/34981" source="SECUNIA">34981</ref>
      <ref url="http://secunia.com/advisories/34917" source="SECUNIA">34917</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2009-0473.html" source="REDHAT">RHSA-2009:0473</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:8295" source="OVAL">oval:org.mitre.oval:def:8295</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11206" source="OVAL">oval:org.mitre.oval:def:11206</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10919" source="OVAL">oval:org.mitre.oval:def:10919</ref>
      <ref url="http://marc.info/?l=linux-kernel&amp;m=123560588713763&amp;w=2" source="MLIST">[linux-kernel] 20090225 Re: [PATCH 2/2] exit_notify: kill the wrong capable(CAP_KILL) check</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-06/msg00002.html" source="SUSE">SUSE-SA:2009:032</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-06/msg00001.html" source="SUSE">SUSE-SA:2009:031</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-06/msg00000.html" source="SUSE">SUSE-SA:2009:030</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-05/msg00002.html" source="SUSE">SUSE-SA:2009:028</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="kernel">
        <vers num="2.2.27" />
        <vers num="2.4.36" />
        <vers num="2.4.36.1" />
        <vers num="2.4.36.2" />
        <vers num="2.4.36.3" />
        <vers num="2.4.36.4" />
        <vers num="2.4.36.5" />
        <vers num="2.4.36.6" />
        <vers num="2.6" />
        <vers num="2.6.0" />
        <vers num="2.6.1" />
        <vers num="2.6.10" />
        <vers num="2.6.11" />
        <vers num="2.6.11.1" />
        <vers num="2.6.11.10" />
        <vers num="2.6.11.11" />
        <vers num="2.6.11.12" />
        <vers num="2.6.11.2" />
        <vers num="2.6.11.3" />
        <vers num="2.6.11.4" />
        <vers num="2.6.11.5" />
        <vers num="2.6.11.6" />
        <vers num="2.6.11.7" />
        <vers num="2.6.11.8" />
        <vers num="2.6.11.9" />
        <vers num="2.6.12" />
        <vers num="2.6.12.1" />
        <vers num="2.6.12.2" />
        <vers num="2.6.12.3" />
        <vers num="2.6.12.4" />
        <vers num="2.6.12.5" />
        <vers num="2.6.12.6" />
        <vers num="2.6.13" />
        <vers num="2.6.13.1" />
        <vers num="2.6.13.2" />
        <vers num="2.6.13.3" />
        <vers num="2.6.13.4" />
        <vers num="2.6.13.5" />
        <vers num="2.6.14" />
        <vers num="2.6.14.1" />
        <vers num="2.6.14.2" />
        <vers num="2.6.14.3" />
        <vers num="2.6.14.4" />
        <vers num="2.6.14.5" />
        <vers num="2.6.14.6" />
        <vers num="2.6.14.7" />
        <vers num="2.6.15" />
        <vers num="2.6.15.1" />
        <vers num="2.6.15.2" />
        <vers num="2.6.15.3" />
        <vers num="2.6.15.4" />
        <vers num="2.6.15.5" />
        <vers num="2.6.15.6" />
        <vers num="2.6.15.7" />
        <vers num="2.6.16" />
        <vers num="2.6.16.1" />
        <vers num="2.6.16.10" />
        <vers num="2.6.16.11" />
        <vers num="2.6.16.12" />
        <vers num="2.6.16.13" />
        <vers num="2.6.16.14" />
        <vers num="2.6.16.15" />
        <vers num="2.6.16.16" />
        <vers num="2.6.16.17" />
        <vers num="2.6.16.18" />
        <vers num="2.6.16.19" />
        <vers num="2.6.16.2" />
        <vers num="2.6.16.20" />
        <vers num="2.6.16.21" />
        <vers num="2.6.16.22" />
        <vers num="2.6.16.23" />
        <vers num="2.6.16.24" />
        <vers num="2.6.16.25" />
        <vers num="2.6.16.26" />
        <vers num="2.6.16.27" />
        <vers num="2.6.16.28" />
        <vers num="2.6.16.29" />
        <vers num="2.6.16.3" />
        <vers num="2.6.16.30" />
        <vers num="2.6.16.31" />
        <vers num="2.6.16.32" />
        <vers num="2.6.16.33" />
        <vers num="2.6.16.34" />
        <vers num="2.6.16.35" />
        <vers num="2.6.16.36" />
        <vers num="2.6.16.37" />
        <vers num="2.6.16.38" />
        <vers num="2.6.16.39" />
        <vers num="2.6.16.4" />
        <vers num="2.6.16.40" />
        <vers num="2.6.16.41" />
        <vers num="2.6.16.42" />
        <vers num="2.6.16.43" />
        <vers num="2.6.16.44" />
        <vers num="2.6.16.45" />
        <vers num="2.6.16.46" />
        <vers num="2.6.16.47" />
        <vers num="2.6.16.48" />
        <vers num="2.6.16.49" />
        <vers num="2.6.16.5" />
        <vers num="2.6.16.50" />
        <vers num="2.6.16.51" />
        <vers num="2.6.16.52" />
        <vers num="2.6.16.53" />
        <vers num="2.6.16.54" />
        <vers num="2.6.16.55" />
        <vers num="2.6.16.56" />
        <vers num="2.6.16.57" />
        <vers num="2.6.16.58" />
        <vers num="2.6.16.59" />
        <vers num="2.6.16.6" />
        <vers num="2.6.16.60" />
        <vers num="2.6.16.61" />
        <vers num="2.6.16.62" />
        <vers num="2.6.16.7" />
        <vers num="2.6.16.8" />
        <vers num="2.6.16.9" />
        <vers num="2.6.17" />
        <vers num="2.6.17.1" />
        <vers num="2.6.17.10" />
        <vers num="2.6.17.11" />
        <vers num="2.6.17.12" />
        <vers num="2.6.17.13" />
        <vers num="2.6.17.14" />
        <vers num="2.6.17.2" />
        <vers num="2.6.17.3" />
        <vers num="2.6.17.4" />
        <vers num="2.6.17.5" />
        <vers num="2.6.17.6" />
        <vers num="2.6.17.7" />
        <vers num="2.6.17.8" />
        <vers num="2.6.17.9" />
        <vers num="2.6.18" edition="rc1" />
        <vers num="2.6.18" edition="rc2" />
        <vers num="2.6.18" edition="rc3" />
        <vers num="2.6.18" edition="rc4" />
        <vers num="2.6.18" edition="rc5" />
        <vers num="2.6.18" edition="rc6" />
        <vers num="2.6.18" edition="rc7" />
        <vers num="2.6.18.1" />
        <vers num="2.6.18.2" />
        <vers num="2.6.18.3" />
        <vers num="2.6.18.4" />
        <vers num="2.6.18.5" />
        <vers num="2.6.18.6" />
        <vers num="2.6.18.7" />
        <vers num="2.6.18.8" />
        <vers num="2.6.19" />
        <vers num="2.6.19.1" />
        <vers num="2.6.19.2" />
        <vers num="2.6.19.3" />
        <vers num="2.6.19.4" />
        <vers num="2.6.19.5" />
        <vers num="2.6.19.6" />
        <vers num="2.6.19.7" />
        <vers num="2.6.2" />
        <vers num="2.6.20" />
        <vers num="2.6.20.1" />
        <vers num="2.6.20.10" />
        <vers num="2.6.20.11" />
        <vers num="2.6.20.12" />
        <vers num="2.6.20.13" />
        <vers num="2.6.20.14" />
        <vers num="2.6.20.15" />
        <vers num="2.6.20.16" />
        <vers num="2.6.20.17" />
        <vers num="2.6.20.18" />
        <vers num="2.6.20.19" />
        <vers num="2.6.20.2" />
        <vers num="2.6.20.20" />
        <vers num="2.6.20.21" />
        <vers num="2.6.20.3" />
        <vers num="2.6.20.4" />
        <vers num="2.6.20.5" />
        <vers num="2.6.20.6" />
        <vers num="2.6.20.7" />
        <vers num="2.6.20.8" />
        <vers num="2.6.20.9" />
        <vers num="2.6.21" />
        <vers num="2.6.21.1" />
        <vers num="2.6.21.2" />
        <vers num="2.6.21.3" />
        <vers num="2.6.21.4" />
        <vers num="2.6.21.5" />
        <vers num="2.6.21.6" />
        <vers num="2.6.21.7" />
        <vers num="2.6.22" />
        <vers num="2.6.22.1" />
        <vers num="2.6.22.10" />
        <vers num="2.6.22.11" />
        <vers num="2.6.22.12" />
        <vers num="2.6.22.13" />
        <vers num="2.6.22.14" />
        <vers num="2.6.22.15" />
        <vers num="2.6.22.16" />
        <vers num="2.6.22.17" />
        <vers num="2.6.22.18" />
        <vers num="2.6.22.19" />
        <vers num="2.6.22.2" />
        <vers num="2.6.22.20" />
        <vers num="2.6.22.21" />
        <vers num="2.6.22.22" />
        <vers num="2.6.22.3" />
        <vers num="2.6.22.4" />
        <vers num="2.6.22.5" />
        <vers num="2.6.22.6" />
        <vers num="2.6.22.7" />
        <vers num="2.6.22.8" />
        <vers num="2.6.22.9" />
        <vers num="2.6.22_rc1" />
        <vers num="2.6.22_rc7" />
        <vers num="2.6.23" edition="rc1" />
        <vers num="2.6.23" edition="rc2" />
        <vers num="2.6.23.1" />
        <vers num="2.6.23.10" />
        <vers num="2.6.23.11" />
        <vers num="2.6.23.12" />
        <vers num="2.6.23.13" />
        <vers num="2.6.23.14" />
        <vers num="2.6.23.15" />
        <vers num="2.6.23.16" />
        <vers num="2.6.23.17" />
        <vers num="2.6.23.2" />
        <vers num="2.6.23.3" />
        <vers num="2.6.23.4" />
        <vers num="2.6.23.5" />
        <vers num="2.6.23.6" />
        <vers num="2.6.23.7" />
        <vers num="2.6.23.8" />
        <vers num="2.6.23.9" />
        <vers num="2.6.24" edition="rc1" />
        <vers num="2.6.24" edition="rc2" />
        <vers num="2.6.24" edition="rc3" />
        <vers num="2.6.24" edition="rc4" />
        <vers num="2.6.24" edition="rc5" />
        <vers num="2.6.24.1" />
        <vers num="2.6.24.2" />
        <vers num="2.6.24.3" />
        <vers num="2.6.24.4" />
        <vers num="2.6.24.5" />
        <vers num="2.6.24.6" />
        <vers num="2.6.24.7" />
        <vers num="2.6.25" edition="" />
        <vers num="2.6.25" edition=":x86_64" />
        <vers num="2.6.25.1" edition="" />
        <vers num="2.6.25.1" edition=":x86_64" />
        <vers num="2.6.25.10" edition="" />
        <vers num="2.6.25.10" edition=":x86_64" />
        <vers num="2.6.25.11" edition="" />
        <vers num="2.6.25.11" edition=":x86_64" />
        <vers num="2.6.25.12" edition="" />
        <vers num="2.6.25.12" edition=":x86_64" />
        <vers num="2.6.25.13" />
        <vers num="2.6.25.14" />
        <vers num="2.6.25.15" />
        <vers num="2.6.25.16" />
        <vers num="2.6.25.17" />
        <vers num="2.6.25.18" />
        <vers num="2.6.25.19" />
        <vers num="2.6.25.2" edition="" />
        <vers num="2.6.25.2" edition=":x86_64" />
        <vers num="2.6.25.20" />
        <vers num="2.6.25.3" edition="" />
        <vers num="2.6.25.3" edition=":x86_64" />
        <vers num="2.6.25.4" edition="" />
        <vers num="2.6.25.4" edition=":x86_64" />
        <vers num="2.6.25.5" edition="" />
        <vers num="2.6.25.5" edition=":x86_64" />
        <vers num="2.6.25.6" edition="" />
        <vers num="2.6.25.6" edition=":x86_64" />
        <vers num="2.6.25.7" edition="" />
        <vers num="2.6.25.7" edition=":x86_64" />
        <vers num="2.6.25.8" edition="" />
        <vers num="2.6.25.8" edition=":x86_64" />
        <vers num="2.6.25.9" edition="" />
        <vers num="2.6.25.9" edition=":x86_64" />
        <vers num="2.6.26" edition="rc4" />
        <vers num="2.6.26.1" />
        <vers num="2.6.26.2" />
        <vers num="2.6.26.3" />
        <vers num="2.6.26.4" />
        <vers num="2.6.26.5" />
        <vers num="2.6.26.6" />
        <vers num="2.6.26.7" />
        <vers num="2.6.26.8" />
        <vers num="2.6.27" edition="rc1" />
        <vers num="2.6.27" edition="rc2" />
        <vers num="2.6.27" edition="rc3" />
        <vers num="2.6.27" edition="rc4" />
        <vers num="2.6.27" edition="rc5" />
        <vers num="2.6.27" edition="rc6" />
        <vers num="2.6.27" edition="rc7" />
        <vers num="2.6.27" edition="rc8" />
        <vers num="2.6.27" edition="rc9" />
        <vers num="2.6.27.1" />
        <vers num="2.6.27.10" />
        <vers num="2.6.27.11" />
        <vers num="2.6.27.12" />
        <vers num="2.6.27.2" />
        <vers num="2.6.27.3" />
        <vers num="2.6.27.4" />
        <vers num="2.6.27.5" />
        <vers num="2.6.27.6" />
        <vers num="2.6.27.7" />
        <vers num="2.6.27.8" />
        <vers num="2.6.27.9" />
        <vers num="2.6.28" edition="git7" />
        <vers num="2.6.28" edition="rc1" />
        <vers num="2.6.28" edition="rc2" />
        <vers num="2.6.28" edition="rc3" />
        <vers num="2.6.28" edition="rc4" />
        <vers num="2.6.28" edition="rc5" />
        <vers num="2.6.28" edition="rc6" />
        <vers num="2.6.28" edition="rc7" />
        <vers num="2.6.28.1" />
        <vers num="2.6.28.2" />
        <vers num="2.6.28.3" />
        <vers num="2.6.28.4" />
        <vers num="2.6.28.5" />
        <vers num="2.6.28.6" />
        <vers num="2.6.28.7" />
        <vers num="2.6.28.8" />
        <vers num="2.6.28.9" />
        <vers prev="1" num="2.6.29" edition="git1" />
        <vers prev="1" num="2.6.29" edition="rc1" />
        <vers prev="1" num="2.6.29" edition="rc2" />
        <vers prev="1" num="2.6.29" edition="rc2_git7" />
        <vers num="2.6.3" />
        <vers num="2.6.4" />
        <vers num="2.6.5" />
        <vers num="2.6.6" />
        <vers num="2.6.7" />
        <vers num="2.6.8" />
        <vers num="2.6.8.1" />
        <vers num="2.6.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1338" published="2009-04-22" name="CVE-2009-1338" modified="2010-05-08" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">The kill_something_info function in kernel/signal.c in the Linux kernel before 2.6.28 does not consider PID namespaces when processing signals directed to PID -1, which allows local users to bypass the intended namespace isolation, and send arbitrary signals to all processes in all namespaces, via a kill command.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=496031" source="CONFIRM" patch="1">https://bugzilla.redhat.com/show_bug.cgi?id=496031</ref>
      <ref url="http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.28" source="CONFIRM" patch="1" adv="1">http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.28</ref>
      <ref url="http://lkml.org/lkml/2008/7/23/148" source="MLIST" patch="1">[linux-kernel] 20080723 Re: [PATCH 1/2] signals: kill(-1) should only signal processes in the same namespace</ref>
      <ref url="http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=d25141a818383b3c3b09f065698c544a7a0ec6e7" source="CONFIRM" patch="1" adv="1">http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=d25141a818383b3c3b09f065698c544a7a0ec6e7</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/50386" source="XF">kernel-killsomethinginfo-security-bypass(50386)</ref>
      <ref url="http://www.ubuntu.com/usn/usn-793-1" source="UBUNTU">USN-793-1</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/503610/100/0/threaded" source="BUGTRAQ">20090516 rPSA-2009-0084-1 kernel</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-1081.html" source="REDHAT">RHSA-2009:1081</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2009/04/21/1" source="MLIST">[oss-security] 20090421 Re: CVE request: kernel: 'kill sig -1' must only apply to caller's PID namespace</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2009/04/17/4" source="MLIST">[oss-security] 20090417 Re: CVE request: kernel: 'kill sig -1' must only apply to caller's PID namespace</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2009/04/16/2" source="MLIST">[oss-security] 20090416 CVE request: kernel: 'kill sig -1' must only apply to caller's PID namespace</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1800" source="DEBIAN">DSA-1800</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1787" source="DEBIAN">DSA-1787</ref>
      <ref url="http://wiki.rpath.com/Advisories:rPSA-2009-0084" source="CONFIRM">http://wiki.rpath.com/Advisories:rPSA-2009-0084</ref>
      <ref url="http://secunia.com/advisories/35656" source="SECUNIA">35656</ref>
      <ref url="http://secunia.com/advisories/35343" source="SECUNIA">35343</ref>
      <ref url="http://secunia.com/advisories/35121" source="SECUNIA">35121</ref>
      <ref url="http://secunia.com/advisories/35120" source="SECUNIA">35120</ref>
      <ref url="http://secunia.com/advisories/34981" source="SECUNIA">34981</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="kernel">
        <vers num="2.2.27" />
        <vers num="2.4.36" />
        <vers num="2.4.36.1" />
        <vers num="2.4.36.2" />
        <vers num="2.4.36.3" />
        <vers num="2.4.36.4" />
        <vers num="2.4.36.5" />
        <vers num="2.4.36.6" />
        <vers num="2.6" />
        <vers num="2.6.18" edition="rc1" />
        <vers num="2.6.18" edition="rc2" />
        <vers num="2.6.18" edition="rc3" />
        <vers num="2.6.18" edition="rc4" />
        <vers num="2.6.18" edition="rc5" />
        <vers num="2.6.18" edition="rc6" />
        <vers num="2.6.18" edition="rc7" />
        <vers num="2.6.19.4" />
        <vers num="2.6.19.5" />
        <vers num="2.6.19.6" />
        <vers num="2.6.19.7" />
        <vers num="2.6.20.16" />
        <vers num="2.6.20.17" />
        <vers num="2.6.20.18" />
        <vers num="2.6.20.19" />
        <vers num="2.6.20.20" />
        <vers num="2.6.20.21" />
        <vers num="2.6.21.5" />
        <vers num="2.6.21.6" />
        <vers num="2.6.21.7" />
        <vers num="2.6.22" />
        <vers num="2.6.22.1" />
        <vers num="2.6.22.10" />
        <vers num="2.6.22.11" />
        <vers num="2.6.22.12" />
        <vers num="2.6.22.13" />
        <vers num="2.6.22.14" />
        <vers num="2.6.22.15" />
        <vers num="2.6.22.17" />
        <vers num="2.6.22.18" />
        <vers num="2.6.22.19" />
        <vers num="2.6.22.2" />
        <vers num="2.6.22.20" />
        <vers num="2.6.22.21" />
        <vers num="2.6.22.22" />
        <vers num="2.6.22.8" />
        <vers num="2.6.22.9" />
        <vers num="2.6.22_rc1" />
        <vers num="2.6.22_rc7" />
        <vers num="2.6.23" />
        <vers num="2.6.23.10" />
        <vers num="2.6.23.11" />
        <vers num="2.6.23.12" />
        <vers num="2.6.23.13" />
        <vers num="2.6.23.15" />
        <vers num="2.6.23.16" />
        <vers num="2.6.23.17" />
        <vers num="2.6.23.8" />
        <vers num="2.6.23.9" />
        <vers num="2.6.23_rc1" />
        <vers num="2.6.24" />
        <vers num="2.6.24.1" />
        <vers num="2.6.24.2" />
        <vers num="2.6.24.3" />
        <vers num="2.6.24.4" />
        <vers num="2.6.24.5" />
        <vers num="2.6.24.6" />
        <vers num="2.6.24.7" />
        <vers num="2.6.24_rc1" />
        <vers num="2.6.24_rc4" />
        <vers num="2.6.24_rc5" />
        <vers num="2.6.25" edition="" />
        <vers num="2.6.25" edition=":x86_64" />
        <vers num="2.6.25.1" edition="" />
        <vers num="2.6.25.1" edition=":x86_64" />
        <vers num="2.6.25.10" edition="" />
        <vers num="2.6.25.10" edition=":x86_64" />
        <vers num="2.6.25.11" edition="" />
        <vers num="2.6.25.11" edition=":x86_64" />
        <vers num="2.6.25.12" edition="" />
        <vers num="2.6.25.12" edition=":x86_64" />
        <vers num="2.6.25.13" />
        <vers num="2.6.25.14" />
        <vers num="2.6.25.15" />
        <vers num="2.6.25.16" />
        <vers num="2.6.25.17" />
        <vers num="2.6.25.2" edition="" />
        <vers num="2.6.25.2" edition=":x86_64" />
        <vers num="2.6.25.3" edition="" />
        <vers num="2.6.25.3" edition=":x86_64" />
        <vers num="2.6.25.4" edition="" />
        <vers num="2.6.25.4" edition=":x86_64" />
        <vers num="2.6.25.5" edition="" />
        <vers num="2.6.25.5" edition=":x86_64" />
        <vers num="2.6.25.6" edition="" />
        <vers num="2.6.25.6" edition=":x86_64" />
        <vers num="2.6.25.7" edition="" />
        <vers num="2.6.25.7" edition=":x86_64" />
        <vers num="2.6.25.8" edition="" />
        <vers num="2.6.25.8" edition=":x86_64" />
        <vers num="2.6.25.9" edition="" />
        <vers num="2.6.25.9" edition=":x86_64" />
        <vers num="2.6.26" />
        <vers num="2.6.26.1" />
        <vers num="2.6.26.2" />
        <vers num="2.6.26.3" />
        <vers num="2.6.26.4" />
        <vers num="2.6.26.5" />
        <vers num="2.6.27" />
        <vers num="2.6.27.1" />
        <vers num="2.6.27.10" />
        <vers num="2.6.27.11" />
        <vers num="2.6.27.12" />
        <vers num="2.6.27.13" />
        <vers num="2.6.27.14" />
        <vers num="2.6.27.15" />
        <vers num="2.6.27.16" />
        <vers num="2.6.27.17" />
        <vers num="2.6.27.18" />
        <vers num="2.6.27.19" />
        <vers num="2.6.27.2" />
        <vers num="2.6.27.20" />
        <vers prev="1" num="2.6.27.21" />
        <vers num="2.6.27.3" />
        <vers num="2.6.27.4" />
        <vers num="2.6.27.5" />
        <vers num="2.6.27.6" />
        <vers num="2.6.27.7" />
        <vers num="2.6.27.8" />
        <vers num="2.6.27.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1339" published="2009-04-30" name="CVE-2009-1339" modified="2009-05-14" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:S/C:P/I:P/A:P)" CVSS_score="6.0" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="6.8" CVSS_base_score="6.0">
    <desc>
      <descript source="cve">Cross-site request forgery (CSRF) vulnerability in TWiki before 4.3.1 allows remote authenticated users to hijack the authentication of arbitrary users for requests that update pages, as demonstrated by a URL for a save script in the SRC attribute of an IMG element, a related issue to CVE-2009-1434.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://securitytracker.com/id?1022146" source="SECTRACK" patch="1">1022146</ref>
      <ref url="https://launchpad.net/bugs/cve/2009-1339" source="CONFIRM">https://launchpad.net/bugs/cve/2009-1339</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/50254" source="XF">twiki-unspecified-csrf(50254)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1217" source="VUPEN">ADV-2009-1217</ref>
      <ref url="http://www.nabble.com/Bug-526258:-CVE-2009-1339:-CSRF-Vulnerability-with-Image-Tag-td23311575.html" source="MLIST">[debian-bugs-rc] 20090430 Bug#526258: CVE-2009-1339: CSRF Vulnerability with Image Tag</ref>
      <ref url="http://twiki.org/p/pub/Codev/SecurityAlert-CVE-2009-1339/TWiki-4.3.0-c-diff-cve-2009-1339.txt" source="CONFIRM">http://twiki.org/p/pub/Codev/SecurityAlert-CVE-2009-1339/TWiki-4.3.0-c-diff-cve-2009-1339.txt</ref>
      <ref url="http://twiki.org/cgi-bin/view/Codev/SecurityAlert-CVE-2009-1339" source="CONFIRM" adv="1">http://twiki.org/cgi-bin/view/Codev/SecurityAlert-CVE-2009-1339</ref>
      <ref url="http://sourceforge.net/mailarchive/forum.php?thread_name=7E0723DC-CBFF-4DBD-B26C-8686287FF689%40twiki.net&amp;forum_name=twiki-announce" source="MLIST">[twiki-announce] 20090430 Announcement: TWiki 4.3.1 Production Release</ref>
      <ref url="http://secunia.com/advisories/34880" source="SECUNIA" adv="1">34880</ref>
      <ref url="http://bugs.debian.org/526258" source="CONFIRM">http://bugs.debian.org/526258</ref>
    </refs>
    <vuln_soft>
      <prod vendor="twiki" name="twiki">
        <vers num="4.1.2" />
        <vers num="4.2.0" />
        <vers num="4.2.1" />
        <vers num="4.2.2" />
        <vers num="4.2.3" />
        <vers num="4.2.4" />
        <vers prev="1" num="4.3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1341" published="2009-04-30" name="CVE-2009-1341" modified="2012-01-06" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Memory leak in the dequote_bytea function in quote.c in the DBD::Pg (aka DBD-Pg or libdbd-pg-perl) module before 2.0.0 for Perl allows context-dependent attackers to cause a denial of service (memory consumption) by fetching data with BYTEA columns.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="https://launchpad.net/bugs/cve/2009-1341" source="MISC">https://launchpad.net/bugs/cve/2009-1341</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/50387" source="XF">libdbdpgperl-dequotebytea-dos(50387)</ref>
      <ref url="http://www.securityfocus.com/bid/34757" source="BID">34757</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-1067.html" source="REDHAT">RHSA-2009:1067</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-0479.html" source="REDHAT">RHSA-2009:0479</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1780" source="DEBIAN">DSA-1780</ref>
      <ref url="http://security.debian.org/pool/updates/main/libd/libdbd-pg-perl/libdbd-pg-perl_1.49-2+etch1.diff.gz" source="CONFIRM">http://security.debian.org/pool/updates/main/libd/libdbd-pg-perl/libdbd-pg-perl_1.49-2+etch1.diff.gz</ref>
      <ref url="http://secunia.com/advisories/35685" source="SECUNIA">35685</ref>
      <ref url="http://secunia.com/advisories/35058" source="SECUNIA" adv="1">35058</ref>
      <ref url="http://secunia.com/advisories/34909" source="SECUNIA" adv="1">34909</ref>
      <ref url="http://rt.cpan.org/Public/Bug/Display.html?id=21392" source="CONFIRM">http://rt.cpan.org/Public/Bug/Display.html?id=21392</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9680" source="OVAL">oval:org.mitre.oval:def:9680</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-07/msg00002.html" source="SUSE">SUSE-SR:2009:012</ref>
      <ref url="http://cpansearch.perl.org/src/TURNSTEP/DBD-Pg-2.13.1/Changes" source="CONFIRM">http://cpansearch.perl.org/src/TURNSTEP/DBD-Pg-2.13.1/Changes</ref>
    </refs>
    <vuln_soft>
      <prod vendor="debian" name="libdbd-pg-perl">
        <vers num="0.1" />
        <vers num="0.2" />
        <vers num="0.3" />
        <vers num="0.4" />
        <vers num="0.5" />
        <vers num="0.51" />
        <vers num="0.52" />
        <vers num="0.61" />
        <vers num="0.62" />
        <vers num="0.63" />
        <vers num="0.64" />
        <vers num="0.65" />
        <vers num="0.66" />
        <vers num="0.67" />
        <vers num="0.68" />
        <vers num="0.69" />
        <vers num="0.70" />
        <vers num="0.71" />
        <vers num="0.72" />
        <vers num="0.73" />
        <vers num="0.80" />
        <vers num="0.81" />
        <vers num="0.82" />
        <vers num="0.83" />
        <vers num="0.84" />
        <vers num="0.85" />
        <vers num="0.86" />
        <vers num="0.87" />
        <vers num="0.88" />
        <vers num="0.89" />
        <vers num="0.90" />
        <vers num="0.91" />
        <vers num="0.92" />
        <vers num="0.93" />
        <vers num="0.94" />
        <vers num="0.95" />
        <vers num="0.96" />
        <vers num="0.97" />
        <vers num="0.98" />
        <vers num="0.99" />
        <vers num="1.0.0" />
        <vers num="1.0.1" />
        <vers num="1.2.0" />
        <vers num="1.2.1" />
        <vers num="1.2.2" />
        <vers num="1.3.1" />
        <vers num="1.3.2" />
        <vers num="1.4.0" />
        <vers num="1.4.1" />
        <vers num="1.4.2" />
        <vers num="1.4.3" />
        <vers num="1.4.4" />
        <vers num="1.4.5" />
        <vers num="1.4.6" />
        <vers num="1.4.7" />
        <vers num="1.4.8" />
        <vers prev="1" num="1.4.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1342" published="2009-04-20" name="CVE-2009-1342" modified="2009-04-20" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the CCK comment reference module 6.x before 6.x-1.2, a module for Drupal, allows remote attackers to inject arbitrary web script or HTML via certain comment titles associated with a node edit form.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2009/1060" source="VUPEN" patch="1" adv="1">ADV-2009-1060</ref>
      <ref url="http://drupal.org/node/434836" source="CONFIRM" patch="1" adv="1">http://drupal.org/node/434836</ref>
      <ref url="http://www.securityfocus.com/bid/34547" source="BID">34547</ref>
      <ref url="http://secunia.com/advisories/34739" source="SECUNIA" adv="1">34739</ref>
      <ref url="http://osvdb.org/53702" source="OSVDB">53702</ref>
    </refs>
    <vuln_soft>
      <prod vendor="drupal" name="cck_comment_reference">
        <vers num="6.x" />
        <vers num="6.x-1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1343" published="2009-04-20" name="CVE-2009-1343" modified="2009-04-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the Print (aka Printer, e-mail and PDF versions) module 5.x before 5.x-4.5 and 6.x before 6.x-1.5, a module for Drupal, allows remote attackers to inject arbitrary web script or HTML via content titles.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2009/1060" source="VUPEN" patch="1" adv="1">ADV-2009-1060</ref>
      <ref url="http://www.securityfocus.com/bid/34545" source="BID" patch="1">34545</ref>
      <ref url="http://drupal.org/node/434748" source="CONFIRM" patch="1">http://drupal.org/node/434748</ref>
      <ref url="http://www.osvdb.org/53704" source="OSVDB">53704</ref>
      <ref url="http://secunia.com/advisories/34738" source="SECUNIA" adv="1">34738</ref>
    </refs>
    <vuln_soft>
      <prod vendor="drupal" name="print">
        <vers num="5.x" />
        <vers num="5.x-1.0" />
        <vers num="5.x-1.1" />
        <vers num="5.x-1.2" />
        <vers num="5.x-1.x-dev" />
        <vers num="5.x-2.1" />
        <vers num="5.x-2.2" />
        <vers num="5.x-2.x-dev" />
        <vers num="5.x-3.0" />
        <vers num="5.x-3.1" />
        <vers num="5.x-3.2" />
        <vers num="5.x-3.3" />
        <vers num="5.x-3.4" />
        <vers num="5.x-3.5" />
        <vers num="5.x-3.6" />
        <vers num="5.x-3.7" />
        <vers num="5.x-4.0" />
        <vers num="5.x-4.1" />
        <vers num="5.x-4.2" />
        <vers num="5.x-4.3" />
        <vers num="5.x-4.4" />
        <vers num="5.x-4.x" edition="dev" />
        <vers num="6.x-1.0" />
        <vers num="6.x-1.0-rc3" />
        <vers num="6.x-1.0-rc4" />
        <vers num="6.x-1.0-rc5" />
        <vers num="6.x-1.0-rc8" />
        <vers num="6.x-1.0-rc9" />
        <vers num="6.x-1.1" />
        <vers num="6.x-1.2" />
        <vers num="6.x-1.3" />
        <vers num="6.x-1.4" />
        <vers num="6.x-1.x-dev" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1344" published="2009-04-20" name="CVE-2009-1344" modified="2009-04-20" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the Localization client module 5.x before 5.x-1.2 and 6.x before 6.x-1.7, a module for Drupal, allows remote attackers to inject arbitrary web script or HTML via input to the translation functionality.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2009/1060" source="VUPEN" patch="1" adv="1">ADV-2009-1060</ref>
      <ref url="http://www.securityfocus.com/bid/34546" source="BID" patch="1">34546</ref>
      <ref url="http://drupal.org/node/434682" source="CONFIRM" patch="1" adv="1">http://drupal.org/node/434682</ref>
      <ref url="http://secunia.com/advisories/34718" source="SECUNIA" adv="1">34718</ref>
      <ref url="http://osvdb.org/53703" source="OSVDB">53703</ref>
    </refs>
    <vuln_soft>
      <prod vendor="drupal" name="localization_client">
        <vers num="5.x-1.0" />
        <vers num="5.x-1.1" />
        <vers num="5.x-1.xdev" />
        <vers num="6.x-1.0" />
        <vers num="6.x-1.1" />
        <vers num="6.x-1.2" />
        <vers num="6.x-1.3" />
        <vers num="6.x-1.4" />
        <vers num="6.x-1.5" />
        <vers num="6.x-1.6" />
        <vers num="6.x-1.xdev" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1345" published="2009-04-20" name="CVE-2009-1345" modified="2009-04-28" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in document.php in cpCommerce 1.2.8 allows remote attackers to execute arbitrary SQL commands via the id_document parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/49901" source="XF">cpcommerce-document-sql-injection(49901)</ref>
      <ref url="http://www.securitytracker.com/id?1022082" source="SECTRACK">1022082</ref>
      <ref url="http://www.securityfocus.com/bid/34556" source="BID">34556</ref>
      <ref url="http://www.milw0rm.com/exploits/8455" source="MILW0RM">8455</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cpcommerce" name="cpcommerce">
        <vers num="1.2.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1346" published="2009-04-20" name="CVE-2009-1346" modified="2009-04-28" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in publico/ficha.php in NetHoteles 3.0 allows remote attackers to execute arbitrary SQL commands via the id_establecimiento parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/49897" source="XF">nethoteles-ficha-sql-injection(49897)</ref>
      <ref url="http://www.securityfocus.com/bid/34561" source="BID">34561</ref>
      <ref url="http://www.milw0rm.com/exploits/8457" source="MILW0RM">8457</ref>
      <ref url="http://secunia.com/advisories/34743" source="SECUNIA">34743</ref>
      <ref url="http://osvdb.org/53814" source="OSVDB">53814</ref>
    </refs>
    <vuln_soft>
      <prod vendor="interguias" name="nethoteles">
        <vers num="3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1347" published="2009-04-20" name="CVE-2009-1347" modified="2009-04-20" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in stats/index.php in chCounter 3.1.3 allow remote attackers to execute arbitrary SQL commands via (1) the login_name parameter (aka the username field) or (2) the login_pw parameter (aka the password field).</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/34572" source="BID">34572</ref>
      <ref url="http://www.milw0rm.com/exploits/8461" source="MILW0RM">8461</ref>
      <ref url="http://secunia.com/advisories/24879" source="SECUNIA" adv="1">24879</ref>
    </refs>
    <vuln_soft>
      <prod vendor="chcounter" name="chcounter">
        <vers num="3.1.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1348" published="2009-04-30" name="CVE-2009-1348" modified="2009-05-19" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)" CVSS_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_base_score="7.6">
    <desc>
      <descript source="cve">The AV engine before DAT 5600 in McAfee VirusScan, Total Protection, Internet Security, SecurityShield for Microsoft ISA Server, Security for Microsoft Sharepoint, Security for Email Servers, Email Gateway, and Active Virus Defense allows remote attackers to bypass virus detection via (1) an invalid Headflags field in a malformed RAR archive, (2) an invalid Packsize field in a malformed RAR archive, or (3) an invalid Filelength field in a malformed ZIP archive.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="https://kc.mcafee.com/corporate/index?page=content&amp;id=SB10001&amp;actp=LIST_RECENT" source="CONFIRM" patch="1" adv="1">https://kc.mcafee.com/corporate/index?page=content&amp;id=SB10001&amp;actp=LIST_RECENT</ref>
      <ref url="http://www.securityfocus.com/bid/34780" source="BID">34780</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/503173/100/0/threaded" source="BUGTRAQ">20090501 [TZO-18-2009] Mcafee multiple evasions/bypasses (RAR, ZIP)</ref>
      <ref url="http://secunia.com/advisories/34949" source="SECUNIA" adv="1">34949</ref>
      <ref url="http://blog.zoller.lu/2009/04/mcafee-multiple-bypassesevasions-ziprar.html" source="MISC">http://blog.zoller.lu/2009/04/mcafee-multiple-bypassesevasions-ziprar.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mcafee" name="active_virus_defense">
        <vers num="" />
      </prod>
      <prod vendor="mcafee" name="active_virusscan">
        <vers num="" />
      </prod>
      <prod vendor="mcafee" name="email_gateway">
        <vers num="" />
      </prod>
      <prod vendor="mcafee" name="internet_security_suite">
        <vers num="2004" />
        <vers num="2005" />
        <vers num="2006" />
        <vers num="2009" />
      </prod>
      <prod vendor="mcafee" name="securityshield_for_email_servers">
        <vers num="" />
      </prod>
      <prod vendor="mcafee" name="securityshield_for_microsoft_isa_server">
        <vers num="" />
      </prod>
      <prod vendor="mcafee" name="securityshield_for_microsoft_sharepoint">
        <vers num="" />
      </prod>
      <prod vendor="mcafee" name="total_protection">
        <vers num="2009" />
      </prod>
      <prod vendor="mcafee" name="total_protection_for_endpoint">
        <vers num="" />
      </prod>
      <prod vendor="mcafee" name="virusscan_commandline">
        <vers num="" />
      </prod>
      <prod vendor="mcafee" name="virusscan_enterprise">
        <vers num="-" edition="-" />
        <vers num="-" edition="-:storage" />
        <vers num="-" edition="-:linux" />
        <vers num="-" edition="-:sap" />
      </prod>
      <prod vendor="mcafee" name="virusscan_plus">
        <vers num="2009" />
      </prod>
      <prod vendor="mcafee" name="virusscan_usb">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1349" published="2009-04-21" name="CVE-2009-1349" modified="2009-04-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in C2Net Stronghold 2.3 allows remote attackers to inject arbitrary web script or HTML via the URI.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/34606" source="BID">34606</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/502799/100/0/threaded" source="BUGTRAQ">20090418 Cross-site Scripting vulnerability in Stronghold/2.3 Apache/1.2.6 C2NetUS/2007</ref>
    </refs>
    <vuln_soft>
      <prod vendor="redhat" name="stronghold">
        <vers num="2.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1350" published="2009-04-21" name="CVE-2009-1350" modified="2009-04-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in xtagent.exe in Novell NetIdentity Client before 1.2.4 allows remote attackers to execute arbitrary code by establishing an IPC$ connection to the XTIERRPCPIPE named pipe, and sending RPC messages that trigger a dereference of an arbitrary pointer.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.zerodayinitiative.com/advisories/ZDI-09-016/" source="MISC" patch="1">http://www.zerodayinitiative.com/advisories/ZDI-09-016/</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/0954" source="VUPEN" patch="1" adv="1">ADV-2009-0954</ref>
      <ref url="http://download.novell.com/Download?buildid=6ERQGPjRZ8o~" source="CONFIRM" patch="1" adv="1">http://download.novell.com/Download?buildid=6ERQGPjRZ8o~</ref>
      <ref url="https://bugzilla.novell.com/show_bug.cgi?id=437511" source="MISC">https://bugzilla.novell.com/show_bug.cgi?id=437511</ref>
      <ref url="http://www.securitytracker.com/id?1021990" source="SECTRACK">1021990</ref>
      <ref url="http://www.securityfocus.com/bid/34400" source="BID">34400</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/502514/100/0/threaded" source="BUGTRAQ">20090406 ZDI-09-016: Novell Client/NetIdentity Agent Remote Arbitrary Pointer Dereference Code Execution Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="novell" name="netidentity_client1.2.3">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1351" published="2009-04-21" name="CVE-2009-1351" modified="2009-04-28" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Heap-based buffer overflow in Apollo 37zz allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a long URI in a playlist (.m3u) file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/34554" source="BID">34554</ref>
      <ref url="http://www.milw0rm.com/exploits/8451" source="MILW0RM">8451</ref>
      <ref url="http://secunia.com/advisories/34050" source="SECUNIA">34050</ref>
      <ref url="http://osvdb.org/53770" source="OSVDB">53770</ref>
    </refs>
    <vuln_soft>
      <prod vendor="heikki_ylinen" name="apollo">
        <vers num="37zz" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1352" published="2009-04-21" name="CVE-2009-1352" modified="2009-04-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Stack-based buffer overflow in Dawningsoft PowerCHM 5.7 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via an HTML file with a link to a long URL, as demonstrated by a .rar URL.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/49882" source="XF">powerchm-url-bo(49882)</ref>
      <ref url="http://www.securityfocus.com/bid/34517" source="BID">34517</ref>
      <ref url="http://www.milw0rm.com/exploits/8434" source="MILW0RM">8434</ref>
    </refs>
    <vuln_soft>
      <prod vendor="dawningsoft" name="powerchm">
        <vers num="5.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1353" published="2009-04-21" name="CVE-2009-1353" modified="2009-04-29" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Buffer overflow in the http_parse_hex function in libz/misc.c in Zervit Webserver 0.02 allows remote attackers to cause a denial of service (daemon crash) via a long URI, related to http.c.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://zervit.svn.sourceforge.net/viewvc/zervit/trunk/src/libz/misc.c?view=log" source="CONFIRM">http://zervit.svn.sourceforge.net/viewvc/zervit/trunk/src/libz/misc.c?view=log</ref>
      <ref url="http://zervit.svn.sourceforge.net/viewvc/zervit/trunk/src/libz/misc.c?r1=17&amp;r2=19" source="CONFIRM">http://zervit.svn.sourceforge.net/viewvc/zervit/trunk/src/libz/misc.c?r1=17&amp;r2=19</ref>
      <ref url="http://www.securityfocus.com/bid/34530" source="BID">34530</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/502693/100/0/threaded" source="BUGTRAQ">20090414 Zervit Webserver Buffer Overflow</ref>
      <ref url="http://www.milw0rm.com/exploits/8447" source="MILW0RM">8447</ref>
      <ref url="http://secunia.com/advisories/34735" source="SECUNIA">34735</ref>
      <ref url="http://osvdb.org/53768" source="OSVDB">53768</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sebastian_fernandez" name="zervit">
        <vers num="0.02" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1354" published="2009-04-21" name="CVE-2009-1354" modified="2009-04-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:N/A:N)" CVSS_score="4.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.0" CVSS_base_score="4.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in Mongoose 2.4 allows remote attackers to read arbitrary files via a .. (dot dot) in the URI.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/49878" source="XF">mongoose-directory-traversal(49878)</ref>
      <ref url="http://www.securityfocus.com/bid/34510" source="BID">34510</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/502648/100/0/threaded" source="BUGTRAQ">20090413 MonGoose 2.4 Directory Traversal Vulnerability</ref>
      <ref url="http://www.milw0rm.com/exploits/8428" source="MILW0RM">8428</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sergey_lyubka" name="mongoose">
        <vers num="2.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1355" published="2009-04-21" name="CVE-2009-1355" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Stack-based buffer overflow in muxatmd in IBM AIX 5.2, 5.3, and 6.1 allows local users to gain privileges via a long filename.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2009/1056" source="VUPEN" patch="1" adv="1">ADV-2009-1056</ref>
      <ref url="http://www.securityfocus.com/bid/34543" source="BID" patch="1">34543</ref>
      <ref url="http://www.securitytracker.com/id?1022065" source="SECTRACK">1022065</ref>
      <ref url="http://www.ibm.com/support/docview.wss?uid=isg1IZ48562" source="AIXAPAR" adv="1">IZ48562</ref>
      <ref url="http://www.ibm.com/support/docview.wss?uid=isg1IZ48561" source="AIXAPAR">IZ48561</ref>
      <ref url="http://www.ibm.com/support/docview.wss?uid=isg1IZ48502" source="AIXAPAR" adv="1">IZ48502</ref>
      <ref url="http://www.ibm.com/support/docview.wss?uid=isg1IZ48501" source="AIXAPAR">IZ48501</ref>
      <ref url="http://www.ibm.com/support/docview.wss?uid=isg1IZ48500" source="AIXAPAR">IZ48500</ref>
      <ref url="http://www.ibm.com/support/docview.wss?uid=isg1IZ48499" source="AIXAPAR" adv="1">IZ48499</ref>
      <ref url="http://www.ibm.com/support/docview.wss?uid=isg1IZ48496" source="AIXAPAR" adv="1">IZ48496</ref>
      <ref url="http://www.ibm.com/support/docview.wss?uid=isg1IZ48495" source="AIXAPAR">IZ48495</ref>
      <ref url="http://secunia.com/advisories/34662" source="SECUNIA" adv="1">34662</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6402" source="OVAL">oval:org.mitre.oval:def:6402</ref>
      <ref url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=784" source="IDEFENSE">20090415 IBM AIX muxatmd Buffer Overflow Vulnerability</ref>
      <ref url="http://aix.software.ibm.com/aix/efixes/security/muxatmd_advisory.asc" source="CONFIRM" adv="1">http://aix.software.ibm.com/aix/efixes/security/muxatmd_advisory.asc</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="aix">
        <vers num="5.2" />
        <vers num="5.3" />
        <vers num="6.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1356" published="2009-04-21" name="CVE-2009-1356" modified="2009-04-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Stack-based buffer overflow in Elecard AVC HD Player allows remote attackers to execute arbitrary code via a long MP3 filename in a playlist (.xpl) file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/34560" source="BID">34560</ref>
      <ref url="http://www.milw0rm.com/exploits/8452" source="MILW0RM">8452</ref>
    </refs>
    <vuln_soft>
      <prod vendor="elecard" name="elecard_avc_hd_player">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1357" published="2009-04-23" name="CVE-2009-1357" modified="2010-06-02" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">CRLF injection vulnerability in da/DA/Login in Sun Java System Delegated Administrator 6.2 through 6.4 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the HELP_PAGE parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2009/1122" source="VUPEN" patch="1" adv="1">ADV-2009-1122</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-255928-1" source="SUNALERT" patch="1" adv="1">255928</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-21-121581-20-1" source="CONFIRM" patch="1">http://sunsolve.sun.com/search/document.do?assetkey=1-21-121581-20-1</ref>
      <ref url="http://securitytracker.com/id?1022108" source="SECTRACK" patch="1">1022108</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/50004" source="XF">sjs-delegated-login-response-splitting(50004)</ref>
      <ref url="http://www.securityfocus.com/bid/34643" source="BID">34643</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/502863/100/0/threaded" source="BUGTRAQ">20090421 CORE-2009-0114 - HTTP Response Splitting vulnerability in Sun Delegated Administrator</ref>
      <ref url="http://www.coresecurity.com/content/sun-delegated-administrator" source="MISC">http://www.coresecurity.com/content/sun-delegated-administrator</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-77-1020305.1-1" source="SUNALERT">1020305</ref>
      <ref url="http://secunia.com/advisories/34760" source="SECUNIA" adv="1">34760</ref>
      <ref url="http://osvdb.org/53920" source="OSVDB">53920</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="java_system_delegated_administrator">
        <vers num="6.2" edition="-" />
        <vers num="6.2" edition="-:x86" />
        <vers num="6.2" edition="-:sparc" />
        <vers num="6.2" edition="-:linux" />
        <vers num="6.3" edition="-" />
        <vers num="6.3" edition="-:x86" />
        <vers num="6.3" edition="-:linux" />
        <vers num="6.3" edition="-:sparc" />
        <vers num="6.4" edition="-" />
        <vers num="6.4" edition="-:sparc" />
        <vers num="6.4" edition="-:x86" />
        <vers num="6.4" edition="-:linux" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1358" published="2009-04-21" name="CVE-2009-1358" modified="2009-05-19" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">apt-get in apt before 0.7.21 does not check for the correct error code from gpgv, which causes apt to treat a repository as valid even when it has been signed with a key that has been revoked or expired, which might allow remote attackers to trick apt into installing malicious repositories.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="https://bugs.launchpad.net/ubuntu/+source/apt/+bug/356012" source="CONFIRM">https://bugs.launchpad.net/ubuntu/+source/apt/+bug/356012</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/50086" source="XF">apt-aptget-gpgv-security-bypass(50086)</ref>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-762-1" source="UBUNTU">USN-762-1</ref>
      <ref url="http://www.securityfocus.com/bid/34630" source="BID">34630</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1779" source="DEBIAN">DSA-1779</ref>
      <ref url="http://secunia.com/advisories/34874" source="SECUNIA">34874</ref>
      <ref url="http://secunia.com/advisories/34832" source="SECUNIA">34832</ref>
      <ref url="http://secunia.com/advisories/34829" source="SECUNIA">34829</ref>
      <ref url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=433091" source="CONFIRM">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=433091</ref>
    </refs>
    <vuln_soft>
      <prod vendor="debian" name="apt">
        <vers num="0.0.1" />
        <vers num="0.0.10" />
        <vers num="0.0.11" />
        <vers num="0.0.12" />
        <vers num="0.0.13" />
        <vers num="0.0.13-bo1" />
        <vers num="0.0.14" />
        <vers num="0.0.15" />
        <vers num="0.0.15-0.1bo" />
        <vers num="0.0.15-0.2bo" />
        <vers num="0.0.16-1" />
        <vers num="0.0.17-1" />
        <vers num="0.0.2" />
        <vers num="0.0.3" />
        <vers num="0.0.4" />
        <vers num="0.0.5" />
        <vers num="0.0.6" />
        <vers num="0.0.7" />
        <vers num="0.0.8" />
        <vers num="0.0.9" />
        <vers num="0.1" />
        <vers num="0.1.1" />
        <vers num="0.1.3" />
        <vers num="0.1.5" />
        <vers num="0.1.6" />
        <vers num="0.1.7" />
        <vers num="0.1.9" />
        <vers num="0.3.0" />
        <vers num="0.3.1" />
        <vers num="0.3.11" />
        <vers num="0.3.12" />
        <vers num="0.3.13" />
        <vers num="0.3.14" />
        <vers num="0.3.15" />
        <vers num="0.3.16" />
        <vers num="0.3.17" />
        <vers num="0.3.18" />
        <vers num="0.3.19" />
        <vers num="0.3.2" />
        <vers num="0.3.3" />
        <vers num="0.3.4" />
        <vers num="0.3.6" />
        <vers num="0.3.7" />
        <vers num="0.3.9" />
        <vers num="0.5.0" />
        <vers num="0.5.1" />
        <vers num="0.5.10" />
        <vers num="0.5.11" />
        <vers num="0.5.12" />
        <vers num="0.5.13" />
        <vers num="0.5.14" />
        <vers num="0.5.15" />
        <vers num="0.5.16" />
        <vers num="0.5.17" />
        <vers num="0.5.18" />
        <vers num="0.5.19" />
        <vers num="0.5.2" />
        <vers num="0.5.20" />
        <vers num="0.5.21" />
        <vers num="0.5.22" />
        <vers num="0.5.23" />
        <vers num="0.5.24" />
        <vers num="0.5.25" />
        <vers num="0.5.26" />
        <vers num="0.5.27" />
        <vers num="0.5.28" />
        <vers num="0.5.29" />
        <vers num="0.5.3" />
        <vers num="0.5.30" edition="ubuntu1" />
        <vers num="0.5.30" edition="ubuntu2" />
        <vers num="0.5.31" />
        <vers num="0.5.32" />
        <vers num="0.5.4" />
        <vers num="0.5.5" />
        <vers num="0.5.5.1" />
        <vers num="0.5.6" />
        <vers num="0.5.7" />
        <vers num="0.5.8" />
        <vers num="0.5.9" />
        <vers num="0.6.0" />
        <vers num="0.6.1" />
        <vers num="0.6.10" />
        <vers num="0.6.11" />
        <vers num="0.6.12" />
        <vers num="0.6.13" />
        <vers num="0.6.14" />
        <vers num="0.6.15" />
        <vers num="0.6.16" />
        <vers num="0.6.17" />
        <vers num="0.6.18" />
        <vers num="0.6.19" />
        <vers num="0.6.2" />
        <vers num="0.6.20" />
        <vers num="0.6.21" />
        <vers num="0.6.22" />
        <vers num="0.6.23" />
        <vers num="0.6.24" />
        <vers num="0.6.25" />
        <vers num="0.6.27" edition="ubuntu1" />
        <vers num="0.6.27" edition="ubuntu2" />
        <vers num="0.6.27" edition="ubuntu3" />
        <vers num="0.6.27" edition="ubuntu4" />
        <vers num="0.6.28" />
        <vers num="0.6.29" />
        <vers num="0.6.3" />
        <vers num="0.6.30" />
        <vers num="0.6.31" />
        <vers num="0.6.32" />
        <vers num="0.6.33" />
        <vers num="0.6.34" />
        <vers num="0.6.35" />
        <vers num="0.6.36" edition="ubuntu1" />
        <vers num="0.6.37" />
        <vers num="0.6.38" />
        <vers num="0.6.39" />
        <vers num="0.6.4" />
        <vers num="0.6.40" />
        <vers num="0.6.40.1" />
        <vers num="0.6.41" />
        <vers num="0.6.42" />
        <vers num="0.6.42.1" />
        <vers num="0.6.42.2" />
        <vers num="0.6.42.3" />
        <vers num="0.6.43" />
        <vers num="0.6.43.1" />
        <vers num="0.6.43.2" />
        <vers num="0.6.43.3" />
        <vers num="0.6.44" />
        <vers num="0.6.44.1" />
        <vers num="0.6.44.1-0.1" />
        <vers num="0.6.44.2" edition="exp1" />
        <vers num="0.6.45" />
        <vers num="0.6.46" />
        <vers num="0.6.46.1" />
        <vers num="0.6.46.2" />
        <vers num="0.6.46.3" />
        <vers num="0.6.46.3-0.1" />
        <vers num="0.6.46.3-0.2" />
        <vers num="0.6.46.4-0.1" />
        <vers num="0.6.5" />
        <vers num="0.6.6" />
        <vers num="0.6.7" />
        <vers num="0.6.8" />
        <vers num="0.6.9" />
        <vers num="0.7.0" />
        <vers num="0.7.1" />
        <vers num="0.7.10" />
        <vers num="0.7.11" />
        <vers num="0.7.12" />
        <vers num="0.7.13" />
        <vers num="0.7.14" />
        <vers num="0.7.15" edition="exp1" />
        <vers num="0.7.15" edition="exp2" />
        <vers num="0.7.15" edition="exp3" />
        <vers num="0.7.16" />
        <vers num="0.7.17" edition="exp1" />
        <vers num="0.7.17" edition="exp2" />
        <vers num="0.7.17" edition="exp3" />
        <vers num="0.7.17" edition="exp4" />
        <vers num="0.7.18" />
        <vers num="0.7.19" />
        <vers num="0.7.2" />
        <vers num="0.7.2-0.1" />
        <vers prev="1" num="0.7.20" />
        <vers num="0.7.20.1" />
        <vers num="0.7.20.2" />
        <vers num="0.7.21" />
        <vers num="0.7.3" />
        <vers num="0.7.4" />
        <vers num="0.7.5" />
        <vers num="0.7.6" />
        <vers num="0.7.7" />
        <vers num="0.7.8" />
        <vers num="0.7.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1359" published="2009-04-22" name="CVE-2009-1359" modified="2009-05-14" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="4.9" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="3.9" CVSS_base_score="4.9">
    <desc>
      <descript source="cve">Unspecified vulnerability in the SCTP sockets implementation in Sun OpenSolaris snv_106 through snv_107 allows local users to cause a denial of service (panic) via unknown vectors.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-257331-1" source="SUNALERT" patch="1" adv="1">257331</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1120" source="VUPEN">ADV-2009-1120</ref>
      <ref url="http://www.securityfocus.com/bid/34628" source="BID">34628</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="opensolaris">
        <vers num="snv_106" edition="" />
        <vers num="snv_106" edition=":x86" />
        <vers num="snv_106" edition=":sparc" />
        <vers num="snv_107" edition="" />
        <vers num="snv_107" edition=":x86" />
        <vers num="snv_107" edition=":sparc" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1360" published="2009-04-22" name="CVE-2009-1360" modified="2010-05-04" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:C)" CVSS_score="7.1" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="8.6" CVSS_base_score="7.1">
    <desc>
      <descript source="cve">The __inet6_check_established function in net/ipv6/inet6_hashtables.c in the Linux kernel before 2.6.29, when Network Namespace Support (aka NET_NS) is enabled, allows remote attackers to cause a denial of service (NULL pointer dereference and system crash) via vectors involving IPv6 packets.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.29" source="CONFIRM" patch="1" adv="1">http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.29</ref>
      <ref url="http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=3f53a38131a4e7a053c0aa060aba0411242fb6b9" source="CONFIRM" patch="1" adv="1">http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=3f53a38131a4e7a053c0aa060aba0411242fb6b9</ref>
      <ref url="http://xorl.wordpress.com/2009/04/21/linux-kernel-net_ns-ipv6-null-pointer-dereference/" source="MISC">http://xorl.wordpress.com/2009/04/21/linux-kernel-net_ns-ipv6-null-pointer-dereference/</ref>
      <ref url="http://www.ubuntu.com/usn/usn-793-1" source="UBUNTU">USN-793-1</ref>
      <ref url="http://www.securityfocus.com/bid/34602" source="BID">34602</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:135" source="MANDRIVA">MDVSA-2009:135</ref>
      <ref url="http://secunia.com/advisories/35656" source="SECUNIA">35656</ref>
      <ref url="http://secunia.com/advisories/35387" source="SECUNIA">35387</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-06/msg00002.html" source="SUSE">SUSE-SA:2009:032</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="kernel">
        <vers num="2.2.27" />
        <vers num="2.4.36" />
        <vers num="2.4.36.1" />
        <vers num="2.4.36.2" />
        <vers num="2.4.36.3" />
        <vers num="2.4.36.4" />
        <vers num="2.4.36.5" />
        <vers num="2.4.36.6" />
        <vers num="2.6" />
        <vers num="2.6.0" />
        <vers num="2.6.1" />
        <vers num="2.6.10" />
        <vers num="2.6.11" />
        <vers num="2.6.11.1" />
        <vers num="2.6.11.10" />
        <vers num="2.6.11.11" />
        <vers num="2.6.11.12" />
        <vers num="2.6.11.2" />
        <vers num="2.6.11.3" />
        <vers num="2.6.11.4" />
        <vers num="2.6.11.5" />
        <vers num="2.6.11.6" />
        <vers num="2.6.11.7" />
        <vers num="2.6.11.8" />
        <vers num="2.6.11.9" />
        <vers num="2.6.12" />
        <vers num="2.6.12.1" />
        <vers num="2.6.12.2" />
        <vers num="2.6.12.3" />
        <vers num="2.6.12.4" />
        <vers num="2.6.12.5" />
        <vers num="2.6.12.6" />
        <vers num="2.6.13" />
        <vers num="2.6.13.1" />
        <vers num="2.6.13.2" />
        <vers num="2.6.13.3" />
        <vers num="2.6.13.4" />
        <vers num="2.6.13.5" />
        <vers num="2.6.14" />
        <vers num="2.6.14.1" />
        <vers num="2.6.14.2" />
        <vers num="2.6.14.3" />
        <vers num="2.6.14.4" />
        <vers num="2.6.14.5" />
        <vers num="2.6.14.6" />
        <vers num="2.6.14.7" />
        <vers num="2.6.15" />
        <vers num="2.6.15.1" />
        <vers num="2.6.15.2" />
        <vers num="2.6.15.3" />
        <vers num="2.6.15.4" />
        <vers num="2.6.15.5" />
        <vers num="2.6.15.6" />
        <vers num="2.6.15.7" />
        <vers num="2.6.16" />
        <vers num="2.6.16.1" />
        <vers num="2.6.16.10" />
        <vers num="2.6.16.11" />
        <vers num="2.6.16.12" />
        <vers num="2.6.16.13" />
        <vers num="2.6.16.14" />
        <vers num="2.6.16.15" />
        <vers num="2.6.16.16" />
        <vers num="2.6.16.17" />
        <vers num="2.6.16.18" />
        <vers num="2.6.16.19" />
        <vers num="2.6.16.2" />
        <vers num="2.6.16.20" />
        <vers num="2.6.16.21" />
        <vers num="2.6.16.22" />
        <vers num="2.6.16.23" />
        <vers num="2.6.16.24" />
        <vers num="2.6.16.25" />
        <vers num="2.6.16.26" />
        <vers num="2.6.16.27" />
        <vers num="2.6.16.28" />
        <vers num="2.6.16.29" />
        <vers num="2.6.16.3" />
        <vers num="2.6.16.30" />
        <vers num="2.6.16.31" />
        <vers num="2.6.16.32" />
        <vers num="2.6.16.33" />
        <vers num="2.6.16.34" />
        <vers num="2.6.16.35" />
        <vers num="2.6.16.36" />
        <vers num="2.6.16.37" />
        <vers num="2.6.16.38" />
        <vers num="2.6.16.39" />
        <vers num="2.6.16.4" />
        <vers num="2.6.16.40" />
        <vers num="2.6.16.41" />
        <vers num="2.6.16.42" />
        <vers num="2.6.16.43" />
        <vers num="2.6.16.44" />
        <vers num="2.6.16.45" />
        <vers num="2.6.16.46" />
        <vers num="2.6.16.47" />
        <vers num="2.6.16.48" />
        <vers num="2.6.16.49" />
        <vers num="2.6.16.5" />
        <vers num="2.6.16.50" />
        <vers num="2.6.16.51" />
        <vers num="2.6.16.52" />
        <vers num="2.6.16.53" />
        <vers num="2.6.16.54" />
        <vers num="2.6.16.55" />
        <vers num="2.6.16.56" />
        <vers num="2.6.16.57" />
        <vers num="2.6.16.58" />
        <vers num="2.6.16.59" />
        <vers num="2.6.16.6" />
        <vers num="2.6.16.60" />
        <vers num="2.6.16.61" />
        <vers num="2.6.16.62" />
        <vers num="2.6.16.7" />
        <vers num="2.6.16.8" />
        <vers num="2.6.16.9" />
        <vers num="2.6.17" />
        <vers num="2.6.17.1" />
        <vers num="2.6.17.10" />
        <vers num="2.6.17.11" />
        <vers num="2.6.17.12" />
        <vers num="2.6.17.13" />
        <vers num="2.6.17.14" />
        <vers num="2.6.17.2" />
        <vers num="2.6.17.3" />
        <vers num="2.6.17.4" />
        <vers num="2.6.17.5" />
        <vers num="2.6.17.6" />
        <vers num="2.6.17.7" />
        <vers num="2.6.17.8" />
        <vers num="2.6.17.9" />
        <vers num="2.6.18" edition="rc1" />
        <vers num="2.6.18" edition="rc2" />
        <vers num="2.6.18" edition="rc3" />
        <vers num="2.6.18" edition="rc4" />
        <vers num="2.6.18" edition="rc5" />
        <vers num="2.6.18" edition="rc6" />
        <vers num="2.6.18" edition="rc7" />
        <vers num="2.6.18.1" />
        <vers num="2.6.18.2" />
        <vers num="2.6.18.3" />
        <vers num="2.6.18.4" />
        <vers num="2.6.18.5" />
        <vers num="2.6.18.6" />
        <vers num="2.6.18.7" />
        <vers num="2.6.18.8" />
        <vers num="2.6.19" />
        <vers num="2.6.19.1" />
        <vers num="2.6.19.2" />
        <vers num="2.6.19.3" />
        <vers num="2.6.19.4" />
        <vers num="2.6.19.5" />
        <vers num="2.6.19.6" />
        <vers num="2.6.19.7" />
        <vers num="2.6.2" />
        <vers num="2.6.20" />
        <vers num="2.6.20.1" />
        <vers num="2.6.20.10" />
        <vers num="2.6.20.11" />
        <vers num="2.6.20.12" />
        <vers num="2.6.20.13" />
        <vers num="2.6.20.14" />
        <vers num="2.6.20.15" />
        <vers num="2.6.20.16" />
        <vers num="2.6.20.17" />
        <vers num="2.6.20.18" />
        <vers num="2.6.20.19" />
        <vers num="2.6.20.2" />
        <vers num="2.6.20.20" />
        <vers num="2.6.20.21" />
        <vers num="2.6.20.3" />
        <vers num="2.6.20.4" />
        <vers num="2.6.20.5" />
        <vers num="2.6.20.6" />
        <vers num="2.6.20.7" />
        <vers num="2.6.20.8" />
        <vers num="2.6.20.9" />
        <vers num="2.6.21" />
        <vers num="2.6.21.1" />
        <vers num="2.6.21.2" />
        <vers num="2.6.21.3" />
        <vers num="2.6.21.4" />
        <vers num="2.6.21.5" />
        <vers num="2.6.21.6" />
        <vers num="2.6.21.7" />
        <vers num="2.6.22" />
        <vers num="2.6.22.1" />
        <vers num="2.6.22.10" />
        <vers num="2.6.22.11" />
        <vers num="2.6.22.12" />
        <vers num="2.6.22.13" />
        <vers num="2.6.22.14" />
        <vers num="2.6.22.15" />
        <vers num="2.6.22.16" />
        <vers num="2.6.22.17" />
        <vers num="2.6.22.18" />
        <vers num="2.6.22.19" />
        <vers num="2.6.22.2" />
        <vers num="2.6.22.20" />
        <vers num="2.6.22.21" />
        <vers num="2.6.22.22" />
        <vers num="2.6.22.3" />
        <vers num="2.6.22.4" />
        <vers num="2.6.22.5" />
        <vers num="2.6.22.6" />
        <vers num="2.6.22.7" />
        <vers num="2.6.22.8" />
        <vers num="2.6.22.9" />
        <vers num="2.6.22_rc1" />
        <vers num="2.6.22_rc7" />
        <vers num="2.6.23" edition="rc1" />
        <vers num="2.6.23" edition="rc2" />
        <vers num="2.6.23.1" />
        <vers num="2.6.23.10" />
        <vers num="2.6.23.11" />
        <vers num="2.6.23.12" />
        <vers num="2.6.23.13" />
        <vers num="2.6.23.14" />
        <vers num="2.6.23.15" />
        <vers num="2.6.23.16" />
        <vers num="2.6.23.17" />
        <vers num="2.6.23.2" />
        <vers num="2.6.23.3" />
        <vers num="2.6.23.4" />
        <vers num="2.6.23.5" />
        <vers num="2.6.23.6" />
        <vers num="2.6.23.7" />
        <vers num="2.6.23.8" />
        <vers num="2.6.23.9" />
        <vers num="2.6.24" edition="rc1" />
        <vers num="2.6.24" edition="rc2" />
        <vers num="2.6.24" edition="rc3" />
        <vers num="2.6.24" edition="rc4" />
        <vers num="2.6.24" edition="rc5" />
        <vers num="2.6.24.1" />
        <vers num="2.6.24.2" />
        <vers num="2.6.24.3" />
        <vers num="2.6.24.4" />
        <vers num="2.6.24.5" />
        <vers num="2.6.24.6" />
        <vers num="2.6.24.7" />
        <vers num="2.6.25" edition="" />
        <vers num="2.6.25" edition=":x86_64" />
        <vers num="2.6.25.1" edition="" />
        <vers num="2.6.25.1" edition=":x86_64" />
        <vers num="2.6.25.10" edition="" />
        <vers num="2.6.25.10" edition=":x86_64" />
        <vers num="2.6.25.11" edition="" />
        <vers num="2.6.25.11" edition=":x86_64" />
        <vers num="2.6.25.12" edition="" />
        <vers num="2.6.25.12" edition=":x86_64" />
        <vers num="2.6.25.13" />
        <vers num="2.6.25.14" />
        <vers num="2.6.25.15" />
        <vers num="2.6.25.16" />
        <vers num="2.6.25.17" />
        <vers num="2.6.25.18" />
        <vers num="2.6.25.19" />
        <vers num="2.6.25.2" edition="" />
        <vers num="2.6.25.2" edition=":x86_64" />
        <vers num="2.6.25.20" />
        <vers num="2.6.25.3" edition="" />
        <vers num="2.6.25.3" edition=":x86_64" />
        <vers num="2.6.25.4" edition="" />
        <vers num="2.6.25.4" edition=":x86_64" />
        <vers num="2.6.25.5" edition="" />
        <vers num="2.6.25.5" edition=":x86_64" />
        <vers num="2.6.25.6" edition="" />
        <vers num="2.6.25.6" edition=":x86_64" />
        <vers num="2.6.25.7" edition="" />
        <vers num="2.6.25.7" edition=":x86_64" />
        <vers num="2.6.25.8" edition="" />
        <vers num="2.6.25.8" edition=":x86_64" />
        <vers num="2.6.25.9" edition="" />
        <vers num="2.6.25.9" edition=":x86_64" />
        <vers num="2.6.26" edition="rc4" />
        <vers num="2.6.26.1" />
        <vers num="2.6.26.2" />
        <vers num="2.6.26.3" />
        <vers num="2.6.26.4" />
        <vers num="2.6.26.5" />
        <vers num="2.6.26.6" />
        <vers num="2.6.26.7" />
        <vers num="2.6.26.8" />
        <vers num="2.6.27" edition="rc1" />
        <vers num="2.6.27" edition="rc2" />
        <vers num="2.6.27" edition="rc3" />
        <vers num="2.6.27" edition="rc4" />
        <vers num="2.6.27" edition="rc5" />
        <vers num="2.6.27" edition="rc6" />
        <vers num="2.6.27" edition="rc7" />
        <vers num="2.6.27" edition="rc8" />
        <vers num="2.6.27" edition="rc9" />
        <vers num="2.6.27.1" />
        <vers num="2.6.27.10" />
        <vers num="2.6.27.11" />
        <vers num="2.6.27.12" />
        <vers num="2.6.27.2" />
        <vers num="2.6.27.3" />
        <vers num="2.6.27.4" />
        <vers num="2.6.27.5" />
        <vers num="2.6.27.6" />
        <vers num="2.6.27.7" />
        <vers num="2.6.27.8" />
        <vers num="2.6.27.9" />
        <vers num="2.6.28" edition="git7" />
        <vers num="2.6.28" edition="rc1" />
        <vers num="2.6.28" edition="rc2" />
        <vers num="2.6.28" edition="rc3" />
        <vers num="2.6.28" edition="rc4" />
        <vers num="2.6.28" edition="rc5" />
        <vers num="2.6.28" edition="rc6" />
        <vers num="2.6.28" edition="rc7" />
        <vers num="2.6.28.1" />
        <vers num="2.6.28.2" />
        <vers num="2.6.28.3" />
        <vers num="2.6.28.4" />
        <vers num="2.6.28.5" />
        <vers num="2.6.28.6" />
        <vers num="2.6.28.7" />
        <vers num="2.6.28.8" />
        <vers prev="1" num="2.6.28.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1361" published="2009-04-22" name="CVE-2009-1361" modified="2009-04-23" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">dig.php in GScripts.net DNS Tools allows remote attackers to execute arbitrary commands via shell metacharacters in the host parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/34773" source="SECUNIA" adv="1">34773</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gscripts" name="dns_tools">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1362" published="2009-04-22" name="CVE-2009-1362" modified="2009-05-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">SQL injection vulnerability in administration/index.php in chCounter 3.1.3 allows remote attackers to execute arbitrary SQL commands via the login_name parameter.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/50353" source="XF">chcounter-administration-sql-injection(50353)</ref>
      <ref url="http://secunia.com/advisories/24879" source="SECUNIA" adv="1">24879</ref>
    </refs>
    <vuln_soft>
      <prod vendor="chcounter" name="chcounter">
        <vers num="3.1.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1364" published="2009-05-01" name="CVE-2009-1364" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Use-after-free vulnerability in the embedded GD library in libwmf 0.2.8.4 allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted WMF file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-May/msg01269.html" source="FEDORA">FEDORA-2009-5517</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-May/msg01266.html" source="FEDORA">FEDORA-2009-5524</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-May/msg01263.html" source="FEDORA">FEDORA-2009-5518</ref>
      <ref url="https://launchpad.net/bugs/cve/2009-1364" source="CONFIRM">https://launchpad.net/bugs/cve/2009-1364</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=496864" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=496864</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/50290" source="XF">libwmf-gdlibrary-code-execution(50290)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1228" source="VUPEN">ADV-2009-1228</ref>
      <ref url="http://www.ubuntu.com/usn/USN-769-1" source="UBUNTU">USN-769-1</ref>
      <ref url="http://www.securitytracker.com/id?1022154" source="SECTRACK">1022154</ref>
      <ref url="http://www.securityfocus.com/bid/34792" source="BID">34792</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:106" source="MANDRIVA">MDVSA-2009:106</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1796" source="DEBIAN">DSA-1796</ref>
      <ref url="http://wvware.cvs.sourceforge.net/viewvc/wvware/libwmf2/src/extra/Makefile.am?hideattic=0&amp;view=log" source="CONFIRM">http://wvware.cvs.sourceforge.net/viewvc/wvware/libwmf2/src/extra/Makefile.am?hideattic=0&amp;view=log</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200907-01.xml" source="GENTOO">GLSA-200907-01</ref>
      <ref url="http://secunia.com/advisories/35686" source="SECUNIA">35686</ref>
      <ref url="http://secunia.com/advisories/35416" source="SECUNIA">35416</ref>
      <ref url="http://secunia.com/advisories/35190" source="SECUNIA">35190</ref>
      <ref url="http://secunia.com/advisories/35025" source="SECUNIA">35025</ref>
      <ref url="http://secunia.com/advisories/35001" source="SECUNIA">35001</ref>
      <ref url="http://secunia.com/advisories/34964" source="SECUNIA">34964</ref>
      <ref url="http://secunia.com/advisories/34901" source="SECUNIA">34901</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2009-0457.html" source="REDHAT">RHSA-2009:0457</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10959" source="OVAL">oval:org.mitre.oval:def:10959</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-06/msg00003.html" source="SUSE">SUSE-SR:2009:011</ref>
    </refs>
    <vuln_soft>
      <prod vendor="francis_james_franklin" name="libwmf">
        <vers num="0.2.8.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1365" published="2009-05-01" name="CVE-2009-1365" modified="2009-05-19" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Unspecified vulnerability in Adobe Flash Media Server (FMS) before 3.0.4 and 3.5.x before 3.5.2, as used in Flash Media Interactive Server and Flash Media Streaming Server, allows remote attackers to execute arbitrary remote procedures within an ActionScript file on the server via RPC requests.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/34790" source="BID" patch="1">34790</ref>
      <ref url="http://www.adobe.com/support/security/bulletins/apsb09-05.html" source="CONFIRM" patch="1" adv="1">http://www.adobe.com/support/security/bulletins/apsb09-05.html</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1234" source="VUPEN">ADV-2009-1234</ref>
      <ref url="http://www.securitytracker.com/id?1022148" source="SECTRACK">1022148</ref>
      <ref url="http://secunia.com/advisories/34878" source="SECUNIA">34878</ref>
    </refs>
    <vuln_soft>
      <prod vendor="adobe" name="flash_media_server">
        <vers num="2.0.1" />
        <vers num="2.0.2" />
        <vers num="2.0.3" />
        <vers num="2.0.4" />
        <vers num="2.0.5" />
        <vers num="3.0" />
        <vers num="3.0.1" />
        <vers num="3.0.2" />
        <vers prev="1" num="3.0.3" />
        <vers num="3.5" />
        <vers num="3.5.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1366" published="2009-04-22" name="CVE-2009-1366" modified="2009-05-14" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Website\admin\Sales\paypalipn.aspx in DotNetNuke (DNN) before 4.9.3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors related to "name/value pairs" and "paypal IPN functionality."</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/34484" source="BID">34484</ref>
      <ref url="http://www.dotnetnuke.com/News/SecurityPolicy/Securitybulletinno25/tabid/1260/Default.aspx" source="CONFIRM" adv="1">http://www.dotnetnuke.com/News/SecurityPolicy/Securitybulletinno25/tabid/1260/Default.aspx</ref>
      <ref url="http://secunia.com/advisories/34686" source="SECUNIA" adv="1">34686</ref>
    </refs>
    <vuln_soft>
      <prod vendor="dotnetnuke" name="dotnetnuke">
        <vers num="1.0.10d" />
        <vers num="1.0.10e" />
        <vers num="1.0.6" />
        <vers num="1.0.7" />
        <vers num="1.0.8" />
        <vers num="1.0.9" />
        <vers num="2.1.1" />
        <vers num="2.1.2" />
        <vers num="3.0.11" />
        <vers num="3.0.7" />
        <vers num="3.0.8" />
        <vers num="3.1.0" />
        <vers num="3.3.5" />
        <vers num="4.0" />
        <vers num="4.3.5" />
        <vers num="4.5.2" />
        <vers num="4.5.4" />
        <vers num="4.5.5" />
        <vers num="4.6.0" />
        <vers num="4.6.1" />
        <vers num="4.6.2" />
        <vers num="4.7.0" />
        <vers num="4.8.0" />
        <vers num="4.8.1" />
        <vers num="4.8.2" />
        <vers num="4.8.3" />
        <vers num="4.8.4" />
        <vers num="4.9" />
        <vers num="4.9.1" />
        <vers prev="1" num="4.9.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1367" published="2009-04-22" name="CVE-2009-1367" modified="2009-04-23" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in index.php in moziloCMS 1.11 allows remote attackers to inject arbitrary web script or HTML via the query parameter in search action, a different issue than CVE-2008-6127.2a.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/49812" source="XF">mozilocms-indexphp-xss(49812)</ref>
      <ref url="http://www.securityfocus.com/bid/34474" source="BID">34474</ref>
      <ref url="http://www.milw0rm.com/exploits/8394" source="MILW0RM">8394</ref>
      <ref url="http://cms.mozilo.de/index.php?cat=10_moziloCMS&amp;page=60_Changelog" source="CONFIRM" adv="1">http://cms.mozilo.de/index.php?cat=10_moziloCMS&amp;page=60_Changelog</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilo" name="mozilocms">
        <vers num="1.11" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1368" published="2009-04-22" name="CVE-2009-1368" modified="2009-04-23" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Directory traversal vulnerability in index.php in moziloCMS 1.11 allows remote attackers to read arbitrary files via a .. (dot dot) in the page parameter.  NOTE: this might be the same issue as CVE-2008-6126.2, which may have been fixed in 1.10.3.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://cms.mozilo.de/index.php?cat=10_moziloCMS&amp;page=60_Changelog" source="CONFIRM" patch="1" adv="1">http://cms.mozilo.de/index.php?cat=10_moziloCMS&amp;page=60_Changelog</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/49813" source="XF">mozilocms-index-file-include(49813)</ref>
      <ref url="http://www.securityfocus.com/bid/34474" source="BID">34474</ref>
      <ref url="http://www.milw0rm.com/exploits/8394" source="MILW0RM">8394</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilo" name="mozilocms">
        <vers num="1.11" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1369" published="2009-04-22" name="CVE-2009-1369" modified="2009-04-23" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">moziloCMS 1.11 allows remote attackers to obtain sensitive information via the (1) gal[] parameter to gallery.php, (2) page[] and (3) cat[] parameter to index.php, or (4) file[] parameter to download.php, which reveals the installation path in an error message.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/49811" source="XF">mozilocms-index-path-disclosure(49811)</ref>
      <ref url="http://www.milw0rm.com/exploits/8394" source="MILW0RM">8394</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilo" name="mozilocms">
        <vers num="1.11" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1370" published="2009-04-22" name="CVE-2009-1370" modified="2009-04-23" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Stack-based buffer overflow in ape_plugin.plg in Xilisoft Video Converter 3.1.53.0704n and 5.1.23.0402 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long string in a .cue file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/49807" source="XF">vcw-cue-bo(49807)</ref>
      <ref url="http://www.securityfocus.com/bid/34472" source="BID">34472</ref>
      <ref url="http://www.milw0rm.com/exploits/8390" source="MILW0RM">8390</ref>
      <ref url="http://secunia.com/advisories/34660" source="SECUNIA" adv="1">34660</ref>
    </refs>
    <vuln_soft>
      <prod vendor="xilisoft" name="xilisoft_video_converter">
        <vers num="3.1.53" />
        <vers num="5.1.23" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1371" published="2009-04-23" name="CVE-2009-1371" modified="2009-09-16" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The CLI_ISCONTAINED macro in libclamav/others.h in ClamAV before 0.95.1 allows remote attackers to cause a denial of service (application crash) via a malformed file with UPack encoding.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2009/0985" source="VUPEN" patch="1" adv="1">ADV-2009-0985</ref>
      <ref url="http://www.securityfocus.com/bid/34446" source="BID" patch="1">34446</ref>
      <ref url="https://wwws.clamav.net/bugzilla/show_bug.cgi?id=1552" source="CONFIRM">https://wwws.clamav.net/bugzilla/show_bug.cgi?id=1552</ref>
      <ref url="https://launchpad.net/bugs/360502" source="CONFIRM">https://launchpad.net/bugs/360502</ref>
      <ref url="http://www.ubuntu.com/usn/usn-756-1" source="UBUNTU">USN-756-1</ref>
      <ref url="http://www.securitytracker.com/id?1022028" source="SECTRACK">1022028</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:097" source="MANDRIVA">MDVSA-2009:097</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1771" source="DEBIAN">DSA-1771</ref>
      <ref url="http://svn.clamav.net/websvn/filedetails.php?repname=clamav-devel&amp;path=%2Ftrunk%2FChangeLog&amp;rev=5032" source="CONFIRM">http://svn.clamav.net/websvn/filedetails.php?repname=clamav-devel&amp;path=%2Ftrunk%2FChangeLog&amp;rev=5032</ref>
      <ref url="http://support.apple.com/kb/HT3865" source="CONFIRM">http://support.apple.com/kb/HT3865</ref>
      <ref url="http://secunia.com/advisories/36701" source="SECUNIA">36701</ref>
      <ref url="http://secunia.com/advisories/34716" source="SECUNIA">34716</ref>
      <ref url="http://secunia.com/advisories/34654" source="SECUNIA" adv="1">34654</ref>
      <ref url="http://secunia.com/advisories/34612" source="SECUNIA" adv="1">34612</ref>
      <ref url="http://osvdb.org/53602" source="OSVDB">53602</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2009/Sep/msg00004.html" source="APPLE">APPLE-SA-2009-09-10-2</ref>
    </refs>
    <vuln_soft>
      <prod vendor="clamav" name="clamav">
        <vers num="0.01" />
        <vers num="0.02" />
        <vers num="0.03" />
        <vers num="0.05" />
        <vers num="0.10" />
        <vers num="0.12" />
        <vers num="0.13" />
        <vers num="0.14" edition="pre" />
        <vers num="0.15" />
        <vers num="0.20" />
        <vers num="0.21" />
        <vers num="0.22" />
        <vers num="0.23" />
        <vers num="0.24" />
        <vers num="0.3" />
        <vers num="0.51" />
        <vers num="0.52" />
        <vers num="0.53" />
        <vers num="0.54" />
        <vers num="0.60" />
        <vers num="0.60p" />
        <vers num="0.65" />
        <vers num="0.66" />
        <vers num="0.67" />
        <vers num="0.67-1" />
        <vers num="0.68" />
        <vers num="0.68.1" />
        <vers num="0.70" edition="rc" />
        <vers num="0.71" />
        <vers num="0.72" />
        <vers num="0.73" />
        <vers num="0.74" />
        <vers num="0.75" />
        <vers num="0.75.1" />
        <vers num="0.80" edition="rc4" />
        <vers num="0.80_rc" />
        <vers num="0.80_rc1" />
        <vers num="0.80_rc2" />
        <vers num="0.80_rc3" />
        <vers num="0.81" />
        <vers num="0.81_rc1" />
        <vers num="0.82" />
        <vers num="0.83" />
        <vers num="0.84" />
        <vers num="0.84_rc1" />
        <vers num="0.84_rc2" />
        <vers num="0.85" />
        <vers num="0.85.1" />
        <vers num="0.86" />
        <vers num="0.86.1" />
        <vers num="0.86.2" />
        <vers num="0.86_rc1" />
        <vers num="0.87" />
        <vers num="0.87.1" />
        <vers num="0.88" />
        <vers num="0.88.1" />
        <vers num="0.88.2" />
        <vers num="0.88.3" />
        <vers num="0.88.4" />
        <vers num="0.88.5" />
        <vers num="0.88.6" />
        <vers num="0.88.7" />
        <vers num="0.88.7_p0" />
        <vers num="0.88.7_p1" />
        <vers num="0.8_" edition="rc3" />
        <vers num="0.90" />
        <vers num="0.90.1" />
        <vers num="0.90.1_p0" />
        <vers num="0.90.2" />
        <vers num="0.90.2_p0" />
        <vers num="0.90.3" />
        <vers num="0.90.3_p0" />
        <vers num="0.90.3_p1" />
        <vers num="0.90_rc1" />
        <vers num="0.90_rc1.1" />
        <vers num="0.90_rc2" />
        <vers num="0.90_rc3" />
        <vers num="0.91" />
        <vers num="0.91.1" />
        <vers num="0.91.2" />
        <vers num="0.91.2_p0" />
        <vers num="0.91_rc1" />
        <vers num="0.91_rc2" />
        <vers num="0.92" />
        <vers num="0.92.1" />
        <vers num="0.92_p0" />
        <vers num="0.93" />
        <vers num="0.93.1" />
        <vers num="0.93.2" />
        <vers num="0.93.3" />
        <vers num="0.94" />
        <vers num="0.94.1" />
        <vers num="0.94.2" />
        <vers prev="1" num="0.95" edition="src1" />
        <vers prev="1" num="0.95" edition="src2" />
        <vers num="0.9_rc1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1372" published="2009-04-23" name="CVE-2009-1372" modified="2009-09-16" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Stack-based buffer overflow in the cli_url_canon function in libclamav/phishcheck.c in ClamAV before 0.95.1 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted URL.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2009/0985" source="VUPEN" patch="1" adv="1">ADV-2009-0985</ref>
      <ref url="https://wwws.clamav.net/bugzilla/show_bug.cgi?id=1553" source="CONFIRM">https://wwws.clamav.net/bugzilla/show_bug.cgi?id=1553</ref>
      <ref url="http://www.securitytracker.com/id?1022028" source="SECTRACK">1022028</ref>
      <ref url="http://www.securityfocus.com/bid/34446" source="BID">34446</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:097" source="MANDRIVA">MDVSA-2009:097</ref>
      <ref url="http://svn.clamav.net/websvn/filedetails.php?repname=clamav-devel&amp;path=%2Ftrunk%2FChangeLog&amp;rev=5032" source="CONFIRM">http://svn.clamav.net/websvn/filedetails.php?repname=clamav-devel&amp;path=%2Ftrunk%2FChangeLog&amp;rev=5032</ref>
      <ref url="http://support.apple.com/kb/HT3865" source="CONFIRM">http://support.apple.com/kb/HT3865</ref>
      <ref url="http://secunia.com/advisories/36701" source="SECUNIA">36701</ref>
      <ref url="http://secunia.com/advisories/34612" source="SECUNIA" adv="1">34612</ref>
      <ref url="http://osvdb.org/53603" source="OSVDB">53603</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2009/Sep/msg00004.html" source="APPLE">APPLE-SA-2009-09-10-2</ref>
    </refs>
    <vuln_soft>
      <prod vendor="clamav" name="clamav">
        <vers num="0.01" />
        <vers num="0.02" />
        <vers num="0.03" />
        <vers num="0.05" />
        <vers num="0.10" />
        <vers num="0.12" />
        <vers num="0.13" />
        <vers num="0.14" edition="pre" />
        <vers num="0.15" />
        <vers num="0.20" />
        <vers num="0.21" />
        <vers num="0.22" />
        <vers num="0.23" />
        <vers num="0.24" />
        <vers num="0.3" />
        <vers num="0.51" />
        <vers num="0.52" />
        <vers num="0.53" />
        <vers num="0.54" />
        <vers num="0.60" />
        <vers num="0.60p" />
        <vers num="0.65" />
        <vers num="0.66" />
        <vers num="0.67" />
        <vers num="0.67-1" />
        <vers num="0.68" />
        <vers num="0.68.1" />
        <vers num="0.70" edition="rc" />
        <vers num="0.71" />
        <vers num="0.72" />
        <vers num="0.73" />
        <vers num="0.74" />
        <vers num="0.75" />
        <vers num="0.75.1" />
        <vers num="0.80" edition="rc4" />
        <vers num="0.80_rc" />
        <vers num="0.80_rc1" />
        <vers num="0.80_rc2" />
        <vers num="0.80_rc3" />
        <vers num="0.81" />
        <vers num="0.81_rc1" />
        <vers num="0.82" />
        <vers num="0.83" />
        <vers num="0.84" />
        <vers num="0.84_rc1" />
        <vers num="0.84_rc2" />
        <vers num="0.85" />
        <vers num="0.85.1" />
        <vers num="0.86" />
        <vers num="0.86.1" />
        <vers num="0.86.2" />
        <vers num="0.86_rc1" />
        <vers num="0.87" />
        <vers num="0.87.1" />
        <vers num="0.88" />
        <vers num="0.88.1" />
        <vers num="0.88.2" />
        <vers num="0.88.3" />
        <vers num="0.88.4" />
        <vers num="0.88.5" />
        <vers num="0.88.6" />
        <vers num="0.88.7" />
        <vers num="0.88.7_p0" />
        <vers num="0.88.7_p1" />
        <vers num="0.8_" edition="rc3" />
        <vers num="0.90" />
        <vers num="0.90.1" />
        <vers num="0.90.1_p0" />
        <vers num="0.90.2" />
        <vers num="0.90.2_p0" />
        <vers num="0.90.3" />
        <vers num="0.90.3_p0" />
        <vers num="0.90.3_p1" />
        <vers num="0.90_rc1" />
        <vers num="0.90_rc1.1" />
        <vers num="0.90_rc2" />
        <vers num="0.90_rc3" />
        <vers num="0.91" />
        <vers num="0.91.1" />
        <vers num="0.91.2" />
        <vers num="0.91.2_p0" />
        <vers num="0.91_rc1" />
        <vers num="0.91_rc2" />
        <vers num="0.92" />
        <vers num="0.92.1" />
        <vers num="0.92_p0" />
        <vers num="0.93" />
        <vers num="0.93.1" />
        <vers num="0.93.2" />
        <vers num="0.93.3" />
        <vers num="0.94" />
        <vers num="0.94.1" />
        <vers num="0.94.2" />
        <vers prev="1" num="0.95" edition="src1" />
        <vers prev="1" num="0.95" edition="src2" />
        <vers num="0.9_rc1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1373" published="2009-05-26" name="CVE-2009-1373" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:S/C:C/I:C/A:C)" CVSS_score="7.1" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.1">
    <desc>
      <descript source="cve">Buffer overflow in the XMPP SOCKS5 bytestream server in Pidgin (formerly Gaim) before 2.5.6 allows remote authenticated users to execute arbitrary code via vectors involving an outbound XMPP file transfer.  NOTE: some of these details are obtained from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/35067" source="BID" patch="1">35067</ref>
      <ref url="http://www.pidgin.im/news/security/?id=29" source="CONFIRM" patch="1" adv="1">http://www.pidgin.im/news/security/?id=29</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-June/msg00075.html" source="FEDORA">FEDORA-2009-5597</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-June/msg00051.html" source="FEDORA">FEDORA-2009-5583</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-June/msg00033.html" source="FEDORA">FEDORA-2009-5552</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=500488" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=500488</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/50682" source="XF">pidgin-xmppsocks5-bo(50682)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1396" source="VUPEN">ADV-2009-1396</ref>
      <ref url="http://www.ubuntu.com/usn/USN-781-2" source="UBUNTU">USN-781-2</ref>
      <ref url="http://www.ubuntu.com/usn/USN-781-1" source="UBUNTU">USN-781-1</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-1060.html" source="REDHAT">RHSA-2009:1060</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-1059.html" source="REDHAT">RHSA-2009:1059</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:173" source="MANDRIVA">MDVSA-2009:173</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:140" source="MANDRIVA">MDVSA-2009:140</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200905-07.xml" source="GENTOO">GLSA-200905-07</ref>
      <ref url="http://secunia.com/advisories/35330" source="SECUNIA">35330</ref>
      <ref url="http://secunia.com/advisories/35329" source="SECUNIA">35329</ref>
      <ref url="http://secunia.com/advisories/35294" source="SECUNIA">35294</ref>
      <ref url="http://secunia.com/advisories/35215" source="SECUNIA">35215</ref>
      <ref url="http://secunia.com/advisories/35202" source="SECUNIA" adv="1">35202</ref>
      <ref url="http://secunia.com/advisories/35194" source="SECUNIA" adv="1">35194</ref>
      <ref url="http://secunia.com/advisories/35188" source="SECUNIA">35188</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9005" source="OVAL">oval:org.mitre.oval:def:9005</ref>
      <ref url="http://debian.org/security/2009/dsa-1805" source="DEBIAN">DSA-1805</ref>
    </refs>
    <vuln_soft>
      <prod vendor="pidgin" name="pidgin">
        <vers num="2.0.0" />
        <vers num="2.0.1" />
        <vers num="2.0.2" edition="" />
        <vers num="2.0.2" edition=":linux" />
        <vers num="2.1.0" />
        <vers num="2.1.1" />
        <vers num="2.2.0" />
        <vers num="2.2.1" />
        <vers num="2.2.2" />
        <vers num="2.3.0" />
        <vers num="2.3.1" />
        <vers num="2.4.0" />
        <vers num="2.4.1" />
        <vers num="2.4.2" />
        <vers num="2.4.3" />
        <vers num="2.5.0" />
        <vers num="2.5.1" />
        <vers num="2.5.2" />
        <vers num="2.5.3" />
        <vers num="2.5.4" />
        <vers prev="1" num="2.5.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1374" published="2009-05-26" name="CVE-2009-1374" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Buffer overflow in the decrypt_out function in Pidgin (formerly Gaim) before 2.5.6 allows remote attackers to cause a denial of service (application crash) via a QQ packet.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/35067" source="BID" patch="1">35067</ref>
      <ref url="http://www.pidgin.im/news/security/?id=30" source="CONFIRM" patch="1" adv="1">http://www.pidgin.im/news/security/?id=30</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-June/msg00075.html" source="FEDORA">FEDORA-2009-5597</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-June/msg00051.html" source="FEDORA">FEDORA-2009-5583</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-June/msg00033.html" source="FEDORA">FEDORA-2009-5552</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=500490" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=500490</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/50684" source="XF">pidgin-decryptout-bo(50684)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1396" source="VUPEN">ADV-2009-1396</ref>
      <ref url="http://www.ubuntu.com/usn/USN-781-1" source="UBUNTU">USN-781-1</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-1060.html" source="REDHAT">RHSA-2009:1060</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:173" source="MANDRIVA">MDVSA-2009:173</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200905-07.xml" source="GENTOO">GLSA-200905-07</ref>
      <ref url="http://secunia.com/advisories/35329" source="SECUNIA">35329</ref>
      <ref url="http://secunia.com/advisories/35294" source="SECUNIA">35294</ref>
      <ref url="http://secunia.com/advisories/35202" source="SECUNIA" adv="1">35202</ref>
      <ref url="http://secunia.com/advisories/35194" source="SECUNIA" adv="1">35194</ref>
      <ref url="http://secunia.com/advisories/35188" source="SECUNIA">35188</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11654" source="OVAL">oval:org.mitre.oval:def:11654</ref>
    </refs>
    <vuln_soft>
      <prod vendor="pidgin" name="pidgin">
        <vers num="2.0.0" />
        <vers num="2.0.1" />
        <vers num="2.0.2" edition="" />
        <vers num="2.0.2" edition=":linux" />
        <vers num="2.1.0" />
        <vers num="2.1.1" />
        <vers num="2.2.0" />
        <vers num="2.2.1" />
        <vers num="2.2.2" />
        <vers num="2.3.0" />
        <vers num="2.3.1" />
        <vers num="2.4.0" />
        <vers num="2.4.1" />
        <vers num="2.4.2" />
        <vers num="2.4.3" />
        <vers num="2.5.0" />
        <vers num="2.5.1" />
        <vers num="2.5.2" />
        <vers num="2.5.3" />
        <vers num="2.5.4" />
        <vers prev="1" num="2.5.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1375" published="2009-05-26" name="CVE-2009-1375" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The PurpleCircBuffer implementation in Pidgin (formerly Gaim) before 2.5.6 does not properly maintain a certain buffer, which allows remote attackers to cause a denial of service (memory corruption and application crash) via vectors involving the (1) XMPP or (2) Sametime protocol.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/35067" source="BID" patch="1">35067</ref>
      <ref url="http://www.pidgin.im/news/security/?id=31" source="CONFIRM" patch="1" adv="1">http://www.pidgin.im/news/security/?id=31</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-June/msg00075.html" source="FEDORA">FEDORA-2009-5597</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-June/msg00051.html" source="FEDORA">FEDORA-2009-5583</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-June/msg00033.html" source="FEDORA">FEDORA-2009-5552</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=500491" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=500491</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/50683" source="XF">pidgin-purplecircbuffer-dos(50683)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1396" source="VUPEN">ADV-2009-1396</ref>
      <ref url="http://www.ubuntu.com/usn/USN-781-1" source="UBUNTU">USN-781-1</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-1060.html" source="REDHAT">RHSA-2009:1060</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:173" source="MANDRIVA">MDVSA-2009:173</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200905-07.xml" source="GENTOO">GLSA-200905-07</ref>
      <ref url="http://secunia.com/advisories/35329" source="SECUNIA">35329</ref>
      <ref url="http://secunia.com/advisories/35294" source="SECUNIA">35294</ref>
      <ref url="http://secunia.com/advisories/35215" source="SECUNIA">35215</ref>
      <ref url="http://secunia.com/advisories/35202" source="SECUNIA" adv="1">35202</ref>
      <ref url="http://secunia.com/advisories/35194" source="SECUNIA" adv="1">35194</ref>
      <ref url="http://secunia.com/advisories/35188" source="SECUNIA">35188</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10829" source="OVAL">oval:org.mitre.oval:def:10829</ref>
      <ref url="http://osvdb.org/54649" source="OSVDB">54649</ref>
      <ref url="http://debian.org/security/2009/dsa-1805" source="DEBIAN">DSA-1805</ref>
    </refs>
    <vuln_soft>
      <prod vendor="pidgin" name="pidgin">
        <vers num="2.0.0" />
        <vers num="2.0.1" />
        <vers num="2.0.2" edition="" />
        <vers num="2.0.2" edition=":linux" />
        <vers num="2.1.0" />
        <vers num="2.1.1" />
        <vers num="2.2.0" />
        <vers num="2.2.1" />
        <vers num="2.2.2" />
        <vers num="2.3.0" />
        <vers num="2.3.1" />
        <vers num="2.4.0" />
        <vers num="2.4.1" />
        <vers num="2.4.2" />
        <vers num="2.4.3" />
        <vers num="2.5.0" />
        <vers num="2.5.1" />
        <vers num="2.5.2" />
        <vers num="2.5.3" />
        <vers num="2.5.4" />
        <vers prev="1" num="2.5.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1376" published="2009-05-26" name="CVE-2009-1376" modified="2011-09-14" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Multiple integer overflows in the msn_slplink_process_msg functions in the MSN protocol handler in (1) libpurple/protocols/msn/slplink.c and (2) libpurple/protocols/msnp9/slplink.c in Pidgin (formerly Gaim) before 2.5.6 on 32-bit platforms allow remote attackers to execute arbitrary code via a malformed SLP message with a crafted offset value, leading to buffer overflows.  NOTE: this issue exists because of an incomplete fix for CVE-2008-2927.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=500493" source="CONFIRM" patch="1">https://bugzilla.redhat.com/show_bug.cgi?id=500493</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-June/msg00075.html" source="FEDORA">FEDORA-2009-5597</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-June/msg00051.html" source="FEDORA">FEDORA-2009-5583</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-June/msg00033.html" source="FEDORA">FEDORA-2009-5552</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/50680" source="XF">pidgin-msn-slp-bo(50680)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1396" source="VUPEN">ADV-2009-1396</ref>
      <ref url="http://www.ubuntu.com/usn/USN-781-2" source="UBUNTU">USN-781-2</ref>
      <ref url="http://www.ubuntu.com/usn/USN-781-1" source="UBUNTU">USN-781-1</ref>
      <ref url="http://www.securityfocus.com/bid/35067" source="BID">35067</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-1060.html" source="REDHAT">RHSA-2009:1060</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-1059.html" source="REDHAT">RHSA-2009:1059</ref>
      <ref url="http://www.pidgin.im/news/security/?id=32" source="CONFIRM" adv="1">http://www.pidgin.im/news/security/?id=32</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:173" source="MANDRIVA">MDVSA-2009:173</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:140" source="MANDRIVA">MDVSA-2009:140</ref>
      <ref url="http://www.gentoo.org/security/en/glsa/glsa-200905-07.xml" source="GENTOO">GLSA-200905-07</ref>
      <ref url="http://secunia.com/advisories/37071" source="SECUNIA">37071</ref>
      <ref url="http://secunia.com/advisories/35330" source="SECUNIA" adv="1">35330</ref>
      <ref url="http://secunia.com/advisories/35329" source="SECUNIA" adv="1">35329</ref>
      <ref url="http://secunia.com/advisories/35294" source="SECUNIA" adv="1">35294</ref>
      <ref url="http://secunia.com/advisories/35215" source="SECUNIA" adv="1">35215</ref>
      <ref url="http://secunia.com/advisories/35202" source="SECUNIA" adv="1">35202</ref>
      <ref url="http://secunia.com/advisories/35194" source="SECUNIA" adv="1">35194</ref>
      <ref url="http://secunia.com/advisories/35188" source="SECUNIA">35188</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10476" source="OVAL">oval:org.mitre.oval:def:10476</ref>
      <ref url="http://debian.org/security/2009/dsa-1805" source="DEBIAN">DSA-1805</ref>
    </refs>
    <vuln_soft>
      <prod vendor="pidgin" name="pidgin">
        <vers num="2.4.0" edition="32_bit" />
        <vers num="2.4.1" edition="32_bit" />
        <vers num="2.4.2" edition="32_bit" />
        <vers num="2.4.3" edition="32_bit" />
        <vers num="2.5.0" edition="32_bit" />
        <vers num="2.5.2" edition="32_bit" />
        <vers num="2.5.3" edition="32_bit" />
        <vers num="2.5.4" edition="32_bit" />
        <vers prev="1" num="2.5.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1377" published="2009-05-19" name="CVE-2009-1377" modified="2011-01-19" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The dtls1_buffer_record function in ssl/d1_pkt.c in OpenSSL 0.9.8k and earlier 0.9.8 versions allows remote attackers to cause a denial of service (memory consumption) via a large series of "future epoch" DTLS records that are buffered in a queue, aka "DTLS record buffer limitation bug."</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://rt.openssl.org/Ticket/Display.html?id=1930&amp;user=guest&amp;pass=guest" source="CONFIRM" patch="1">http://rt.openssl.org/Ticket/Display.html?id=1930&amp;user=guest&amp;pass=guest</ref>
      <ref url="http://marc.info/?l=openssl-dev&amp;m=124247675613888&amp;w=2" source="MLIST" patch="1">[openssl-dev] 20090516 [openssl.org #1930] [PATCH] DTLS record buffer limitation bug</ref>
      <ref url="http://cvs.openssl.org/chngview?cn=18187" source="CONFIRM" patch="1">http://cvs.openssl.org/chngview?cn=18187</ref>
      <ref url="https://launchpad.net/bugs/cve/2009-1377" source="MISC">https://launchpad.net/bugs/cve/2009-1377</ref>
      <ref url="https://kb.bluecoat.com/index?page=content&amp;id=SA50" source="CONFIRM">https://kb.bluecoat.com/index?page=content&amp;id=SA50</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0528" source="VUPEN">ADV-2010-0528</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1377" source="VUPEN">ADV-2009-1377</ref>
      <ref url="http://www.ubuntu.com/usn/USN-792-1" source="UBUNTU">USN-792-1</ref>
      <ref url="http://www.securitytracker.com/id?1022241" source="SECTRACK">1022241</ref>
      <ref url="http://www.securityfocus.com/bid/35001" source="BID">35001</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2009/05/18/1" source="MLIST">[oss-security] 20090518 Two OpenSSL DTLS remote DoS</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:120" source="MANDRIVA">MDVSA-2009:120</ref>
      <ref url="http://voodoo-circle.sourceforge.net/sa/sa-20091012-01.html" source="CONFIRM">http://voodoo-circle.sourceforge.net/sa/sa-20091012-01.html</ref>
      <ref url="http://sourceforge.net/mailarchive/message.php?msg_name=4AD43807.7080105%40users.sourceforge.net" source="CONFIRM">http://sourceforge.net/mailarchive/message.php?msg_name=4AD43807.7080105%40users.sourceforge.net</ref>
      <ref url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2010&amp;m=slackware-security.663049" source="SLACKWARE">SSA:2010-060-02</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200912-01.xml" source="GENTOO">GLSA-200912-01</ref>
      <ref url="http://secunia.com/advisories/42733" source="SECUNIA">42733</ref>
      <ref url="http://secunia.com/advisories/42724" source="SECUNIA">42724</ref>
      <ref url="http://secunia.com/advisories/38834" source="SECUNIA">38834</ref>
      <ref url="http://secunia.com/advisories/38794" source="SECUNIA">38794</ref>
      <ref url="http://secunia.com/advisories/38761" source="SECUNIA">38761</ref>
      <ref url="http://secunia.com/advisories/37003" source="SECUNIA">37003</ref>
      <ref url="http://secunia.com/advisories/35729" source="SECUNIA">35729</ref>
      <ref url="http://secunia.com/advisories/35571" source="SECUNIA">35571</ref>
      <ref url="http://secunia.com/advisories/35461" source="SECUNIA">35461</ref>
      <ref url="http://secunia.com/advisories/35416" source="SECUNIA">35416</ref>
      <ref url="http://secunia.com/advisories/35128" source="SECUNIA" adv="1">35128</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9663" source="OVAL">oval:org.mitre.oval:def:9663</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6683" source="OVAL">oval:org.mitre.oval:def:6683</ref>
      <ref url="http://lists.vmware.com/pipermail/security-announce/2010/000082.html" source="MLIST">[security-announce] 20100303 VMSA-2010-0004 ESX Service Console and vMA third party updates</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-06/msg00003.html" source="SUSE">SUSE-SR:2009:011</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c02029444" source="HP">SSRT100079</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c02029444" source="HP">SSRT100079</ref>
      <ref url="ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2009-009.txt.asc" source="NETBSD">NetBSD-SA2009-009</ref>
    </refs>
    <vuln_soft>
      <prod vendor="openssl" name="openssl">
        <vers num="0.9.8a" />
        <vers num="0.9.8b" />
        <vers num="0.9.8c" />
        <vers num="0.9.8d" />
        <vers num="0.9.8e" />
        <vers num="0.9.8f" />
        <vers num="0.9.8g" />
        <vers num="0.9.8h" />
        <vers num="0.9.8i" />
        <vers num="0.9.8j" />
        <vers prev="1" num="0.9.8k" />
      </prod>
      <prod vendor="openssl_project" name="openssl">
        <vers num="0.9.8c-1" />
        <vers num="0.9.8c-2" />
        <vers num="0.9.8c-3" />
        <vers num="0.9.8c-4" />
        <vers num="0.9.8c-5" />
        <vers num="0.9.8c-6" />
        <vers num="0.9.8c-7" />
        <vers num="0.9.8c-8" />
        <vers num="0.9.8c-9" />
        <vers num="0.9.8d-1" />
        <vers num="0.9.8d-2" />
        <vers num="0.9.8d-3" />
        <vers num="0.9.8d-4" />
        <vers num="0.9.8d-5" />
        <vers num="0.9.8d-6" />
        <vers num="0.9.8d-7" />
        <vers num="0.9.8d-8" />
        <vers num="0.9.8d-9" />
        <vers num="0.9.8e-1" />
        <vers num="0.9.8e-2" />
        <vers num="0.9.8e-3" />
        <vers num="0.9.8e-4" />
        <vers num="0.9.8e-5" />
        <vers num="0.9.8e-6" />
        <vers num="0.9.8e-7" />
        <vers num="0.9.8e-8" />
        <vers num="0.9.8e-9" />
        <vers num="0.9.8f" />
        <vers num="0.9.8f-1" />
        <vers num="0.9.8f-2" />
        <vers num="0.9.8f-3" />
        <vers num="0.9.8f-4" />
        <vers num="0.9.8f-5" />
        <vers num="0.9.8f-6" />
        <vers num="0.9.8f-7" />
        <vers num="0.9.8f-8" />
        <vers num="0.9.8f-9" />
        <vers num="0.9.8g" />
        <vers num="0.9.8g-1" />
        <vers num="0.9.8g-2" />
        <vers num="0.9.8g-3" />
        <vers num="0.9.8g-4" />
        <vers num="0.9.8g-5" />
        <vers num="0.9.8g-6" />
        <vers num="0.9.8g-7" />
        <vers num="0.9.8g-8" />
        <vers num="0.9.8g-9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1378" published="2009-05-19" name="CVE-2009-1378" modified="2011-01-19" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Multiple memory leaks in the dtls1_process_out_of_seq_message function in ssl/d1_both.c in OpenSSL 0.9.8k and earlier 0.9.8 versions allow remote attackers to cause a denial of service (memory consumption) via DTLS records that (1) are duplicates or (2) have sequence numbers much greater than current sequence numbers, aka "DTLS fragment handling memory leak."</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://rt.openssl.org/Ticket/Display.html?id=1931&amp;user=guest&amp;pass=guest" source="CONFIRM" patch="1">http://rt.openssl.org/Ticket/Display.html?id=1931&amp;user=guest&amp;pass=guest</ref>
      <ref url="http://marc.info/?l=openssl-dev&amp;m=124247679213944&amp;w=2" source="MLIST" patch="1">[openssl-dev] 20090516 [openssl.org #1931] [PATCH] DTLS fragment handling memory leak</ref>
      <ref url="http://cvs.openssl.org/chngview?cn=18188" source="CONFIRM" patch="1">http://cvs.openssl.org/chngview?cn=18188</ref>
      <ref url="https://launchpad.net/bugs/cve/2009-1378" source="MISC">https://launchpad.net/bugs/cve/2009-1378</ref>
      <ref url="https://kb.bluecoat.com/index?page=content&amp;id=SA50" source="CONFIRM">https://kb.bluecoat.com/index?page=content&amp;id=SA50</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0528" source="VUPEN">ADV-2010-0528</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1377" source="VUPEN">ADV-2009-1377</ref>
      <ref url="http://www.ubuntu.com/usn/USN-792-1" source="UBUNTU">USN-792-1</ref>
      <ref url="http://www.securitytracker.com/id?1022241" source="SECTRACK">1022241</ref>
      <ref url="http://www.securityfocus.com/bid/35001" source="BID">35001</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2009/05/18/1" source="MLIST">[oss-security] 20090518 Two OpenSSL DTLS remote DoS</ref>
      <ref url="http://www.milw0rm.com/exploits/8720" source="MILW0RM">8720</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:120" source="MANDRIVA">MDVSA-2009:120</ref>
      <ref url="http://voodoo-circle.sourceforge.net/sa/sa-20091012-01.html" source="CONFIRM">http://voodoo-circle.sourceforge.net/sa/sa-20091012-01.html</ref>
      <ref url="http://sourceforge.net/mailarchive/message.php?msg_name=4AD43807.7080105%40users.sourceforge.net" source="CONFIRM">http://sourceforge.net/mailarchive/message.php?msg_name=4AD43807.7080105%40users.sourceforge.net</ref>
      <ref url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2010&amp;m=slackware-security.663049" source="SLACKWARE">SSA:2010-060-02</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200912-01.xml" source="GENTOO">GLSA-200912-01</ref>
      <ref url="http://secunia.com/advisories/42733" source="SECUNIA">42733</ref>
      <ref url="http://secunia.com/advisories/42724" source="SECUNIA">42724</ref>
      <ref url="http://secunia.com/advisories/38834" source="SECUNIA">38834</ref>
      <ref url="http://secunia.com/advisories/38794" source="SECUNIA">38794</ref>
      <ref url="http://secunia.com/advisories/38761" source="SECUNIA">38761</ref>
      <ref url="http://secunia.com/advisories/37003" source="SECUNIA">37003</ref>
      <ref url="http://secunia.com/advisories/35729" source="SECUNIA">35729</ref>
      <ref url="http://secunia.com/advisories/35571" source="SECUNIA">35571</ref>
      <ref url="http://secunia.com/advisories/35461" source="SECUNIA">35461</ref>
      <ref url="http://secunia.com/advisories/35416" source="SECUNIA">35416</ref>
      <ref url="http://secunia.com/advisories/35128" source="SECUNIA" adv="1">35128</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7229" source="OVAL">oval:org.mitre.oval:def:7229</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11309" source="OVAL">oval:org.mitre.oval:def:11309</ref>
      <ref url="http://marc.info/?l=openssl-dev&amp;m=124263491424212&amp;w=2" source="MLIST">[openssl-dev] 20090518 Re: [openssl.org #1931] [PATCH] DTLS fragment handling memory leak</ref>
      <ref url="http://lists.vmware.com/pipermail/security-announce/2010/000082.html" source="MLIST">[security-announce] 20100303 VMSA-2010-0004 ESX Service Console and vMA third party updates</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-06/msg00003.html" source="SUSE">SUSE-SR:2009:011</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c02029444" source="HP">HPSBMA02492</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c02029444" source="HP">HPSBMA02492</ref>
      <ref url="ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2009-009.txt.asc" source="NETBSD">NetBSD-SA2009-009</ref>
    </refs>
    <vuln_soft>
      <prod vendor="openssl" name="openssl">
        <vers num="0.9.8a" />
        <vers num="0.9.8b" />
        <vers num="0.9.8c" />
        <vers num="0.9.8d" />
        <vers num="0.9.8e" />
        <vers num="0.9.8f" />
        <vers num="0.9.8g" />
        <vers num="0.9.8h" />
        <vers num="0.9.8i" />
        <vers num="0.9.8j" />
        <vers prev="1" num="0.9.8k" />
      </prod>
      <prod vendor="openssl_project" name="openssl">
        <vers num="0.9.8c-1" />
        <vers num="0.9.8c-2" />
        <vers num="0.9.8c-3" />
        <vers num="0.9.8c-4" />
        <vers num="0.9.8c-5" />
        <vers num="0.9.8c-6" />
        <vers num="0.9.8c-7" />
        <vers num="0.9.8c-8" />
        <vers num="0.9.8c-9" />
        <vers num="0.9.8d-1" />
        <vers num="0.9.8d-2" />
        <vers num="0.9.8d-3" />
        <vers num="0.9.8d-4" />
        <vers num="0.9.8d-5" />
        <vers num="0.9.8d-6" />
        <vers num="0.9.8d-7" />
        <vers num="0.9.8d-8" />
        <vers num="0.9.8d-9" />
        <vers num="0.9.8e-1" />
        <vers num="0.9.8e-2" />
        <vers num="0.9.8e-3" />
        <vers num="0.9.8e-4" />
        <vers num="0.9.8e-5" />
        <vers num="0.9.8e-6" />
        <vers num="0.9.8e-7" />
        <vers num="0.9.8e-8" />
        <vers num="0.9.8e-9" />
        <vers num="0.9.8f" />
        <vers num="0.9.8f-1" />
        <vers num="0.9.8f-2" />
        <vers num="0.9.8f-3" />
        <vers num="0.9.8f-4" />
        <vers num="0.9.8f-5" />
        <vers num="0.9.8f-6" />
        <vers num="0.9.8f-7" />
        <vers num="0.9.8f-8" />
        <vers num="0.9.8f-9" />
        <vers num="0.9.8g" />
        <vers num="0.9.8g-1" />
        <vers num="0.9.8g-2" />
        <vers num="0.9.8g-3" />
        <vers num="0.9.8g-4" />
        <vers num="0.9.8g-5" />
        <vers num="0.9.8g-6" />
        <vers num="0.9.8g-7" />
        <vers num="0.9.8g-8" />
        <vers num="0.9.8g-9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1379" published="2009-05-19" name="CVE-2009-1379" modified="2011-01-19" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Use-after-free vulnerability in the dtls1_retrieve_buffered_fragment function in ssl/d1_both.c in OpenSSL 1.0.0 Beta 2 allows remote attackers to cause a denial of service (openssl s_client crash) and possibly have unspecified other impact via a DTLS packet, as demonstrated by a packet from a server that uses a crafted server certificate.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="https://launchpad.net/bugs/cve/2009-1379" source="MISC">https://launchpad.net/bugs/cve/2009-1379</ref>
      <ref url="https://kb.bluecoat.com/index?page=content&amp;id=SA50" source="CONFIRM">https://kb.bluecoat.com/index?page=content&amp;id=SA50</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/50661" source="XF">openssl-dtls1retrievebufferedfragment-dos(50661)</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0528" source="VUPEN">ADV-2010-0528</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1377" source="VUPEN">ADV-2009-1377</ref>
      <ref url="http://www.ubuntu.com/usn/USN-792-1" source="UBUNTU">USN-792-1</ref>
      <ref url="http://www.securitytracker.com/id?1022241" source="SECTRACK">1022241</ref>
      <ref url="http://www.securityfocus.com/bid/35138" source="BID">35138</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2009/05/18/4" source="MLIST">[oss-security] 20090518 Re: Two OpenSSL DTLS remote DoS</ref>
      <ref url="http://voodoo-circle.sourceforge.net/sa/sa-20091012-01.html" source="CONFIRM">http://voodoo-circle.sourceforge.net/sa/sa-20091012-01.html</ref>
      <ref url="http://sourceforge.net/mailarchive/message.php?msg_name=4AD43807.7080105%40users.sourceforge.net" source="CONFIRM">http://sourceforge.net/mailarchive/message.php?msg_name=4AD43807.7080105%40users.sourceforge.net</ref>
      <ref url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2010&amp;m=slackware-security.663049" source="SLACKWARE">SSA:2010-060-02</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200912-01.xml" source="GENTOO">GLSA-200912-01</ref>
      <ref url="http://secunia.com/advisories/42733" source="SECUNIA">42733</ref>
      <ref url="http://secunia.com/advisories/42724" source="SECUNIA">42724</ref>
      <ref url="http://secunia.com/advisories/38834" source="SECUNIA">38834</ref>
      <ref url="http://secunia.com/advisories/38794" source="SECUNIA">38794</ref>
      <ref url="http://secunia.com/advisories/38761" source="SECUNIA">38761</ref>
      <ref url="http://secunia.com/advisories/37003" source="SECUNIA">37003</ref>
      <ref url="http://secunia.com/advisories/35729" source="SECUNIA">35729</ref>
      <ref url="http://secunia.com/advisories/35571" source="SECUNIA">35571</ref>
      <ref url="http://secunia.com/advisories/35461" source="SECUNIA">35461</ref>
      <ref url="http://secunia.com/advisories/35416" source="SECUNIA">35416</ref>
      <ref url="http://rt.openssl.org/Ticket/Display.html?id=1923&amp;user=guest&amp;pass=guest" source="CONFIRM">http://rt.openssl.org/Ticket/Display.html?id=1923&amp;user=guest&amp;pass=guest</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9744" source="OVAL">oval:org.mitre.oval:def:9744</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6848" source="OVAL">oval:org.mitre.oval:def:6848</ref>
      <ref url="http://lists.vmware.com/pipermail/security-announce/2010/000082.html" source="MLIST">[security-announce] 20100303 VMSA-2010-0004 ESX Service Console and vMA third party updates</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-06/msg00003.html" source="SUSE">SUSE-SR:2009:011</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c02029444" source="HP">SSRT100079</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c02029444" source="HP">SSRT100079</ref>
      <ref url="ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2009-009.txt.asc" source="NETBSD">NetBSD-SA2009-009</ref>
    </refs>
    <vuln_soft>
      <prod vendor="openssl" name="openssl">
        <vers num="1.0.0" edition="beta2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1380" published="2009-12-15" name="CVE-2009-1380" modified="2009-12-16" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in JMX-Console in JBossAs in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2 before 4.2.0.CP08 and 4.3 before 4.3.0.CP07 allows remote attackers to inject arbitrary web script or HTML via the filter parameter, related to the key property and the position of quote and colon characters.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=511224" source="CONFIRM" patch="1">https://bugzilla.redhat.com/show_bug.cgi?id=511224</ref>
      <ref url="https://rhn.redhat.com/errata/RHSA-2009-1650.html" source="REDHAT" adv="1">RHSA-2009:1650</ref>
      <ref url="https://rhn.redhat.com/errata/RHSA-2009-1649.html" source="REDHAT" adv="1">RHSA-2009:1649</ref>
      <ref url="https://rhn.redhat.com/errata/RHSA-2009-1637.html" source="REDHAT">RHSA-2009:1637</ref>
      <ref url="https://rhn.redhat.com/errata/RHSA-2009-1636.html" source="REDHAT" adv="1">RHSA-2009:1636</ref>
      <ref url="https://jira.jboss.org/jira/browse/JBPAPP-1983" source="CONFIRM">https://jira.jboss.org/jira/browse/JBPAPP-1983</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/54698" source="XF">jboss-enterprise-jmxconsole-xss(54698)</ref>
      <ref url="http://www.securityfocus.com/bid/37276" source="BID">37276</ref>
      <ref url="http://securitytracker.com/id?1023315" source="SECTRACK">1023315</ref>
      <ref url="http://secunia.com/advisories/37671" source="SECUNIA" adv="1">37671</ref>
    </refs>
    <vuln_soft>
      <prod vendor="redhat" name="jboss_enterprise_application_platform">
        <vers num="4.2" edition="cp01" />
        <vers num="4.2" edition="cp02" />
        <vers num="4.2" edition="cp03" />
        <vers num="4.2.0" edition="cp01" />
        <vers num="4.2.0" edition="cp02" />
        <vers num="4.2.0" edition="cp03" />
        <vers num="4.2.0" edition="cp04" />
        <vers num="4.2.0" edition="cp05" />
        <vers num="4.2.0" edition="cp06" />
        <vers num="4.2.0" edition="cp07" />
        <vers num="4.3" edition="cp01" />
        <vers num="4.3.0" edition="cp01" />
        <vers num="4.3.0" edition="cp02" />
        <vers num="4.3.0" edition="cp03" />
        <vers num="4.3.0" edition="cp04" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1381" published="2009-05-22" name="CVE-2009-1381" modified="2009-06-09" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">The map_yp_alias function in functions/imap_general.php in SquirrelMail before 1.4.19-1 on Debian GNU/Linux, and possibly other operating systems and versions, allows remote attackers to execute arbitrary commands via shell metacharacters in a username string that is used by the ypmatch program.  NOTE: this issue exists because of an incomplete fix for CVE-2009-1579.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/503718/100/0/threaded" source="BUGTRAQ" patch="1">20090521 [SECURITY] [DSA 1802-2] New squirrelmail packages correct incomplete fix</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-May/msg01202.html" source="FEDORA">FEDORA-2009-5350</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-May/msg01195.html" source="FEDORA">FEDORA-2009-5471</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:122" source="MANDRIVA">MDVSA-2009:122</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1802" source="DEBIAN" adv="1">DSA-1802</ref>
      <ref url="http://secunia.com/advisories/35140" source="SECUNIA" adv="1">35140</ref>
      <ref url="http://release.debian.org/proposed-updates/stable_diffs/squirrelmail_1.4.15-4+lenny2.debdiff" source="MISC" adv="1">http://release.debian.org/proposed-updates/stable_diffs/squirrelmail_1.4.15-4+lenny2.debdiff</ref>
    </refs>
    <vuln_soft>
      <prod vendor="squirrelmail" name="imap_general.php">
        <vers num="1.2.2" />
      </prod>
      <prod vendor="squirrelmail" name="squirrelmail">
        <vers num="1.2.10" />
        <vers num="1.2.11" />
        <vers num="1.2.5" />
        <vers num="1.2.6" />
        <vers num="1.2.6-rc1" />
        <vers num="1.2.7" />
        <vers num="1.2.8" />
        <vers num="1.2.9" />
        <vers num="1.4.0" />
        <vers num="1.4.0-r1" />
        <vers num="1.4.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1382" published="2009-07-14" name="CVE-2009-1382" modified="2010-04-20" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Multiple stack-based buffer overflows in mimetex.cgi in mimeTeX, when downloaded before 20090713, allow remote attackers to execute arbitrary code via a TeX file with long (1) picture, (2) circle, or (3) input tags.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2009/1875" source="VUPEN" patch="1" adv="1">ADV-2009-1875</ref>
      <ref url="http://groups.google.com/group/comp.text.tex/browse_thread/thread/5d56d3d744351578" source="MISC" patch="1">http://groups.google.com/group/comp.text.tex/browse_thread/thread/5d56d3d744351578</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/51794" source="XF">mimetex-mimetex-bo(51794)</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0877" source="VUPEN">ADV-2010-0877</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/504919/100/0/threaded" source="BUGTRAQ">20090713 [oCERT-2009-010] mimeTeX and mathTeX buffer overflows and commandinjection</ref>
      <ref url="http://www.ocert.org/advisories/ocert-2009-010.html" source="MISC">http://www.ocert.org/advisories/ocert-2009-010.html</ref>
      <ref url="http://secunia.com/advisories/35816" source="SECUNIA" adv="1">35816</ref>
      <ref url="http://secunia.com/advisories/35752" source="SECUNIA" adv="1">35752</ref>
      <ref url="http://scary.beasts.org/security/CESA-2009-009.html" source="MISC">http://scary.beasts.org/security/CESA-2009-009.html</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2010-April/039314.html" source="FEDORA">FEDORA-2010-6546</ref>
    </refs>
    <vuln_soft>
      <prod vendor="forkosh" name="mimetex">
        <vers prev="1" num="1.71" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1383" published="2009-07-14" name="CVE-2009-1383" modified="2009-08-12" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">The getdirective function in mathtex.cgi in mathTeX, when downloaded before 20090713, allows remote attackers to execute arbitrary commands via shell metacharacters in the dpi tag.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/51795" source="XF">mathtex-getdirective-command-execution(51795)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1875" source="VUPEN" adv="1">ADV-2009-1875</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/504919/100/0/threaded" source="BUGTRAQ">20090713 [oCERT-2009-010] mimeTeX and mathTeX buffer overflows and commandinjection</ref>
      <ref url="http://www.ocert.org/advisories/ocert-2009-010.html" source="MISC">http://www.ocert.org/advisories/ocert-2009-010.html</ref>
      <ref url="http://secunia.com/advisories/35816" source="SECUNIA" adv="1">35816</ref>
      <ref url="http://groups.google.com/group/comp.text.tex/browse_thread/thread/5d56d3d744351578" source="MISC">http://groups.google.com/group/comp.text.tex/browse_thread/thread/5d56d3d744351578</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1384" published="2009-05-28" name="CVE-2009-1384" modified="2011-02-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">pam_krb5 2.2.14 through 2.3.4, as used in Red Hat Enterprise Linux (RHEL) 5, generates different password prompts depending on whether the user account exists, which allows remote attackers to enumerate valid usernames.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=502602" source="CONFIRM" adv="1">https://bugzilla.redhat.com/show_bug.cgi?id=502602</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1448" source="VUPEN">ADV-2009-1448</ref>
      <ref url="http://www.vmware.com/security/advisories/VMSA-2011-0003.html" source="CONFIRM">http://www.vmware.com/security/advisories/VMSA-2011-0003.html</ref>
      <ref url="http://www.securityfocus.com/bid/35112" source="BID">35112</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/516397/100/0/threaded" source="BUGTRAQ">20110211 VMSA-2011-0003 Third party component updates for VMware vCenter Server, vCenter Update Manager, ESXi and ESX</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2009/05/27/1" source="MLIST">[oss-security] 20090527 CVE assignment notification (pam_krb5 CVE-2009-1384)</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2010:054" source="MANDRIVA">MDVSA-2010:054</ref>
      <ref url="http://secunia.com/advisories/43314" source="SECUNIA">43314</ref>
      <ref url="http://secunia.com/advisories/35230" source="SECUNIA">35230</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9652" source="OVAL">oval:org.mitre.oval:def:9652</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7081" source="OVAL">oval:org.mitre.oval:def:7081</ref>
      <ref url="http://osvdb.org/54791" source="OSVDB">54791</ref>
    </refs>
    <vuln_soft>
      <prod vendor="eyrie" name="pam-krb5">
        <vers num="2.2.14" />
        <vers num="2.3" />
        <vers num="2.3.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1385" published="2009-06-04" name="CVE-2009-1385" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Integer underflow in the e1000_clean_rx_irq function in drivers/net/e1000/e1000_main.c in the e1000 driver in the Linux kernel before 2.6.30-rc8, the e1000e driver in the Linux kernel, and Intel Wired Ethernet (aka e1000) before 7.5.5 allows remote attackers to cause a denial of service (panic) via a crafted frame size.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=502981" source="CONFIRM" patch="1">https://bugzilla.redhat.com/show_bug.cgi?id=502981</ref>
      <ref url="http://www.kernel.org/pub/linux/kernel/v2.6/testing/ChangeLog-2.6.30-rc8" source="CONFIRM" patch="1" adv="1">http://www.kernel.org/pub/linux/kernel/v2.6/testing/ChangeLog-2.6.30-rc8</ref>
      <ref url="http://sourceforge.net/project/shownotes.php?release_id=504022&amp;group_id=42302" source="CONFIRM" patch="1">http://sourceforge.net/project/shownotes.php?release_id=504022&amp;group_id=42302</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-June/msg01193.html" source="FEDORA">FEDORA-2009-6846</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-June/msg01094.html" source="FEDORA">FEDORA-2009-6768</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-June/msg01048.html" source="FEDORA">FEDORA-2009-6883</ref>
      <ref url="https://rhn.redhat.com/errata/RHSA-2009-1550.html" source="REDHAT">RHSA-2009:1550</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/3316" source="VUPEN">ADV-2009-3316</ref>
      <ref url="http://www.vmware.com/security/advisories/VMSA-2009-0016.html" source="CONFIRM">http://www.vmware.com/security/advisories/VMSA-2009-0016.html</ref>
      <ref url="http://www.ubuntu.com/usn/usn-793-1" source="UBUNTU">USN-793-1</ref>
      <ref url="http://www.securityfocus.com/bid/35185" source="BID">35185</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/512019/100/0/threaded" source="BUGTRAQ">20100625 VMSA-2010-0010 ESX 3.5 third party update for Service Console kernel</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/507985/100/0/threaded" source="BUGTRAQ">20091120 VMSA-2009-0016 VMware vCenter and ESX update release and vMA patch release address multiple security issue in third party components</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/505254/100/0/threaded" source="BUGTRAQ">20090724 rPSA-2009-0111-1 kernel</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-1193.html" source="REDHAT">RHSA-2009:1193</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-1157.html" source="REDHAT">RHSA-2009:1157</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2009/06/03/2" source="MLIST">[oss-security] 20090603 CVE-2009-1385 kernel: e1000_clean_rx_irq() denial of service</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:148" source="MANDRIVA">MDVSA-2009:148</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:135" source="MANDRIVA">MDVSA-2009:135</ref>
      <ref url="http://www.intel.com/support/network/sb/CS-030543.htm" source="CONFIRM">http://www.intel.com/support/network/sb/CS-030543.htm</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1865" source="DEBIAN">DSA-1865</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1844" source="DEBIAN">DSA-1844</ref>
      <ref url="http://wiki.rpath.com/Advisories:rPSA-2009-0111" source="CONFIRM">http://wiki.rpath.com/Advisories:rPSA-2009-0111</ref>
      <ref url="http://secunia.com/advisories/37471" source="SECUNIA">37471</ref>
      <ref url="http://secunia.com/advisories/36327" source="SECUNIA">36327</ref>
      <ref url="http://secunia.com/advisories/36131" source="SECUNIA">36131</ref>
      <ref url="http://secunia.com/advisories/36051" source="SECUNIA">36051</ref>
      <ref url="http://secunia.com/advisories/35847" source="SECUNIA">35847</ref>
      <ref url="http://secunia.com/advisories/35656" source="SECUNIA">35656</ref>
      <ref url="http://secunia.com/advisories/35623" source="SECUNIA">35623</ref>
      <ref url="http://secunia.com/advisories/35566" source="SECUNIA">35566</ref>
      <ref url="http://secunia.com/advisories/35265" source="SECUNIA" adv="1">35265</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:8340" source="OVAL">oval:org.mitre.oval:def:8340</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11681" source="OVAL">oval:org.mitre.oval:def:11681</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11598" source="OVAL">oval:org.mitre.oval:def:11598</ref>
      <ref url="http://osvdb.org/54892" source="OSVDB">54892</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-07/msg00004.html" source="SUSE">SUSE-SA:2009:038</ref>
      <ref url="http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=ea30e11970a96cfe5e32c03a29332554573b4a10" source="CONFIRM" adv="1">http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=ea30e11970a96cfe5e32c03a29332554573b4a10</ref>
    </refs>
    <vuln_soft>
      <prod vendor="intel" name="e1000">
        <vers num="5.2.22" />
        <vers num="5.2.30.1" />
        <vers num="5.2.52" />
        <vers num="5.3.19" />
        <vers num="5.4.11" />
        <vers num="5.5.4" />
        <vers num="5.6.10" />
        <vers num="5.6.10.1" />
        <vers num="5.7.6" />
        <vers num="6.0.54" />
        <vers num="6.0.60" />
        <vers num="6.1.16" />
        <vers num="6.2.15" />
        <vers num="6.3.9" />
        <vers num="7.0.33" />
        <vers num="7.0.41" />
        <vers num="7.1.9" />
        <vers num="7.2.7" />
        <vers num="7.2.9" />
        <vers num="7.3.15" />
        <vers num="7.3.20" />
        <vers num="7.4.27" />
        <vers prev="1" num="7.4.35" />
      </prod>
      <prod vendor="linux" name="kernel">
        <vers num="2.6.24.7" />
        <vers num="2.6.25.15" />
      </prod>
      <prod vendor="linux" name="kernel">
        <vers num="2.2.27" />
        <vers num="2.4.36" />
        <vers num="2.4.36.1" />
        <vers num="2.4.36.2" />
        <vers num="2.4.36.3" />
        <vers num="2.4.36.4" />
        <vers num="2.4.36.5" />
        <vers num="2.4.36.6" />
        <vers num="2.6" />
        <vers num="2.6.18" edition="rc1" />
        <vers num="2.6.18" edition="rc2" />
        <vers num="2.6.18" edition="rc3" />
        <vers num="2.6.18" edition="rc4" />
        <vers num="2.6.18" edition="rc5" />
        <vers num="2.6.18" edition="rc6" />
        <vers num="2.6.18" edition="rc7" />
        <vers num="2.6.19.4" />
        <vers num="2.6.19.5" />
        <vers num="2.6.19.6" />
        <vers num="2.6.19.7" />
        <vers num="2.6.20.16" />
        <vers num="2.6.20.17" />
        <vers num="2.6.20.18" />
        <vers num="2.6.20.19" />
        <vers num="2.6.20.20" />
        <vers num="2.6.20.21" />
        <vers num="2.6.21.5" />
        <vers num="2.6.21.6" />
        <vers num="2.6.21.7" />
        <vers num="2.6.22" />
        <vers num="2.6.22.1" />
        <vers num="2.6.22.10" />
        <vers num="2.6.22.11" />
        <vers num="2.6.22.12" />
        <vers num="2.6.22.13" />
        <vers num="2.6.22.14" />
        <vers num="2.6.22.15" />
        <vers num="2.6.22.17" />
        <vers num="2.6.22.18" />
        <vers num="2.6.22.19" />
        <vers num="2.6.22.2" />
        <vers num="2.6.22.20" />
        <vers num="2.6.22.21" />
        <vers num="2.6.22.22" />
        <vers num="2.6.22.8" />
        <vers num="2.6.22.9" />
        <vers num="2.6.22_rc1" />
        <vers num="2.6.22_rc7" />
        <vers num="2.6.23" />
        <vers num="2.6.23.10" />
        <vers num="2.6.23.11" />
        <vers num="2.6.23.12" />
        <vers num="2.6.23.13" />
        <vers num="2.6.23.15" />
        <vers num="2.6.23.16" />
        <vers num="2.6.23.17" />
        <vers num="2.6.23.8" />
        <vers num="2.6.23.9" />
        <vers num="2.6.23_rc1" />
        <vers num="2.6.24" />
        <vers num="2.6.24.1" />
        <vers num="2.6.24.2" />
        <vers num="2.6.24.3" />
        <vers num="2.6.24.4" />
        <vers num="2.6.24.5" />
        <vers num="2.6.24.6" />
        <vers num="2.6.24_rc1" />
        <vers num="2.6.24_rc4" />
        <vers num="2.6.24_rc5" />
        <vers num="2.6.25" edition="" />
        <vers num="2.6.25" edition=":x86_64" />
        <vers num="2.6.25.1" edition="" />
        <vers num="2.6.25.1" edition=":x86_64" />
        <vers num="2.6.25.10" edition="" />
        <vers num="2.6.25.10" edition=":x86_64" />
        <vers num="2.6.25.11" edition="" />
        <vers num="2.6.25.11" edition=":x86_64" />
        <vers num="2.6.25.12" edition="" />
        <vers num="2.6.25.12" edition=":x86_64" />
        <vers num="2.6.25.13" />
        <vers num="2.6.25.14" />
        <vers num="2.6.25.16" />
        <vers num="2.6.25.17" />
        <vers num="2.6.25.2" edition="" />
        <vers num="2.6.25.2" edition=":x86_64" />
        <vers num="2.6.25.3" edition="" />
        <vers num="2.6.25.3" edition=":x86_64" />
        <vers num="2.6.25.4" edition="" />
        <vers num="2.6.25.4" edition=":x86_64" />
        <vers num="2.6.25.5" edition="" />
        <vers num="2.6.25.5" edition=":x86_64" />
        <vers num="2.6.25.6" edition="" />
        <vers num="2.6.25.6" edition=":x86_64" />
        <vers num="2.6.25.7" edition="" />
        <vers num="2.6.25.7" edition=":x86_64" />
        <vers num="2.6.25.8" edition="" />
        <vers num="2.6.25.8" edition=":x86_64" />
        <vers num="2.6.25.9" edition="" />
        <vers num="2.6.25.9" edition=":x86_64" />
        <vers num="2.6.26" />
        <vers num="2.6.26.1" />
        <vers num="2.6.26.2" />
        <vers num="2.6.26.3" />
        <vers num="2.6.26.4" />
        <vers num="2.6.26.5" />
        <vers num="2.6.27" />
        <vers prev="1" num="2.6.28" />
        <vers num="2.6.29" edition="git1" />
        <vers num="2.6.29" edition="rc1" />
        <vers num="2.6.29" edition="rc2" />
        <vers num="2.6.29" edition="rc2_git7" />
        <vers num="2.6.29" edition="rc8-kk" />
        <vers num="2.6.29.3" />
        <vers num="2.6.29.rc1" />
        <vers num="2.6.29.rc2" />
        <vers num="2.6.29.rc2-git1" />
        <vers prev="1" num="2.6.30" edition="rc1" />
        <vers prev="1" num="2.6.30" edition="rc2" />
        <vers prev="1" num="2.6.30" edition="rc3" />
        <vers prev="1" num="2.6.30" edition="rc7-git6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1386" published="2009-06-04" name="CVE-2009-1386" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">ssl/s3_pkt.c in OpenSSL before 0.9.8i allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a DTLS ChangeCipherSpec packet that occurs before ClientHello.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://cvs.openssl.org/chngview?cn=17369" source="CONFIRM" patch="1">http://cvs.openssl.org/chngview?cn=17369</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/50963" source="XF">openssl-changecipherspec-dos(50963)</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0528" source="VUPEN">ADV-2010-0528</ref>
      <ref url="http://www.ubuntu.com/usn/USN-792-1" source="UBUNTU">USN-792-1</ref>
      <ref url="http://www.securityfocus.com/bid/35174" source="BID">35174</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2009/06/02/1" source="MLIST">[oss-security] 20090602 Re: Two OpenSSL DTLS remote DoS</ref>
      <ref url="http://www.milw0rm.com/exploits/8873" source="MILW0RM">8873</ref>
      <ref url="http://secunia.com/advisories/38834" source="SECUNIA">38834</ref>
      <ref url="http://secunia.com/advisories/38794" source="SECUNIA">38794</ref>
      <ref url="http://secunia.com/advisories/35729" source="SECUNIA">35729</ref>
      <ref url="http://secunia.com/advisories/35685" source="SECUNIA">35685</ref>
      <ref url="http://secunia.com/advisories/35571" source="SECUNIA">35571</ref>
      <ref url="http://rt.openssl.org/Ticket/Display.html?id=1679&amp;user=guest&amp;pass=guest" source="CONFIRM" adv="1">http://rt.openssl.org/Ticket/Display.html?id=1679&amp;user=guest&amp;pass=guest</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7469" source="OVAL">oval:org.mitre.oval:def:7469</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11179" source="OVAL">oval:org.mitre.oval:def:11179</ref>
      <ref url="http://lists.vmware.com/pipermail/security-announce/2010/000082.html" source="MLIST">[security-announce] 20100303 VMSA-2010-0004 ESX Service Console and vMA third party updates</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-07/msg00002.html" source="SUSE">SUSE-SR:2009:012</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c02029444" source="HP">SSRT100079</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c02029444" source="HP">SSRT100079</ref>
      <ref url="ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2009-009.txt.asc" source="NETBSD">NetBSD-SA2009-009</ref>
    </refs>
    <vuln_soft>
      <prod vendor="openssl" name="openssl">
        <vers num="0.9.1c" />
        <vers num="0.9.2b" />
        <vers num="0.9.3" />
        <vers num="0.9.3a" />
        <vers num="0.9.4" />
        <vers num="0.9.5" edition="beta1" />
        <vers num="0.9.5a" edition="beta1" />
        <vers num="0.9.5a" edition="beta2" />
        <vers num="0.9.6" edition="beta1" />
        <vers num="0.9.6" edition="beta2" />
        <vers num="0.9.6" edition="beta3" />
        <vers num="0.9.6a" edition="beta1" />
        <vers num="0.9.6a" edition="beta2" />
        <vers num="0.9.6a" edition="beta3" />
        <vers num="0.9.6b" />
        <vers num="0.9.6c" />
        <vers num="0.9.6d" />
        <vers num="0.9.6e" />
        <vers num="0.9.6f" />
        <vers num="0.9.6g" />
        <vers num="0.9.6h" />
        <vers num="0.9.6i" />
        <vers num="0.9.6j" />
        <vers num="0.9.6k" />
        <vers num="0.9.6l" />
        <vers num="0.9.6m" />
        <vers num="0.9.7" edition="beta1" />
        <vers num="0.9.7" edition="beta2" />
        <vers num="0.9.7" edition="beta3" />
        <vers num="0.9.7" edition="beta4" />
        <vers num="0.9.7" edition="beta5" />
        <vers num="0.9.7" edition="beta6" />
        <vers num="0.9.7a" />
        <vers num="0.9.7b" />
        <vers num="0.9.7c" />
        <vers num="0.9.7d" />
        <vers num="0.9.7e" />
        <vers num="0.9.7f" />
        <vers num="0.9.7g" />
        <vers num="0.9.7h" />
        <vers num="0.9.7i" />
        <vers num="0.9.7j" />
        <vers num="0.9.7k" />
        <vers num="0.9.7l" />
        <vers num="0.9.7m" />
        <vers num="0.9.8" />
        <vers num="0.9.8a" />
        <vers num="0.9.8b" />
        <vers num="0.9.8c" />
        <vers num="0.9.8d" />
        <vers num="0.9.8e" />
        <vers num="0.9.8f" />
        <vers num="0.9.8g" />
        <vers num="0.9.8h" />
      </prod>
      <prod vendor="openssl_project" name="openssl">
        <vers num="0.9.8c-1" />
        <vers num="0.9.8c-2" />
        <vers num="0.9.8c-3" />
        <vers num="0.9.8c-4" />
        <vers num="0.9.8c-5" />
        <vers num="0.9.8c-6" />
        <vers num="0.9.8c-7" />
        <vers num="0.9.8c-8" />
        <vers num="0.9.8c-9" />
        <vers num="0.9.8d-1" />
        <vers num="0.9.8d-2" />
        <vers num="0.9.8d-3" />
        <vers num="0.9.8d-4" />
        <vers num="0.9.8d-5" />
        <vers num="0.9.8d-6" />
        <vers num="0.9.8d-7" />
        <vers num="0.9.8d-8" />
        <vers num="0.9.8d-9" />
        <vers num="0.9.8e-1" />
        <vers num="0.9.8e-2" />
        <vers num="0.9.8e-3" />
        <vers num="0.9.8e-4" />
        <vers num="0.9.8e-5" />
        <vers num="0.9.8e-6" />
        <vers num="0.9.8e-7" />
        <vers num="0.9.8e-8" />
        <vers num="0.9.8e-9" />
        <vers num="0.9.8f" />
        <vers num="0.9.8f-1" />
        <vers num="0.9.8f-2" />
        <vers num="0.9.8f-3" />
        <vers num="0.9.8f-4" />
        <vers num="0.9.8f-5" />
        <vers num="0.9.8f-6" />
        <vers num="0.9.8f-7" />
        <vers num="0.9.8f-8" />
        <vers num="0.9.8f-9" />
        <vers prev="1" num="0.9.8g" />
        <vers num="0.9.8g-1" />
        <vers num="0.9.8g-2" />
        <vers num="0.9.8g-3" />
        <vers num="0.9.8g-4" />
        <vers num="0.9.8g-5" />
        <vers num="0.9.8g-6" />
        <vers num="0.9.8g-7" />
        <vers num="0.9.8g-8" />
        <vers num="0.9.8g-9" />
      </prod>
      <prod vendor="redhat" name="openssl">
        <vers num="0.9.6-15" edition="" />
        <vers num="0.9.6-15" edition=":i386" />
        <vers num="0.9.6b-3" edition="" />
        <vers num="0.9.6b-3" edition=":i386" />
        <vers num="0.9.7a-2" edition="" />
        <vers num="0.9.7a-2" edition=":i386_dev" />
        <vers num="0.9.7a-2" edition=":i386" />
        <vers num="0.9.7a-2" edition=":i386_perl" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1387" published="2009-06-04" name="CVE-2009-1387" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The dtls1_retrieve_buffered_fragment function in ssl/d1_both.c in OpenSSL before 1.0.0 Beta 2 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via an out-of-sequence DTLS handshake message, related to a "fragment bug."</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://rt.openssl.org/Ticket/Display.html?id=1838&amp;user=guest&amp;pass=guest" source="CONFIRM" patch="1">http://rt.openssl.org/Ticket/Display.html?id=1838&amp;user=guest&amp;pass=guest</ref>
      <ref url="http://cvs.openssl.org/chngview?cn=17958" source="CONFIRM" patch="1">http://cvs.openssl.org/chngview?cn=17958</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0528" source="VUPEN">ADV-2010-0528</ref>
      <ref url="http://www.ubuntu.com/usn/USN-792-1" source="UBUNTU">USN-792-1</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2009/06/02/1" source="MLIST">[oss-security] 20090602 Re: Two OpenSSL DTLS remote DoS</ref>
      <ref url="http://voodoo-circle.sourceforge.net/sa/sa-20091012-01.html" source="CONFIRM">http://voodoo-circle.sourceforge.net/sa/sa-20091012-01.html</ref>
      <ref url="http://sourceforge.net/mailarchive/message.php?msg_name=4AD43807.7080105%40users.sourceforge.net" source="CONFIRM">http://sourceforge.net/mailarchive/message.php?msg_name=4AD43807.7080105%40users.sourceforge.net</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200912-01.xml" source="GENTOO">GLSA-200912-01</ref>
      <ref url="http://secunia.com/advisories/38834" source="SECUNIA">38834</ref>
      <ref url="http://secunia.com/advisories/38794" source="SECUNIA">38794</ref>
      <ref url="http://secunia.com/advisories/37003" source="SECUNIA">37003</ref>
      <ref url="http://secunia.com/advisories/35729" source="SECUNIA">35729</ref>
      <ref url="http://secunia.com/advisories/35685" source="SECUNIA">35685</ref>
      <ref url="http://secunia.com/advisories/35571" source="SECUNIA">35571</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7592" source="OVAL">oval:org.mitre.oval:def:7592</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10740" source="OVAL">oval:org.mitre.oval:def:10740</ref>
      <ref url="http://lists.vmware.com/pipermail/security-announce/2010/000082.html" source="MLIST">[security-announce] 20100303 VMSA-2010-0004 ESX Service Console and vMA third party updates</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-07/msg00002.html" source="SUSE">SUSE-SR:2009:012</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c02029444" source="HP">SSRT100079</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c02029444" source="HP">SSRT100079</ref>
      <ref url="ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2009-009.txt.asc" source="NETBSD">NetBSD-SA2009-009</ref>
    </refs>
    <vuln_soft>
      <prod vendor="openssl" name="openssl">
        <vers num="0.9.1c" />
        <vers num="0.9.2b" />
        <vers num="0.9.3" />
        <vers num="0.9.3a" />
        <vers num="0.9.4" />
        <vers num="0.9.5" edition="beta1" />
        <vers num="0.9.5a" edition="beta1" />
        <vers num="0.9.5a" edition="beta2" />
        <vers num="0.9.6" edition="beta1" />
        <vers num="0.9.6" edition="beta2" />
        <vers num="0.9.6" edition="beta3" />
        <vers num="0.9.6a" edition="beta1" />
        <vers num="0.9.6a" edition="beta2" />
        <vers num="0.9.6a" edition="beta3" />
        <vers num="0.9.6b" />
        <vers num="0.9.6c" />
        <vers num="0.9.6d" />
        <vers num="0.9.6e" />
        <vers num="0.9.6f" />
        <vers num="0.9.6g" />
        <vers num="0.9.6h" />
        <vers num="0.9.6i" />
        <vers num="0.9.6j" />
        <vers num="0.9.6k" />
        <vers num="0.9.6l" />
        <vers num="0.9.6m" />
        <vers num="0.9.7" edition="beta1" />
        <vers num="0.9.7" edition="beta2" />
        <vers num="0.9.7" edition="beta3" />
        <vers num="0.9.7" edition="beta4" />
        <vers num="0.9.7" edition="beta5" />
        <vers num="0.9.7" edition="beta6" />
        <vers num="0.9.7a" />
        <vers num="0.9.7b" />
        <vers num="0.9.7c" />
        <vers num="0.9.7d" />
        <vers num="0.9.7e" />
        <vers num="0.9.7f" />
        <vers num="0.9.7g" />
        <vers num="0.9.7h" />
        <vers num="0.9.7i" />
        <vers num="0.9.7j" />
        <vers num="0.9.7k" />
        <vers num="0.9.7l" />
        <vers num="0.9.7m" />
        <vers num="0.9.8" />
        <vers num="0.9.8a" />
        <vers num="0.9.8b" />
        <vers num="0.9.8c" />
        <vers num="0.9.8d" />
        <vers num="0.9.8e" />
        <vers num="0.9.8f" />
        <vers num="0.9.8g" />
        <vers num="0.9.8h" />
        <vers num="0.9.8i" />
        <vers num="0.9.8j" />
        <vers num="0.9.8k" />
        <vers prev="1" num="1.0" edition="" />
        <vers prev="1" num="1.0" edition=":openvms" />
      </prod>
      <prod vendor="openssl_project" name="openssl">
        <vers num="0.9.8c-1" />
        <vers num="0.9.8c-2" />
        <vers num="0.9.8c-3" />
        <vers num="0.9.8c-4" />
        <vers num="0.9.8c-5" />
        <vers num="0.9.8c-6" />
        <vers num="0.9.8c-7" />
        <vers num="0.9.8c-8" />
        <vers num="0.9.8c-9" />
        <vers num="0.9.8d-1" />
        <vers num="0.9.8d-2" />
        <vers num="0.9.8d-3" />
        <vers num="0.9.8d-4" />
        <vers num="0.9.8d-5" />
        <vers num="0.9.8d-6" />
        <vers num="0.9.8d-7" />
        <vers num="0.9.8d-8" />
        <vers num="0.9.8d-9" />
        <vers num="0.9.8e-1" />
        <vers num="0.9.8e-2" />
        <vers num="0.9.8e-3" />
        <vers num="0.9.8e-4" />
        <vers num="0.9.8e-5" />
        <vers num="0.9.8e-6" />
        <vers num="0.9.8e-7" />
        <vers num="0.9.8e-8" />
        <vers num="0.9.8e-9" />
        <vers num="0.9.8f" />
        <vers num="0.9.8f-1" />
        <vers num="0.9.8f-2" />
        <vers num="0.9.8f-3" />
        <vers num="0.9.8f-4" />
        <vers num="0.9.8f-5" />
        <vers num="0.9.8f-6" />
        <vers num="0.9.8f-7" />
        <vers num="0.9.8f-8" />
        <vers num="0.9.8f-9" />
        <vers prev="1" num="0.9.8g" />
        <vers num="0.9.8g-1" />
        <vers num="0.9.8g-2" />
        <vers num="0.9.8g-3" />
        <vers num="0.9.8g-4" />
        <vers num="0.9.8g-5" />
        <vers num="0.9.8g-6" />
        <vers num="0.9.8g-7" />
        <vers num="0.9.8g-8" />
        <vers num="0.9.8g-9" />
      </prod>
      <prod vendor="redhat" name="openssl">
        <vers num="0.9.6-15" edition="" />
        <vers num="0.9.6-15" edition=":i386" />
        <vers num="0.9.6b-3" edition="" />
        <vers num="0.9.6b-3" edition=":i386" />
        <vers num="0.9.7a-2" edition="" />
        <vers num="0.9.7a-2" edition=":i386_dev" />
        <vers num="0.9.7a-2" edition=":i386" />
        <vers num="0.9.7a-2" edition=":i386_perl" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1388" published="2009-07-05" name="CVE-2009-1388" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="4.9" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="3.9" CVSS_base_score="4.9">
    <desc>
      <descript source="cve">The ptrace_start function in kernel/ptrace.c in the Linux kernel 2.6.18 does not properly handle simultaneous execution of the do_coredump function, which allows local users to cause a denial of service (deadlock) via vectors involving the ptrace system call and a coredumping thread.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=504263" source="CONFIRM" patch="1">https://bugzilla.redhat.com/show_bug.cgi?id=504263</ref>
      <ref url="https://bugzilla.redhat.com/attachment.cgi?id=346742" source="CONFIRM" patch="1">https://bugzilla.redhat.com/attachment.cgi?id=346742</ref>
      <ref url="https://bugzilla.redhat.com/attachment.cgi?id=346615" source="CONFIRM" patch="1">https://bugzilla.redhat.com/attachment.cgi?id=346615</ref>
      <ref url="http://marc.info/?l=oss-security&amp;m=124654277229434&amp;w=2" source="MLIST" patch="1">[oss-security] 20090702 CVE-2009-1388 kernel: do_coredump() vs ptrace_start() deadlock</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/3316" source="VUPEN">ADV-2009-3316</ref>
      <ref url="http://www.vmware.com/security/advisories/VMSA-2009-0016.html" source="CONFIRM">http://www.vmware.com/security/advisories/VMSA-2009-0016.html</ref>
      <ref url="http://www.securityfocus.com/bid/35559" source="BID">35559</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/507985/100/0/threaded" source="BUGTRAQ">20091120 VMSA-2009-0016 VMware vCenter and ESX update release and vMA patch release address multiple security issue in third party components</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-1193.html" source="REDHAT">RHSA-2009:1193</ref>
      <ref url="http://secunia.com/advisories/37471" source="SECUNIA">37471</ref>
      <ref url="http://secunia.com/advisories/36131" source="SECUNIA">36131</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:8680" source="OVAL">oval:org.mitre.oval:def:8680</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:8625" source="OVAL">oval:org.mitre.oval:def:8625</ref>
      <ref url="http://osvdb.org/55679" source="OSVDB">55679</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="kernel">
        <vers num="2.6.18" edition="rc1" />
        <vers num="2.6.18" edition="rc2" />
        <vers num="2.6.18" edition="rc3" />
        <vers num="2.6.18" edition="rc4" />
        <vers num="2.6.18" edition="rc5" />
        <vers num="2.6.18" edition="rc6" />
        <vers num="2.6.18" edition="rc7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1389" published="2009-06-16" name="CVE-2009-1389" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Buffer overflow in the RTL8169 NIC driver (drivers/net/r8169.c) in the Linux kernel before 2.6.30 allows remote attackers to cause a denial of service (kernel memory corruption and crash) via a long packet.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-June/msg01193.html" source="FEDORA">FEDORA-2009-6846</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-June/msg01094.html" source="FEDORA">FEDORA-2009-6768</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-June/msg01048.html" source="FEDORA">FEDORA-2009-6883</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=504726" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=504726</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/51051" source="XF">linux-kernel-rtl8169nic-dos(51051)</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1857" source="VUPEN">ADV-2010-1857</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0219" source="VUPEN">ADV-2010-0219</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/3316" source="VUPEN">ADV-2009-3316</ref>
      <ref url="http://www.vmware.com/security/advisories/VMSA-2009-0016.html" source="CONFIRM">http://www.vmware.com/security/advisories/VMSA-2009-0016.html</ref>
      <ref url="http://www.ubuntu.com/usn/usn-807-1" source="UBUNTU">USN-807-1</ref>
      <ref url="http://www.securitytracker.com/id?1023507" source="SECTRACK">1023507</ref>
      <ref url="http://www.securityfocus.com/bid/35281" source="BID">35281</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/507985/100/0/threaded" source="BUGTRAQ">20091120 VMSA-2009-0016 VMware vCenter and ESX update release and vMA patch release address multiple security issue in third party components</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/505254/100/0/threaded" source="BUGTRAQ">20090724 rPSA-2009-0111-1 kernel</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-1193.html" source="REDHAT">RHSA-2009:1193</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-1157.html" source="REDHAT">RHSA-2009:1157</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2009/06/10/1" source="MLIST">[oss-security] 20090610 CVE-2009-1389 kernel: r8169: fix crash when large packets are received</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:148" source="MANDRIVA">MDVSA-2009:148</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1865" source="DEBIAN">DSA-1865</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1844" source="DEBIAN">DSA-1844</ref>
      <ref url="http://wiki.rpath.com/Advisories:rPSA-2009-0111" source="CONFIRM">http://wiki.rpath.com/Advisories:rPSA-2009-0111</ref>
      <ref url="http://support.citrix.com/article/CTX123453" source="CONFIRM">http://support.citrix.com/article/CTX123453</ref>
      <ref url="http://support.avaya.com/css/P8/documents/100067254" source="CONFIRM">http://support.avaya.com/css/P8/documents/100067254</ref>
      <ref url="http://secunia.com/advisories/40645" source="SECUNIA">40645</ref>
      <ref url="http://secunia.com/advisories/37471" source="SECUNIA">37471</ref>
      <ref url="http://secunia.com/advisories/37298" source="SECUNIA">37298</ref>
      <ref url="http://secunia.com/advisories/36327" source="SECUNIA">36327</ref>
      <ref url="http://secunia.com/advisories/36131" source="SECUNIA">36131</ref>
      <ref url="http://secunia.com/advisories/36051" source="SECUNIA">36051</ref>
      <ref url="http://secunia.com/advisories/36045" source="SECUNIA">36045</ref>
      <ref url="http://secunia.com/advisories/35847" source="SECUNIA">35847</ref>
      <ref url="http://secunia.com/advisories/35566" source="SECUNIA">35566</ref>
      <ref url="http://secunia.com/advisories/35265" source="SECUNIA" adv="1">35265</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:8108" source="OVAL">oval:org.mitre.oval:def:8108</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10415" source="OVAL">oval:org.mitre.oval:def:10415</ref>
      <ref url="http://marc.info/?l=linux-netdev&amp;m=123462461713724&amp;w=2" source="MLIST">[linux-netdev] 20090214 r8169: instant crash if receiving packet larger than MTU</ref>
      <ref url="http://lkml.org/lkml/2009/6/8/194" source="MLIST">[linux-kernel] 20090608 [Security, resend] Instant crash with rtl8169 and large packets</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-07/msg00006.html" source="SUSE">SUSE-SA:2010:031</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-07/msg00004.html" source="SUSE">SUSE-SA:2009:038</ref>
      <ref url="http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commitdiff;h=fdd7b4c3302c93f6833e338903ea77245eb510b4" source="CONFIRM">http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commitdiff;h=fdd7b4c3302c93f6833e338903ea77245eb510b4</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="kernel">
        <vers num="2.6.24.7" />
        <vers num="2.6.25.15" />
      </prod>
      <prod vendor="linux" name="kernel">
        <vers num="2.6" />
        <vers num="2.6.0" />
        <vers num="2.6.1" />
        <vers num="2.6.10" />
        <vers num="2.6.11" />
        <vers num="2.6.11.1" />
        <vers num="2.6.11.10" />
        <vers num="2.6.11.11" />
        <vers num="2.6.11.12" />
        <vers num="2.6.11.2" />
        <vers num="2.6.11.3" />
        <vers num="2.6.11.4" />
        <vers num="2.6.11.5" />
        <vers num="2.6.11.6" />
        <vers num="2.6.11.7" />
        <vers num="2.6.11.8" />
        <vers num="2.6.11.9" />
        <vers num="2.6.12" />
        <vers num="2.6.12.1" />
        <vers num="2.6.12.2" />
        <vers num="2.6.12.3" />
        <vers num="2.6.12.4" />
        <vers num="2.6.12.5" />
        <vers num="2.6.12.6" />
        <vers num="2.6.13" />
        <vers num="2.6.13.1" />
        <vers num="2.6.13.2" />
        <vers num="2.6.13.3" />
        <vers num="2.6.13.4" />
        <vers num="2.6.13.5" />
        <vers num="2.6.14" />
        <vers num="2.6.14.1" />
        <vers num="2.6.14.2" />
        <vers num="2.6.14.3" />
        <vers num="2.6.14.4" />
        <vers num="2.6.14.5" />
        <vers num="2.6.14.6" />
        <vers num="2.6.14.7" />
        <vers num="2.6.15" />
        <vers num="2.6.15.1" />
        <vers num="2.6.15.3" />
        <vers num="2.6.15.4" />
        <vers num="2.6.15.5" />
        <vers num="2.6.15.6" />
        <vers num="2.6.15.7" />
        <vers num="2.6.16" />
        <vers num="2.6.16.10" />
        <vers num="2.6.16.11" />
        <vers num="2.6.16.12" />
        <vers num="2.6.16.13" />
        <vers num="2.6.16.14" />
        <vers num="2.6.16.15" />
        <vers num="2.6.16.16" />
        <vers num="2.6.16.17" />
        <vers num="2.6.16.19" />
        <vers num="2.6.16.2" />
        <vers num="2.6.16.20" />
        <vers num="2.6.16.21" />
        <vers num="2.6.16.22" />
        <vers num="2.6.16.23" />
        <vers num="2.6.16.24" />
        <vers num="2.6.16.25" />
        <vers num="2.6.16.26" />
        <vers num="2.6.16.27" />
        <vers num="2.6.16.28" />
        <vers num="2.6.16.29" />
        <vers num="2.6.16.3" />
        <vers num="2.6.16.31" />
        <vers num="2.6.16.32" />
        <vers num="2.6.16.33" />
        <vers num="2.6.16.34" />
        <vers num="2.6.16.36" />
        <vers num="2.6.16.38" />
        <vers num="2.6.16.39" />
        <vers num="2.6.16.4" />
        <vers num="2.6.16.40" />
        <vers num="2.6.16.42" />
        <vers num="2.6.16.44" />
        <vers num="2.6.16.45" />
        <vers num="2.6.16.46" />
        <vers num="2.6.16.47" />
        <vers num="2.6.16.49" />
        <vers num="2.6.16.50" />
        <vers num="2.6.16.51" />
        <vers num="2.6.16.53" />
        <vers num="2.6.16.54" />
        <vers num="2.6.16.55" />
        <vers num="2.6.16.56" />
        <vers num="2.6.16.57" />
        <vers num="2.6.16.58" />
        <vers num="2.6.16.59" />
        <vers num="2.6.16.6" />
        <vers num="2.6.16.60" />
        <vers num="2.6.16.61" />
        <vers num="2.6.16.62" />
        <vers num="2.6.16.7" />
        <vers num="2.6.16.8" />
        <vers num="2.6.16.9" />
        <vers num="2.6.17" />
        <vers num="2.6.17.1" />
        <vers num="2.6.17.10" />
        <vers num="2.6.17.11" />
        <vers num="2.6.17.12" />
        <vers num="2.6.17.13" />
        <vers num="2.6.17.14" />
        <vers num="2.6.17.2" />
        <vers num="2.6.17.3" />
        <vers num="2.6.17.4" />
        <vers num="2.6.17.5" />
        <vers num="2.6.17.6" />
        <vers num="2.6.17.7" />
        <vers num="2.6.17.8" />
        <vers num="2.6.17.9" />
        <vers num="2.6.18" edition="rc1" />
        <vers num="2.6.18" edition="rc2" />
        <vers num="2.6.18" edition="rc3" />
        <vers num="2.6.18" edition="rc4" />
        <vers num="2.6.18" edition="rc5" />
        <vers num="2.6.18" edition="rc6" />
        <vers num="2.6.18" edition="rc7" />
        <vers num="2.6.18.1" />
        <vers num="2.6.18.2" />
        <vers num="2.6.18.3" />
        <vers num="2.6.18.4" />
        <vers num="2.6.18.5" />
        <vers num="2.6.18.6" />
        <vers num="2.6.18.7" />
        <vers num="2.6.18.8" />
        <vers num="2.6.19" />
        <vers num="2.6.19.1" />
        <vers num="2.6.19.2" />
        <vers num="2.6.19.3" />
        <vers num="2.6.19.4" />
        <vers num="2.6.19.5" />
        <vers num="2.6.19.6" />
        <vers num="2.6.19.7" />
        <vers num="2.6.2" />
        <vers num="2.6.2.27.13" />
        <vers num="2.6.20" />
        <vers num="2.6.20.1" />
        <vers num="2.6.20.10" />
        <vers num="2.6.20.11" />
        <vers num="2.6.20.12" />
        <vers num="2.6.20.13" />
        <vers num="2.6.20.14" />
        <vers num="2.6.20.15" />
        <vers num="2.6.20.16" />
        <vers num="2.6.20.17" />
        <vers num="2.6.20.18" />
        <vers num="2.6.20.19" />
        <vers num="2.6.20.2" />
        <vers num="2.6.20.20" />
        <vers num="2.6.20.21" />
        <vers num="2.6.20.3" />
        <vers num="2.6.20.4" />
        <vers num="2.6.20.5" />
        <vers num="2.6.20.6" />
        <vers num="2.6.20.7" />
        <vers num="2.6.20.8" />
        <vers num="2.6.20.9" />
        <vers num="2.6.21" />
        <vers num="2.6.21.1" />
        <vers num="2.6.21.2" />
        <vers num="2.6.21.3" />
        <vers num="2.6.21.4" />
        <vers num="2.6.21.5" />
        <vers num="2.6.21.6" />
        <vers num="2.6.21.7" />
        <vers num="2.6.22" />
        <vers num="2.6.22.1" />
        <vers num="2.6.22.10" />
        <vers num="2.6.22.11" />
        <vers num="2.6.22.12" />
        <vers num="2.6.22.13" />
        <vers num="2.6.22.14" />
        <vers num="2.6.22.15" />
        <vers num="2.6.22.16" />
        <vers num="2.6.22.17" />
        <vers num="2.6.22.18" />
        <vers num="2.6.22.19" />
        <vers num="2.6.22.2" />
        <vers num="2.6.22.20" />
        <vers num="2.6.22.21" />
        <vers num="2.6.22.22" />
        <vers num="2.6.22.3" />
        <vers num="2.6.22.4" />
        <vers num="2.6.27" edition="rc1" />
        <vers num="2.6.27" edition="rc2" />
        <vers num="2.6.27" edition="rc3" />
        <vers num="2.6.27" edition="rc4" />
        <vers num="2.6.27" edition="rc5" />
        <vers num="2.6.27" edition="rc6" />
        <vers num="2.6.27" edition="rc7" />
        <vers num="2.6.27" edition="rc8" />
        <vers num="2.6.27" edition="rc9" />
        <vers num="2.6.27.2" />
        <vers num="2.6.27.20" />
        <vers num="2.6.27.21" />
        <vers num="2.6.27.22" />
        <vers num="2.6.27.23" />
        <vers num="2.6.27.24" />
        <vers num="2.6.27.3" />
        <vers num="2.6.27.4" />
        <vers num="2.6.27.5" />
        <vers num="2.6.27.6" />
        <vers num="2.6.27.7" />
        <vers num="2.6.27.8" />
        <vers num="2.6.27.9" />
        <vers num="2.6.28" edition="git7" />
        <vers num="2.6.28" edition="rc1" />
        <vers num="2.6.28" edition="rc2" />
        <vers num="2.6.28" edition="rc3" />
        <vers num="2.6.28" edition="rc4" />
        <vers num="2.6.28" edition="rc5" />
        <vers num="2.6.28" edition="rc6" />
        <vers num="2.6.28" edition="rc7" />
        <vers num="2.6.28.1" />
        <vers num="2.6.28.10" />
        <vers num="2.6.28.2" />
        <vers num="2.6.28.3" />
        <vers num="2.6.28.4" />
        <vers num="2.6.28.5" />
        <vers num="2.6.28.6" />
        <vers num="2.6.28.7" />
        <vers num="2.6.28.8" />
        <vers num="2.6.28.9" />
        <vers num="2.6.29" edition="git1" />
        <vers num="2.6.29" edition="rc1" />
        <vers num="2.6.29" edition="rc2" />
        <vers num="2.6.29" edition="rc2_git7" />
        <vers num="2.6.29" edition="rc8-kk" />
        <vers num="2.6.29.3" />
        <vers num="2.6.29.rc1" />
        <vers num="2.6.29.rc2" />
        <vers num="2.6.29.rc2-git1" />
        <vers num="2.6.3" />
        <vers num="2.6.30" edition="rc3" />
        <vers num="2.6.4" />
        <vers num="2.6.5" />
        <vers num="2.6.6" />
        <vers num="2.6.7" />
        <vers num="2.6.8" />
        <vers num="2.6.8.1" />
        <vers num="2.6.9" />
      </prod>
      <prod vendor="linux" name="linux_kernel">
        <vers num="2.2.6" />
        <vers num="2.6.0" edition="" />
        <vers num="2.6.0" edition=":itanium_ia64_montecito" />
        <vers num="2.6.0" edition=":64-bit_x86" />
        <vers num="2.6.0" edition="test1" />
        <vers num="2.6.0" edition="test10" />
        <vers num="2.6.0" edition="test11" />
        <vers num="2.6.0" edition="test2" />
        <vers num="2.6.0" edition="test3" />
        <vers num="2.6.0" edition="test4" />
        <vers num="2.6.0" edition="test5" />
        <vers num="2.6.0" edition="test6" />
        <vers num="2.6.0" edition="test7" />
        <vers num="2.6.0" edition="test8" />
        <vers num="2.6.0" edition="test9" />
        <vers num="2.6.1" edition="rc1" />
        <vers num="2.6.1" edition="rc2" />
        <vers num="2.6.1" edition="rc3" />
        <vers num="2.6.10" edition="rc1" />
        <vers num="2.6.10" edition="rc2" />
        <vers num="2.6.10" edition="rc3" />
        <vers num="2.6.11" edition="" />
        <vers num="2.6.11" edition=":x86_64" />
        <vers num="2.6.11" edition="rc1" />
        <vers num="2.6.11" edition="rc2" />
        <vers num="2.6.11" edition="rc3" />
        <vers num="2.6.11" edition="rc4" />
        <vers num="2.6.11" edition="rc5" />
        <vers num="2.6.11.1" />
        <vers num="2.6.11.10" />
        <vers num="2.6.11.11" />
        <vers num="2.6.11.12" />
        <vers num="2.6.11.2" />
        <vers num="2.6.11.3" />
        <vers num="2.6.11.4" />
        <vers num="2.6.11.5" />
        <vers num="2.6.11.6" />
        <vers num="2.6.11.7" />
        <vers num="2.6.11.8" />
        <vers num="2.6.11.9" />
        <vers num="2.6.11_rc1_bk6" />
        <vers num="2.6.12" edition="rc1" />
        <vers num="2.6.12" edition="rc2" />
        <vers num="2.6.12" edition="rc3" />
        <vers num="2.6.12" edition="rc4" />
        <vers num="2.6.12" edition="rc5" />
        <vers num="2.6.12" edition="rc6" />
        <vers num="2.6.12.1" />
        <vers num="2.6.12.12" />
        <vers num="2.6.12.2" />
        <vers num="2.6.12.22" />
        <vers num="2.6.12.3" />
        <vers num="2.6.12.4" />
        <vers num="2.6.12.5" />
        <vers num="2.6.12.6" />
        <vers num="2.6.13" edition="rc1" />
        <vers num="2.6.13" edition="rc2" />
        <vers num="2.6.13" edition="rc3" />
        <vers num="2.6.13" edition="rc4" />
        <vers num="2.6.13" edition="rc5" />
        <vers num="2.6.13" edition="rc6" />
        <vers num="2.6.13" edition="rc7" />
        <vers num="2.6.13.1" />
        <vers num="2.6.13.2" />
        <vers num="2.6.13.3" />
        <vers num="2.6.13.4" />
        <vers num="2.6.13.5" />
        <vers num="2.6.14" edition="rc1" />
        <vers num="2.6.14" edition="rc2" />
        <vers num="2.6.14" edition="rc3" />
        <vers num="2.6.14" edition="rc4" />
        <vers num="2.6.14" edition="rc5" />
        <vers num="2.6.14.1" />
        <vers num="2.6.14.2" />
        <vers num="2.6.14.3" />
        <vers num="2.6.14.4" />
        <vers num="2.6.14.5" />
        <vers num="2.6.14.6" />
        <vers num="2.6.14.7" />
        <vers num="2.6.15" edition="rc1" />
        <vers num="2.6.15" edition="rc2" />
        <vers num="2.6.15" edition="rc3" />
        <vers num="2.6.15" edition="rc4" />
        <vers num="2.6.15" edition="rc5" />
        <vers num="2.6.15" edition="rc6" />
        <vers num="2.6.15" edition="rc7" />
        <vers num="2.6.15.1" />
        <vers num="2.6.15.11" />
        <vers num="2.6.15.2" />
        <vers num="2.6.15.3" />
        <vers num="2.6.15.4" />
        <vers num="2.6.15.5" />
        <vers num="2.6.15.6" />
        <vers num="2.6.15.7" />
        <vers num="2.6.16" edition="rc1" />
        <vers num="2.6.16" edition="rc2" />
        <vers num="2.6.16" edition="rc3" />
        <vers num="2.6.16" edition="rc4" />
        <vers num="2.6.16" edition="rc5" />
        <vers num="2.6.16" edition="rc6" />
        <vers num="2.6.16.1" />
        <vers num="2.6.16.10" />
        <vers num="2.6.16.11" />
        <vers num="2.6.16.12" />
        <vers num="2.6.16.13" />
        <vers num="2.6.16.14" />
        <vers num="2.6.16.15" />
        <vers num="2.6.16.16" />
        <vers num="2.6.16.17" />
        <vers num="2.6.16.18" />
        <vers num="2.6.16.19" />
        <vers num="2.6.16.2" />
        <vers num="2.6.16.20" />
        <vers num="2.6.16.21" />
        <vers num="2.6.16.22" />
        <vers num="2.6.16.23" />
        <vers num="2.6.16.24" />
        <vers num="2.6.16.25" />
        <vers num="2.6.16.26" />
        <vers num="2.6.16.27" />
        <vers num="2.6.16.28" />
        <vers num="2.6.16.29" />
        <vers num="2.6.16.3" />
        <vers num="2.6.16.30" />
        <vers num="2.6.16.31" />
        <vers num="2.6.16.32" />
        <vers num="2.6.16.33" />
        <vers num="2.6.16.34" />
        <vers num="2.6.16.35" />
        <vers num="2.6.16.36" />
        <vers num="2.6.16.37" />
        <vers num="2.6.16.38" />
        <vers num="2.6.16.39" />
        <vers num="2.6.16.4" />
        <vers num="2.6.16.40" />
        <vers num="2.6.16.41" />
        <vers num="2.6.16.43" />
        <vers num="2.6.16.44" />
        <vers num="2.6.16.45" />
        <vers num="2.6.16.46" />
        <vers num="2.6.16.47" />
        <vers num="2.6.16.48" />
        <vers num="2.6.16.49" />
        <vers num="2.6.16.5" />
        <vers num="2.6.16.50" />
        <vers num="2.6.16.51" />
        <vers num="2.6.16.52" />
        <vers num="2.6.16.53" />
        <vers num="2.6.16.6" />
        <vers num="2.6.16.7" />
        <vers num="2.6.16.8" />
        <vers num="2.6.16.9" />
        <vers num="2.6.16_rc7" />
        <vers num="2.6.17" edition="rc1" />
        <vers num="2.6.17" edition="rc2" />
        <vers num="2.6.17" edition="rc3" />
        <vers num="2.6.17" edition="rc4" />
        <vers num="2.6.17" edition="rc5" />
        <vers num="2.6.17" edition="rc6" />
        <vers num="2.6.17.1" />
        <vers num="2.6.17.10" />
        <vers num="2.6.17.11" />
        <vers num="2.6.17.12" />
        <vers num="2.6.17.13" />
        <vers num="2.6.17.14" />
        <vers num="2.6.17.2" />
        <vers num="2.6.17.3" />
        <vers num="2.6.17.4" />
        <vers num="2.6.17.5" />
        <vers num="2.6.17.6" />
        <vers num="2.6.17.7" />
        <vers num="2.6.17.8" />
        <vers num="2.6.17.9" />
        <vers num="2.6.18" edition="" />
        <vers num="2.6.18" edition=":x86_32" />
        <vers num="2.6.18" edition="rc1" />
        <vers num="2.6.18" edition="rc2" />
        <vers num="2.6.18" edition="rc3" />
        <vers num="2.6.18" edition="rc4" />
        <vers num="2.6.18" edition="rc5" />
        <vers num="2.6.18" edition="rc6" />
        <vers num="2.6.18" edition="rc7" />
        <vers num="2.6.18.0" />
        <vers num="2.6.18.1" />
        <vers num="2.6.18.2" />
        <vers num="2.6.18.3" />
        <vers num="2.6.18.4" />
        <vers num="2.6.18.5" />
        <vers num="2.6.18.6" />
        <vers num="2.6.18.7" />
        <vers num="2.6.18.8" />
        <vers num="2.6.19" edition="rc1" />
        <vers num="2.6.19" edition="rc2" />
        <vers num="2.6.19" edition="rc3" />
        <vers num="2.6.19" edition="rc4" />
        <vers num="2.6.19.0" />
        <vers num="2.6.19.1" />
        <vers num="2.6.19.2" />
        <vers num="2.6.19.3" />
        <vers num="2.6.19.4" />
        <vers num="2.6.2" edition="rc1" />
        <vers num="2.6.2" edition="rc2" />
        <vers num="2.6.2" edition="rc3" />
        <vers num="2.6.20" edition="rc2" />
        <vers num="2.6.20.1" />
        <vers num="2.6.20.10" />
        <vers num="2.6.20.11" />
        <vers num="2.6.20.12" />
        <vers num="2.6.20.13" />
        <vers num="2.6.20.14" />
        <vers num="2.6.20.15" />
        <vers num="2.6.20.2" />
        <vers num="2.6.20.3" />
        <vers num="2.6.20.4" />
        <vers num="2.6.20.5" />
        <vers num="2.6.20.6" />
        <vers num="2.6.20.7" />
        <vers num="2.6.20.8" />
        <vers num="2.6.20.9" />
        <vers num="2.6.21" edition="git1" />
        <vers num="2.6.21" edition="git2" />
        <vers num="2.6.21" edition="git3" />
        <vers num="2.6.21" edition="git4" />
        <vers num="2.6.21" edition="git5" />
        <vers num="2.6.21" edition="git6" />
        <vers num="2.6.21" edition="git7" />
        <vers num="2.6.21" edition="rc3" />
        <vers num="2.6.21" edition="rc4" />
        <vers num="2.6.21" edition="rc5" />
        <vers num="2.6.21" edition="rc6" />
        <vers num="2.6.21" edition="rc7" />
        <vers num="2.6.21.1" />
        <vers num="2.6.21.2" />
        <vers num="2.6.21.3" />
        <vers num="2.6.21.4" />
        <vers num="2.6.22" edition="rc6" />
        <vers num="2.6.22.1" />
        <vers num="2.6.22.16" />
        <vers num="2.6.22.3" />
        <vers num="2.6.22.4" />
        <vers num="2.6.22.5" />
        <vers num="2.6.22.6" edition="" />
        <vers num="2.6.22.6" edition=":x86_64" />
        <vers num="2.6.22.7" />
        <vers num="2.6.23" edition="rc1" />
        <vers num="2.6.23" edition="rc2" />
        <vers num="2.6.23.1" />
        <vers num="2.6.23.14" />
        <vers num="2.6.23.2" />
        <vers num="2.6.23.3" />
        <vers num="2.6.23.4" />
        <vers num="2.6.23.5" />
        <vers num="2.6.23.6" />
        <vers num="2.6.23.7" />
        <vers num="2.6.23.9" />
        <vers num="2.6.24" edition="rc2" />
        <vers num="2.6.24" edition="rc3" />
        <vers num="2.6.3" edition="rc1" />
        <vers num="2.6.3" edition="rc2" />
        <vers num="2.6.3" edition="rc3" />
        <vers num="2.6.3" edition="rc4" />
        <vers num="2.6.30" edition="rc4" />
        <vers num="2.6.30" edition="rc4:x86_32" />
        <vers num="2.6.4" edition="rc1" />
        <vers num="2.6.4" edition="rc2" />
        <vers num="2.6.4" edition="rc3" />
        <vers num="2.6.5" edition="rc1" />
        <vers num="2.6.5" edition="rc2" />
        <vers num="2.6.5" edition="rc3" />
        <vers num="2.6.6" edition="rc1" />
        <vers num="2.6.6" edition="rc2" />
        <vers num="2.6.6" edition="rc3" />
        <vers num="2.6.7" edition="rc1" />
        <vers num="2.6.7" edition="rc2" />
        <vers num="2.6.7" edition="rc3" />
        <vers num="2.6.8" edition="rc1" />
        <vers num="2.6.8" edition="rc2" />
        <vers num="2.6.8" edition="rc3" />
        <vers num="2.6.8" edition="rc4" />
        <vers num="2.6.8.1" />
        <vers num="2.6.8.1.5" edition="" />
        <vers num="2.6.8.1.5" edition=":686" />
        <vers num="2.6.8.1.5" edition=":k7" />
        <vers num="2.6.8.1.5" edition=":amd64_k8" />
        <vers num="2.6.8.1.5" edition=":power3_smp" />
        <vers num="2.6.8.1.5" edition=":686_smp" />
        <vers num="2.6.8.1.5" edition=":k7_smp" />
        <vers num="2.6.8.1.5" edition=":386" />
        <vers num="2.6.8.1.5" edition=":power4_smp" />
        <vers num="2.6.8.1.5" edition=":powerpc" />
        <vers num="2.6.8.1.5" edition=":power3" />
        <vers num="2.6.8.1.5" edition=":power4" />
        <vers num="2.6.8.1.5" edition=":amd64" />
        <vers num="2.6.8.1.5" edition=":amd64_k8_smp" />
        <vers num="2.6.8.1.5" edition=":amd64_xeon" />
        <vers num="2.6.8.1.5" edition=":powerpc_smp" />
        <vers num="2.6.9" edition="2.6.20" />
        <vers num="2.6.9" edition="final" />
        <vers num="2.6.9" edition="rc1" />
        <vers num="2.6.9" edition="rc2" />
        <vers num="2.6.9" edition="rc3" />
        <vers num="2.6.9" edition="rc4" />
        <vers num="2.6_test9_cvs" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1390" published="2009-06-16" name="CVE-2009-1390" modified="2009-06-19" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Mutt 1.5.19, when linked against (1) OpenSSL (mutt_ssl.c) or (2) GnuTLS (mutt_ssl_gnutls.c), allows connections when only one TLS certificate in the chain is accepted instead of verifying the entire chain, which allows remote attackers to spoof trusted servers via a man-in-the-middle attack.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/51068" source="XF" patch="1">mutt-x509-security-bypass(51068)</ref>
      <ref url="http://www.securityfocus.com/bid/35288" source="BID" patch="1">35288</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2009/06/10/2" source="MLIST" patch="1">[oss-security] 20090610 Mutt 1.5.19 SSL chain verification flaw</ref>
      <ref url="http://dev.mutt.org/hg/mutt/rev/64bf199c8d8a" source="CONFIRM" patch="1">http://dev.mutt.org/hg/mutt/rev/64bf199c8d8a</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-June/msg00715.html" source="FEDORA">FEDORA-2009-6465</ref>
      <ref url="http://dev.mutt.org/hg/mutt/rev/8f11dd00c770" source="CONFIRM">http://dev.mutt.org/hg/mutt/rev/8f11dd00c770</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mutt" name="mutt">
        <vers num="1.5.19" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1391" published="2009-06-16" name="CVE-2009-1391" modified="2009-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Off-by-one error in the inflate function in Zlib.xs in Compress::Raw::Zlib Perl module before 2.017, as used in AMaViS, SpamAssassin, and possibly other products, allows context-dependent attackers to cause a denial of service (hang or crash) via a crafted zlib compressed stream that triggers a heap-based buffer overflow, as exploited in the wild by Trojan.Downloader-71014 in June 2009.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/51062" source="XF" patch="1">perl-compressrawzlib-inflate-bo(51062)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1571" source="VUPEN" patch="1" adv="1">ADV-2009-1571</ref>
      <ref url="http://www.securityfocus.com/bid/35307" source="BID" patch="1">35307</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-July/msg00607.html" source="FEDORA">FEDORA-2009-7680</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=504386" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=504386</ref>
      <ref url="https://bugs.gentoo.org/show_bug.cgi?id=273141" source="CONFIRM">https://bugs.gentoo.org/show_bug.cgi?id=273141</ref>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-794-1" source="UBUNTU">USN-794-1</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:157" source="MANDRIVA">MDVSA-2009:157</ref>
      <ref url="http://thread.gmane.org/gmane.mail.virus.amavis.user/33635" source="MISC">http://thread.gmane.org/gmane.mail.virus.amavis.user/33635</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200908-07.xml" source="GENTOO">GLSA-200908-07</ref>
      <ref url="http://secunia.com/advisories/35876" source="SECUNIA">35876</ref>
      <ref url="http://secunia.com/advisories/35689" source="SECUNIA">35689</ref>
      <ref url="http://secunia.com/advisories/35685" source="SECUNIA">35685</ref>
      <ref url="http://secunia.com/advisories/35422" source="SECUNIA" adv="1">35422</ref>
      <ref url="http://osvdb.org/55041" source="OSVDB">55041</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-07/msg00002.html" source="SUSE">SUSE-SR:2009:012</ref>
      <ref url="http://article.gmane.org/gmane.mail.virus.amavis.user/33638" source="MISC">http://article.gmane.org/gmane.mail.virus.amavis.user/33638</ref>
      <ref url="http://article.gmane.org/gmane.mail.virus.amavis.user/33635" source="MISC">http://article.gmane.org/gmane.mail.virus.amavis.user/33635</ref>
    </refs>
    <vuln_soft>
      <prod vendor="paul_marquess" name="compress-raw-zlib_perl_module">
        <vers num="2.001" />
        <vers num="2.002" />
        <vers num="2.003" />
        <vers num="2.004" />
        <vers num="2.005" />
        <vers num="2.006" />
        <vers num="2.008" />
        <vers num="2.009" />
        <vers num="2.010" />
        <vers num="2.011" />
        <vers num="2.012" />
        <vers num="2.014" />
        <vers prev="1" num="2.015" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1392" published="2009-06-12" name="CVE-2009-1392" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">The browser engine in Mozilla Firefox 3 before 3.0.11, Thunderbird before 2.0.0.22, and SeaMonkey before 1.1.17 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to (1) nsEventStateManager::GetContentState and nsNativeTheme::CheckBooleanAttr; (2) UnhookTextRunFromFrames and ClearAllTextRunReferences; (3) nsTextFrame::ClearTextRun; (4) IsPercentageAware; (5) PL_DHashTableFinish; (6) nsListBoxBodyFrame::GetNextItemBox; (7) AtomTableClearEntry, related to the atom table, DOM mutation events, and Unicode surrogates; (8) nsHTMLEditor::HideResizers; and (9) nsWindow::SetCursor, related to changing the cursor; and other vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="https://rhn.redhat.com/errata/RHSA-2009-1095.html" source="REDHAT" patch="1" adv="1">RHSA-2009:1095</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1572" source="VUPEN" patch="1" adv="1">ADV-2009-1572</ref>
      <ref url="http://securitytracker.com/id?1022376" source="SECTRACK" patch="1">1022376</ref>
      <ref url="http://rhn.redhat.com/errata/RHSA-2009-1096.html" source="REDHAT" patch="1" adv="1">RHSA-2009:1096</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-June/msg00657.html" source="FEDORA">FEDORA-2009-6411</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-June/msg00574.html" source="FEDORA">FEDORA-2009-6366</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=503568" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=503568</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=490513" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=490513</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=490425" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=490425</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=490410" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=490410</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=489041" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=489041</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=486398" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=486398</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=472776" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=472776</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=451341" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=451341</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=432068" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=432068</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=431086" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=431086</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=429969" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=429969</ref>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=380359" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=380359</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/2152" source="VUPEN">ADV-2009-2152</ref>
      <ref url="http://www.ubuntu.com/usn/usn-782-1" source="UBUNTU">USN-782-1</ref>
      <ref url="http://www.slackware.com/security/viewer.php?l=slackware-security&amp;y=2009&amp;m=slackware-security.454275" source="SLACKWARE">SSA:2009-178-01</ref>
      <ref url="http://www.securitytracker.com/id?1022397" source="SECTRACK">1022397</ref>
      <ref url="http://www.securityfocus.com/bid/35370" source="BID">35370</ref>
      <ref url="http://www.securityfocus.com/bid/35326" source="BID">35326</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-1126.html" source="REDHAT">RHSA-2009:1126</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-1125.html" source="REDHAT">RHSA-2009:1125</ref>
      <ref url="http://www.mozilla.org/security/announce/2009/mfsa2009-24.html" source="CONFIRM" adv="1">http://www.mozilla.org/security/announce/2009/mfsa2009-24.html</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:141" source="MANDRIVA">MDVSA-2009:141</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1830" source="DEBIAN">DSA-1830</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1820" source="DEBIAN">DSA-1820</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-77-1020800.1-1" source="SUNALERT">1020800</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-265068-1" source="SUNALERT">265068</ref>
      <ref url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2009&amp;m=slackware-security.425408" source="SLACKWARE">SSA:2009-176-01</ref>
      <ref url="http://slackware.com/security/viewer.php?l=slackware-security&amp;y=2009&amp;m=slackware-security.372468" source="SLACKWARE">SSA:2009-167-01</ref>
      <ref url="http://secunia.com/advisories/35602" source="SECUNIA">35602</ref>
      <ref url="http://secunia.com/advisories/35561" source="SECUNIA">35561</ref>
      <ref url="http://secunia.com/advisories/35536" source="SECUNIA">35536</ref>
      <ref url="http://secunia.com/advisories/35468" source="SECUNIA">35468</ref>
      <ref url="http://secunia.com/advisories/35440" source="SECUNIA" adv="1">35440</ref>
      <ref url="http://secunia.com/advisories/35439" source="SECUNIA" adv="1">35439</ref>
      <ref url="http://secunia.com/advisories/35431" source="SECUNIA" adv="1">35431</ref>
      <ref url="http://secunia.com/advisories/35428" source="SECUNIA" adv="1">35428</ref>
      <ref url="http://secunia.com/advisories/35415" source="SECUNIA">35415</ref>
      <ref url="http://secunia.com/advisories/35331" source="SECUNIA" adv="1">35331</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9501" source="OVAL">oval:org.mitre.oval:def:9501</ref>
      <ref url="http://osvdb.org/55147" source="OSVDB">55147</ref>
      <ref url="http://osvdb.org/55146" source="OSVDB">55146</ref>
      <ref url="http://osvdb.org/55145" source="OSVDB">55145</ref>
      <ref url="http://osvdb.org/55144" source="OSVDB">55144</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="3.0" edition="alpha" />
        <vers num="3.0" edition="beta2" />
        <vers num="3.0.1" />
        <vers num="3.0.10" />
        <vers num="3.0.2" />
        <vers num="3.0.3" />
        <vers num="3.0.4" />
        <vers num="3.0.5" />
        <vers num="3.0.6" />
        <vers num="3.0.7" />
        <vers num="3.0.8" />
        <vers num="3.0.9" />
      </prod>
      <prod vendor="mozilla" name="seamonkey">
        <vers num="1.0" edition="" />
        <vers num="1.0" edition=":dev" />
        <vers num="1.0" edition=":alpha" />
        <vers num="1.0" edition=":beta" />
        <vers num="1.0" edition="alpha" />
        <vers num="1.0" edition="beta" />
        <vers num="1.0.1" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.6" />
        <vers num="1.0.8" />
        <vers num="1.0.9" />
        <vers num="1.0.99" />
        <vers num="1.1" edition="" />
        <vers num="1.1" edition=":alpha" />
        <vers num="1.1" edition=":beta" />
        <vers num="1.1" edition="alpha" />
        <vers num="1.1" edition="beta" />
        <vers num="1.1.1" />
        <vers num="1.1.10" />
        <vers num="1.1.11" />
        <vers num="1.1.12" />
        <vers num="1.1.13" />
        <vers num="1.1.15" />
        <vers prev="1" num="1.1.16" />
        <vers num="1.1.3" />
        <vers num="1.1.5" edition="1.1.10" />
        <vers num="1.1.6" />
        <vers num="1.1.7" />
        <vers num="1.1.8" />
        <vers num="1.1.9" />
      </prod>
      <prod vendor="mozilla" name="thunderbird">
        <vers num="0.1" />
        <vers num="0.2" />
        <vers num="0.3" />
        <vers num="0.4" />
        <vers num="0.5" />
        <vers num="0.6" />
        <vers num="0.7" />
        <vers num="0.7.1" />
        <vers num="0.7.2" />
        <vers num="0.7.3" />
        <vers num="0.8" />
        <vers num="0.9" />
        <vers num="1.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.5" edition="beta" />
        <vers num="1.0.6" />
        <vers num="1.0.7" />
        <vers num="1.0.8" />
        <vers num="1.5" edition="beta2" />
        <vers num="1.5.0.1" />
        <vers num="1.5.0.10" />
        <vers num="1.5.0.11" />
        <vers num="1.5.0.12" />
        <vers num="1.5.0.13" />
        <vers num="1.5.0.14" />
        <vers num="1.5.0.2" />
        <vers num="1.5.0.3" />
        <vers num="1.5.0.4" />
        <vers num="1.5.0.5" />
        <vers num="1.5.0.6" />
        <vers num="1.5.0.7" />
        <vers num="1.5.0.8" />
        <vers num="1.5.0.9" />
        <vers num="1.5.1" />
        <vers num="1.5.2" />
        <vers num="1.7.1" />
        <vers num="1.7.3" />
        <vers num="2.0.0.0" />
        <vers num="2.0.0.1" />
        <vers num="2.0.0.11" />
        <vers num="2.0.0.12" />
        <vers num="2.0.0.13" />
        <vers num="2.0.0.14" />
        <vers num="2.0.0.15" />
        <vers num="2.0.0.16" />
        <vers num="2.0.0.17" />
        <vers num="2.0.0.18" />
        <vers prev="1" num="2.0.0.19" />
        <vers num="2.0.0.2" />
        <vers num="2.0.0.3" />
        <vers num="2.0.0.4" />
        <vers num="2.0.0.5" />
        <vers num="2.0.0.6" />
        <vers num="2.0.0.7" />
        <vers num="2.0.0.8" />
        <vers num="2.0.0.9" />
        <vers num="2.0.14" />
        <vers num="2.0_.12" />
        <vers num="2.0_.13" />
        <vers num="2.0_.14" />
        <vers num="2.0_.4" />
        <vers num="2.0_.5" />
        <vers num="2.0_.6" />
        <vers num="2.0_.9" />
        <vers num="2.0_8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1394" published="2009-06-26" name="CVE-2009-1394" modified="2009-06-30" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Stack-based buffer overflow in Motorola Timbuktu Pro 8.6.5 on Windows allows remote attackers to execute arbitrary code by sending a long malformed string over the PlughNTCommand named pipe.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securitytracker.com/id?1022455" source="SECTRACK">1022455</ref>
      <ref url="http://www.securityfocus.com/bid/35496" source="BID">35496</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/504554/100/0/threaded" source="BUGTRAQ">20090625 iDefense Security Advisory 06.25.09: Motorola Timbuktu Pro PlughNTCommand Stack Based Buffer Overflow Vulnerability</ref>
      <ref url="http://www.netopia.com/software/products/tb2/" source="MISC" adv="1">http://www.netopia.com/software/products/tb2/</ref>
      <ref url="http://secunia.com/advisories/35533" source="SECUNIA">35533</ref>
      <ref url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=809" source="IDEFENSE">20090625 Motorola Timbuktu Pro PlughNTCommand Stack Based Buffer Overflow Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="motorola" name="timbuktu_pro">
        <vers num="8.6.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1403" published="2009-04-24" name="CVE-2009-1403" modified="2009-04-24" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in product_info.php in CRE Loaded 6.2 allows remote attackers to execute arbitrary SQL commands via the products_id parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/49987" source="XF">creloaded-productinfo-sql-injection(49987)</ref>
      <ref url="http://www.securityfocus.com/bid/34640" source="BID">34640</ref>
      <ref url="http://www.milw0rm.com/exploits/8501" source="MILW0RM">8501</ref>
    </refs>
    <vuln_soft>
      <prod vendor="creloaded" name="cre_loaded">
        <vers num="6.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1404" published="2009-04-24" name="CVE-2009-1404" modified="2009-04-24" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">SQL injection vulnerability in admin.php in PastelCMS 0.8.0, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the user (Username) parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/49985" source="XF">pastelcms-admin-sql-injection(49985)</ref>
      <ref url="http://www.securityfocus.com/bid/34635" source="BID">34635</ref>
      <ref url="http://www.milw0rm.com/exploits/8502" source="MILW0RM">8502</ref>
      <ref url="http://secunia.com/advisories/34853" source="SECUNIA" adv="1">34853</ref>
    </refs>
    <vuln_soft>
      <prod vendor="pastel" name="pastelcms">
        <vers num="0.8.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1405" published="2009-04-24" name="CVE-2009-1405" modified="2009-04-24" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Directory traversal vulnerability in index.php in PastelCMS 0.8.0, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the set_lng parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/49986" source="XF">pastelcms-setlng-file-include(49986)</ref>
      <ref url="http://www.securityfocus.com/bid/34635" source="BID">34635</ref>
      <ref url="http://www.milw0rm.com/exploits/8502" source="MILW0RM">8502</ref>
      <ref url="http://secunia.com/advisories/34853" source="SECUNIA" adv="1">34853</ref>
    </refs>
    <vuln_soft>
      <prod vendor="pastel" name="pastelcms">
        <vers num="0.8.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1406" published="2009-04-24" name="CVE-2009-1406" modified="2009-06-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Directory traversal vulnerability in cms_detect.php in TotalCalendar 2.4 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the include parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/49980" source="XF">totalcalendar-cmsdetect-file-include(49980)</ref>
      <ref url="http://www.securityfocus.com/bid/34634" source="BID">34634</ref>
      <ref url="http://www.milw0rm.com/exploits/8503" source="MILW0RM">8503</ref>
      <ref url="http://secunia.com/advisories/34824" source="SECUNIA" adv="1">34824</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sweetphp" name="totalcalendar">
        <vers num="2.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1407" published="2009-04-24" name="CVE-2009-1407" modified="2009-04-24" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Directory traversal vulnerability in config.php in NotFTP 1.3.1 allows remote attackers to read arbitrary files via a .. (dot dot) in a certain languages[][file] parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/49988" source="XF">notftp-config-file-include(49988)</ref>
      <ref url="http://www.securityfocus.com/bid/34636" source="BID">34636</ref>
      <ref url="http://www.milw0rm.com/exploits/8504" source="MILW0RM">8504</ref>
    </refs>
    <vuln_soft>
      <prod vendor="wonko" name="notftp">
        <vers num="1.3.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1408" published="2009-04-24" name="CVE-2009-1408" modified="2009-04-24" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in webSPELL 4.2.0c allows remote attackers to inject arbitrary web script or HTML allows remote attackers to inject arbitrary web script or HTML via Javascript events such as onmouseover in nested BBcode tags, as demonstrated using (1) email, (2) img, and (3) url tags.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.webspell.org/index.php?site=news_comments&amp;newsID=126&amp;lang=uk" source="CONFIRM" patch="1" adv="1">http://www.webspell.org/index.php?site=news_comments&amp;newsID=126&amp;lang=uk</ref>
      <ref url="http://www.webspell.org/index.php?site=files&amp;file=25" source="CONFIRM" patch="1" adv="1">http://www.webspell.org/index.php?site=files&amp;file=25</ref>
      <ref url="http://www.securityfocus.com/bid/34595" source="BID" patch="1">34595</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/49937" source="XF" adv="1">webspell-bbcode-xss(49937)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/502732/100/0/threaded" source="BUGTRAQ">20090416 webSPELL 4.2.0c XSS (BYPASS BBCODE) COOKIES STEALING VULNERABILITY</ref>
      <ref url="http://www.milw0rm.com/exploits/8453" source="MILW0RM">8453</ref>
      <ref url="http://secunia.com/advisories/34764" source="SECUNIA" adv="1">34764</ref>
      <ref url="http://osvdb.org/53782" source="OSVDB">53782</ref>
    </refs>
    <vuln_soft>
      <prod vendor="webspell" name="webspell">
        <vers num="4.2.0c" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1409" published="2009-04-24" name="CVE-2009-1409" modified="2009-04-24" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_score="5.1" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="4.9" CVSS_base_score="5.1">
    <desc>
      <descript source="cve">SQL injection vulnerability in usersettings.php in e107 0.7.15 and earlier, when "Extended User Fields" is enabled and magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the hide parameter, a different vector than CVE-2005-4224 and CVE-2008-5320.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/49981" source="XF">e107-hide-sql-injection(49981)</ref>
      <ref url="http://www.securityfocus.com/bid/34614" source="BID">34614</ref>
      <ref url="http://www.milw0rm.com/exploits/8495" source="MILW0RM">8495</ref>
      <ref url="http://secunia.com/advisories/34823" source="SECUNIA" adv="1">34823</ref>
      <ref url="http://osvdb.org/53812" source="OSVDB">53812</ref>
    </refs>
    <vuln_soft>
      <prod vendor="e107" name="e107">
        <vers num="0.545" />
        <vers num="0.547_beta" />
        <vers num="0.548_beta" />
        <vers num="0.549_beta" />
        <vers num="0.551_beta" />
        <vers num="0.552_beta" />
        <vers num="0.553_beta" />
        <vers num="0.554" />
        <vers num="0.554_beta" />
        <vers num="0.555_beta" />
        <vers num="0.600" />
        <vers num="0.601" />
        <vers num="0.602" />
        <vers num="0.603" />
        <vers num="0.604" />
        <vers num="0.605" />
        <vers num="0.606" />
        <vers num="0.607" />
        <vers num="0.608" />
        <vers num="0.609" />
        <vers num="0.610" />
        <vers num="0.611" />
        <vers num="0.612" />
        <vers num="0.613" />
        <vers num="0.614" />
        <vers num="0.615" />
        <vers num="0.615a" />
        <vers num="0.616" />
        <vers num="0.617" />
        <vers num="0.6171" />
        <vers num="0.6172" />
        <vers num="0.6173" />
        <vers num="0.6174" />
        <vers num="0.6175" />
        <vers num="0.6_10" />
        <vers num="0.6_11" />
        <vers num="0.6_12" />
        <vers num="0.6_13" />
        <vers num="0.6_14" />
        <vers num="0.6_15" />
        <vers num="0.6_15a" />
        <vers num="0.7" />
        <vers num="0.7.1" />
        <vers num="0.7.10" />
        <vers num="0.7.11" />
        <vers num="0.7.13" />
        <vers num="0.7.2" />
        <vers num="0.7.3" />
        <vers num="0.7.4" />
        <vers num="0.7.5" />
        <vers num="0.7.6" />
        <vers num="0.7.7" />
        <vers num="0.7.8" />
        <vers num="0.7.9" />
        <vers num="1.0.1" />
        <vers num="5.04" />
        <vers num="5.05" />
        <vers num="5.1" />
        <vers num="5.2" />
        <vers num="5.21" />
        <vers num="5.3_beta" />
        <vers num="5.3_beta2" />
        <vers num="5.4_beta1" />
        <vers num="5.4_beta3" />
        <vers num="5.4_beta4" />
        <vers num="5.4_beta5" />
        <vers num="5.4_beta6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1410" published="2009-04-24" name="CVE-2009-1410" modified="2009-04-24" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in index.php in Quick.Cms.Lite 0.5 allows remote attackers to execute arbitrary SQL commands via the id parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/49989" source="XF">quickcmslite-index-sql-injection(49989)</ref>
      <ref url="http://www.securityfocus.com/bid/34647" source="BID">34647</ref>
      <ref url="http://www.milw0rm.com/exploits/8505" source="MILW0RM">8505</ref>
    </refs>
    <vuln_soft>
      <prod vendor="opensolution" name="quick.cms.lite">
        <vers num="0.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1411" published="2009-04-24" name="CVE-2009-1411" modified="2009-04-27" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in events/inc/events.inc.php in the Events plugin for Seditio CMS 1.0 allows remote attackers to execute arbitrary SQL commands via the c parameter to plug.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/49975" source="XF">seditio-events-eventsinc-sql-injection(49975)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1112" source="VUPEN" adv="1">ADV-2009-1112</ref>
      <ref url="http://www.securityfocus.com/bid/34608" source="BID">34608</ref>
      <ref url="http://www.milw0rm.com/exploits/8482" source="MILW0RM">8482</ref>
      <ref url="http://secunia.com/advisories/34812" source="SECUNIA" adv="1">34812</ref>
      <ref url="http://osvdb.org/53827" source="OSVDB">53827</ref>
    </refs>
    <vuln_soft>
      <prod vendor="neocrome" name="seditio">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1412" published="2009-04-24" name="CVE-2009-1412" modified="2009-05-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:N/A:N)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Argument injection vulnerability in the chromehtml: protocol handler in Google Chrome before 1.0.154.59, when invoked by Internet Explorer, allows remote attackers to determine the existence of files, and open tabs for URLs that do not satisfy the IsWebSafeScheme restriction, via a web page that sets document.location to a chromehtml: value, as demonstrated by use of a (1) javascript: or (2) data: URL.  NOTE: this can be leveraged for Universal XSS by exploiting certain behavior involving persistence across page transitions.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/50449" source="XF">googlechrome-chromehtml-command-execution(50449)</ref>
      <ref url="http://googlechromereleases.blogspot.com/2009/04/stable-update-security-fix.html" source="CONFIRM">http://googlechromereleases.blogspot.com/2009/04/stable-update-security-fix.html</ref>
      <ref url="http://code.google.com/p/chromium/issues/detail?id=9860" source="CONFIRM">http://code.google.com/p/chromium/issues/detail?id=9860</ref>
      <ref url="http://chromium.googlecode.com/issues/attachment?aid=5579180911289877192&amp;name=Google+Chrome+Advisory.doc" source="MISC" adv="1">http://chromium.googlecode.com/issues/attachment?aid=5579180911289877192&amp;name=Google+Chrome+Advisory.doc</ref>
    </refs>
    <vuln_soft>
      <prod vendor="google" name="chrome">
        <vers num="0.2.149.29" />
        <vers num="0.2.149.30" />
        <vers num="0.2.152.1" />
        <vers num="0.2.153.1" />
        <vers num="0.3.154.0" />
        <vers num="0.3.154.3" />
        <vers num="0.4.154.18" />
        <vers num="0.4.154.22" />
        <vers num="0.4.154.31" />
        <vers num="0.4.154.33" />
        <vers num="1.0.154.36" />
        <vers num="1.0.154.39" />
        <vers num="1.0.154.42" />
        <vers num="1.0.154.43" />
        <vers num="1.0.154.46" />
        <vers prev="1" num="1.0.154.53" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1413" published="2009-04-24" name="CVE-2009-1413" modified="2009-05-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Google Chrome 1.0.x does not cancel timeouts upon a page transition, which makes it easier for attackers to conduct Universal XSS attacks by calling setTimeout to trigger future execution of JavaScript code, and then modifying document.location to arrange for JavaScript execution in the context of an arbitrary web site.  NOTE: this can be leveraged for a remote attack by exploiting a chromehtml: argument-injection vulnerability.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/50447" source="XF">googlechrome-settimeout-xss(50447)</ref>
      <ref url="http://code.google.com/p/chromium/issues/detail?id=9860" source="CONFIRM">http://code.google.com/p/chromium/issues/detail?id=9860</ref>
      <ref url="http://chromium.googlecode.com/issues/attachment?aid=5579180911289877192&amp;name=Google+Chrome+Advisory.doc" source="MISC" adv="1">http://chromium.googlecode.com/issues/attachment?aid=5579180911289877192&amp;name=Google+Chrome+Advisory.doc</ref>
    </refs>
    <vuln_soft>
      <prod vendor="google" name="chrome">
        <vers num="1.0.154.36" />
        <vers num="1.0.154.39" />
        <vers num="1.0.154.42" />
        <vers num="1.0.154.43" />
        <vers num="1.0.154.46" />
        <vers num="1.0.154.53" />
        <vers num="1.0.154.59" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1414" published="2009-04-24" name="CVE-2009-1414" modified="2009-05-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Google Chrome 2.0.x lets modifications to the global object persist across a page transition, which makes it easier for attackers to conduct Universal XSS attacks via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/50446" source="XF">googlechrome-globalobject-xss(50446)</ref>
      <ref url="http://code.google.com/p/chromium/issues/detail?id=9860" source="CONFIRM" adv="1">http://code.google.com/p/chromium/issues/detail?id=9860</ref>
    </refs>
    <vuln_soft>
      <prod vendor="google" name="chrome">
        <vers num="2.0.156.1" />
        <vers num="2.0.157.0" />
        <vers num="2.0.157.2" />
        <vers num="2.0.158.0" />
        <vers num="2.0.159.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1415" published="2009-04-30" name="CVE-2009-1415" modified="2009-06-10" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">lib/pk-libgcrypt.c in libgnutls in GnuTLS before 2.6.6 does not properly handle invalid DSA signatures, which allows remote attackers to cause a denial of service (application crash) and possibly have unspecified other impact via a malformed DSA key that triggers a (1) free of an uninitialized pointer or (2) double free.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://article.gmane.org/gmane.comp.encryption.gpg.gnutls.devel/3515" source="MLIST" patch="1">[gnutls-devel] 20090430 Double free and free of invalid pointer on certain errors [GNUTLS-SA-2009-1] [CVE-2009-1415]</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/50445" source="XF">gnutls-libgnutls-dos(50445)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/50260" source="XF">gnutls-dsa-dos(50260)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/50257" source="XF">gnutls-dsa-code-execution(50257)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1218" source="VUPEN">ADV-2009-1218</ref>
      <ref url="http://www.securitytracker.com/id?1022157" source="SECTRACK">1022157</ref>
      <ref url="http://www.securityfocus.com/bid/34783" source="BID">34783</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:116" source="MANDRIVA">MDVSA-2009:116</ref>
      <ref url="http://thread.gmane.org/gmane.comp.encryption.gpg.gnutls.devel/3488" source="CONFIRM">http://thread.gmane.org/gmane.comp.encryption.gpg.gnutls.devel/3488</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200905-04.xml" source="GENTOO">GLSA-200905-04</ref>
      <ref url="http://secunia.com/advisories/35211" source="SECUNIA">35211</ref>
      <ref url="http://secunia.com/advisories/34842" source="SECUNIA" adv="1">34842</ref>
      <ref url="http://permalink.gmane.org/gmane.comp.encryption.gpg.gnutls.devel/3502" source="MLIST">[gnutls-devel] 20090423 Re: some crashes on using DSA keys</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gnu" name="gnutls">
        <vers num="1.0.16" />
        <vers num="1.0.17" />
        <vers num="1.0.18" />
        <vers num="1.0.19" />
        <vers num="1.0.20" />
        <vers num="1.0.21" />
        <vers num="1.0.22" />
        <vers num="1.0.23" />
        <vers num="1.0.24" />
        <vers num="1.0.25" />
        <vers num="1.1.13" />
        <vers num="1.1.14" />
        <vers num="1.1.15" />
        <vers num="1.1.16" />
        <vers num="1.1.17" />
        <vers num="1.1.18" />
        <vers num="1.1.19" />
        <vers num="1.1.20" />
        <vers num="1.1.21" />
        <vers num="1.1.22" />
        <vers num="1.1.23" />
        <vers num="1.2.0" />
        <vers num="1.2.1" />
        <vers num="1.2.10" />
        <vers num="1.2.11" />
        <vers num="1.2.2" />
        <vers num="1.2.3" />
        <vers num="1.2.4" />
        <vers num="1.2.5" />
        <vers num="1.2.6" />
        <vers num="1.2.7" />
        <vers num="1.2.8" />
        <vers num="1.2.8.1a1" />
        <vers num="1.2.9" />
        <vers num="1.3.0" />
        <vers num="1.3.1" />
        <vers num="1.3.2" />
        <vers num="1.3.3" />
        <vers num="1.3.4" />
        <vers num="1.3.5" />
        <vers num="1.4.0" />
        <vers num="1.4.1" />
        <vers num="1.4.2" />
        <vers num="1.4.3" />
        <vers num="1.4.4" />
        <vers num="1.4.5" />
        <vers num="1.5.0" />
        <vers num="1.5.1" />
        <vers num="1.5.2" />
        <vers num="1.5.3" />
        <vers num="1.5.4" />
        <vers num="1.5.5" />
        <vers num="1.6.0" />
        <vers num="1.6.1" />
        <vers num="1.6.2" />
        <vers num="1.6.3" />
        <vers num="1.7.0" />
        <vers num="1.7.1" />
        <vers num="1.7.10" />
        <vers num="1.7.11" />
        <vers num="1.7.12" />
        <vers num="1.7.13" />
        <vers num="1.7.14" />
        <vers num="1.7.15" />
        <vers num="1.7.16" />
        <vers num="1.7.17" />
        <vers num="1.7.18" />
        <vers num="1.7.19" />
        <vers num="1.7.2" />
        <vers num="1.7.3" />
        <vers num="1.7.4" />
        <vers num="1.7.5" />
        <vers num="1.7.6" />
        <vers num="1.7.7" />
        <vers num="1.7.8" />
        <vers num="1.7.9" />
        <vers num="2.0.0" />
        <vers num="2.0.1" />
        <vers num="2.0.2" />
        <vers num="2.0.3" />
        <vers num="2.0.4" />
        <vers num="2.1.0" />
        <vers num="2.1.1" />
        <vers num="2.1.2" />
        <vers num="2.1.3" />
        <vers num="2.1.4" />
        <vers num="2.1.5" />
        <vers num="2.1.6" />
        <vers num="2.1.7" />
        <vers num="2.1.8" />
        <vers num="2.2.0" />
        <vers num="2.2.1" />
        <vers num="2.2.2" />
        <vers num="2.2.3" />
        <vers num="2.2.4" />
        <vers num="2.2.5" />
        <vers num="2.3.0" />
        <vers num="2.3.1" />
        <vers num="2.3.10" />
        <vers num="2.3.11" />
        <vers num="2.3.2" />
        <vers num="2.3.3" />
        <vers num="2.3.4" />
        <vers num="2.3.5" />
        <vers num="2.3.6" />
        <vers num="2.3.7" />
        <vers num="2.3.8" />
        <vers num="2.3.9" />
        <vers num="2.4.0" />
        <vers num="2.4.1" />
        <vers num="2.4.2" />
        <vers num="2.6.0" />
        <vers num="2.6.1" />
        <vers num="2.6.2" />
        <vers num="2.6.3" />
        <vers num="2.6.4" />
        <vers prev="1" num="2.6.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1416" published="2009-04-30" name="CVE-2009-1416" modified="2009-06-10" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">lib/gnutls_pk.c in libgnutls in GnuTLS 2.5.0 through 2.6.5 generates RSA keys stored in DSA structures, instead of the intended DSA keys, which might allow remote attackers to spoof signatures on certificates or have unspecified other impact by leveraging an invalid DSA key.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://article.gmane.org/gmane.comp.encryption.gpg.gnutls.devel/3516" source="MLIST" patch="1">[gnutls-devel] 20090430 All DSA keys generated using GnuTLS 2.6.x are corrupt [GNUTLS-SA-2009-2] [CVE-2009-1416]</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1218" source="VUPEN">ADV-2009-1218</ref>
      <ref url="http://www.securitytracker.com/id?1022158" source="SECTRACK">1022158</ref>
      <ref url="http://www.securityfocus.com/bid/34783" source="BID">34783</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:116" source="MANDRIVA">MDVSA-2009:116</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200905-04.xml" source="GENTOO">GLSA-200905-04</ref>
      <ref url="http://secunia.com/advisories/35211" source="SECUNIA">35211</ref>
      <ref url="http://secunia.com/advisories/34842" source="SECUNIA" adv="1">34842</ref>
      <ref url="http://lists.gnu.org/archive/html/help-gnutls/2009-04/msg00018.html" source="MLIST" adv="1">[help-gnutls] 20090420 Encryption using DSA keys</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gnu" name="gnutls">
        <vers num="2.5.0" />
        <vers num="2.6.0" />
        <vers num="2.6.1" />
        <vers num="2.6.2" />
        <vers num="2.6.3" />
        <vers num="2.6.4" />
        <vers num="2.6.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1417" published="2009-04-30" name="CVE-2009-1417" modified="2009-06-10" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">gnutls-cli in GnuTLS before 2.6.6 does not verify the activation and expiration times of X.509 certificates, which allows remote attackers to successfully present a certificate that is (1) not yet valid or (2) no longer valid, related to lack of time checks in the _gnutls_x509_verify_certificate function in lib/x509/verify.c in libgnutls_x509, as used by (a) Exim, (b) OpenLDAP, and (c) libsoup.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://article.gmane.org/gmane.comp.encryption.gpg.gnutls.devel/3517" source="MLIST" patch="1">[gnutls-devel] 20090430 Certificate expiration not checked by gnutls-cli [GNUTLS-SA-2009-3] [CVE-2009-1417]</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/50261" source="XF">gnutls-gnutlscli-spoofing(50261)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1218" source="VUPEN">ADV-2009-1218</ref>
      <ref url="http://www.securitytracker.com/id?1022159" source="SECTRACK">1022159</ref>
      <ref url="http://www.securityfocus.com/bid/34783" source="BID">34783</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:116" source="MANDRIVA">MDVSA-2009:116</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200905-04.xml" source="GENTOO">GLSA-200905-04</ref>
      <ref url="http://secunia.com/advisories/35211" source="SECUNIA">35211</ref>
      <ref url="http://secunia.com/advisories/34842" source="SECUNIA" adv="1">34842</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gnu" name="gnutls">
        <vers num="1.0.16" />
        <vers num="1.0.17" />
        <vers num="1.0.18" />
        <vers num="1.0.19" />
        <vers num="1.0.20" />
        <vers num="1.0.21" />
        <vers num="1.0.22" />
        <vers num="1.0.23" />
        <vers num="1.0.24" />
        <vers num="1.0.25" />
        <vers num="1.1.13" />
        <vers num="1.1.14" />
        <vers num="1.1.15" />
        <vers num="1.1.16" />
        <vers num="1.1.17" />
        <vers num="1.1.18" />
        <vers num="1.1.19" />
        <vers num="1.1.20" />
        <vers num="1.1.21" />
        <vers num="1.1.22" />
        <vers num="1.1.23" />
        <vers num="1.2.0" />
        <vers num="1.2.1" />
        <vers num="1.2.10" />
        <vers num="1.2.11" />
        <vers num="1.2.2" />
        <vers num="1.2.3" />
        <vers num="1.2.4" />
        <vers num="1.2.5" />
        <vers num="1.2.6" />
        <vers num="1.2.7" />
        <vers num="1.2.8" />
        <vers num="1.2.8.1a1" />
        <vers num="1.2.9" />
        <vers num="1.3.0" />
        <vers num="1.3.1" />
        <vers num="1.3.2" />
        <vers num="1.3.3" />
        <vers num="1.3.4" />
        <vers num="1.3.5" />
        <vers num="1.4.0" />
        <vers num="1.4.1" />
        <vers num="1.4.2" />
        <vers num="1.4.3" />
        <vers num="1.4.4" />
        <vers num="1.4.5" />
        <vers num="1.5.0" />
        <vers num="1.5.1" />
        <vers num="1.5.2" />
        <vers num="1.5.3" />
        <vers num="1.5.4" />
        <vers num="1.5.5" />
        <vers num="1.6.0" />
        <vers num="1.6.1" />
        <vers num="1.6.2" />
        <vers num="1.6.3" />
        <vers num="1.7.0" />
        <vers num="1.7.1" />
        <vers num="1.7.10" />
        <vers num="1.7.11" />
        <vers num="1.7.12" />
        <vers num="1.7.13" />
        <vers num="1.7.14" />
        <vers num="1.7.15" />
        <vers num="1.7.16" />
        <vers num="1.7.17" />
        <vers num="1.7.18" />
        <vers num="1.7.19" />
        <vers num="1.7.2" />
        <vers num="1.7.3" />
        <vers num="1.7.4" />
        <vers num="1.7.5" />
        <vers num="1.7.6" />
        <vers num="1.7.7" />
        <vers num="1.7.8" />
        <vers num="1.7.9" />
        <vers num="2.0.0" />
        <vers num="2.0.1" />
        <vers num="2.0.2" />
        <vers num="2.0.3" />
        <vers num="2.0.4" />
        <vers num="2.1.0" />
        <vers num="2.1.1" />
        <vers num="2.1.2" />
        <vers num="2.1.3" />
        <vers num="2.1.4" />
        <vers num="2.1.5" />
        <vers num="2.1.6" />
        <vers num="2.1.7" />
        <vers num="2.1.8" />
        <vers num="2.2.0" />
        <vers num="2.2.1" />
        <vers num="2.2.2" />
        <vers num="2.2.3" />
        <vers num="2.2.4" />
        <vers num="2.2.5" />
        <vers num="2.3.0" />
        <vers num="2.3.1" />
        <vers num="2.3.10" />
        <vers num="2.3.11" />
        <vers num="2.3.2" />
        <vers num="2.3.3" />
        <vers num="2.3.4" />
        <vers num="2.3.5" />
        <vers num="2.3.6" />
        <vers num="2.3.7" />
        <vers num="2.3.8" />
        <vers num="2.3.9" />
        <vers num="2.4.0" />
        <vers num="2.4.1" />
        <vers num="2.4.2" />
        <vers num="2.6.0" />
        <vers num="2.6.1" />
        <vers num="2.6.2" />
        <vers num="2.6.3" />
        <vers num="2.6.4" />
        <vers prev="1" num="2.6.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1418" published="2009-05-19" name="CVE-2009-1418" modified="2009-06-09" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in HP System Management Homepage (SMH) before 3.0.1.73 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.</descript>
      <descript source="nvd">Per: http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01745065


"SUPPORTED SOFTWARE VERSIONS*: ONLY impacted versions are listed.

HP System Management Homepage (SMH) before v3.0.1.73 running on Linux and Windows Server 2003, 2008."</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://securitytracker.com/id?1022242" source="SECTRACK" patch="1">1022242</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01745065" source="HP" patch="1" adv="1">HPSBMA02428</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01745065" source="HP" patch="1" adv="1">HPSBMA02428</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/50633" source="XF">smh-win-unspecified-xss(50633)</ref>
      <ref url="http://www.securityfocus.com/bid/35031" source="BID">35031</ref>
      <ref url="http://secunia.com/advisories/35108" source="SECUNIA">35108</ref>
      <ref url="http://jvndb.jvn.jp/en/contents/2009/JVNDB-2009-000029.html" source="JVNDB">JVNDB-2009-000029</ref>
      <ref url="http://jvn.jp/en/jp/JVN02331156/index.html" source="JVN">JVN#02331156</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="system_management_homepage">
        <vers num="2.0.0" />
        <vers num="2.0.1" />
        <vers num="2.0.2" />
        <vers num="2.1" />
        <vers num="2.1.0-103" />
        <vers num="2.1.0-103(a)" />
        <vers num="2.1.0-109" />
        <vers num="2.1.0-118" />
        <vers num="2.1.1" />
        <vers num="2.1.10" />
        <vers num="2.1.10-186" />
        <vers num="2.1.11" />
        <vers num="2.1.11-197" />
        <vers num="2.1.12-118" />
        <vers num="2.1.12-200" />
        <vers num="2.1.15-210" />
        <vers num="2.1.2" />
        <vers num="2.1.2-127" />
        <vers num="2.1.3" />
        <vers num="2.1.3.132" />
        <vers num="2.1.4" />
        <vers num="2.1.4-143" />
        <vers num="2.1.5" />
        <vers num="2.1.5-146" />
        <vers num="2.1.6" />
        <vers num="2.1.6-156" />
        <vers num="2.1.7" />
        <vers num="2.1.7-168" />
        <vers num="2.1.8" />
        <vers num="2.1.8-177" />
        <vers num="2.1.9" />
        <vers num="2.1.9-178" />
        <vers num="2.2.6" />
        <vers num="2.2.8" />
        <vers prev="1" num="3.0.0-68" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1419" published="2009-06-07" name="CVE-2009-1419" modified="2009-06-23" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:N)" CVSS_score="4.0" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="4.9" CVSS_base_score="4.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in HP Discovery &amp; Dependency Mapping Inventory (DDMI) 2.0.0 through 2.52, 7.50, and 7.51 on Windows allows remote attackers to access DDMI agents via unknown vectors.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.info/?l=bugtraq&amp;m=124423677616704&amp;w=2" source="HP" patch="1" adv="1">SSRT090084</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=124423677616704&amp;w=2" source="HP" patch="1" adv="1">SSRT090084</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1514" source="VUPEN" adv="1">ADV-2009-1514</ref>
      <ref url="http://www.securitytracker.com/id?1022339" source="SECTRACK">1022339</ref>
      <ref url="http://www.securityfocus.com/bid/35250" source="BID">35250</ref>
      <ref url="http://secunia.com/advisories/35270" source="SECUNIA" adv="1">35270</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="discovery&amp;dependency_mapping_inventory">
        <vers num="2.0.0" />
        <vers num="2.0.1" />
        <vers num="2.0.2" />
        <vers num="2.0.3" />
        <vers num="2.0.4" />
        <vers num="2.1.0" />
        <vers num="2.1.1" />
        <vers num="2.1.2" />
        <vers num="2.1.3" />
        <vers num="2.20" />
        <vers num="2.21" />
        <vers num="2.22" />
        <vers num="2.50" />
        <vers num="2.51" />
        <vers num="2.52" />
        <vers num="7.50" />
        <vers num="7.51" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1420" published="2009-06-11" name="CVE-2009-1420" modified="2009-07-11" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Stack-based buffer overflow in rping in HP OpenView Network Node Manager (OV NNM) 7.51 and 7.53, when used with SNMP (aka HPOvNNM.HPOVSNMP) before 1.30.009 and MIB (aka HPOvNNM.HPOVMIB) before 1.30.009, allows remote attackers to execute arbitrary code or cause a denial of service via unknown vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/35267" source="BID" patch="1">35267</ref>
      <ref url="http://securitytracker.com/id?1022360" source="SECTRACK" patch="1">1022360</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=124457320614552&amp;w=2" source="HP" patch="1">SSRT080094</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=124457320614552&amp;w=2" source="HP" patch="1">SSRT080094</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1549" source="VUPEN">ADV-2009-1549</ref>
      <ref url="http://secunia.com/advisories/35408" source="SECUNIA" adv="1">35408</ref>
      <ref url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=810" source="IDEFENSE">20090626 HP Network Node Manager rping Stack Buffer Overflow Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="openview_network_node_manager">
        <vers num="7.51" edition="-" />
        <vers num="7.51" edition="-:solaris" />
        <vers num="7.51" edition="-:hp-ux" />
        <vers num="7.51" edition="-:linux" />
        <vers num="7.51" edition="-:windows" />
        <vers num="7.53" edition="-" />
        <vers num="7.53" edition="-:solaris" />
        <vers num="7.53" edition="-:windows" />
        <vers num="7.53" edition="-:linux" />
        <vers num="7.53" edition="-:hp-ux" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1421" published="2009-07-02" name="CVE-2009-1421" modified="2009-07-07" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="4.9" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="3.9" CVSS_base_score="4.9">
    <desc>
      <descript source="cve">Unspecified vulnerability in NFS / ONCplus B.11.31_06 and B.11.31_07 on HP HP-UX B.11.31 allows local users to cause a denial of service via unknown attack vectors.</descript>
    </desc>
    <impacts>
      <impact source="nvd">Per: http://www.vupen.com/english/advisories/2009/1755

"Affected Products

HP-UX B.11.31 running NFS / ONCplus version B.11.31_07 and B.11.31_06 "</impact>
    </impacts>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2009/1755" source="VUPEN" adv="1">ADV-2009-1755</ref>
      <ref url="http://www.securityfocus.com/bid/35547" source="BID">35547</ref>
      <ref url="http://securitytracker.com/id?1022493" source="SECTRACK">1022493</ref>
      <ref url="http://secunia.com/advisories/35644" source="SECUNIA" adv="1">35644</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=124654506100944&amp;w=2" source="HP">SSRT090106</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=124654506100944&amp;w=2" source="HP">SSRT090106</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="oncplus">
        <vers num="b.11.31_06" />
        <vers num="b.11.31_07" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1422" published="2009-07-14" name="CVE-2009-1422" modified="2009-07-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in HP ProCurve Threat Management Services zl Module (J9155A) ST.1.0.090213 and earlier allows remote attackers to gain privileges via unknown vectors, aka PR_41209.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.info/?l=bugtraq&amp;m=124751363528317&amp;w=2" source="HP" patch="1">SSRT090111</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=124751363528317&amp;w=2" source="HP" patch="1">SSRT090111</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1869" source="VUPEN">ADV-2009-1869</ref>
      <ref url="http://www.securitytracker.com/id?1022536" source="SECTRACK">1022536</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="procurve_threat_management_services_zl_module">
        <vers prev="1" num="st.1.0.090213" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1423" published="2009-07-14" name="CVE-2009-1423" modified="2009-07-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Unspecified vulnerability in HP ProCurve Threat Management Services zl Module (J9155A) ST.1.0.090213 and earlier allows remote attackers to cause a denial of service via unknown vectors, aka PR_39898, a different vulnerability than CVE-2009-1424 and CVE-2009-1425.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.info/?l=bugtraq&amp;m=124751363528317&amp;w=2" source="HP" patch="1">SSRT090111</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=124751363528317&amp;w=2" source="HP" patch="1">SSRT090111</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/51689" source="XF">procurve-vpn-dos(51689)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1869" source="VUPEN">ADV-2009-1869</ref>
      <ref url="http://www.securitytracker.com/id?1022536" source="SECTRACK">1022536</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="procurve_threat_management_services_zl_module">
        <vers prev="1" num="st.1.0.090213" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1424" published="2009-07-14" name="CVE-2009-1424" modified="2009-07-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Unspecified vulnerability in HP ProCurve Threat Management Services zl Module (J9155A) ST.1.0.090213 and earlier allows remote attackers to cause a denial of service via unknown vectors, aka PR_39412, a different vulnerability than CVE-2009-1423 and CVE-2009-1425.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.info/?l=bugtraq&amp;m=124751363528317&amp;w=2" source="HP" patch="1">SSRT090111</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=124751363528317&amp;w=2" source="HP" patch="1">SSRT090111</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1869" source="VUPEN">ADV-2009-1869</ref>
      <ref url="http://www.securitytracker.com/id?1022536" source="SECTRACK">1022536</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="procurve_threat_management_services_zl_module">
        <vers prev="1" num="st.1.0.090213" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1425" published="2009-07-14" name="CVE-2009-1425" modified="2009-07-22" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Unspecified vulnerability in HP ProCurve Threat Management Services zl Module (J9155A) ST.1.0.090213 and earlier allows remote attackers to cause a denial of service by triggering a stop or crash in httpd, aka PR_18770, a different vulnerability than CVE-2009-1423 and CVE-2009-1424.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2009/1869" source="VUPEN" patch="1" adv="1">ADV-2009-1869</ref>
      <ref url="http://www.securityfocus.com/bid/35653" source="BID" patch="1">35653</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=124751363528317&amp;w=2" source="HP" patch="1">SSRT090111</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=124751363528317&amp;w=2" source="HP" patch="1">SSRT090111</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/51691" source="XF">procurve-httpd-dos(51691)</ref>
      <ref url="http://www.securitytracker.com/id?1022536" source="SECTRACK">1022536</ref>
      <ref url="http://cdn.procurve.com/training/Manuals/TMSzlModule-RelNotes-90603-59900224.pdf" source="CONFIRM" adv="1">http://cdn.procurve.com/training/Manuals/TMSzlModule-RelNotes-90603-59900224.pdf</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="procurve_threat_management_services_zl_module">
        <vers prev="1" num="st.1.0.090213" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1426" published="2009-07-29" name="CVE-2009-1426" modified="2009-08-11" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Unspecified vulnerability on HP ProLiant DL and ML 100 Series G5, G5p, and G6 servers with ProLiant Onboard Administrator Powered by LO100i (formerly Lights Out 100) 3.07 and earlier allows remote attackers to cause a denial of service via unknown vectors.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://marc.info/?l=bugtraq&amp;m=124881779623139&amp;w=2" source="HP" patch="1">SSRT090092</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=124881779623139&amp;w=2" source="HP" patch="1">SSRT090092</ref>
      <ref url="http://www.securitytracker.com/id?1022617" source="SECTRACK">1022617</ref>
      <ref url="http://secunia.com/advisories/35990" source="SECUNIA">35990</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="proliant_dl120">
        <vers num="-" edition="g5" />
      </prod>
      <prod vendor="hp" name="proliant_dl160">
        <vers num="-" edition="g5" />
        <vers num="-" edition="g5p" />
        <vers num="-" edition="g6" />
      </prod>
      <prod vendor="hp" name="proliant_dl165">
        <vers num="-" edition="g6" />
      </prod>
      <prod vendor="hp" name="proliant_dl180">
        <vers num="-" edition="g5" />
        <vers num="-" edition="g6" />
      </prod>
      <prod vendor="hp" name="proliant_dl185">
        <vers num="-" edition="g5" />
      </prod>
      <prod vendor="hp" name="proliant_ml110">
        <vers num="-" edition="g5" />
      </prod>
      <prod vendor="hp" name="proliant_ml115">
        <vers num="-" edition="g5" />
      </prod>
      <prod vendor="hp" name="proliant_ml150">
        <vers num="-" edition="g5" />
      </prod>
      <prod vendor="hp" name="proliant_onboard_administrator">
        <vers num="3.07" edition="" />
        <vers num="3.07" edition=":powered_by_lo100i" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1427" published="2009-08-12" name="CVE-2009-1427" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="4.9" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="3.9" CVSS_base_score="4.9">
    <desc>
      <descript source="cve">Unspecified vulnerability in HP-UX B.11.31 allows local users to cause a denial of service (system crash) via unknown vectors related to the ttrace system call.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2009/2230" source="VUPEN" patch="1" adv="1">ADV-2009-2230</ref>
      <ref url="http://www.securitytracker.com/id?1022706" source="SECTRACK" patch="1">1022706</ref>
      <ref url="http://www.securityfocus.com/bid/36017" source="BID">36017</ref>
      <ref url="http://secunia.com/advisories/36261" source="SECUNIA" adv="1">36261</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6215" source="OVAL">oval:org.mitre.oval:def:6215</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01832652" source="HP" adv="1">SSRT090141</ref>
      <ref url="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01832652" source="HP" adv="1">SSRT090141</ref>
    </refs>
    <vuln_soft>
      <prod vendor="hp" name="hpux">
        <vers num="b.11.31" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1428" published="2009-04-29" name="CVE-2009-1428" modified="2009-05-14" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in ccLgView.exe in the Symantec Log Viewer, as used in Symantec AntiVirus (SAV) before 10.1 MR8, Symantec Endpoint Protection (SEP) 11.0 before 11.0 MR1, Norton 360 1.0, and Norton Internet Security 2005 through 2008, allow remote attackers to inject arbitrary web script or HTML via a crafted e-mail message, related to "two parsing errors."</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.symantec.com/business/security_response/securityupdates/detail.jsp?fid=security_advisory&amp;pvid=security_advisory&amp;year=2009&amp;suid=20090428_01" source="CONFIRM" patch="1" adv="1">http://www.symantec.com/business/security_response/securityupdates/detail.jsp?fid=security_advisory&amp;pvid=security_advisory&amp;year=2009&amp;suid=20090428_01</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/50170" source="XF">multiple-symantec-log-xss(50170)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1203" source="VUPEN">ADV-2009-1203</ref>
      <ref url="http://www.securitytracker.com/id?1022135" source="SECTRACK">1022135</ref>
      <ref url="http://www.securitytracker.com/id?1022134" source="SECTRACK">1022134</ref>
      <ref url="http://www.securitytracker.com/id?1022133" source="SECTRACK">1022133</ref>
      <ref url="http://www.securityfocus.com/bid/34669" source="BID">34669</ref>
      <ref url="http://secunia.com/advisories/34936" source="SECUNIA">34936</ref>
      <ref url="http://osvdb.org/54132" source="OSVDB">54132</ref>
    </refs>
    <vuln_soft>
      <prod vendor="symantec" name="antivirus">
        <vers num="10.0" />
        <vers num="10.0.1" />
        <vers num="10.0.1.1" />
        <vers num="10.0.2" />
        <vers num="10.0.2.1" />
        <vers num="10.0.2.2" />
        <vers num="10.0.3" />
        <vers num="10.0.4" />
        <vers num="10.0.5" />
        <vers num="10.0.6" />
        <vers num="10.0.7" />
        <vers num="10.0.8" />
        <vers num="10.0.9" />
        <vers prev="1" num="10.1" />
      </prod>
      <prod vendor="symantec" name="endpoint_protection">
        <vers num="11.0" />
      </prod>
      <prod vendor="symantec" name="norton_360">
        <vers num="1.0" />
      </prod>
      <prod vendor="symantec" name="norton_internet_security">
        <vers num="2005" edition="" />
        <vers num="2005" edition=":anti_spyware" />
        <vers num="2005" edition=":professional" />
        <vers num="2005" edition="11.0" />
        <vers num="2005" edition="11.0.9" />
        <vers num="2005" edition="11.5.6.14" />
        <vers num="2005_contains_nav_11.0.0" />
        <vers num="2006" edition="" />
        <vers num="2006" edition=":professional" />
        <vers num="2007" />
        <vers num="2008" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1429" published="2009-04-29" name="CVE-2009-1429" modified="2011-09-22" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">The Intel LANDesk Common Base Agent (CBA) in Symantec Alert Management System 2 (AMS2), as used in Symantec System Center (SSS); Symantec AntiVirus Server; Symantec AntiVirus Central Quarantine Server; Symantec AntiVirus (SAV) Corporate Edition 9 before 9.0 MR7, 10.0 and 10.1 before 10.1 MR8, and 10.2 before 10.2 MR2; Symantec Client Security (SCS) 2 before 2.0 MR7 and 3 before 3.1 MR8; and Symantec Endpoint Protection (SEP) before 11.0 MR3, allows remote attackers to execute arbitrary commands via a crafted packet whose contents are interpreted as a command to be launched in a new process by the CreateProcessA function.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/50176" source="XF">symantec-cba-command-execution(50176)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1204" source="VUPEN" adv="1">ADV-2009-1204</ref>
      <ref url="http://www.symantec.com/business/security_response/securityupdates/detail.jsp?fid=security_advisory&amp;pvid=security_advisory&amp;year=2009&amp;suid=20090428_02" source="CONFIRM" adv="1">http://www.symantec.com/business/security_response/securityupdates/detail.jsp?fid=security_advisory&amp;pvid=security_advisory&amp;year=2009&amp;suid=20090428_02</ref>
      <ref url="http://www.securitytracker.com/id?1022132" source="SECTRACK">1022132</ref>
      <ref url="http://www.securitytracker.com/id?1022131" source="SECTRACK">1022131</ref>
      <ref url="http://www.securitytracker.com/id?1022130" source="SECTRACK">1022130</ref>
      <ref url="http://www.securityfocus.com/bid/34671" source="BID">34671</ref>
      <ref url="http://securityreason.com/securityalert/8346" source="SREASON">8346</ref>
      <ref url="http://secunia.com/advisories/34856" source="SECUNIA" adv="1">34856</ref>
      <ref url="http://osvdb.org/54157" source="OSVDB">54157</ref>
    </refs>
    <vuln_soft>
      <prod vendor="symantec" name="antivirus">
        <vers num="-" edition="-" />
        <vers num="-" edition="-:srv" />
        <vers num="10.0" edition="" />
        <vers num="10.0" edition=":corporate" />
        <vers num="10.0.1" edition="" />
        <vers num="10.0.1" edition=":corporate" />
        <vers num="10.0.1.1" edition="" />
        <vers num="10.0.1.1" edition=":corporate" />
        <vers num="10.0.2" edition="" />
        <vers num="10.0.2" edition=":corporate" />
        <vers num="10.0.2.1" edition="" />
        <vers num="10.0.2.1" edition=":corporate" />
        <vers num="10.0.2.2" edition="" />
        <vers num="10.0.2.2" edition=":corporate" />
        <vers num="10.0.3" edition="" />
        <vers num="10.0.3" edition=":corporate" />
        <vers num="10.0.4" edition="" />
        <vers num="10.0.4" edition=":corporate" />
        <vers num="10.0.5" edition="" />
        <vers num="10.0.5" edition=":corporate" />
        <vers num="10.0.6" edition="" />
        <vers num="10.0.6" edition=":corporate" />
        <vers num="10.0.7" edition="" />
        <vers num="10.0.7" edition=":corporate" />
        <vers num="10.0.8" edition="" />
        <vers num="10.0.8" edition=":corporate" />
        <vers num="10.0.9" edition="" />
        <vers num="10.0.9" edition=":corporate" />
        <vers prev="1" num="10.1" edition="" />
        <vers prev="1" num="10.1" edition=":corporate" />
        <vers prev="1" num="10.2" edition="" />
        <vers prev="1" num="10.2" edition=":corporate" />
        <vers prev="1" num="9.0" edition="-" />
        <vers prev="1" num="9.0" edition="-:corporate" />
      </prod>
      <prod vendor="symantec" name="antivirus_central_quarantine_server">
        <vers num="" />
      </prod>
      <prod vendor="symantec" name="client_security">
        <vers num="2.0" />
        <vers num="3.0" />
        <vers num="3.0.0.359" />
        <vers num="3.0.1.1000" />
        <vers num="3.0.1.1001" />
        <vers num="3.0.1.1007" />
        <vers num="3.0.1.1008" />
        <vers num="3.0.1.1009" />
        <vers num="3.0.2" />
        <vers num="3.0.2.2000" />
        <vers num="3.0.2.2001" />
        <vers num="3.0.2.2002" />
        <vers num="3.0.2.2010" />
        <vers num="3.0.2.2011" />
        <vers num="3.0.2.2020" />
        <vers num="3.0.2.2021" />
        <vers prev="1" num="3.1" />
      </prod>
      <prod vendor="symantec" name="endpoint_protection">
        <vers prev="1" num="11.0" />
      </prod>
      <prod vendor="symantec" name="system_center">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1430" published="2009-04-29" name="CVE-2009-1430" modified="2009-05-14" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Multiple stack-based buffer overflows in IAO.EXE in the Intel Alert Originator Service in Symantec Alert Management System 2 (AMS2), as used in Symantec System Center (SSS); Symantec AntiVirus Server; Symantec AntiVirus Central Quarantine Server; Symantec AntiVirus (SAV) Corporate Edition 9 before 9.0 MR7, 10.0 and 10.1 before 10.1 MR8, and 10.2 before 10.2 MR2; Symantec Client Security (SCS) 2 before 2.0 MR7 and 3 before 3.1 MR8; and Symantec Endpoint Protection (SEP) before 11.0 MR3, allow remote attackers to execute arbitrary code via (1) a crafted packet or (2) data that ostensibly arrives from the MsgSys.exe process.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/50178" source="XF">symantec-msgsys-bo(50178)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/50177" source="XF">symantec-iao-bo(50177)</ref>
      <ref url="http://www.zerodayinitiative.com/advisories/ZDI-09-018/" source="MISC">http://www.zerodayinitiative.com/advisories/ZDI-09-018/</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1204" source="VUPEN">ADV-2009-1204</ref>
      <ref url="http://www.symantec.com/business/security_response/securityupdates/detail.jsp?fid=security_advisory&amp;pvid=security_advisory&amp;year=2009&amp;suid=20090428_02" source="CONFIRM" adv="1">http://www.symantec.com/business/security_response/securityupdates/detail.jsp?fid=security_advisory&amp;pvid=security_advisory&amp;year=2009&amp;suid=20090428_02</ref>
      <ref url="http://www.securitytracker.com/id?1022132" source="SECTRACK">1022132</ref>
      <ref url="http://www.securitytracker.com/id?1022131" source="SECTRACK">1022131</ref>
      <ref url="http://www.securitytracker.com/id?1022130" source="SECTRACK">1022130</ref>
      <ref url="http://www.securityfocus.com/bid/34674" source="BID">34674</ref>
      <ref url="http://www.securityfocus.com/bid/34672" source="BID">34672</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/503080/100/0/threaded" source="BUGTRAQ">20090428 ZDI-09-018: Symantec Client Security Alert Originator Service Stack Overflow Vulnerability</ref>
      <ref url="http://secunia.com/advisories/34856" source="SECUNIA">34856</ref>
    </refs>
    <vuln_soft>
      <prod vendor="symantec" name="antivirus">
        <vers num="-" edition="-" />
        <vers num="-" edition="-:srv" />
        <vers num="10.0" edition="" />
        <vers num="10.0" edition=":corporate" />
        <vers num="10.0.1" edition="" />
        <vers num="10.0.1" edition=":corporate" />
        <vers num="10.0.1.1" edition="" />
        <vers num="10.0.1.1" edition=":corporate" />
        <vers num="10.0.2" edition="" />
        <vers num="10.0.2" edition=":corporate" />
        <vers num="10.0.2.1" edition="" />
        <vers num="10.0.2.1" edition=":corporate" />
        <vers num="10.0.2.2" edition="" />
        <vers num="10.0.2.2" edition=":corporate" />
        <vers num="10.0.3" edition="" />
        <vers num="10.0.3" edition=":corporate" />
        <vers num="10.0.4" edition="" />
        <vers num="10.0.4" edition=":corporate" />
        <vers num="10.0.5" edition="" />
        <vers num="10.0.5" edition=":corporate" />
        <vers num="10.0.6" edition="" />
        <vers num="10.0.6" edition=":corporate" />
        <vers num="10.0.7" edition="" />
        <vers num="10.0.7" edition=":corporate" />
        <vers num="10.0.8" edition="" />
        <vers num="10.0.8" edition=":corporate" />
        <vers num="10.0.9" edition="" />
        <vers num="10.0.9" edition=":corporate" />
        <vers prev="1" num="10.1" edition="" />
        <vers prev="1" num="10.1" edition=":corporate" />
        <vers prev="1" num="10.2" edition="" />
        <vers prev="1" num="10.2" edition=":corporate" />
        <vers prev="1" num="9.0" edition="-" />
        <vers prev="1" num="9.0" edition="-:corporate" />
      </prod>
      <prod vendor="symantec" name="antivirus_central_quarantine_server">
        <vers num="" />
      </prod>
      <prod vendor="symantec" name="client_security">
        <vers num="2.0" />
        <vers num="3.0" />
        <vers num="3.0.0.359" />
        <vers num="3.0.1.1000" />
        <vers num="3.0.1.1001" />
        <vers num="3.0.1.1007" />
        <vers num="3.0.1.1008" />
        <vers num="3.0.1.1009" />
        <vers num="3.0.2" />
        <vers num="3.0.2.2000" />
        <vers num="3.0.2.2001" />
        <vers num="3.0.2.2002" />
        <vers num="3.0.2.2010" />
        <vers num="3.0.2.2011" />
        <vers num="3.0.2.2020" />
        <vers num="3.0.2.2021" />
        <vers prev="1" num="3.1" />
      </prod>
      <prod vendor="symantec" name="endpoint_protection">
        <vers prev="1" num="11.0" />
      </prod>
      <prod vendor="symantec" name="system_center">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1431" published="2009-04-29" name="CVE-2009-1431" modified="2009-05-14" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">XFR.EXE in the Intel File Transfer service in the console in Symantec Alert Management System 2 (AMS2), as used in Symantec System Center (SSS); Symantec AntiVirus Server; Symantec AntiVirus Central Quarantine Server; Symantec AntiVirus (SAV) Corporate Edition 9 before 9.0 MR7, 10.0 and 10.1 before 10.1 MR8, and 10.2 before 10.2 MR2; Symantec Client Security (SCS) 2 before 2.0 MR7 and 3 before 3.1 MR8; and Symantec Endpoint Protection (SEP) before 11.0 MR3, allows remote attackers to execute arbitrary code by placing the code on a (1) share or (2) WebDAV server, and then sending the UNC share pathname to this service.</descript>
    </desc>
    <impacts>
      <impact source="nvd">Per vendor: http://www.symantec.com/business/security_response/securityupdates/detail.jsp?fid=security_advisory&amp;pvid=security_advisory&amp;year=2009&amp;suid=20090428_02

"Symantec System Center Impact

Symantec System Center (SSS) is a Microsoft Management Console (MMC) plug-in which allows an administrator to manage all Symantec AntiVirus platforms from a single, centralized location. Alert Management System 2 (AMS2) is an alerting feature of System Center that listens for specific events and sends notifications as specified by the administrator.

AMS2 is installed by default with Symantec System Center 9.0. AMS2 is an optional component in Symantec System Center 10.0 or 10.1. These vulnerabilities will only impact systems if AMS has been installed.

Symantec AntiVirus Server Impact

AMS2 is installed by default with Symantec AntiVirus Server 9.0. AMS2 is an optional component in Symantec AntiVirus Server 10.0 or 10.1. These vulnerabilities will only impact systems if AMS has been installed.

Symantec AntiVirus and Symantec Endpoint Protection Central Quarantine Server Impact

AMS2 is installed by default by Central Quarantine Server. These vulnerabilities will only impact systems if Quarantine Server has been installed.

Symantec is not aware of any customers impacted by these issues, or of any attempts to exploit them. However, we recommend that any affected customers update their product immediately to protect against potential attempts to exploit these issues.

Certain localized language versions of SCS 2.0/SAV 9.x were not patched due to compatibility issues on the localized platforms. As a result, customers who are running the following versions are strongly recommended to update to a non-vulnerable SCS 2.0/SAV 9 International English version or upgrade to a non-vulnerable version of SEP 11.x:

Symantec Client Security 2.0/Symantec AntiVirus Corporate Edition 9.x (Chinese Simplified and Chinese Traditional)
Symantec Client Security 2.0/Symantec AntiVirus Business Pack 9.x (Chinese Simplified and Chinese Traditional)
Symantec Client Security 2.0/Symantec AntiVirus Business Pack 9.x (Korean)
Symantec Client Security 2.0/Symantec AntiVirus Business Pack 9.x (Japanese licensed)"</impact>
    </impacts>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/50179" source="XF">symantec-xfr-code-execution(50179)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1204" source="VUPEN">ADV-2009-1204</ref>
      <ref url="http://www.symantec.com/business/security_response/securityupdates/detail.jsp?fid=security_advisory&amp;pvid=security_advisory&amp;year=2009&amp;suid=20090428_02" source="CONFIRM" adv="1">http://www.symantec.com/business/security_response/securityupdates/detail.jsp?fid=security_advisory&amp;pvid=security_advisory&amp;year=2009&amp;suid=20090428_02</ref>
      <ref url="http://www.securitytracker.com/id?1022132" source="SECTRACK">1022132</ref>
      <ref url="http://www.securitytracker.com/id?1022131" source="SECTRACK">1022131</ref>
      <ref url="http://www.securitytracker.com/id?1022130" source="SECTRACK">1022130</ref>
      <ref url="http://www.securityfocus.com/bid/34675" source="BID">34675</ref>
      <ref url="http://secunia.com/advisories/34856" source="SECUNIA">34856</ref>
      <ref url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=786" source="IDEFENSE">20090429 Symantec System Center Alert Management System Console Arbitrary Program Execution Design Error Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="symantec" name="antivirus">
        <vers num="-" edition="-" />
        <vers num="-" edition="-:srv" />
        <vers num="10.0" edition="" />
        <vers num="10.0" edition=":corporate" />
        <vers num="10.0.1" edition="" />
        <vers num="10.0.1" edition=":corporate" />
        <vers num="10.0.1.1" edition="" />
        <vers num="10.0.1.1" edition=":corporate" />
        <vers num="10.0.2" edition="" />
        <vers num="10.0.2" edition=":corporate" />
        <vers num="10.0.2.1" edition="" />
        <vers num="10.0.2.1" edition=":corporate" />
        <vers num="10.0.2.2" edition="" />
        <vers num="10.0.2.2" edition=":corporate" />
        <vers num="10.0.3" edition="" />
        <vers num="10.0.3" edition=":corporate" />
        <vers num="10.0.4" edition="" />
        <vers num="10.0.4" edition=":corporate" />
        <vers num="10.0.5" edition="" />
        <vers num="10.0.5" edition=":corporate" />
        <vers num="10.0.6" edition="" />
        <vers num="10.0.6" edition=":corporate" />
        <vers num="10.0.7" edition="" />
        <vers num="10.0.7" edition=":corporate" />
        <vers num="10.0.8" edition="" />
        <vers num="10.0.8" edition=":corporate" />
        <vers num="10.0.9" edition="" />
        <vers num="10.0.9" edition=":corporate" />
        <vers prev="1" num="10.1" edition="" />
        <vers prev="1" num="10.1" edition=":corporate" />
        <vers prev="1" num="10.2" edition="" />
        <vers prev="1" num="10.2" edition=":corporate" />
        <vers prev="1" num="9.0" edition="-" />
        <vers prev="1" num="9.0" edition="-:corporate" />
      </prod>
      <prod vendor="symantec" name="antivirus_central_quarantine_server">
        <vers num="" />
      </prod>
      <prod vendor="symantec" name="client_security">
        <vers prev="1" num="2.0" />
        <vers num="3.0" />
        <vers num="3.0.0.359" />
        <vers num="3.0.1.1000" />
        <vers num="3.0.1.1001" />
        <vers num="3.0.1.1007" />
        <vers num="3.0.1.1008" />
        <vers num="3.0.1.1009" />
        <vers num="3.0.2" />
        <vers num="3.0.2.2000" />
        <vers num="3.0.2.2001" />
        <vers num="3.0.2.2002" />
        <vers num="3.0.2.2010" />
        <vers num="3.0.2.2011" />
        <vers num="3.0.2.2020" />
        <vers num="3.0.2.2021" />
        <vers prev="1" num="3.1" />
      </prod>
      <prod vendor="symantec" name="endpoint_protection">
        <vers prev="1" num="11.0" />
      </prod>
      <prod vendor="symantec" name="system_center">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1432" published="2009-04-30" name="CVE-2009-1432" modified="2009-05-14" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Symantec Reporting Server, as used in Symantec AntiVirus (SAV) Corporate Edition 10.1 before 10.1 MR8 and 10.2 before 10.2 MR2, Symantec Client Security (SCS) before 3.1 MR8, and the Symantec Endpoint Protection Manager (SEPM) component in Symantec Endpoint Protection (SEP) before 11.0 MR2, allows remote attackers to inject arbitrary text into the login screen, and possibly conduct phishing attacks, via vectors involving a URL that is not properly handled.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/50172" source="XF">multiple-symantec-login-spoofing(50172)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1204" source="VUPEN">ADV-2009-1204</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1202" source="VUPEN" adv="1">ADV-2009-1202</ref>
      <ref url="http://www.symantec.com/business/security_response/securityupdates/detail.jsp?fid=security_advisory&amp;pvid=security_advisory&amp;year=2009&amp;suid=20090428_00" source="CONFIRM">http://www.symantec.com/business/security_response/securityupdates/detail.jsp?fid=security_advisory&amp;pvid=security_advisory&amp;year=2009&amp;suid=20090428_00</ref>
      <ref url="http://www.securityfocus.com/bid/34668" source="BID">34668</ref>
      <ref url="http://securitytracker.com/id?1022138" source="SECTRACK">1022138</ref>
      <ref url="http://securitytracker.com/id?1022137" source="SECTRACK">1022137</ref>
      <ref url="http://securitytracker.com/id?1022136" source="SECTRACK">1022136</ref>
      <ref url="http://secunia.com/advisories/34935" source="SECUNIA" adv="1">34935</ref>
      <ref url="http://secunia.com/advisories/34856" source="SECUNIA">34856</ref>
    </refs>
    <vuln_soft>
      <prod vendor="symantec" name="antivirus">
        <vers num="-" edition="-" />
        <vers num="-" edition="-:srv" />
        <vers num="10.0" edition="" />
        <vers num="10.0" edition=":corporate" />
        <vers num="10.0.1" edition="" />
        <vers num="10.0.1" edition=":corporate" />
        <vers num="10.0.1.1" edition="" />
        <vers num="10.0.1.1" edition=":corporate" />
        <vers num="10.0.2" edition="" />
        <vers num="10.0.2" edition=":corporate" />
        <vers num="10.0.2.1" edition="" />
        <vers num="10.0.2.1" edition=":corporate" />
        <vers num="10.0.2.2" edition="" />
        <vers num="10.0.2.2" edition=":corporate" />
        <vers num="10.0.3" edition="" />
        <vers num="10.0.3" edition=":corporate" />
        <vers num="10.0.4" edition="" />
        <vers num="10.0.4" edition=":corporate" />
        <vers num="10.0.5" edition="" />
        <vers num="10.0.5" edition=":corporate" />
        <vers num="10.0.6" edition="" />
        <vers num="10.0.6" edition=":corporate" />
        <vers num="10.0.7" edition="" />
        <vers num="10.0.7" edition=":corporate" />
        <vers num="10.0.8" edition="" />
        <vers num="10.0.8" edition=":corporate" />
        <vers num="10.0.9" edition="" />
        <vers num="10.0.9" edition=":corporate" />
        <vers prev="1" num="10.1" edition="" />
        <vers prev="1" num="10.1" edition=":corporate" />
        <vers prev="1" num="10.2" edition="" />
        <vers prev="1" num="10.2" edition=":corporate" />
        <vers prev="1" num="9.0" edition="-" />
        <vers prev="1" num="9.0" edition="-:corporate" />
      </prod>
      <prod vendor="symantec" name="antivirus_central_quarantine_server">
        <vers num="" />
      </prod>
      <prod vendor="symantec" name="client_security">
        <vers prev="1" num="2.0" />
        <vers num="3.0" />
        <vers num="3.0.0.359" />
        <vers num="3.0.1.1000" />
        <vers num="3.0.1.1001" />
        <vers num="3.0.1.1007" />
        <vers num="3.0.1.1008" />
        <vers num="3.0.1.1009" />
        <vers num="3.0.2" />
        <vers num="3.0.2.2000" />
        <vers num="3.0.2.2001" />
        <vers num="3.0.2.2002" />
        <vers num="3.0.2.2010" />
        <vers num="3.0.2.2011" />
        <vers num="3.0.2.2020" />
        <vers num="3.0.2.2021" />
        <vers prev="1" num="3.1" />
      </prod>
      <prod vendor="symantec" name="endpoint_protection">
        <vers prev="1" num="11.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1433" published="2009-04-24" name="CVE-2009-1433" modified="2009-04-27" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in File::find (filesystem/File.php) in SilverStripe before 2.3.1 allows remote attackers to execute arbitrary SQL commands via the filename parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://open.silverstripe.com/ticket/3721" source="CONFIRM" patch="1">http://open.silverstripe.com/ticket/3721</ref>
      <ref url="http://www.securityfocus.com/bid/34485" source="BID">34485</ref>
      <ref url="http://secunia.com/advisories/34633" source="SECUNIA" adv="1">34633</ref>
      <ref url="http://osvdb.org/53589" source="OSVDB">53589</ref>
      <ref url="http://open.silverstripe.com/wiki/ChangeLog/2.3.1" source="CONFIRM">http://open.silverstripe.com/wiki/ChangeLog/2.3.1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="silverstripe" name="silverstripe">
        <vers num="2.0.0" />
        <vers num="2.0.1" />
        <vers num="2.0.2" />
        <vers num="2.1.0" />
        <vers num="2.1.1" />
        <vers num="2.2.0" />
        <vers num="2.2.1" />
        <vers num="2.2.2" />
        <vers num="2.2.4" />
        <vers num="2.3.0" edition="rc1" />
        <vers num="2.3.0" edition="rc2" />
        <vers num="2.3.0" edition="rc3" />
        <vers prev="1" num="2.3.1" edition="rc1" />
        <vers prev="1" num="2.3.1" edition="rc2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1434" published="2009-04-30" name="CVE-2009-1434" modified="2009-05-14" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site request forgery (CSRF) vulnerability in Foswiki before 1.0.5 allows remote attackers to hijack the authentication of arbitrary users for requests that modify pages, change permissions, or change group memberships, as demonstrated by a URL for a (1) save or (2) view script in the SRC attribute of an IMG element, a related issue to CVE-2009-1339.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://sourceforge.net/mailarchive/forum.php?thread_name=49F61C4E.2040806%40lavrsen.dk&amp;forum_name=foswiki-announce" source="MLIST" patch="1">[foswiki-announce] 20090427 Security Alert CVE-2009-1434: Foswiki Page View Cross-Site Request Forgery (CSRF)</ref>
      <ref url="http://foswiki.org/Support/SecurityAlert-CVE-2009-1434" source="CONFIRM" patch="1" adv="1">http://foswiki.org/Support/SecurityAlert-CVE-2009-1434</ref>
      <ref url="https://launchpad.net/bugs/cve/2009-1434" source="CONFIRM">https://launchpad.net/bugs/cve/2009-1434</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/50256" source="XF">foswiki-unspecified-csrf(50256)</ref>
      <ref url="http://secunia.com/advisories/34863" source="SECUNIA" adv="1">34863</ref>
      <ref url="http://osvdb.org/54148" source="OSVDB">54148</ref>
    </refs>
    <vuln_soft>
      <prod vendor="foswiki" name="foswiki">
        <vers num="1.0.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers prev="1" num="1.0.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2009-1435" published="2009-04-27" name="CVE-2009-1435" modified="2009-04-29" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">NTRtScan.exe in Trend Micro OfficeScan Client 8.0 SP1 and 8.0 SP1 Patch 1 allows local users to cause a denial of service (application crash) via directories with long pathnames.  NOTE: some of these details are obtained from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2009/1146" source="VUPEN" adv="1">ADV-2009-1146</ref>
      <ref url="http://www.securitytracker.com/id?1022109" source="SECTRACK">1022109</ref>
      <ref url="http://www.securityfocus.com/bid/34642" source="BID">34642</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/502860/100/0/threaded" source="BUGTRAQ">20090421 Re: Trend Micro OfficeScan Client - DOS</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/502847/100/0/threaded" source="BUGTRAQ">20090421 Trend Micro OfficeScan Client - DOS</ref>
      <ref url="http://secunia.com/advisories/34737" source="SECUNIA" adv="1">34737</ref>
      <ref url="http://osvdb.org/53890" source="OSVDB">53890</ref>
      <ref url="http://es.geocities.com/jplopezy/officescan.zip" source="MISC">http://es.geocities.com/jplopezy/officescan.zip</ref>
    </refs>
    <vuln_soft>
      <prod vendor="trendmicro" name="officescan">
        <vers num="8.0" edition="sp1" />
        <vers num="8.0" edition="sp1:client" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1436" published="2009-04-27" name="CVE-2009-1436" modified="2009-06-15" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:N/A:N)" CVSS_score="4.9" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="3.9" CVSS_base_score="4.9">
    <desc>
      <descript source="cve">The db interface in libc in FreeBSD 6.3, 6.4, 7.0, 7.1, and 7.2-PRERELEASE does not properly initialize memory for Berkeley DB 1.85 database structures, which allows local users to obtain sensitive information by reading a database file.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/34666" source="BID" patch="1">34666</ref>
      <ref url="http://www.securitytracker.com/id?1022113" source="SECTRACK">1022113</ref>
      <ref url="http://security.freebsd.org/advisories/FreeBSD-SA-09:07.libc.asc" source="FREEBSD" adv="1">FreeBSD-SA-09:07</ref>
      <ref url="http://secunia.com/advisories/34810" source="SECUNIA" adv="1">34810</ref>
      <ref url="http://osvdb.org/53918" source="OSVDB">53918</ref>
    </refs>
    <vuln_soft>
      <prod vendor="freebsd" name="freebsd">
        <vers num="6.3" edition="release_p10" />
        <vers num="6.4" edition="release_p4" />
        <vers num="6.4" edition="stable" />
        <vers num="7.0" edition="release-p12" />
        <vers num="7.1" edition="release-p5" />
        <vers num="7.2" edition="pre-release" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1437" published="2009-04-27" name="CVE-2009-1437" modified="2009-04-27" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Stack-based buffer overflow in PortableApps CoolPlayer Portable (aka CoolPlayer+ Portable) 2.19.1 allows remote attackers to execute arbitrary code via a long string in a malformed playlist (.m3u) file. NOTE: this may overlap CVE-2008-3408.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/49984" source="XF">coolplayerportable-m3u-bo(49984)</ref>
      <ref url="http://www.milw0rm.com/exploits/8520" source="MILW0RM">8520</ref>
      <ref url="http://www.milw0rm.com/exploits/8519" source="MILW0RM">8519</ref>
      <ref url="http://www.milw0rm.com/exploits/8489" source="MILW0RM">8489</ref>
      <ref url="http://secunia.com/advisories/34816" source="SECUNIA" adv="1">34816</ref>
      <ref url="http://osvdb.org/53885" source="OSVDB">53885</ref>
    </refs>
    <vuln_soft>
      <prod vendor="coolplayer" name="coolplayer">
        <vers num="2.19.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1438" published="2009-04-27" name="CVE-2009-1438" modified="2009-08-08" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Integer overflow in the CSoundFile::ReadMed function (src/load_med.cpp) in libmodplug before 0.8.6, as used in gstreamer-plugins, TTPlayer, and other products, allows context-dependent attackers to execute arbitrary code via a MED file with a crafted (1) song comment or (2) song name, which triggers a heap-based buffer overflow, as exploited in the wild in August 2008.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2009/1104" source="VUPEN" patch="1" adv="1">ADV-2009-1104</ref>
      <ref url="http://www.securityfocus.com/bid/30801" source="BID" patch="1">30801</ref>
      <ref url="http://sourceforge.net/project/shownotes.php?release_id=677065&amp;group_id=1275" source="CONFIRM" patch="1">http://sourceforge.net/project/shownotes.php?release_id=677065&amp;group_id=1275</ref>
      <ref url="http://osvdb.org/53801" source="OSVDB" patch="1">53801</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=496834" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=496834</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/50388" source="XF">libmodplug-csoundfilereadmed-bo(50388)</ref>
      <ref url="http://www.ubuntu.com/usn/USN-771-1" source="UBUNTU">USN-771-1</ref>
      <ref url="http://www.redhat.com/archives/fedora-package-announce/2009-April/msg00908.html" source="FEDORA">FEDORA-2009-4068</ref>
      <ref url="http://www.redhat.com/archives/fedora-package-announce/2009-April/msg00907.html" source="FEDORA">FEDORA-2009-4064</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2009/04/21/4" source="MLIST">[oss-security] 20090421 CVE Request -- libmodplug</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:128" source="MANDRIVA">MDVSA-2009:128</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1851" source="DEBIAN">DSA-1851</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1850" source="DEBIAN">DSA-1850</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200907-07.xml" source="GENTOO">GLSA-200907-07</ref>
      <ref url="http://secunia.com/advisories/36183" source="SECUNIA">36183</ref>
      <ref url="http://secunia.com/advisories/36158" source="SECUNIA">36158</ref>
      <ref url="http://secunia.com/advisories/35736" source="SECUNIA">35736</ref>
      <ref url="http://secunia.com/advisories/35685" source="SECUNIA">35685</ref>
      <ref url="http://secunia.com/advisories/35026" source="SECUNIA">35026</ref>
      <ref url="http://secunia.com/advisories/34930" source="SECUNIA">34930</ref>
      <ref url="http://secunia.com/advisories/34797" source="SECUNIA" adv="1">34797</ref>
      <ref url="http://modplug-xmms.cvs.sourceforge.net/viewvc/modplug-xmms/libmodplug/src/load_med.cpp?r1=1.1&amp;amp;r2=1.2" source="MISC">http://modplug-xmms.cvs.sourceforge.net/viewvc/modplug-xmms/libmodplug/src/load_med.cpp?r1=1.1&amp;amp;r2=1.2</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-07/msg00002.html" source="SUSE">SUSE-SR:2009:012</ref>
      <ref url="http://bugs.gentoo.org/show_bug.cgi?id=266913" source="CONFIRM">http://bugs.gentoo.org/show_bug.cgi?id=266913</ref>
    </refs>
    <vuln_soft>
      <prod vendor="konstanty_bialkowski" name="libmodplug">
        <vers num="0.8" />
        <vers num="0.8.4" />
        <vers prev="1" num="0.8.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1439" published="2009-04-27" name="CVE-2009-1439" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Buffer overflow in fs/cifs/connect.c in CIFS in the Linux kernel 2.6.29 and earlier allows remote attackers to cause a denial of service (crash) via a long nativeFileSystem field in a Tree Connect response to an SMB mount request.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-May/msg01271.html" source="FEDORA">FEDORA-2009-5383</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-May/msg01126.html" source="FEDORA">FEDORA-2009-5356</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=494275" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=494275</ref>
      <ref url="https://bugzilla.novell.com/show_bug.cgi?id=492282" source="CONFIRM">https://bugzilla.novell.com/show_bug.cgi?id=492282</ref>
      <ref url="http://xorl.wordpress.com/2009/04/07/linux-kernel-tree-connect-cifs-remote-buffer-overflow/" source="MISC">http://xorl.wordpress.com/2009/04/07/linux-kernel-tree-connect-cifs-remote-buffer-overflow/</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/3316" source="VUPEN">ADV-2009-3316</ref>
      <ref url="http://www.vmware.com/security/advisories/VMSA-2009-0016.html" source="CONFIRM">http://www.vmware.com/security/advisories/VMSA-2009-0016.html</ref>
      <ref url="http://www.ubuntu.com/usn/usn-793-1" source="UBUNTU">USN-793-1</ref>
      <ref url="http://www.securityfocus.com/bid/34453" source="BID">34453</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/507985/100/0/threaded" source="BUGTRAQ">20091120 VMSA-2009-0016 VMware vCenter and ESX update release and vMA patch release address multiple security issue in third party components</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/503610/100/0/threaded" source="BUGTRAQ">20090516 rPSA-2009-0084-1 kernel</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-1081.html" source="REDHAT">RHSA-2009:1081</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2009/04/07/7" source="MLIST">[oss-security] 20090407 Re: CVE request? buffer overflow in CIFS in 2.6.*</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2009/04/07/3" source="MLIST">[oss-security] 20090407 Re: CVE request? buffer overflow in CIFS in 2.6.*</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2009/04/04/1" source="MLIST">[oss-security] 20090405 CVE request? buffer overflow in CIFS in 2.6.*</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1800" source="DEBIAN">DSA-1800</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1794" source="DEBIAN">DSA-1794</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1787" source="DEBIAN">DSA-1787</ref>
      <ref url="http://wiki.rpath.com/Advisories:rPSA-2009-0084" source="CONFIRM">http://wiki.rpath.com/Advisories:rPSA-2009-0084</ref>
      <ref url="http://secunia.com/advisories/37471" source="SECUNIA">37471</ref>
      <ref url="http://secunia.com/advisories/35656" source="SECUNIA">35656</ref>
      <ref url="http://secunia.com/advisories/35394" source="SECUNIA">35394</ref>
      <ref url="http://secunia.com/advisories/35390" source="SECUNIA">35390</ref>
      <ref url="http://secunia.com/advisories/35387" source="SECUNIA">35387</ref>
      <ref url="http://secunia.com/advisories/35343" source="SECUNIA">35343</ref>
      <ref url="http://secunia.com/advisories/35226" source="SECUNIA">35226</ref>
      <ref url="http://secunia.com/advisories/35217" source="SECUNIA">35217</ref>
      <ref url="http://secunia.com/advisories/35185" source="SECUNIA">35185</ref>
      <ref url="http://secunia.com/advisories/35121" source="SECUNIA">35121</ref>
      <ref url="http://secunia.com/advisories/35120" source="SECUNIA">35120</ref>
      <ref url="http://secunia.com/advisories/35011" source="SECUNIA">35011</ref>
      <ref url="http://secunia.com/advisories/34981" source="SECUNIA">34981</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:8265" source="OVAL">oval:org.mitre.oval:def:8265</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10321" source="OVAL">oval:org.mitre.oval:def:10321</ref>
      <ref url="http://lists.samba.org/archive/linux-cifs-client/2009-April/004322.html" source="MLIST">[linux-cifs-client] 20090406 [PATCH] cifs: Fix insufficient memory allocation for nativeFileSystem field</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-06/msg00002.html" source="SUSE">SUSE-SA:2009:032</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-06/msg00001.html" source="SUSE">SUSE-SA:2009:031</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-06/msg00000.html" source="SUSE">SUSE-SA:2009:030</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-05/msg00002.html" source="SUSE">SUSE-SA:2009:028</ref>
      <ref url="http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=b363b3304bcf68c4541683b2eff70b29f0446a5b" source="CONFIRM">http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=b363b3304bcf68c4541683b2eff70b29f0446a5b</ref>
      <ref url="http://blog.fefe.de/?ts=b72905a8" source="MISC">http://blog.fefe.de/?ts=b72905a8</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="kernel">
        <vers num="2.2.27" />
        <vers num="2.4.36" />
        <vers num="2.4.36.1" />
        <vers num="2.4.36.2" />
        <vers num="2.4.36.3" />
        <vers num="2.4.36.4" />
        <vers num="2.4.36.5" />
        <vers num="2.4.36.6" />
        <vers num="2.6" />
        <vers num="2.6.0" />
        <vers num="2.6.1" />
        <vers num="2.6.10" />
        <vers num="2.6.11" />
        <vers num="2.6.11.1" />
        <vers num="2.6.11.10" />
        <vers num="2.6.11.11" />
        <vers num="2.6.11.12" />
        <vers num="2.6.11.2" />
        <vers num="2.6.11.3" />
        <vers num="2.6.11.4" />
        <vers num="2.6.11.5" />
        <vers num="2.6.11.6" />
        <vers num="2.6.11.7" />
        <vers num="2.6.11.8" />
        <vers num="2.6.11.9" />
        <vers num="2.6.12" />
        <vers num="2.6.12.1" />
        <vers num="2.6.12.2" />
        <vers num="2.6.12.3" />
        <vers num="2.6.12.4" />
        <vers num="2.6.12.5" />
        <vers num="2.6.12.6" />
        <vers num="2.6.13" />
        <vers num="2.6.13.1" />
        <vers num="2.6.13.2" />
        <vers num="2.6.13.3" />
        <vers num="2.6.13.4" />
        <vers num="2.6.13.5" />
        <vers num="2.6.14" />
        <vers num="2.6.14.1" />
        <vers num="2.6.14.2" />
        <vers num="2.6.14.3" />
        <vers num="2.6.14.4" />
        <vers num="2.6.14.5" />
        <vers num="2.6.14.6" />
        <vers num="2.6.14.7" />
        <vers num="2.6.15" />
        <vers num="2.6.15.1" />
        <vers num="2.6.15.2" />
        <vers num="2.6.15.3" />
        <vers num="2.6.15.4" />
        <vers num="2.6.15.5" />
        <vers num="2.6.15.6" />
        <vers num="2.6.15.7" />
        <vers num="2.6.16" />
        <vers num="2.6.16.1" />
        <vers num="2.6.16.10" />
        <vers num="2.6.16.11" />
        <vers num="2.6.16.12" />
        <vers num="2.6.16.13" />
        <vers num="2.6.16.14" />
        <vers num="2.6.16.15" />
        <vers num="2.6.16.16" />
        <vers num="2.6.16.17" />
        <vers num="2.6.16.18" />
        <vers num="2.6.16.19" />
        <vers num="2.6.16.2" />
        <vers num="2.6.16.20" />
        <vers num="2.6.16.21" />
        <vers num="2.6.16.22" />
        <vers num="2.6.16.23" />
        <vers num="2.6.16.24" />
        <vers num="2.6.16.25" />
        <vers num="2.6.16.26" />
        <vers num="2.6.16.27" />
        <vers num="2.6.16.28" />
        <vers num="2.6.16.29" />
        <vers num="2.6.16.3" />
        <vers num="2.6.16.30" />
        <vers num="2.6.16.31" />
        <vers num="2.6.16.32" />
        <vers num="2.6.16.33" />
        <vers num="2.6.16.34" />
        <vers num="2.6.16.35" />
        <vers num="2.6.16.36" />
        <vers num="2.6.16.37" />
        <vers num="2.6.16.38" />
        <vers num="2.6.16.39" />
        <vers num="2.6.16.4" />
        <vers num="2.6.16.40" />
        <vers num="2.6.16.41" />
        <vers num="2.6.16.42" />
        <vers num="2.6.16.43" />
        <vers num="2.6.16.44" />
        <vers num="2.6.16.45" />
        <vers num="2.6.16.46" />
        <vers num="2.6.16.47" />
        <vers num="2.6.16.48" />
        <vers num="2.6.16.49" />
        <vers num="2.6.16.5" />
        <vers num="2.6.16.50" />
        <vers num="2.6.16.51" />
        <vers num="2.6.16.52" />
        <vers num="2.6.16.53" />
        <vers num="2.6.16.54" />
        <vers num="2.6.16.55" />
        <vers num="2.6.16.56" />
        <vers num="2.6.16.57" />
        <vers num="2.6.16.58" />
        <vers num="2.6.16.59" />
        <vers num="2.6.16.6" />
        <vers num="2.6.16.60" />
        <vers num="2.6.16.61" />
        <vers num="2.6.16.62" />
        <vers num="2.6.16.7" />
        <vers num="2.6.16.8" />
        <vers num="2.6.16.9" />
        <vers num="2.6.17" />
        <vers num="2.6.17.1" />
        <vers num="2.6.17.10" />
        <vers num="2.6.17.11" />
        <vers num="2.6.17.12" />
        <vers num="2.6.17.13" />
        <vers num="2.6.17.14" />
        <vers num="2.6.17.2" />
        <vers num="2.6.17.3" />
        <vers num="2.6.17.4" />
        <vers num="2.6.17.5" />
        <vers num="2.6.17.6" />
        <vers num="2.6.17.7" />
        <vers num="2.6.17.8" />
        <vers num="2.6.17.9" />
        <vers num="2.6.18" edition="rc1" />
        <vers num="2.6.18" edition="rc2" />
        <vers num="2.6.18" edition="rc3" />
        <vers num="2.6.18" edition="rc4" />
        <vers num="2.6.18" edition="rc5" />
        <vers num="2.6.18" edition="rc6" />
        <vers num="2.6.18" edition="rc7" />
        <vers num="2.6.18.1" />
        <vers num="2.6.18.2" />
        <vers num="2.6.18.3" />
        <vers num="2.6.18.4" />
        <vers num="2.6.18.5" />
        <vers num="2.6.18.6" />
        <vers num="2.6.18.7" />
        <vers num="2.6.18.8" />
        <vers num="2.6.19" />
        <vers num="2.6.19.1" />
        <vers num="2.6.19.2" />
        <vers num="2.6.19.3" />
        <vers num="2.6.19.4" />
        <vers num="2.6.19.5" />
        <vers num="2.6.19.6" />
        <vers num="2.6.19.7" />
        <vers num="2.6.2" />
        <vers num="2.6.20" />
        <vers num="2.6.20.1" />
        <vers num="2.6.20.10" />
        <vers num="2.6.20.11" />
        <vers num="2.6.20.12" />
        <vers num="2.6.20.13" />
        <vers num="2.6.20.14" />
        <vers num="2.6.20.15" />
        <vers num="2.6.20.16" />
        <vers num="2.6.20.17" />
        <vers num="2.6.20.18" />
        <vers num="2.6.20.19" />
        <vers num="2.6.20.2" />
        <vers num="2.6.20.20" />
        <vers num="2.6.20.21" />
        <vers num="2.6.20.3" />
        <vers num="2.6.20.4" />
        <vers num="2.6.20.5" />
        <vers num="2.6.20.6" />
        <vers num="2.6.20.7" />
        <vers num="2.6.20.8" />
        <vers num="2.6.20.9" />
        <vers num="2.6.21" />
        <vers num="2.6.21.1" />
        <vers num="2.6.21.2" />
        <vers num="2.6.21.3" />
        <vers num="2.6.21.4" />
        <vers num="2.6.21.5" />
        <vers num="2.6.21.6" />
        <vers num="2.6.21.7" />
        <vers num="2.6.22" />
        <vers num="2.6.22.1" />
        <vers num="2.6.22.10" />
        <vers num="2.6.22.11" />
        <vers num="2.6.22.12" />
        <vers num="2.6.22.13" />
        <vers num="2.6.22.14" />
        <vers num="2.6.22.15" />
        <vers num="2.6.22.16" />
        <vers num="2.6.22.17" />
        <vers num="2.6.22.18" />
        <vers num="2.6.22.19" />
        <vers num="2.6.22.2" />
        <vers num="2.6.22.20" />
        <vers num="2.6.22.21" />
        <vers num="2.6.22.22" />
        <vers num="2.6.22.3" />
        <vers num="2.6.22.4" />
        <vers num="2.6.22.5" />
        <vers num="2.6.22.6" />
        <vers num="2.6.22.7" />
        <vers num="2.6.22.8" />
        <vers num="2.6.22.9" />
        <vers num="2.6.22_rc1" />
        <vers num="2.6.22_rc7" />
        <vers num="2.6.23" edition="rc1" />
        <vers num="2.6.23" edition="rc2" />
        <vers num="2.6.23.1" />
        <vers num="2.6.23.10" />
        <vers num="2.6.23.11" />
        <vers num="2.6.23.12" />
        <vers num="2.6.23.13" />
        <vers num="2.6.23.14" />
        <vers num="2.6.23.15" />
        <vers num="2.6.23.16" />
        <vers num="2.6.23.17" />
        <vers num="2.6.23.2" />
        <vers num="2.6.23.3" />
        <vers num="2.6.23.4" />
        <vers num="2.6.23.5" />
        <vers num="2.6.23.6" />
        <vers num="2.6.23.7" />
        <vers num="2.6.23.8" />
        <vers num="2.6.23.9" />
        <vers num="2.6.24" edition="rc1" />
        <vers num="2.6.24" edition="rc2" />
        <vers num="2.6.24" edition="rc3" />
        <vers num="2.6.24" edition="rc4" />
        <vers num="2.6.24" edition="rc5" />
        <vers num="2.6.24.1" />
        <vers num="2.6.24.2" />
        <vers num="2.6.24.3" />
        <vers num="2.6.24.4" />
        <vers num="2.6.24.5" />
        <vers num="2.6.24.6" />
        <vers num="2.6.24.7" />
        <vers num="2.6.25" edition="" />
        <vers num="2.6.25" edition=":x86_64" />
        <vers num="2.6.25.1" edition="" />
        <vers num="2.6.25.1" edition=":x86_64" />
        <vers num="2.6.25.10" edition="" />
        <vers num="2.6.25.10" edition=":x86_64" />
        <vers num="2.6.25.11" edition="" />
        <vers num="2.6.25.11" edition=":x86_64" />
        <vers num="2.6.25.12" edition="" />
        <vers num="2.6.25.12" edition=":x86_64" />
        <vers num="2.6.25.13" />
        <vers num="2.6.25.14" />
        <vers num="2.6.25.15" />
        <vers num="2.6.25.16" />
        <vers num="2.6.25.17" />
        <vers num="2.6.25.18" />
        <vers num="2.6.25.19" />
        <vers num="2.6.25.2" edition="" />
        <vers num="2.6.25.2" edition=":x86_64" />
        <vers num="2.6.25.20" />
        <vers num="2.6.25.3" edition="" />
        <vers num="2.6.25.3" edition=":x86_64" />
        <vers num="2.6.25.4" edition="" />
        <vers num="2.6.25.4" edition=":x86_64" />
        <vers num="2.6.25.5" edition="" />
        <vers num="2.6.25.5" edition=":x86_64" />
        <vers num="2.6.25.6" edition="" />
        <vers num="2.6.25.6" edition=":x86_64" />
        <vers num="2.6.25.7" edition="" />
        <vers num="2.6.25.7" edition=":x86_64" />
        <vers num="2.6.25.8" edition="" />
        <vers num="2.6.25.8" edition=":x86_64" />
        <vers num="2.6.25.9" edition="" />
        <vers num="2.6.25.9" edition=":x86_64" />
        <vers num="2.6.26" edition="rc4" />
        <vers num="2.6.26.1" />
        <vers num="2.6.26.2" />
        <vers num="2.6.26.3" />
        <vers num="2.6.26.4" />
        <vers num="2.6.26.5" />
        <vers num="2.6.26.6" />
        <vers num="2.6.26.7" />
        <vers num="2.6.26.8" />
        <vers num="2.6.27" edition="rc1" />
        <vers num="2.6.27" edition="rc2" />
        <vers num="2.6.27" edition="rc3" />
        <vers num="2.6.27" edition="rc4" />
        <vers num="2.6.27" edition="rc5" />
        <vers num="2.6.27" edition="rc6" />
        <vers num="2.6.27" edition="rc7" />
        <vers num="2.6.27" edition="rc8" />
        <vers num="2.6.27" edition="rc9" />
        <vers num="2.6.27.1" />
        <vers num="2.6.27.10" />
        <vers num="2.6.27.11" />
        <vers num="2.6.27.12" />
        <vers num="2.6.27.2" />
        <vers num="2.6.27.3" />
        <vers num="2.6.27.4" />
        <vers num="2.6.27.5" />
        <vers num="2.6.27.6" />
        <vers num="2.6.27.7" />
        <vers num="2.6.27.8" />
        <vers num="2.6.27.9" />
        <vers num="2.6.28" edition="rc1" />
        <vers num="2.6.28" edition="rc2" />
        <vers num="2.6.28" edition="rc3" />
        <vers num="2.6.28" edition="rc4" />
        <vers num="2.6.28" edition="rc5" />
        <vers num="2.6.28" edition="rc6" />
        <vers num="2.6.28" edition="rc7" />
        <vers num="2.6.28.1" />
        <vers num="2.6.28.2" />
        <vers num="2.6.28.3" />
        <vers num="2.6.28.4" />
        <vers num="2.6.28.5" />
        <vers num="2.6.28.6" />
        <vers num="2.6.28.7" />
        <vers num="2.6.28.8" />
        <vers num="2.6.28.9" />
        <vers prev="1" num="2.6.29" edition="git1" />
        <vers prev="1" num="2.6.29" edition="rc1" />
        <vers prev="1" num="2.6.29" edition="rc2" />
        <vers prev="1" num="2.6.29" edition="rc2_git7" />
        <vers prev="1" num="2.6.29" edition="rc8-kk" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1440" published="2009-04-27" name="CVE-2009-1440" modified="2009-06-25" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Incomplete blacklist vulnerability in DownloadListCtrl.cpp in amule 2.2.4 allows remote attackers to conduct argument injection attacks into a command for mplayer via a crafted filename.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/50205" source="XF">amule-downloadlistctrl-command-execution(50205)</ref>
      <ref url="http://www.securityfocus.com/bid/34683" source="BID">34683</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2009/04/22/1" source="MLIST">[oss-security] 20090422 CVE id request: amule</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1821" source="DEBIAN">DSA-1821</ref>
      <ref url="http://secunia.com/advisories/34839" source="SECUNIA">34839</ref>
      <ref url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=525078" source="MISC">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=525078</ref>
    </refs>
    <vuln_soft>
      <prod vendor="amule" name="amule">
        <vers num="2.2.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1441" published="2009-05-07" name="CVE-2009-1441" modified="2009-05-19" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Heap-based buffer overflow in the ParamTraits&lt;SkBitmap>::Read function in Google Chrome before 1.0.154.64 allows attackers to leverage renderer access to cause a denial of service (application crash) or possibly execute arbitrary code via vectors related to a large bitmap that arrives over the IPC channel.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/50362" source="XF">chrome-paramtraitsskbitmapread-bo(50362)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1266" source="VUPEN" adv="1">ADV-2009-1266</ref>
      <ref url="http://www.securitytracker.com/id?1022174" source="SECTRACK">1022174</ref>
      <ref url="http://www.securityfocus.com/bid/34859" source="BID">34859</ref>
      <ref url="http://secunia.com/advisories/35014" source="SECUNIA" adv="1">35014</ref>
      <ref url="http://osvdb.org/54288" source="OSVDB">54288</ref>
      <ref url="http://googlechromereleases.blogspot.com/2009/05/stable-update-security-fix.html" source="CONFIRM" adv="1">http://googlechromereleases.blogspot.com/2009/05/stable-update-security-fix.html</ref>
      <ref url="http://code.google.com/p/chromium/issues/detail?id=10869" source="CONFIRM">http://code.google.com/p/chromium/issues/detail?id=10869</ref>
    </refs>
    <vuln_soft>
      <prod vendor="google" name="chrome">
        <vers num="0.2.149.29" />
        <vers num="0.2.149.30" />
        <vers num="0.2.152.1" />
        <vers num="0.2.153.1" />
        <vers num="0.3.154.0" />
        <vers num="0.3.154.3" />
        <vers num="0.4.154.18" />
        <vers num="0.4.154.22" />
        <vers num="0.4.154.31" />
        <vers num="0.4.154.33" />
        <vers num="1.0.154.36" />
        <vers num="1.0.154.39" />
        <vers num="1.0.154.42" />
        <vers num="1.0.154.43" />
        <vers num="1.0.154.46" />
        <vers prev="1" num="1.0.154.53" />
        <vers num="1.0.154.59" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1442" published="2009-05-07" name="CVE-2009-1442" modified="2009-05-19" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple integer overflows in Skia, as used in Google Chrome 1.x before 1.0.154.64 and 2.x, and possibly Android, might allow remote attackers to execute arbitrary code in the renderer process via a crafted (1) image or (2) canvas.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://googlechromereleases.blogspot.com/2009/05/stable-update-security-fix.html" source="CONFIRM" patch="1" adv="1">http://googlechromereleases.blogspot.com/2009/05/stable-update-security-fix.html</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1266" source="VUPEN">ADV-2009-1266</ref>
      <ref url="http://www.securitytracker.com/id?1022175" source="SECTRACK">1022175</ref>
      <ref url="http://www.securityfocus.com/bid/34859" source="BID">34859</ref>
      <ref url="http://secunia.com/advisories/35014" source="SECUNIA">35014</ref>
      <ref url="http://osvdb.org/54248" source="OSVDB">54248</ref>
      <ref url="http://code.google.com/p/skia/source/detail?r=159" source="CONFIRM">http://code.google.com/p/skia/source/detail?r=159</ref>
      <ref url="http://code.google.com/p/chromium/issues/detail?id=10736" source="CONFIRM">http://code.google.com/p/chromium/issues/detail?id=10736</ref>
    </refs>
    <vuln_soft>
      <prod vendor="google" name="chrome">
        <vers num="0.2.149.29" />
        <vers num="0.2.149.30" />
        <vers num="0.2.152.1" />
        <vers num="0.2.153.1" />
        <vers num="0.3.154.0" />
        <vers num="0.3.154.3" />
        <vers num="0.4.154.18" />
        <vers num="0.4.154.22" />
        <vers num="0.4.154.31" />
        <vers num="0.4.154.33" />
        <vers num="1.0.154.36" />
        <vers num="1.0.154.39" />
        <vers num="1.0.154.42" />
        <vers num="1.0.154.43" />
        <vers num="1.0.154.46" />
        <vers prev="1" num="1.0.154.53" />
        <vers num="1.0.154.59" />
        <vers num="2.0.156.1" />
        <vers num="2.0.157.0" />
        <vers num="2.0.157.2" />
        <vers num="2.0.158.0" />
        <vers num="2.0.159.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1443" published="2009-04-27" name="CVE-2009-1443" modified="2009-04-28" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Multiple unspecified vulnerabilities in the Server component in OCS Inventory NG before 1.02 have unknown impact and attack vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2009/1152" source="VUPEN" patch="1" adv="1">ADV-2009-1152</ref>
      <ref url="http://www.ocsinventory-ng.org/index.php?mact=News,cntnt01,detail,0&amp;cntnt01articleid=133&amp;cntnt01returnid=51" source="CONFIRM" patch="1" adv="1">http://www.ocsinventory-ng.org/index.php?mact=News,cntnt01,detail,0&amp;cntnt01articleid=133&amp;cntnt01returnid=51</ref>
      <ref url="http://www.securityfocus.com/bid/34694" source="BID">34694</ref>
      <ref url="http://secunia.com/advisories/34763" source="SECUNIA" adv="1">34763</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ocsinventory-ng" name="ocs_inventory_ng">
        <vers num="1.0" edition="beta" />
        <vers num="1.0" edition="rc1" />
        <vers num="1.0" edition="rc2" />
        <vers num="1.0" edition="rc3" />
        <vers num="1.0" edition="rc3-1" />
        <vers prev="1" num="1.01" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1444" published="2009-04-27" name="CVE-2009-1444" modified="2009-05-14" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in indexk.php in WebPortal CMS 0.8-beta allows remote attackers to execute arbitrary PHP code via a URL in the lib_path parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/34687" source="BID">34687</ref>
      <ref url="http://www.milw0rm.com/exploits/8516" source="MILW0RM">8516</ref>
      <ref url="http://osvdb.org/54121" source="OSVDB">54121</ref>
    </refs>
    <vuln_soft>
      <prod vendor="webportal" name="webportal_cms">
        <vers num="0.8_beta" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1445" published="2009-04-27" name="CVE-2009-1445" modified="2009-05-14" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple directory traversal vulnerabilities in WebPortal CMS 0.8-beta allow remote attackers to (1) read arbitrary files via directory traversal sequences in the lang parameter to libraries/helpdocs/help.php and (2) include and execute arbitrary local files via directory traversal sequences in the error parameter to index.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/34687" source="BID">34687</ref>
      <ref url="http://www.milw0rm.com/exploits/8516" source="MILW0RM">8516</ref>
      <ref url="http://osvdb.org/54120" source="OSVDB">54120</ref>
      <ref url="http://osvdb.org/54119" source="OSVDB">54119</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ivano_culmine" name="webportal_cms">
        <vers num="0.8" edition="beta" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1446" published="2009-04-27" name="CVE-2009-1446" modified="2009-05-14" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)" CVSS_score="6.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.0" CVSS_base_score="6.5">
    <desc>
      <descript source="cve">Unrestricted file upload vulnerability in upload.php in Elkagroup Image Gallery 1.0 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in gallery/pictures/. NOTE: some of these details are obtained from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2009/1149" source="VUPEN" adv="1">ADV-2009-1149</ref>
      <ref url="http://www.securityfocus.com/bid/34679" source="BID">34679</ref>
      <ref url="http://www.milw0rm.com/exploits/8514" source="MILW0RM">8514</ref>
      <ref url="http://secunia.com/advisories/25844" source="SECUNIA" adv="1">25844</ref>
      <ref url="http://osvdb.org/54115" source="OSVDB">54115</ref>
    </refs>
    <vuln_soft>
      <prod vendor="elkagroup" name="image_gallery">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1447" published="2009-04-27" name="CVE-2009-1447" modified="2009-04-28" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Unrestricted file upload vulnerability in admin/editor/image.php in e-cart.biz Free Shopping Cart allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in images/.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/49956" source="XF">ecart-image-file-upload(49956)</ref>
      <ref url="http://www.securityfocus.com/bid/34590" source="BID">34590</ref>
      <ref url="http://www.milw0rm.com/exploits/8474" source="MILW0RM">8474</ref>
      <ref url="http://secunia.com/advisories/34736" source="SECUNIA" adv="1">34736</ref>
    </refs>
    <vuln_soft>
      <prod vendor="e-cart" name="free_shopping_cart">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1448" published="2009-04-27" name="CVE-2009-1448" modified="2009-04-29" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in apricot.php in LovPop.net APRICOT, probably 1.20, allows remote attackers to inject arbitrary web script or HTML via unspecified parameters.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/49948" source="XF">apricot-apricot-xss(49948)</ref>
      <ref url="http://jvndb.jvn.jp/en/contents/2009/JVNDB-2009-000019.html" source="JVNDB">JVNDB-2009-000019</ref>
      <ref url="http://jvn.jp/en/jp/JVN82744714/index.html" source="JVN">JVN#82744714</ref>
    </refs>
    <vuln_soft>
      <prod vendor="lovpop" name="apricot">
        <vers num="1.20" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1449" published="2009-04-27" name="CVE-2009-1449" modified="2009-05-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Stack-based buffer overflow in PortableApps CoolPlayer Portable (aka CoolPlayer+ Portable) 2.19.1 allows remote attackers to execute arbitrary code via a skin file (skin.ini) with a large PlaylistSkin parameter.  NOTE: this may overlap CVE-2008-5735.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/50448" source="XF">coolplayerportable-skin-bo(50448)</ref>
      <ref url="http://www.milw0rm.com/exploits/8527" source="MILW0RM">8527</ref>
      <ref url="http://secunia.com/advisories/34816" source="SECUNIA" adv="1">34816</ref>
      <ref url="http://osvdb.org/54113" source="OSVDB">54113</ref>
    </refs>
    <vuln_soft>
      <prod vendor="coolplayer" name="coolplayer">
        <vers num="2.19.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1450" published="2009-04-28" name="CVE-2009-1450" modified="2009-04-28" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in format.php in SMA-DB 0.3.12 allows remote attackers to execute arbitrary PHP code via a URL in the _page_content parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.milw0rm.com/exploits/7936" source="MILW0RM">7936</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bluevirus-design" name="sma-db">
        <vers num="0.3.12" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1451" published="2009-04-28" name="CVE-2009-1451" modified="2009-04-28" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in startpage.php in SMA-DB 0.3.12 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.milw0rm.com/exploits/7936" source="MILW0RM">7936</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bluevirus-design" name="sma-db">
        <vers num="0.3.12" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1452" published="2009-04-28" name="CVE-2009-1452" modified="2009-04-28" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple PHP remote file inclusion vulnerabilities in theme/format.php in SMA-DB 0.3.13 allow remote attackers to execute arbitrary PHP code via a URL in the (1) _page_css and (2) _page_javascript parameters. NOTE: the _page_content vector is already is covered by CVE-2009-1450.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/49928" source="XF">smadb-formatphp-file-include(49928)</ref>
      <ref url="http://www.securityfocus.com/bid/34569" source="BID">34569</ref>
      <ref url="http://www.milw0rm.com/exploits/8460" source="MILW0RM">8460</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bluevirus-design" name="sma-db">
        <vers num="0.3.13" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1453" published="2009-04-28" name="CVE-2009-1453" modified="2009-04-28" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">SQL injection vulnerability in class.eport.php in Tiny Blogr 1.0.0 rc4, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the txtUsername parameter (aka the Username field).  NOTE: some of these details are obtained from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/34581" source="BID">34581</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/502747/100/0/threaded" source="BUGTRAQ">20090417 Tiny Blogr 1.0.0 rc4 Authentication Bypass</ref>
      <ref url="http://www.milw0rm.com/exploits/8464" source="MILW0RM">8464</ref>
      <ref url="http://secunia.com/advisories/34768" source="SECUNIA" adv="1">34768</ref>
    </refs>
    <vuln_soft>
      <prod vendor="anoochit_chalothorn" name="tiny_blogr">
        <vers num="1.0.0" edition="rc4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1454" published="2009-04-28" name="CVE-2009-1454" modified="2009-04-28" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in tasks.php in WebCollab before 2.50 (aka Billy Goat) allows remote attackers to inject arbitrary web script or HTML via the selection parameter in a todo action.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://sourceforge.net/project/shownotes.php?release_id=676245&amp;group_id=75945" source="CONFIRM" patch="1">http://sourceforge.net/project/shownotes.php?release_id=676245&amp;group_id=75945</ref>
      <ref url="http://holisticinfosec.org/content/view/108/45/" source="MISC" patch="1">http://holisticinfosec.org/content/view/108/45/</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/49939" source="XF">webcollab-tasks-xss(49939)</ref>
      <ref url="http://www.securityfocus.com/bid/34576" source="BID">34576</ref>
      <ref url="http://www.osvdb.org/53780" source="OSVDB">53780</ref>
      <ref url="http://secunia.com/advisories/34568" source="SECUNIA" adv="1">34568</ref>
    </refs>
    <vuln_soft>
      <prod vendor="andrew_simpson" name="webcollab">
        <vers num="2.20" />
        <vers num="2.30" />
        <vers num="2.31" />
        <vers prev="1" num="2.40" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1455" published="2009-04-28" name="CVE-2009-1455" modified="2009-04-28" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple cross-site request forgery (CSRF) vulnerabilities in WebCollab before 2.50 (aka Billy Goat) allow remote attackers to hijack the authentication of administrators for requests that change an arbitrary password or have other unspecified impact.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://sourceforge.net/project/shownotes.php?release_id=676245&amp;group_id=75945" source="CONFIRM" patch="1">http://sourceforge.net/project/shownotes.php?release_id=676245&amp;group_id=75945</ref>
      <ref url="http://holisticinfosec.org/content/view/108/45/" source="MISC" patch="1">http://holisticinfosec.org/content/view/108/45/</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/49940" source="XF">webcollab-unspecifed-csrf(49940)</ref>
      <ref url="http://www.osvdb.org/53781" source="OSVDB">53781</ref>
      <ref url="http://secunia.com/advisories/34568" source="SECUNIA" adv="1">34568</ref>
    </refs>
    <vuln_soft>
      <prod vendor="andrew_simpson" name="webcollab">
        <vers num="2.20" />
        <vers num="2.30" />
        <vers num="2.31" />
        <vers num="2.40" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1456" published="2009-04-28" name="CVE-2009-1456" modified="2009-04-28" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)" CVSS_score="6.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.0" CVSS_base_score="6.5">
    <desc>
      <descript source="cve">Directory traversal vulnerability in admin.php in Malleo 1.2.3 allows remote authenticated administrators to include and execute arbitrary local files via a .. (dot dot) in the module parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/34588" source="BID">34588</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/502763/100/0/threaded" source="BUGTRAQ">20090417 Malleo 1.2.3 Local File Inclusion Vulnerability</ref>
      <ref url="http://secunia.com/advisories/34766" source="SECUNIA" adv="1">34766</ref>
    </refs>
    <vuln_soft>
      <prod vendor="stephane_rajalu" name="malleo">
        <vers num="1.2.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1457" published="2009-04-28" name="CVE-2009-1457" modified="2009-07-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in player.php in Nuke Evolution Xtreme 2.x allows remote attackers to inject arbitrary web script or HTML via the defaultVisualExt parameter.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/49944" source="XF">nex-player-xss(49944)</ref>
      <ref url="http://www.securityfocus.com/bid/34594" source="BID">34594</ref>
      <ref url="http://secunia.com/advisories/34783" source="SECUNIA" adv="1">34783</ref>
      <ref url="http://osvdb.org/53779" source="OSVDB">53779</ref>
    </refs>
    <vuln_soft>
      <prod vendor="evolution-extreme" name="nuke_evolution_xtreme">
        <vers num="2.0" />
        <vers num="2.0.7" />
        <vers num="2.1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1458" published="2009-04-28" name="CVE-2009-1458" modified="2009-04-28" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in admin/index.php in razorCMS before 0.4 allow remote attackers to inject arbitrary web script or HTML via (1) the slab parameter in an edit action, (2) the catname parameter in a showcats action, and (3) the cat parameter in a reordercat action.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/49945" source="XF">razorcms-index-xss(49945)</ref>
      <ref url="http://www.securityfocus.com/bid/34566" source="BID">34566</ref>
      <ref url="http://secunia.com/advisories/34744" source="SECUNIA" adv="1">34744</ref>
      <ref url="http://razorcms.co.uk/support/viewtopic.php?f=13&amp;t=325" source="CONFIRM" adv="1">http://razorcms.co.uk/support/viewtopic.php?f=13&amp;t=325</ref>
      <ref url="http://osvdb.org/53776" source="OSVDB">53776</ref>
      <ref url="http://marc.info/?l=full-disclosure&amp;m=123998062108561&amp;w=2" source="FULLDISC">20090416 [follow-up] razorCMS - Multiple Vulnerabilities</ref>
      <ref url="http://marc.info/?l=full-disclosure&amp;m=123990481506680&amp;w=2" source="FULLDISC">20090416 razorCMS - Multiple Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="razorcms" name="razorcms">
        <vers num="0.2" />
        <vers prev="1" num="0.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1459" published="2009-04-28" name="CVE-2009-1459" modified="2009-04-28" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site request forgery (CSRF) vulnerability in razorCMS before 0.4 allows remote attackers to hijack the authentication of administrators for requests that create a web page containing PHP code.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/49947" source="XF">razorcms-unspecified-csrf(49947)</ref>
      <ref url="http://www.securityfocus.com/bid/34566" source="BID">34566</ref>
      <ref url="http://secunia.com/advisories/34744" source="SECUNIA" adv="1">34744</ref>
      <ref url="http://razorcms.co.uk/support/viewtopic.php?f=13&amp;t=325" source="CONFIRM" adv="1">http://razorcms.co.uk/support/viewtopic.php?f=13&amp;t=325</ref>
      <ref url="http://osvdb.org/53778" source="OSVDB">53778</ref>
      <ref url="http://marc.info/?l=full-disclosure&amp;m=123998062108561&amp;w=2" source="FULLDISC">20090416 [follow-up] razorCMS - Multiple Vulnerabilities</ref>
      <ref url="http://marc.info/?l=full-disclosure&amp;m=123990481506680&amp;w=2" source="FULLDISC">20090416 razorCMS - Multiple Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="razorcms" name="razorcms">
        <vers num="0.2" />
        <vers prev="1" num="0.3" edition="rc2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1460" published="2009-04-28" name="CVE-2009-1460" modified="2009-04-28" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">razorCMS before 0.4 uses weak permissions for (1) admin/core/admin_config.php, which allows local users to obtain the administrator's password hash and FTP user credentials; and (2) the root directory, (3) datastore/, and (4) admin/core/, which allows local users to have an unspecified impact.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/49946" source="XF">razorcms-adminconfig-info-disclosure(49946)</ref>
      <ref url="http://www.securityfocus.com/bid/34566" source="BID">34566</ref>
      <ref url="http://secunia.com/advisories/34744" source="SECUNIA" adv="1">34744</ref>
      <ref url="http://razorcms.co.uk/support/viewtopic.php?f=13&amp;t=325" source="CONFIRM" adv="1">http://razorcms.co.uk/support/viewtopic.php?f=13&amp;t=325</ref>
      <ref url="http://osvdb.org/53777" source="OSVDB">53777</ref>
      <ref url="http://marc.info/?l=full-disclosure&amp;m=123998062108561&amp;w=2" source="FULLDISC">20090416 [follow-up] razorCMS - Multiple Vulnerabilities</ref>
      <ref url="http://marc.info/?l=full-disclosure&amp;m=123990481506680&amp;w=2" source="FULLDISC">20090416 razorCMS - Multiple Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="razorcms" name="razorcms">
        <vers num="0.2" />
        <vers prev="1" num="0.3" edition="rc2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2009-1461" published="2009-04-28" name="CVE-2009-1461" modified="2009-05-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:S/C:N/I:P/A:N)" CVSS_score="3.5" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="6.8" CVSS_base_score="3.5">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the Create New Page form in razorCMS 0.3 RC2 and earlier allows remote authenticated users to inject arbitrary web script or HTML via the Page Title field.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/50357" source="XF">razorcms-createnewpage-xss(50357)</ref>
      <ref url="http://www.securityfocus.com/bid/34854" source="BID">34854</ref>
      <ref url="http://razorcms.co.uk/support/viewtopic.php?f=13&amp;t=325" source="MISC" adv="1">http://razorcms.co.uk/support/viewtopic.php?f=13&amp;t=325</ref>
      <ref url="http://marc.info/?l=full-disclosure&amp;m=123998062108561&amp;w=2" source="FULLDISC">20090416 [follow-up] razorCMS - Multiple Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="razorcms" name="razorcms">
        <vers num="0.2" />
        <vers prev="1" num="0.3" edition="rc2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1462" published="2009-04-28" name="CVE-2009-1462" modified="2009-05-13" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">The Security Manager in razorCMS before 0.4 does not verify the permissions of every file owned by the apache user account, which is inconsistent with the documentation and allows local users to have an unspecified impact.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/50358" source="XF">razorcms-security-manager-unspecified(50358)</ref>
      <ref url="http://www.securityfocus.com/bid/34566" source="BID">34566</ref>
      <ref url="http://razorcms.co.uk/support/viewtopic.php?f=13&amp;t=325" source="CONFIRM" adv="1">http://razorcms.co.uk/support/viewtopic.php?f=13&amp;t=325</ref>
      <ref url="http://marc.info/?l=full-disclosure&amp;m=123998062108561&amp;w=2" source="FULLDISC">20090416 [follow-up] razorCMS - Multiple Vulnerabilities</ref>
      <ref url="http://marc.info/?l=full-disclosure&amp;m=123990481506680&amp;w=2" source="FULLDISC">20090416 razorCMS - Multiple Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="razorcms" name="razorcms">
        <vers num="0.2" />
        <vers prev="1" num="0.3" edition="rc2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1463" published="2009-04-28" name="CVE-2009-1463" modified="2009-05-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Static code injection vulnerability in razorCMS before 0.4 allows remote attackers to inject arbitrary PHP code into any page by saving content as a .php file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/50359" source="XF">razorcms-phpfile-code-execution(50359)</ref>
      <ref url="http://www.securityfocus.com/bid/34566" source="BID">34566</ref>
      <ref url="http://razorcms.co.uk/support/viewtopic.php?f=13&amp;t=325" source="CONFIRM" adv="1">http://razorcms.co.uk/support/viewtopic.php?f=13&amp;t=325</ref>
      <ref url="http://marc.info/?l=full-disclosure&amp;m=123998062108561&amp;w=2" source="FULLDISC">20090416 [follow-up] razorCMS - Multiple Vulnerabilities</ref>
      <ref url="http://marc.info/?l=full-disclosure&amp;m=123990481506680&amp;w=2" source="FULLDISC">20090416 razorCMS - Multiple Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="razorcms" name="razorcms">
        <vers num="0.2" />
        <vers prev="1" num="0.3" edition="rc2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1464" published="2009-05-14" name="CVE-2009-1464" modified="2010-05-11" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple cross-site request forgery (CSRF) vulnerabilities in index.aas in Application Access Server (A-A-S) 2.0.48 allow remote attackers to hijack the authentication of administrators for requests that (1) execute arbitrary programs via a command job, (2) stop services via a setservice job, or (3) terminate processes via a killprocess job.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.syhunt.com/advisories/aashack.txt" source="MISC">http://www.syhunt.com/advisories/aashack.txt</ref>
      <ref url="http://www.syhunt.com/advisories/?id=aas-multiple" source="MISC">http://www.syhunt.com/advisories/?id=aas-multiple</ref>
      <ref url="http://www.securityfocus.com/bid/34911" source="BID">34911</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/503434/100/0/threaded" source="BUGTRAQ">20090512 Syhunt: A-A-S (Application Access Server) Multiple Security Vulnerabilities</ref>
      <ref url="http://securitytracker.com/id?1022204" source="SECTRACK">1022204</ref>
      <ref url="http://secunia.com/advisories/35034" source="SECUNIA" adv="1">35034</ref>
    </refs>
    <vuln_soft>
      <prod vendor="klinzmann" name="application_access_server">
        <vers num="2.0.48" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1465" published="2009-05-14" name="CVE-2009-1465" modified="2009-05-23" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Application Access Server (A-A-S) 2.0.48 has "wildbat" as its default password for the admin account, which makes it easier for remote attackers to obtain access.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/50589" source="XF">aas-default-password(50589)</ref>
      <ref url="http://www.syhunt.com/advisories/?id=aas-multiple" source="MISC">http://www.syhunt.com/advisories/?id=aas-multiple</ref>
      <ref url="http://www.securityfocus.com/bid/34911" source="BID">34911</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/503434/100/0/threaded" source="BUGTRAQ">20090512 Syhunt: A-A-S (Application Access Server) Multiple Security Vulnerabilities</ref>
      <ref url="http://securitytracker.com/id?1022204" source="SECTRACK">1022204</ref>
    </refs>
    <vuln_soft>
      <prod vendor="klinzmann" name="application_access_server">
        <vers num="2.0.48" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2009-1466" published="2009-05-14" name="CVE-2009-1466" modified="2009-05-23" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Application Access Server (A-A-S) 2.0.48 stores (1) passwords and (2) the port keyword in cleartext in aas.ini, which allows local users to obtain sensitive information by reading this file.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/50590" source="XF">aas-aas-info-disclosure(50590)</ref>
      <ref url="http://www.syhunt.com/advisories/?id=aas-multiple" source="MISC">http://www.syhunt.com/advisories/?id=aas-multiple</ref>
      <ref url="http://www.securityfocus.com/bid/34911" source="BID">34911</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/503434/100/0/threaded" source="BUGTRAQ">20090512 Syhunt: A-A-S (Application Access Server) Multiple Security Vulnerabilities</ref>
      <ref url="http://securitytracker.com/id?1022204" source="SECTRACK">1022204</ref>
    </refs>
    <vuln_soft>
      <prod vendor="klinzmann" name="application_access_server">
        <vers num="2.0.48" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1467" published="2009-05-05" name="CVE-2009-1467" modified="2009-05-16" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in IceWarp eMail Server and WebMail Server before 9.4.2 allow remote attackers to inject arbitrary web script or HTML via (1) the body of a message, related to the email view and incorrect HTML filtering in the cleanHTML function in server/inc/tools.php; or the (2) title, (3) link, or (4) description element in an RSS feed, related to the getHTML function in server/inc/rss/item.php.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.redteam-pentesting.de/advisories/rt-sa-2009-002" source="MISC" patch="1">http://www.redteam-pentesting.de/advisories/rt-sa-2009-002</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/50331" source="XF">merak-webmail-xss(50331)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1253" source="VUPEN">ADV-2009-1253</ref>
      <ref url="http://www.securitytracker.com/id?1022168" source="SECTRACK">1022168</ref>
      <ref url="http://www.securitytracker.com/id?1022167" source="SECTRACK">1022167</ref>
      <ref url="http://www.securityfocus.com/bid/34825" source="BID">34825</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/503229/100/0/threaded" source="BUGTRAQ">20090505 [RT-SA-2009-002] IceWarp WebMail Server: User-assisted Cross Site Scripting in RSS Feed Reader</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/503225/100/0/threaded" source="BUGTRAQ">20090505 [RT-SA-2009-001] IceWarp WebMail Server: Cross Site Scripting in Email View</ref>
      <ref url="http://www.redteam-pentesting.de/advisories/rt-sa-2009-001" source="MISC">http://www.redteam-pentesting.de/advisories/rt-sa-2009-001</ref>
      <ref url="http://osvdb.org/54227" source="OSVDB">54227</ref>
      <ref url="http://osvdb.org/54226" source="OSVDB">54226</ref>
    </refs>
    <vuln_soft>
      <prod vendor="icewarp" name="email_server">
        <vers num="2.10.105" />
        <vers num="2.10.110" />
        <vers num="2.10.115" />
        <vers num="2.10.140" />
        <vers num="2.10.150" />
        <vers num="2.10.165" />
        <vers num="2.10.170" />
        <vers num="2.10.190" />
        <vers num="2.10.200" />
        <vers num="2.10.210" />
        <vers num="2.10.220" />
        <vers num="2.10.240" />
        <vers num="2.10.250" />
        <vers num="2.10.260" />
        <vers num="2.10.280" />
        <vers num="2.10.290" />
        <vers num="2.10.310" />
        <vers num="2.10.320" />
        <vers num="2.10.330" />
        <vers num="2.10.331" />
        <vers num="2.10.340" />
        <vers num="2.10.350" />
        <vers num="2.10.360" />
        <vers num="3.00.100" />
        <vers num="3.00.110" />
        <vers num="3.00.120" />
        <vers num="3.00.130" />
        <vers num="3.00.140" />
        <vers num="3.10.011" />
        <vers num="3.10.110" />
        <vers num="4.00.30" />
        <vers num="4.10.040" />
        <vers num="4.10.050" />
        <vers num="4.2.1" />
        <vers num="4.2.2" />
        <vers num="4.2.3" />
        <vers num="4.4.1" />
        <vers num="4.4.2" />
        <vers num="5.1.2" />
        <vers num="5.1.3" />
        <vers num="5.1.5" />
        <vers num="5.3.0" />
        <vers num="5.3.2" />
        <vers num="5.4.1" />
        <vers num="5.4.2" />
        <vers num="5.4.3" />
        <vers num="5.4.4" />
        <vers num="5.5.3" />
        <vers num="5.5.4" />
        <vers num="5.5.5" />
        <vers num="5.5.6" />
        <vers num="5.5.7" />
        <vers num="5.7.3" />
        <vers num="5.8.2" />
        <vers num="5.8.3" />
        <vers num="5.8.4" />
        <vers num="5.8.5" />
        <vers num="5.8.6" />
        <vers num="5.9.4" />
        <vers num="6.0.2" />
        <vers num="6.0.3" />
        <vers num="6.0.5" />
        <vers num="6.0.7" />
        <vers num="6.1.0" />
        <vers num="6.2.1" />
        <vers num="7.0.1" />
        <vers num="7.1.4" />
        <vers num="7.1.6" />
        <vers num="7.2.0" />
        <vers num="7.4.0" />
        <vers num="7.4.2" />
        <vers num="7.4.5" />
        <vers num="7.5.2" />
        <vers num="7.6.0" />
        <vers num="7.6.4" />
        <vers num="8.0.1" />
        <vers num="8.0.2" />
        <vers num="8.0.3" />
        <vers num="8.2.0" />
        <vers num="8.2.2" />
        <vers num="8.3.5" />
        <vers num="8.3.8" />
        <vers num="8.5.0" />
        <vers num="8.9.1" />
        <vers num="9.0.0" />
        <vers num="9.1.0" />
        <vers num="9.2.0" />
        <vers prev="1" num="9.3.0" />
      </prod>
      <prod vendor="icewarp" name="webmail_server">
        <vers num="2.10.105" />
        <vers num="2.10.110" />
        <vers num="2.10.115" />
        <vers num="2.10.140" />
        <vers num="2.10.150" />
        <vers num="2.10.165" />
        <vers num="2.10.170" />
        <vers num="2.10.190" />
        <vers num="2.10.200" />
        <vers num="2.10.210" />
        <vers num="2.10.220" />
        <vers num="2.10.240" />
        <vers num="2.10.250" />
        <vers num="2.10.260" />
        <vers num="2.10.280" />
        <vers num="2.10.290" />
        <vers num="2.10.310" />
        <vers num="2.10.320" />
        <vers num="2.10.330" />
        <vers num="2.10.331" />
        <vers num="2.10.340" />
        <vers num="2.10.350" />
        <vers num="2.10.360" />
        <vers num="3.00.100" />
        <vers num="3.00.110" />
        <vers num="3.00.120" />
        <vers num="3.00.130" />
        <vers num="3.00.140" />
        <vers num="3.10.011" />
        <vers num="3.10.110" />
        <vers num="4.00.30" />
        <vers num="4.10.040" />
        <vers num="4.10.050" />
        <vers num="4.2.1" />
        <vers num="4.2.2" />
        <vers num="4.2.3" />
        <vers num="4.4.1" />
        <vers num="4.4.2" />
        <vers num="5.1.2" />
        <vers num="5.1.3" />
        <vers num="5.1.5" />
        <vers num="5.3.0" />
        <vers num="5.3.2" />
        <vers num="5.4.1" />
        <vers num="5.4.2" />
        <vers num="5.4.3" />
        <vers num="5.4.4" />
        <vers num="5.5.3" />
        <vers num="5.5.4" />
        <vers num="5.5.5" />
        <vers num="5.5.6" />
        <vers num="5.5.7" />
        <vers num="5.7.3" />
        <vers num="5.8.2" />
        <vers num="5.8.3" />
        <vers num="5.8.4" />
        <vers num="5.8.5" />
        <vers num="5.8.6" />
        <vers num="5.9.4" />
        <vers num="6.0.2" />
        <vers num="6.0.3" />
        <vers num="6.0.5" />
        <vers num="6.0.7" />
        <vers num="6.1.0" />
        <vers num="6.2.1" />
        <vers num="7.0.1" />
        <vers num="7.1.4" />
        <vers num="7.1.6" />
        <vers num="7.2.0" />
        <vers num="7.4.0" />
        <vers num="7.4.2" />
        <vers num="7.4.5" />
        <vers num="7.5.2" />
        <vers num="7.6.0" />
        <vers num="7.6.4" />
        <vers num="8.0.1" />
        <vers num="8.0.2" />
        <vers num="8.0.3" />
        <vers num="8.2.0" />
        <vers num="8.2.2" />
        <vers num="8.3.5" />
        <vers num="8.3.8" />
        <vers num="8.5.0" />
        <vers num="8.9.1" />
        <vers num="9.0.0" />
        <vers num="9.1.0" />
        <vers num="9.2.0" />
        <vers prev="1" num="9.3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1468" published="2009-05-05" name="CVE-2009-1468" modified="2009-05-16" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)" CVSS_score="6.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.0" CVSS_base_score="6.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in the search form in server/webmail.php in the Groupware component in IceWarp eMail Server and WebMail Server before 9.4.2 allow remote authenticated users to execute arbitrary SQL commands via the (1) sql and (2) order_by elements in an XML search query.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2009/1253" source="VUPEN">ADV-2009-1253</ref>
      <ref url="http://www.securitytracker.com/id?1022169" source="SECTRACK">1022169</ref>
      <ref url="http://www.securityfocus.com/bid/34820" source="BID">34820</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/503226/100/0/threaded" source="BUGTRAQ">20090505 [RT-SA-2009-003] IceWarp WebMail Server: SQL Injection in Groupware Component</ref>
      <ref url="http://www.redteam-pentesting.de/advisories/rt-sa-2009-003" source="MISC">http://www.redteam-pentesting.de/advisories/rt-sa-2009-003</ref>
      <ref url="http://osvdb.org/54228" source="OSVDB">54228</ref>
    </refs>
    <vuln_soft>
      <prod vendor="icewarp" name="email_server">
        <vers num="2.10.105" />
        <vers num="2.10.110" />
        <vers num="2.10.115" />
        <vers num="2.10.140" />
        <vers num="2.10.150" />
        <vers num="2.10.165" />
        <vers num="2.10.170" />
        <vers num="2.10.190" />
        <vers num="2.10.200" />
        <vers num="2.10.210" />
        <vers num="2.10.220" />
        <vers num="2.10.240" />
        <vers num="2.10.250" />
        <vers num="2.10.260" />
        <vers num="2.10.280" />
        <vers num="2.10.290" />
        <vers num="2.10.310" />
        <vers num="2.10.320" />
        <vers num="2.10.330" />
        <vers num="2.10.331" />
        <vers num="2.10.340" />
        <vers num="2.10.350" />
        <vers num="2.10.360" />
        <vers num="3.00.100" />
        <vers num="3.00.110" />
        <vers num="3.00.120" />
        <vers num="3.00.130" />
        <vers num="3.00.140" />
        <vers num="3.10.011" />
        <vers num="3.10.110" />
        <vers num="4.00.30" />
        <vers num="4.10.040" />
        <vers num="4.10.050" />
        <vers num="4.2.1" />
        <vers num="4.2.2" />
        <vers num="4.2.3" />
        <vers num="4.4.1" />
        <vers num="4.4.2" />
        <vers num="5.1.2" />
        <vers num="5.1.3" />
        <vers num="5.1.5" />
        <vers num="5.3.0" />
        <vers num="5.3.2" />
        <vers num="5.4.1" />
        <vers num="5.4.2" />
        <vers num="5.4.3" />
        <vers num="5.4.4" />
        <vers num="5.5.3" />
        <vers num="5.5.4" />
        <vers num="5.5.5" />
        <vers num="5.5.6" />
        <vers num="5.5.7" />
        <vers num="5.7.3" />
        <vers num="5.8.2" />
        <vers num="5.8.3" />
        <vers num="5.8.4" />
        <vers num="5.8.5" />
        <vers num="5.8.6" />
        <vers num="5.9.4" />
        <vers num="6.0.2" />
        <vers num="6.0.3" />
        <vers num="6.0.5" />
        <vers num="6.0.7" />
        <vers num="6.1.0" />
        <vers num="6.2.1" />
        <vers num="7.0.1" />
        <vers num="7.1.4" />
        <vers num="7.1.6" />
        <vers num="7.2.0" />
        <vers num="7.4.0" />
        <vers num="7.4.2" />
        <vers num="7.4.5" />
        <vers num="7.5.2" />
        <vers num="7.6.0" />
        <vers num="7.6.4" />
        <vers num="8.0.1" />
        <vers num="8.0.2" />
        <vers num="8.0.3" />
        <vers num="8.2.0" />
        <vers num="8.2.2" />
        <vers num="8.3.5" />
        <vers num="8.3.8" />
        <vers num="8.5.0" />
        <vers num="8.9.1" />
        <vers num="9.0.0" />
        <vers num="9.1.0" />
        <vers num="9.2.0" />
        <vers prev="1" num="9.3.0" />
      </prod>
      <prod vendor="icewarp" name="webmail_server">
        <vers num="2.10.105" />
        <vers num="2.10.110" />
        <vers num="2.10.115" />
        <vers num="2.10.140" />
        <vers num="2.10.150" />
        <vers num="2.10.165" />
        <vers num="2.10.170" />
        <vers num="2.10.190" />
        <vers num="2.10.200" />
        <vers num="2.10.210" />
        <vers num="2.10.220" />
        <vers num="2.10.240" />
        <vers num="2.10.250" />
        <vers num="2.10.260" />
        <vers num="2.10.280" />
        <vers num="2.10.290" />
        <vers num="2.10.310" />
        <vers num="2.10.320" />
        <vers num="2.10.330" />
        <vers num="2.10.331" />
        <vers num="2.10.340" />
        <vers num="2.10.350" />
        <vers num="2.10.360" />
        <vers num="3.00.100" />
        <vers num="3.00.110" />
        <vers num="3.00.120" />
        <vers num="3.00.130" />
        <vers num="3.00.140" />
        <vers num="3.10.011" />
        <vers num="3.10.110" />
        <vers num="4.00.30" />
        <vers num="4.10.040" />
        <vers num="4.10.050" />
        <vers num="4.2.1" />
        <vers num="4.2.2" />
        <vers num="4.2.3" />
        <vers num="4.4.1" />
        <vers num="4.4.2" />
        <vers num="5.1.2" />
        <vers num="5.1.3" />
        <vers num="5.1.5" />
        <vers num="5.3.0" />
        <vers num="5.3.2" />
        <vers num="5.4.1" />
        <vers num="5.4.2" />
        <vers num="5.4.3" />
        <vers num="5.4.4" />
        <vers num="5.5.3" />
        <vers num="5.5.4" />
        <vers num="5.5.5" />
        <vers num="5.5.6" />
        <vers num="5.5.7" />
        <vers num="5.7.3" />
        <vers num="5.8.2" />
        <vers num="5.8.3" />
        <vers num="5.8.4" />
        <vers num="5.8.5" />
        <vers num="5.8.6" />
        <vers num="5.9.4" />
        <vers num="6.0.2" />
        <vers num="6.0.3" />
        <vers num="6.0.5" />
        <vers num="6.0.7" />
        <vers num="6.1.0" />
        <vers num="6.2.1" />
        <vers num="7.0.1" />
        <vers num="7.1.4" />
        <vers num="7.1.6" />
        <vers num="7.2.0" />
        <vers num="7.4.0" />
        <vers num="7.4.2" />
        <vers num="7.4.5" />
        <vers num="7.5.2" />
        <vers num="7.6.0" />
        <vers num="7.6.4" />
        <vers num="8.0.1" />
        <vers num="8.0.2" />
        <vers num="8.0.3" />
        <vers num="8.2.0" />
        <vers num="8.2.2" />
        <vers num="8.3.5" />
        <vers num="8.3.8" />
        <vers num="8.5.0" />
        <vers num="8.9.1" />
        <vers num="9.0.0" />
        <vers num="9.1.0" />
        <vers num="9.2.0" />
        <vers prev="1" num="9.3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1469" published="2009-05-05" name="CVE-2009-1469" modified="2009-05-16" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">CRLF injection vulnerability in the Forgot Password implementation in server/webmail.php in IceWarp eMail Server and WebMail Server before 9.4.2 makes it easier for remote attackers to trick a user into disclosing credentials via CRLF sequences preceding a Reply-To header in the subject element of an XML document, as demonstrated by triggering an e-mail message from the server that contains a user's correct credentials, and requests that the user compose a reply that includes this message.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/50332" source="XF">merak-forgot-password-header-injection(50332)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1253" source="VUPEN">ADV-2009-1253</ref>
      <ref url="http://www.securitytracker.com/id?1022166" source="SECTRACK">1022166</ref>
      <ref url="http://www.securityfocus.com/bid/34827" source="BID">34827</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/503227/100/0/threaded" source="BUGTRAQ">20090505 [RT-SA-2009-004] IceWarp WebMail Server: Client-Side Specification of "Forgot Password" eMail Content</ref>
      <ref url="http://www.redteam-pentesting.de/advisories/rt-sa-2009-004" source="MISC">http://www.redteam-pentesting.de/advisories/rt-sa-2009-004</ref>
      <ref url="http://osvdb.org/54229" source="OSVDB">54229</ref>
    </refs>
    <vuln_soft>
      <prod vendor="icewarp" name="email_server">
        <vers num="2.10.105" />
        <vers num="2.10.110" />
        <vers num="2.10.115" />
        <vers num="2.10.140" />
        <vers num="2.10.150" />
        <vers num="2.10.165" />
        <vers num="2.10.170" />
        <vers num="2.10.190" />
        <vers num="2.10.200" />
        <vers num="2.10.210" />
        <vers num="2.10.220" />
        <vers num="2.10.240" />
        <vers num="2.10.250" />
        <vers num="2.10.260" />
        <vers num="2.10.280" />
        <vers num="2.10.290" />
        <vers num="2.10.310" />
        <vers num="2.10.320" />
        <vers num="2.10.330" />
        <vers num="2.10.331" />
        <vers num="2.10.340" />
        <vers num="2.10.350" />
        <vers num="2.10.360" />
        <vers num="3.00.100" />
        <vers num="3.00.110" />
        <vers num="3.00.120" />
        <vers num="3.00.130" />
        <vers num="3.00.140" />
        <vers num="3.10.011" />
        <vers num="3.10.110" />
        <vers num="4.00.30" />
        <vers num="4.10.040" />
        <vers num="4.10.050" />
        <vers num="4.2.1" />
        <vers num="4.2.2" />
        <vers num="4.2.3" />
        <vers num="4.4.1" />
        <vers num="4.4.2" />
        <vers num="5.1.2" />
        <vers num="5.1.3" />
        <vers num="5.1.5" />
        <vers num="5.3.0" />
        <vers num="5.3.2" />
        <vers num="5.4.1" />
        <vers num="5.4.2" />
        <vers num="5.4.3" />
        <vers num="5.4.4" />
        <vers num="5.5.3" />
        <vers num="5.5.4" />
        <vers num="5.5.5" />
        <vers num="5.5.6" />
        <vers num="5.5.7" />
        <vers num="5.7.3" />
        <vers num="5.8.2" />
        <vers num="5.8.3" />
        <vers num="5.8.4" />
        <vers num="5.8.5" />
        <vers num="5.8.6" />
        <vers num="5.9.4" />
        <vers num="6.0.2" />
        <vers num="6.0.3" />
        <vers num="6.0.5" />
        <vers num="6.0.7" />
        <vers num="6.1.0" />
        <vers num="6.2.1" />
        <vers num="7.0.1" />
        <vers num="7.1.4" />
        <vers num="7.1.6" />
        <vers num="7.2.0" />
        <vers num="7.4.0" />
        <vers num="7.4.2" />
        <vers num="7.4.5" />
        <vers num="7.5.2" />
        <vers num="7.6.0" />
        <vers num="7.6.4" />
        <vers num="8.0.1" />
        <vers num="8.0.2" />
        <vers num="8.0.3" />
        <vers num="8.2.0" />
        <vers num="8.2.2" />
        <vers num="8.3.5" />
        <vers num="8.3.8" />
        <vers num="8.5.0" />
        <vers num="8.9.1" />
        <vers num="9.0.0" />
        <vers num="9.1.0" />
        <vers num="9.2.0" />
        <vers prev="1" num="9.3.0" />
      </prod>
      <prod vendor="icewarp" name="webmail_server">
        <vers num="2.10.105" />
        <vers num="2.10.110" />
        <vers num="2.10.115" />
        <vers num="2.10.140" />
        <vers num="2.10.150" />
        <vers num="2.10.165" />
        <vers num="2.10.170" />
        <vers num="2.10.190" />
        <vers num="2.10.200" />
        <vers num="2.10.210" />
        <vers num="2.10.220" />
        <vers num="2.10.240" />
        <vers num="2.10.250" />
        <vers num="2.10.260" />
        <vers num="2.10.280" />
        <vers num="2.10.290" />
        <vers num="2.10.310" />
        <vers num="2.10.320" />
        <vers num="2.10.330" />
        <vers num="2.10.331" />
        <vers num="2.10.340" />
        <vers num="2.10.350" />
        <vers num="2.10.360" />
        <vers num="3.00.100" />
        <vers num="3.00.110" />
        <vers num="3.00.120" />
        <vers num="3.00.130" />
        <vers num="3.00.140" />
        <vers num="3.10.011" />
        <vers num="3.10.110" />
        <vers num="4.00.30" />
        <vers num="4.10.040" />
        <vers num="4.10.050" />
        <vers num="4.2.1" />
        <vers num="4.2.2" />
        <vers num="4.2.3" />
        <vers num="4.4.1" />
        <vers num="4.4.2" />
        <vers num="5.1.2" />
        <vers num="5.1.3" />
        <vers num="5.1.5" />
        <vers num="5.3.0" />
        <vers num="5.3.2" />
        <vers num="5.4.1" />
        <vers num="5.4.2" />
        <vers num="5.4.3" />
        <vers num="5.4.4" />
        <vers num="5.5.3" />
        <vers num="5.5.4" />
        <vers num="5.5.5" />
        <vers num="5.5.6" />
        <vers num="5.5.7" />
        <vers num="5.7.3" />
        <vers num="5.8.2" />
        <vers num="5.8.3" />
        <vers num="5.8.4" />
        <vers num="5.8.5" />
        <vers num="5.8.6" />
        <vers num="5.9.4" />
        <vers num="6.0.2" />
        <vers num="6.0.3" />
        <vers num="6.0.5" />
        <vers num="6.0.7" />
        <vers num="6.1.0" />
        <vers num="6.2.1" />
        <vers num="7.0.1" />
        <vers num="7.1.4" />
        <vers num="7.1.6" />
        <vers num="7.2.0" />
        <vers num="7.4.0" />
        <vers num="7.4.2" />
        <vers num="7.4.5" />
        <vers num="7.5.2" />
        <vers num="7.6.0" />
        <vers num="7.6.4" />
        <vers num="8.0.1" />
        <vers num="8.0.2" />
        <vers num="8.0.3" />
        <vers num="8.2.0" />
        <vers num="8.2.2" />
        <vers num="8.3.5" />
        <vers num="8.3.8" />
        <vers num="8.5.0" />
        <vers num="8.9.1" />
        <vers num="9.0.0" />
        <vers num="9.1.0" />
        <vers num="9.2.0" />
        <vers prev="1" num="9.3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1472" published="2009-05-27" name="CVE-2009-1472" modified="2009-06-09" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">The Java client program for the ATEN KH1516i IP KVM switch with firmware 1.0.063 and the KN9116 IP KVM switch with firmware 1.1.104 has a hardcoded AES encryption key, which makes it easier for man-in-the-middle attackers to (1) execute arbitrary Java code, or (2) gain access to machines connected to the switch, by hijacking a session.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/35108" source="BID">35108</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/503827/100/0/threaded" source="BUGTRAQ">20090526 Multiple vulnerabilities in several ATEN IP KVM Switches</ref>
    </refs>
    <vuln_soft>
      <prod vendor="aten" name="kh1516i_ip_kvm_switch">
        <vers num="1.0.063" edition="-" />
        <vers num="1.0.063" edition="-:java_client" />
      </prod>
      <prod vendor="aten" name="kn9116_ip_kvm_switch">
        <vers num="1.1.104" edition="-" />
        <vers num="1.1.104" edition="-:java_client" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1473" published="2009-05-27" name="CVE-2009-1473" modified="2009-06-20" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">The (1) Windows and (2) Java client programs for the ATEN KH1516i IP KVM switch with firmware 1.0.063 and the KN9116 IP KVM switch with firmware 1.1.104 do not properly use RSA cryptography for a symmetric session-key negotiation, which makes it easier for remote attackers to (a) decrypt network traffic, or (b) conduct man-in-the-middle attacks, by repeating unspecified "client-side calculations."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/50849" source="XF">aten-kvm-client-weak-security(50849)</ref>
      <ref url="http://www.securityfocus.com/bid/35108" source="BID">35108</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/503827/100/0/threaded" source="BUGTRAQ">20090526 Multiple vulnerabilities in several ATEN IP KVM Switches</ref>
      <ref url="http://secunia.com/advisories/35241" source="SECUNIA">35241</ref>
    </refs>
    <vuln_soft>
      <prod vendor="aten" name="kh1516i_ip_kvm_switch">
        <vers num="1.0.063" edition="-" />
        <vers num="1.0.063" edition="-:windows_client" />
        <vers num="1.0.063" edition="-:java_client" />
      </prod>
      <prod vendor="aten" name="kn9116_ip_kvm_switch">
        <vers num="1.1.104" edition="-" />
        <vers num="1.1.104" edition="-:java_client" />
        <vers num="1.1.104" edition="-:windows_client" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1474" published="2009-05-27" name="CVE-2009-1474" modified="2009-06-20" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)" CVSS_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_base_score="7.6">
    <desc>
      <descript source="cve">The ATEN KH1516i IP KVM switch with firmware 1.0.063 and the KN9116 IP KVM switch with firmware 1.1.104 do not (1) encrypt mouse events, which makes it easier for man-in-the-middle attackers to perform mouse operations on machines connected to the switch by injecting network traffic; and do not (2) set the secure flag for the session cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/50850" source="XF">aten-kvm-mouse-weak-security(50850)</ref>
      <ref url="http://www.securityfocus.com/bid/35108" source="BID">35108</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/503827/100/0/threaded" source="BUGTRAQ">20090526 Multiple vulnerabilities in several ATEN IP KVM Switches</ref>
      <ref url="http://secunia.com/advisories/35241" source="SECUNIA">35241</ref>
    </refs>
    <vuln_soft>
      <prod vendor="aten" name="kh1516i_ip_kvm_switch">
        <vers num="1.0.063" />
      </prod>
      <prod vendor="aten" name="kn9116_ip_kvm_switch">
        <vers num="1.1.104" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1476" published="2009-05-26" name="CVE-2009-1476" modified="2009-06-09" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Buffer overflow in lib/load_http.c in ippool in Darren Reed IPFilter (aka IP Filter) 4.1.31 allows local users to gain privileges via vectors involving a long hostname in a URL.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/50716" source="XF">ipfilter-loadhttp-bo(50716)</ref>
      <ref url="http://www.securitytracker.com/id?1022272" source="SECTRACK">1022272</ref>
      <ref url="http://www.securityfocus.com/bid/35076" source="BID">35076</ref>
      <ref url="http://securityreason.com/achievement_securityalert/62" source="SREASONRES">20090522 IPFilter (ippool) 4.1.31 lib/load_http.c buffer overflow</ref>
      <ref url="http://cvsweb.netbsd.org/bsdweb.cgi/src/dist/ipf/lib/load_http.c.diff?r1=1.1&amp;r2=1.2&amp;f=h" source="CONFIRM">http://cvsweb.netbsd.org/bsdweb.cgi/src/dist/ipf/lib/load_http.c.diff?r1=1.1&amp;r2=1.2&amp;f=h</ref>
      <ref url="http://cvsweb.netbsd.org/bsdweb.cgi/src/dist/ipf/lib/load_http.c" source="CONFIRM">http://cvsweb.netbsd.org/bsdweb.cgi/src/dist/ipf/lib/load_http.c</ref>
    </refs>
    <vuln_soft>
      <prod vendor="darren_reed" name="ipfilter">
        <vers num="4.1.31" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1477" published="2009-05-27" name="CVE-2009-1477" modified="2009-06-09" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">The https web interfaces on the ATEN KH1516i IP KVM switch with firmware 1.0.063, the KN9116 IP KVM switch with firmware 1.1.104, and the PN9108 power-control unit have a hardcoded SSL private key, which makes it easier for remote attackers to decrypt https sessions by extracting this key from their own switch and then sniffing network traffic to a switch owned by a different customer.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/50851" source="XF">aten-kvm-ssl-weak-security(50851)</ref>
      <ref url="http://www.securityfocus.com/bid/35108" source="BID">35108</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/503827/100/0/threaded" source="BUGTRAQ">20090526 Multiple vulnerabilities in several ATEN IP KVM Switches</ref>
    </refs>
    <vuln_soft>
      <prod vendor="aten" name="kh1516i_ip_kvm_switch">
        <vers num="1.0.063" />
      </prod>
      <prod vendor="aten" name="kn9116_ip_kvm_switch">
        <vers num="1.1.104" />
      </prod>
      <prod vendor="aten" name="pn9108_power_over_the_net">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1478" published="2009-04-29" name="CVE-2009-1478" modified="2009-05-23" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="4.9" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="3.9" CVSS_base_score="4.9">
    <desc>
      <descript source="cve">Multiple unspecified vulnerabilities in the DTrace ioctl handlers in Sun Solaris 10, and OpenSolaris before snv_114, allow local users to cause a denial of service (panic) via unknown vectors.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-257708-1" source="SUNALERT" patch="1" adv="1">257708</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/50220" source="XF">solaris-dtrace-ioctl-dos(50220)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1378" source="VUPEN">ADV-2009-1378</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1199" source="VUPEN">ADV-2009-1199</ref>
      <ref url="http://www.securitytracker.com/id?1022143" source="SECTRACK">1022143</ref>
      <ref url="http://www.securityfocus.com/bid/34753" source="BID">34753</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2009-171.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2009-171.htm</ref>
      <ref url="http://secunia.com/advisories/35098" source="SECUNIA">35098</ref>
      <ref url="http://secunia.com/advisories/34836" source="SECUNIA">34836</ref>
      <ref url="http://osvdb.org/54138" source="OSVDB">54138</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="opensolaris">
        <vers num="snv_01" edition="" />
        <vers num="snv_01" edition=":sparc" />
        <vers num="snv_01" edition=":x86" />
        <vers num="snv_02" edition="" />
        <vers num="snv_02" edition=":sparc" />
        <vers num="snv_02" edition=":x86" />
        <vers num="snv_03" edition="" />
        <vers num="snv_03" edition=":x86" />
        <vers num="snv_03" edition=":sparc" />
        <vers num="snv_04" edition="" />
        <vers num="snv_04" edition=":x86" />
        <vers num="snv_04" edition=":sparc" />
        <vers num="snv_05" edition="" />
        <vers num="snv_05" edition=":sparc" />
        <vers num="snv_05" edition=":x86" />
        <vers num="snv_06" edition="" />
        <vers num="snv_06" edition=":sparc" />
        <vers num="snv_06" edition=":x86" />
        <vers num="snv_07" edition="" />
        <vers num="snv_07" edition=":sparc" />
        <vers num="snv_07" edition=":x86" />
        <vers num="snv_08" edition="" />
        <vers num="snv_08" edition=":x86" />
        <vers num="snv_08" edition=":sparc" />
        <vers num="snv_09" edition="" />
        <vers num="snv_09" edition=":x86" />
        <vers num="snv_09" edition=":sparc" />
        <vers num="snv_10" edition="" />
        <vers num="snv_10" edition=":x86" />
        <vers num="snv_10" edition=":sparc" />
        <vers num="snv_100" edition="" />
        <vers num="snv_100" edition=":sparc" />
        <vers num="snv_100" edition=":x86" />
        <vers num="snv_101" edition="" />
        <vers num="snv_101" edition=":x86" />
        <vers num="snv_101" edition=":sparc" />
        <vers num="snv_102" edition="" />
        <vers num="snv_102" edition=":sparc" />
        <vers num="snv_102" edition=":x86" />
        <vers num="snv_103" edition="" />
        <vers num="snv_103" edition=":x86" />
        <vers num="snv_103" edition=":sparc" />
        <vers num="snv_104" edition="" />
        <vers num="snv_104" edition=":x86" />
        <vers num="snv_104" edition=":sparc" />
        <vers num="snv_105" edition="" />
        <vers num="snv_105" edition=":x86" />
        <vers num="snv_105" edition=":sparc" />
        <vers num="snv_106" edition="" />
        <vers num="snv_106" edition=":sparc" />
        <vers num="snv_106" edition=":x86" />
        <vers num="snv_107" edition="" />
        <vers num="snv_107" edition=":x86" />
        <vers num="snv_107" edition=":sparc" />
        <vers num="snv_108" edition="" />
        <vers num="snv_108" edition=":x86" />
        <vers num="snv_108" edition=":sparc" />
        <vers num="snv_109" edition="" />
        <vers num="snv_109" edition=":x86" />
        <vers num="snv_109" edition=":sparc" />
        <vers num="snv_11" edition="" />
        <vers num="snv_11" edition=":x86" />
        <vers num="snv_11" edition=":sparc" />
        <vers num="snv_110" edition="" />
        <vers num="snv_110" edition=":sparc" />
        <vers num="snv_110" edition=":x86" />
        <vers num="snv_111" edition="" />
        <vers num="snv_111" edition=":sparc" />
        <vers num="snv_112" edition="" />
        <vers num="snv_112" edition=":x86" />
        <vers num="snv_112" edition=":sparc" />
        <vers num="snv_113" edition="" />
        <vers num="snv_113" edition=":sparc" />
        <vers num="snv_113" edition=":x86" />
        <vers num="snv_12" edition="" />
        <vers num="snv_12" edition=":x86" />
        <vers num="snv_12" edition=":sparc" />
        <vers num="snv_13" edition="" />
        <vers num="snv_13" edition=":x86" />
        <vers num="snv_13" edition=":sparc" />
        <vers num="snv_14" edition="" />
        <vers num="snv_14" edition=":sparc" />
        <vers num="snv_14" edition=":x86" />
        <vers num="snv_15" edition="" />
        <vers num="snv_15" edition=":x86" />
        <vers num="snv_15" edition=":sparc" />
        <vers num="snv_16" edition="" />
        <vers num="snv_16" edition=":sparc" />
        <vers num="snv_16" edition=":x86" />
        <vers num="snv_17" edition="" />
        <vers num="snv_17" edition=":x86" />
        <vers num="snv_17" edition=":sparc" />
        <vers num="snv_18" edition="" />
        <vers num="snv_18" edition=":x86" />
        <vers num="snv_18" edition=":sparc" />
        <vers num="snv_19" edition="" />
        <vers num="snv_19" edition=":sparc" />
        <vers num="snv_19" edition=":x86" />
        <vers num="snv_20" edition="" />
        <vers num="snv_20" edition=":x86" />
        <vers num="snv_20" edition=":sparc" />
        <vers num="snv_21" edition="" />
        <vers num="snv_21" edition=":sparc" />
        <vers num="snv_21" edition=":x86" />
        <vers num="snv_22" edition="" />
        <vers num="snv_22" edition=":sparc" />
        <vers num="snv_22" edition=":x86" />
        <vers num="snv_23" edition="" />
        <vers num="snv_23" edition=":sparc" />
        <vers num="snv_23" edition=":x86" />
        <vers num="snv_24" edition="" />
        <vers num="snv_24" edition=":sparc" />
        <vers num="snv_24" edition=":x86" />
        <vers num="snv_25" edition="" />
        <vers num="snv_25" edition=":x86" />
        <vers num="snv_25" edition=":sparc" />
        <vers num="snv_26" edition="" />
        <vers num="snv_26" edition=":x86" />
        <vers num="snv_26" edition=":sparc" />
        <vers num="snv_27" edition="" />
        <vers num="snv_27" edition=":sparc" />
        <vers num="snv_27" edition=":x86" />
        <vers num="snv_28" edition="" />
        <vers num="snv_28" edition=":x86" />
        <vers num="snv_28" edition=":sparc" />
        <vers num="snv_29" edition="" />
        <vers num="snv_29" edition=":x86" />
        <vers num="snv_29" edition=":sparc" />
        <vers num="snv_30" edition="" />
        <vers num="snv_30" edition=":sparc" />
        <vers num="snv_30" edition=":x86" />
        <vers num="snv_31" edition="" />
        <vers num="snv_31" edition=":sparc" />
        <vers num="snv_31" edition=":x86" />
        <vers num="snv_32" edition="" />
        <vers num="snv_32" edition=":x86" />
        <vers num="snv_32" edition=":sparc" />
        <vers num="snv_33" edition="" />
        <vers num="snv_33" edition=":x86" />
        <vers num="snv_33" edition=":sparc" />
        <vers num="snv_34" edition="" />
        <vers num="snv_34" edition=":sparc" />
        <vers num="snv_34" edition=":x86" />
        <vers num="snv_35" edition="" />
        <vers num="snv_35" edition=":sparc" />
        <vers num="snv_35" edition=":x86" />
        <vers num="snv_36" edition="" />
        <vers num="snv_36" edition=":x86" />
        <vers num="snv_36" edition=":sparc" />
        <vers num="snv_37" edition="" />
        <vers num="snv_37" edition=":sparc" />
        <vers num="snv_37" edition=":x86" />
        <vers num="snv_38" edition="" />
        <vers num="snv_38" edition=":sparc" />
        <vers num="snv_38" edition=":x86" />
        <vers num="snv_39" edition="" />
        <vers num="snv_39" edition=":sparc" />
        <vers num="snv_39" edition=":x86" />
        <vers num="snv_40" edition="" />
        <vers num="snv_40" edition=":sparc" />
        <vers num="snv_40" edition=":x86" />
        <vers num="snv_41" edition="" />
        <vers num="snv_41" edition=":sparc" />
        <vers num="snv_41" edition=":x86" />
        <vers num="snv_42" edition="" />
        <vers num="snv_42" edition=":x86" />
        <vers num="snv_42" edition=":sparc" />
        <vers num="snv_43" edition="" />
        <vers num="snv_43" edition=":sparc" />
        <vers num="snv_43" edition=":x86" />
        <vers num="snv_44" edition="" />
        <vers num="snv_44" edition=":x86" />
        <vers num="snv_44" edition=":sparc" />
        <vers num="snv_45" edition="" />
        <vers num="snv_45" edition=":x86" />
        <vers num="snv_45" edition=":sparc" />
        <vers num="snv_46" edition="" />
        <vers num="snv_46" edition=":x86" />
        <vers num="snv_46" edition=":sparc" />
        <vers num="snv_47" edition="" />
        <vers num="snv_47" edition=":x86" />
        <vers num="snv_47" edition=":sparc" />
        <vers num="snv_48" edition="" />
        <vers num="snv_48" edition=":sparc" />
        <vers num="snv_48" edition=":x86" />
        <vers num="snv_49" edition="" />
        <vers num="snv_49" edition=":sparc" />
        <vers num="snv_49" edition=":x86" />
        <vers num="snv_50" edition="" />
        <vers num="snv_50" edition=":sparc" />
        <vers num="snv_50" edition=":x86" />
        <vers num="snv_51" edition="" />
        <vers num="snv_51" edition=":sparc" />
        <vers num="snv_51" edition=":x86" />
        <vers num="snv_52" edition="" />
        <vers num="snv_52" edition=":sparc" />
        <vers num="snv_52" edition=":x86" />
        <vers num="snv_53" edition="" />
        <vers num="snv_53" edition=":sparc" />
        <vers num="snv_53" edition=":x86" />
        <vers num="snv_54" edition="" />
        <vers num="snv_54" edition=":x86" />
        <vers num="snv_54" edition=":sparc" />
        <vers num="snv_55" edition="" />
        <vers num="snv_55" edition=":sparc" />
        <vers num="snv_55" edition=":x86" />
        <vers num="snv_56" edition="" />
        <vers num="snv_56" edition=":x86" />
        <vers num="snv_56" edition=":sparc" />
        <vers num="snv_57" edition="" />
        <vers num="snv_57" edition=":x86" />
        <vers num="snv_57" edition=":sparc" />
        <vers num="snv_58" edition="" />
        <vers num="snv_58" edition=":sparc" />
        <vers num="snv_58" edition=":x86" />
        <vers num="snv_59" edition="" />
        <vers num="snv_59" edition=":sparc" />
        <vers num="snv_59" edition=":x86" />
        <vers num="snv_60" edition="" />
        <vers num="snv_60" edition=":x86" />
        <vers num="snv_60" edition=":sparc" />
        <vers num="snv_61" edition="" />
        <vers num="snv_61" edition=":sparc" />
        <vers num="snv_61" edition=":x86" />
        <vers num="snv_62" edition="" />
        <vers num="snv_62" edition=":x86" />
        <vers num="snv_62" edition=":sparc" />
        <vers num="snv_63" edition="" />
        <vers num="snv_63" edition=":sparc" />
        <vers num="snv_63" edition=":x86" />
        <vers num="snv_64" edition="" />
        <vers num="snv_64" edition=":x86" />
        <vers num="snv_64" edition=":sparc" />
        <vers num="snv_65" edition="" />
        <vers num="snv_65" edition=":x86" />
        <vers num="snv_65" edition=":sparc" />
        <vers num="snv_66" edition="" />
        <vers num="snv_66" edition=":x86" />
        <vers num="snv_66" edition=":sparc" />
        <vers num="snv_67" edition="" />
        <vers num="snv_67" edition=":sparc" />
        <vers num="snv_67" edition=":x86" />
        <vers num="snv_68" edition="" />
        <vers num="snv_68" edition=":x86" />
        <vers num="snv_68" edition=":sparc" />
        <vers num="snv_69" edition="" />
        <vers num="snv_69" edition=":sparc" />
        <vers num="snv_69" edition=":x86" />
        <vers num="snv_70" edition="" />
        <vers num="snv_70" edition=":sparc" />
        <vers num="snv_70" edition=":x86" />
        <vers num="snv_71" edition="" />
        <vers num="snv_71" edition=":x86" />
        <vers num="snv_71" edition=":sparc" />
        <vers num="snv_72" edition="" />
        <vers num="snv_72" edition=":x86" />
        <vers num="snv_72" edition=":sparc" />
        <vers num="snv_73" edition="" />
        <vers num="snv_73" edition=":x86" />
        <vers num="snv_73" edition=":sparc" />
        <vers num="snv_74" edition="" />
        <vers num="snv_74" edition=":sparc" />
        <vers num="snv_74" edition=":x86" />
        <vers num="snv_75" edition="" />
        <vers num="snv_75" edition=":sparc" />
        <vers num="snv_75" edition=":x86" />
        <vers num="snv_76" edition="" />
        <vers num="snv_76" edition=":x86" />
        <vers num="snv_76" edition=":sparc" />
        <vers num="snv_77" edition="" />
        <vers num="snv_77" edition=":sparc" />
        <vers num="snv_77" edition=":x86" />
        <vers num="snv_78" edition="" />
        <vers num="snv_78" edition=":sparc" />
        <vers num="snv_78" edition=":x86" />
        <vers num="snv_79" edition="" />
        <vers num="snv_79" edition=":x86" />
        <vers num="snv_79" edition=":sparc" />
        <vers num="snv_80" edition="" />
        <vers num="snv_80" edition=":x86" />
        <vers num="snv_80" edition=":sparc" />
        <vers num="snv_81" edition="" />
        <vers num="snv_81" edition=":x86" />
        <vers num="snv_81" edition=":sparc" />
        <vers num="snv_82" edition="" />
        <vers num="snv_82" edition=":x86" />
        <vers num="snv_82" edition=":sparc" />
        <vers num="snv_83" edition="" />
        <vers num="snv_83" edition=":x86" />
        <vers num="snv_83" edition=":sparc" />
        <vers num="snv_84" edition="" />
        <vers num="snv_84" edition=":x86" />
        <vers num="snv_84" edition=":sparc" />
        <vers num="snv_85" edition="" />
        <vers num="snv_85" edition=":x86" />
        <vers num="snv_85" edition=":sparc" />
        <vers num="snv_86" edition="" />
        <vers num="snv_86" edition=":sparc" />
        <vers num="snv_86" edition=":x86" />
        <vers num="snv_87" edition="" />
        <vers num="snv_87" edition=":sparc" />
        <vers num="snv_87" edition=":x86" />
        <vers num="snv_88" edition="" />
        <vers num="snv_88" edition=":x86" />
        <vers num="snv_88" edition=":sparc" />
        <vers num="snv_89" edition="" />
        <vers num="snv_89" edition=":x86" />
        <vers num="snv_89" edition=":sparc" />
        <vers num="snv_90" edition="" />
        <vers num="snv_90" edition=":sparc" />
        <vers num="snv_90" edition=":x86" />
        <vers num="snv_91" edition="" />
        <vers num="snv_91" edition=":sparc" />
        <vers num="snv_91" edition=":x86" />
        <vers num="snv_92" edition="" />
        <vers num="snv_92" edition=":sparc" />
        <vers num="snv_92" edition=":x86" />
        <vers num="snv_93" edition="" />
        <vers num="snv_93" edition=":sparc" />
        <vers num="snv_93" edition=":x86" />
        <vers num="snv_94" edition="" />
        <vers num="snv_94" edition=":x86" />
        <vers num="snv_94" edition=":sparc" />
        <vers num="snv_95" edition="" />
        <vers num="snv_95" edition=":x86" />
        <vers num="snv_95" edition=":sparc" />
        <vers num="snv_96" edition="" />
        <vers num="snv_96" edition=":sparc" />
        <vers num="snv_96" edition=":x86" />
        <vers num="snv_97" edition="" />
        <vers num="snv_97" edition=":x86" />
        <vers num="snv_97" edition=":sparc" />
        <vers num="snv_98" edition="" />
        <vers num="snv_98" edition=":sparc" />
        <vers num="snv_98" edition=":x86" />
        <vers num="snv_99" edition="" />
        <vers num="snv_99" edition=":sparc" />
        <vers num="snv_99" edition=":x86" />
      </prod>
      <prod vendor="sun" name="solaris">
        <vers num="10" edition="" />
        <vers num="10" edition=":sparc" />
        <vers num="10" edition=":x86" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1479" published="2009-10-22" name="CVE-2009-1479" modified="2009-10-31" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Directory traversal vulnerability in client/desktop/default.htm in Boxalino before 09.05.25-0421 allows remote attackers to read arbitrary files via a .. (dot dot) in the url parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/53932" source="XF">boxalino-default-directory-traversal(53932)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/507319/100/0/threaded" source="BUGTRAQ">20091020 [CVE-2009-1479] Boxalino - Directory Traversal Vulnerability</ref>
      <ref url="http://www.csnc.ch/misc/files/advisories/CVE-2009-1479-Boxalino-Directory_Traversal.txt" source="MISC">http://www.csnc.ch/misc/files/advisories/CVE-2009-1479-Boxalino-Directory_Traversal.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="boxalino" name="boxalino">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1480" published="2009-04-29" name="CVE-2009-1480" modified="2009-04-29" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in index.php Pragyan CMS 2.6.4 allows remote attackers to execute arbitrary SQL commands via the fileget parameter in a view action and other unspecified vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/34707" source="BID">34707</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/502933/100/0/threaded" source="BUGTRAQ">20090424 Pragyan CMS 2.6.4 Multiple SQL Injection Vulnerabilities</ref>
      <ref url="http://www.milw0rm.com/exploits/8533" source="MILW0RM">8533</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sahil_ahuja" name="pragyan_cms">
        <vers num="2.6.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1481" published="2009-04-29" name="CVE-2009-1481" modified="2009-04-29" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in action.asp in PuterJam's Blog (PJBlog3) 3.0.6.170 allows remote attackers to execute arbitrary SQL commands via the cname parameter in a checkAlias action, as exploited in the wild in April 2009.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/50082" source="XF">pjblog3-action-sql-injection(50082)</ref>
      <ref url="http://www.securityfocus.com/bid/34701" source="BID">34701</ref>
      <ref url="http://secunia.com/advisories/34897" source="SECUNIA" adv="1">34897</ref>
      <ref url="http://osvdb.org/53939" source="OSVDB">53939</ref>
      <ref url="http://downloads.securityfocus.com/vulnerabilities/exploits/34701.vbs" source="MISC">http://downloads.securityfocus.com/vulnerabilities/exploits/34701.vbs</ref>
    </refs>
    <vuln_soft>
      <prod vendor="pjhome" name="puterjams_blog">
        <vers num="3.0.6.170" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1482" published="2009-04-29" name="CVE-2009-1482" modified="2009-05-20" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in action/AttachFile.py in MoinMoin 1.8.2 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) an AttachFile sub-action in the error_msg function or (2) multiple vectors related to package file errors in the upload_form function, different vectors than CVE-2009-0260.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://moinmo.in/SecurityFixes" source="CONFIRM" patch="1" adv="1">http://moinmo.in/SecurityFixes</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/50356" source="XF">moinmoin-errormsg-xss(50356)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1119" source="VUPEN" adv="1">ADV-2009-1119</ref>
      <ref url="http://www.ubuntu.com/usn/USN-774-1" source="UBUNTU">USN-774-1</ref>
      <ref url="http://www.securityfocus.com/bid/34631" source="BID">34631</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1791" source="DEBIAN">DSA-1791</ref>
      <ref url="http://secunia.com/advisories/35024" source="SECUNIA">35024</ref>
      <ref url="http://secunia.com/advisories/34945" source="SECUNIA">34945</ref>
      <ref url="http://secunia.com/advisories/34821" source="SECUNIA" adv="1">34821</ref>
      <ref url="http://hg.moinmo.in/moin/1.8/rev/5f51246a4df1" source="CONFIRM">http://hg.moinmo.in/moin/1.8/rev/5f51246a4df1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="moinmo" name="moinmoin">
        <vers num="1.6.1" />
      </prod>
      <prod vendor="moinmoin" name="moinmoin">
        <vers num="0.1" />
        <vers num="0.10" />
        <vers num="0.11" />
        <vers num="0.2" />
        <vers num="0.3" />
        <vers num="0.7" />
        <vers num="0.8" />
        <vers num="0.9" />
        <vers num="1.0" />
        <vers num="1.1" />
        <vers num="1.2" />
        <vers num="1.2.1" />
        <vers num="1.2.2" />
        <vers num="1.5.0" />
        <vers num="1.5.1" />
        <vers num="1.5.2" />
        <vers num="1.5.3" />
        <vers num="1.5.3_rc1" />
        <vers num="1.5.3_rc2" />
        <vers num="1.5.4" />
        <vers num="1.5.5" />
        <vers num="1.5.5_rc1" />
        <vers num="1.5.5a" />
        <vers num="1.5.6" />
        <vers num="1.5.7" />
        <vers num="1.5.8" />
        <vers num="1.6" />
        <vers num="1.6.0" />
        <vers num="1.6.1" />
        <vers num="1.6.2" />
        <vers num="1.6.3" />
        <vers num="1.7" />
        <vers num="1.7.0" />
        <vers num="1.7.1" />
        <vers num="1.7.2" />
        <vers num="1.7.3" />
        <vers num="1.8.0" />
        <vers num="1.8.1" />
        <vers prev="1" num="1.8.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1483" published="2009-04-29" name="CVE-2009-1483" modified="2009-04-29" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Unrestricted file upload vulnerability in upload-file.php in Adam Patterson Studio Lounge Address Book 2.5, as reachable from index2.php, allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in profiles/.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/49972" source="XF">addressbook-uploadfile-file-upload(49972)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1111" source="VUPEN" adv="1">ADV-2009-1111</ref>
      <ref url="http://www.securityfocus.com/bid/34652" source="BID">34652</ref>
      <ref url="http://www.osvdb.org/53813" source="OSVDB">53813</ref>
      <ref url="http://www.milw0rm.com/exploits/8481" source="MILW0RM">8481</ref>
      <ref url="http://secunia.com/advisories/34761" source="SECUNIA" adv="1">34761</ref>
    </refs>
    <vuln_soft>
      <prod vendor="studiolounge" name="address_book">
        <vers num="2.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1484" published="2009-04-29" name="CVE-2009-1484" modified="2009-04-29" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the web mail interface feature in AXIGEN Mail Server 6.2.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors involving e-mail messages.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/34716" source="BID">34716</ref>
      <ref url="http://secunia.com/advisories/34402" source="SECUNIA" adv="1">34402</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gecad" name="axigen_mail_server">
        <vers num="6.2.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1485" published="2009-04-29" name="CVE-2009-1485" modified="2009-04-30" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The logging feature in eMule Plus before 1.2e allows remote attackers to cause a denial of service (infinite loop) via unspecified attack vectors.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/50081" source="XF">emuleplus-logging-dos(50081)</ref>
      <ref url="http://sourceforge.net/project/shownotes.php?release_id=676726" source="CONFIRM">http://sourceforge.net/project/shownotes.php?release_id=676726</ref>
      <ref url="http://secunia.com/advisories/34799" source="SECUNIA" adv="1">34799</ref>
    </refs>
    <vuln_soft>
      <prod vendor="aemuleplus" name="emule_plus">
        <vers num="1.1b" />
      </prod>
      <prod vendor="emuleplus" name="emule_plus">
        <vers num="1.1" />
        <vers num="1.1a" />
        <vers num="1.1c" />
        <vers num="1.1d" />
        <vers num="1.1e" />
        <vers num="1.1f" />
        <vers num="1.2" />
        <vers num="1.2a" />
        <vers num="1.2b" />
        <vers prev="1" num="1.2c" />
        <vers num="1.2d" />
        <vers num="1.h" />
        <vers num="1a" />
        <vers num="1b" />
        <vers num="1c" />
        <vers num="1d" />
        <vers num="1e" />
        <vers num="1f" />
        <vers num="1g" />
        <vers num="1i" />
        <vers num="1j" />
        <vers num="1k" />
        <vers num="1l" />
        <vers num="1m" />
        <vers num="1o" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1486" published="2009-04-29" name="CVE-2009-1486" modified="2009-05-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Directory traversal vulnerability in pmscript.php in Flatchat 3.0 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the with parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.milw0rm.com/exploits/8549" source="MILW0RM">8549</ref>
      <ref url="http://secunia.com/advisories/34904" source="SECUNIA">34904</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ninjadesigns" name="flatchat">
        <vers num="3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1487" published="2009-04-29" name="CVE-2009-1487" modified="2009-04-29" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in pages/login.php in FunGamez RC1 allows remote attackers to execute arbitrary SQL commands via the login_user (aka username) parameter.  NOTE: some of these details are obtained from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/50090" source="XF">fungamez-login-sql-injection(50090)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1117" source="VUPEN" adv="1">ADV-2009-1117</ref>
      <ref url="http://www.securityfocus.com/bid/34610" source="BID">34610</ref>
      <ref url="http://www.milw0rm.com/exploits/8493" source="MILW0RM">8493</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=124025031126068&amp;w=2" source="BUGTRAQ">20090420 Multiple Remote Vulnerabilities--SQLi-(INSECURE-COOKIE-HANDLING)-LFI--></ref>
    </refs>
    <vuln_soft>
      <prod vendor="rens_rikkerink" name="fungamez">
        <vers num="-" edition="rc1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1488" published="2009-04-29" name="CVE-2009-1488" modified="2009-04-29" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Directory traversal vulnerability in admin/load.php in FunGamez RC1 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the module parameter to index.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/50091" source="XF">fungamez-index-file-include(50091)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1117" source="VUPEN" adv="1">ADV-2009-1117</ref>
      <ref url="http://www.securityfocus.com/bid/34610" source="BID">34610</ref>
      <ref url="http://www.milw0rm.com/exploits/8493" source="MILW0RM">8493</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=124025031126068&amp;w=2" source="BUGTRAQ">20090420 Multiple Remote Vulnerabilities--SQLi-(INSECURE-COOKIE-HANDLING)-LFI--></ref>
    </refs>
    <vuln_soft>
      <prod vendor="rens_rikkerink" name="fungamez">
        <vers num="-" edition="rc1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1489" published="2009-04-29" name="CVE-2009-1489" modified="2009-05-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">includes/user.php in Fungamez RC1 allows remote attackers to bypass authentication and gain administrative access by setting the user cookie parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/50424" source="XF">fungamez-user-auth-bypass(50424)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1117" source="VUPEN" adv="1">ADV-2009-1117</ref>
      <ref url="http://www.milw0rm.com/exploits/8493" source="MILW0RM">8493</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=124025031126068&amp;w=2" source="BUGTRAQ">20090420 Multiple Remote Vulnerabilities--SQLi-(INSECURE-COOKIE-HANDLING)-LFI--></ref>
    </refs>
    <vuln_soft>
      <prod vendor="rens_rikkerink" name="fungamez">
        <vers num="-" edition="rc1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1490" published="2009-05-05" name="CVE-2009-1490" modified="2009-05-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Heap-based buffer overflow in Sendmail before 8.13.2 allows remote attackers to cause a denial of service (daemon crash) and possibly execute arbitrary code via a long X- header, as demonstrated by an X-Testing header.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.sendmail.org/releases/8.13.2" source="CONFIRM" patch="1" adv="1">http://www.sendmail.org/releases/8.13.2</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/50355" source="XF">sendmail-xheader-bo(50355)</ref>
      <ref url="http://www.nmrc.org/~thegnome/blog/apr09/" source="MISC">http://www.nmrc.org/~thegnome/blog/apr09/</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sendmail" name="sendmail">
        <vers num="2.6" edition="" />
        <vers num="2.6" edition=":nt" />
        <vers num="2.6.1" edition="" />
        <vers num="2.6.1" edition=":nt" />
        <vers num="2.6.2" />
        <vers num="3.0" edition="" />
        <vers num="3.0" edition=":nt" />
        <vers num="3.0.1" edition="" />
        <vers num="3.0.1" edition=":nt" />
        <vers num="3.0.2" edition="" />
        <vers num="3.0.2" edition=":nt" />
        <vers num="3.0.3" />
        <vers num="4.1" />
        <vers num="4.55" />
        <vers num="5" />
        <vers num="5.59" />
        <vers num="5.61" />
        <vers num="5.65" />
        <vers num="8.10" />
        <vers num="8.10.0" />
        <vers num="8.10.1" />
        <vers num="8.10.2" />
        <vers num="8.11.0" />
        <vers num="8.11.1" />
        <vers num="8.11.2" />
        <vers num="8.11.3" />
        <vers num="8.11.4" />
        <vers num="8.11.5" />
        <vers num="8.11.6" />
        <vers num="8.11.7" />
        <vers num="8.12" edition="beta10" />
        <vers num="8.12" edition="beta12" />
        <vers num="8.12" edition="beta16" />
        <vers num="8.12" edition="beta5" />
        <vers num="8.12" edition="beta7" />
        <vers num="8.12.0" />
        <vers num="8.12.1" />
        <vers num="8.12.10" />
        <vers num="8.12.11" />
        <vers num="8.12.2" />
        <vers num="8.12.3" />
        <vers num="8.12.4" />
        <vers num="8.12.5" />
        <vers num="8.12.6" />
        <vers num="8.12.7" />
        <vers num="8.12.8" />
        <vers num="8.12.9" />
        <vers num="8.13.0" />
        <vers prev="1" num="8.13.1.2" />
        <vers num="8.6.7" />
        <vers num="8.7.10" />
        <vers num="8.7.6" />
        <vers num="8.7.7" />
        <vers num="8.7.8" />
        <vers num="8.7.9" />
        <vers num="8.8.8" />
        <vers num="8.9.0" />
        <vers num="8.9.1" />
        <vers num="8.9.2" />
        <vers num="8.9.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1491" published="2009-05-05" name="CVE-2009-1491" modified="2009-05-19" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">McAfee GroupShield for Microsoft Exchange on Exchange Server 2000, and possibly other anti-virus or anti-spam products from McAfee or other vendors, does not scan X- headers for malicious content, which allows remote attackers to bypass virus detection via a crafted message, as demonstrated by a message with an X-Testing header and no message body.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/50354" source="XF">groupshield-xheaders-security-bypass(50354)</ref>
      <ref url="http://www.nmrc.org/~thegnome/blog/apr09/" source="MISC">http://www.nmrc.org/~thegnome/blog/apr09/</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mcafee" name="groupshield">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1492" published="2009-04-30" name="CVE-2009-1492" modified="2009-08-12" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">The getAnnots Doc method in the JavaScript API in Adobe Reader and Acrobat 9.1, 8.1.4, 7.1.1, and earlier allows remote attackers to cause a denial of service (memory corruption) or execute arbitrary code via a PDF file that contains an annotation, and has an OpenAction entry with JavaScript code that calls this method with crafted integer arguments.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-133B.html" source="CERT">TA09-133B</ref>
      <ref url="http://www.kb.cert.org/vuls/id/970180" source="CERT-VN">VU#970180</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/50145" source="XF">reader-getannots-code-execution(50145)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1317" source="VUPEN">ADV-2009-1317</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1189" source="VUPEN" adv="1">ADV-2009-1189</ref>
      <ref url="http://www.securitytracker.com/id?1022139" source="SECTRACK">1022139</ref>
      <ref url="http://www.securityfocus.com/bid/34736" source="BID">34736</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-0478.html" source="REDHAT">RHSA-2009:0478</ref>
      <ref url="http://www.milw0rm.com/exploits/8569" source="MILW0RM">8569</ref>
      <ref url="http://www.adobe.com/support/security/bulletins/apsb09-06.html" source="CONFIRM">http://www.adobe.com/support/security/bulletins/apsb09-06.html</ref>
      <ref url="http://support.nortel.com/go/main.jsp?cscat=BLTNDETAIL&amp;id=926953" source="CONFIRM">http://support.nortel.com/go/main.jsp?cscat=BLTNDETAIL&amp;id=926953</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-259028-1" source="SUNALERT">259028</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200907-06.xml" source="GENTOO">GLSA-200907-06</ref>
      <ref url="http://secunia.com/advisories/35734" source="SECUNIA">35734</ref>
      <ref url="http://secunia.com/advisories/35416" source="SECUNIA">35416</ref>
      <ref url="http://secunia.com/advisories/35358" source="SECUNIA">35358</ref>
      <ref url="http://secunia.com/advisories/35152" source="SECUNIA">35152</ref>
      <ref url="http://secunia.com/advisories/35096" source="SECUNIA">35096</ref>
      <ref url="http://secunia.com/advisories/35055" source="SECUNIA">35055</ref>
      <ref url="http://secunia.com/advisories/34924" source="SECUNIA" adv="1">34924</ref>
      <ref url="http://packetstorm.linuxsecurity.com/0904-exploits/getannots.txt" source="MISC">http://packetstorm.linuxsecurity.com/0904-exploits/getannots.txt</ref>
      <ref url="http://osvdb.org/54130" source="OSVDB">54130</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-06/msg00003.html" source="SUSE">SUSE-SR:2009:011</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-05/msg00001.html" source="SUSE">SUSE-SA:2009:027</ref>
      <ref url="http://blogs.adobe.com/psirt/2009/05/adobe_reader_issue_update.html" source="CONFIRM">http://blogs.adobe.com/psirt/2009/05/adobe_reader_issue_update.html</ref>
      <ref url="http://blogs.adobe.com/psirt/2009/04/update_on_adobe_reader_issue.html" source="CONFIRM" adv="1">http://blogs.adobe.com/psirt/2009/04/update_on_adobe_reader_issue.html</ref>
      <ref url="http://blogs.adobe.com/psirt/2009/04/potential_adobe_reader_issue.html" source="MISC" adv="1">http://blogs.adobe.com/psirt/2009/04/potential_adobe_reader_issue.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="adobe" name="acrobat">
        <vers num="3.0" edition="" />
        <vers num="3.0" edition=":mac_os_x" />
        <vers num="3.1" edition="" />
        <vers num="3.1" edition=":mac_os_x" />
        <vers num="4.0" edition="" />
        <vers num="4.0" edition=":mac_os_x" />
        <vers num="4.0.5" edition="" />
        <vers num="4.0.5" edition=":mac_os_x" />
        <vers num="4.0.5a" edition="" />
        <vers num="4.0.5a" edition=":mac_os_x" />
        <vers num="4.0.5c" edition="" />
        <vers num="4.0.5c" edition=":mac_os_x" />
        <vers num="5.0" edition="" />
        <vers num="5.0" edition=":mac_os_x" />
        <vers num="5.0.10" edition="" />
        <vers num="5.0.10" edition=":mac_os_x" />
        <vers num="5.0.5" edition="" />
        <vers num="5.0.5" edition=":mac_os_x" />
        <vers num="5.0.6" />
        <vers num="6.0" edition="" />
        <vers num="6.0" edition=":mac_os_x" />
        <vers num="6.0.1" edition="" />
        <vers num="6.0.1" edition=":mac_os_x" />
        <vers num="6.0.2" edition="" />
        <vers num="6.0.2" edition=":mac_os_x" />
        <vers num="6.0.3" edition="" />
        <vers num="6.0.3" edition=":mac_os_x" />
        <vers num="6.0.4" edition="" />
        <vers num="6.0.4" edition=":mac_os_x" />
        <vers num="6.0.5" />
        <vers num="7.0" edition="" />
        <vers num="7.0" edition=":standard" />
        <vers num="7.0" edition=":professional" />
        <vers num="7.0.1" edition="" />
        <vers num="7.0.1" edition=":professional" />
        <vers num="7.0.1" edition=":standard" />
        <vers num="7.0.2" edition="" />
        <vers num="7.0.2" edition=":professional" />
        <vers num="7.0.2" edition=":standard" />
        <vers num="7.0.3" edition="" />
        <vers num="7.0.3" edition=":professional" />
        <vers num="7.0.3" edition=":standard" />
        <vers num="7.0.4" edition="" />
        <vers num="7.0.4" edition=":professional" />
        <vers num="7.0.4" edition=":standard" />
        <vers num="7.0.5" edition="" />
        <vers num="7.0.5" edition=":professional" />
        <vers num="7.0.5" edition=":standard" />
        <vers num="7.0.6" edition="" />
        <vers num="7.0.6" edition=":professional" />
        <vers num="7.0.6" edition=":standard" />
        <vers num="7.0.7" edition="" />
        <vers num="7.0.7" edition=":professional" />
        <vers num="7.0.7" edition=":standard" />
        <vers num="7.0.8" edition="" />
        <vers num="7.0.8" edition=":elements" />
        <vers num="7.0.8" edition=":standard" />
        <vers num="7.0.8" edition=":professional" />
        <vers num="7.0.9" />
        <vers num="7.1" />
        <vers num="7.1.0" />
        <vers prev="1" num="7.1.1" />
        <vers prev="1" num="8.1.4" />
        <vers prev="1" num="9.1" />
      </prod>
      <prod vendor="adobe" name="reader">
        <vers num="3.0" />
        <vers num="4.0" />
        <vers num="4.0.5" />
        <vers num="4.0.5a" />
        <vers num="4.0.5c" />
        <vers num="4.5" />
        <vers num="5.0" />
        <vers num="5.0.10" />
        <vers num="5.0.11" />
        <vers num="5.0.5" />
        <vers num="5.0.6" />
        <vers num="5.0.7" />
        <vers num="5.0.9" />
        <vers num="5.1" />
        <vers num="6.0" />
        <vers num="6.0.1" />
        <vers num="6.0.2" />
        <vers num="6.0.3" />
        <vers num="6.0.4" />
        <vers num="6.0.5" />
        <vers num="7.0.1" />
        <vers num="7.0.2" />
        <vers num="7.0.3" />
        <vers num="7.0.5" />
        <vers num="7.0.7" />
        <vers num="7.0.8" />
        <vers num="7.0.9" />
        <vers num="7.1.0" />
        <vers prev="1" num="7.1.1" />
        <vers prev="1" num="8.1.4" />
        <vers prev="1" num="9.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1493" published="2009-04-30" name="CVE-2009-1493" modified="2009-08-12" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">The customDictionaryOpen spell method in the JavaScript API in Adobe Reader 9.1, 8.1.4, 7.1.1, and earlier on Linux and UNIX allows remote attackers to cause a denial of service (memory corruption) or execute arbitrary code via a PDF file that triggers a call to this method with a long string in the second argument.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-133B.html" source="CERT">TA09-133B</ref>
      <ref url="http://www.kb.cert.org/vuls/id/970180" source="CERT-VN">VU#970180</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/50146" source="XF">reader-spellcustom-code-execution(50146)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1317" source="VUPEN">ADV-2009-1317</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1189" source="VUPEN" adv="1">ADV-2009-1189</ref>
      <ref url="http://www.securitytracker.com/id?1022139" source="SECTRACK">1022139</ref>
      <ref url="http://www.securityfocus.com/bid/34740" source="BID">34740</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-0478.html" source="REDHAT">RHSA-2009:0478</ref>
      <ref url="http://www.milw0rm.com/exploits/8570" source="MILW0RM">8570</ref>
      <ref url="http://www.adobe.com/support/security/bulletins/apsb09-06.html" source="CONFIRM">http://www.adobe.com/support/security/bulletins/apsb09-06.html</ref>
      <ref url="http://support.nortel.com/go/main.jsp?cscat=BLTNDETAIL&amp;id=926953" source="CONFIRM">http://support.nortel.com/go/main.jsp?cscat=BLTNDETAIL&amp;id=926953</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-259028-1" source="SUNALERT">259028</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200907-06.xml" source="GENTOO">GLSA-200907-06</ref>
      <ref url="http://secunia.com/advisories/35734" source="SECUNIA">35734</ref>
      <ref url="http://secunia.com/advisories/35416" source="SECUNIA">35416</ref>
      <ref url="http://secunia.com/advisories/35358" source="SECUNIA">35358</ref>
      <ref url="http://secunia.com/advisories/35152" source="SECUNIA">35152</ref>
      <ref url="http://secunia.com/advisories/35096" source="SECUNIA">35096</ref>
      <ref url="http://secunia.com/advisories/35055" source="SECUNIA">35055</ref>
      <ref url="http://secunia.com/advisories/34924" source="SECUNIA" adv="1">34924</ref>
      <ref url="http://packetstorm.linuxsecurity.com/0904-exploits/spell.txt" source="MISC">http://packetstorm.linuxsecurity.com/0904-exploits/spell.txt</ref>
      <ref url="http://osvdb.org/54129" source="OSVDB">54129</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-06/msg00003.html" source="SUSE">SUSE-SR:2009:011</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-05/msg00001.html" source="SUSE">SUSE-SA:2009:027</ref>
      <ref url="http://blogs.adobe.com/psirt/2009/05/adobe_reader_issue_update.html" source="CONFIRM">http://blogs.adobe.com/psirt/2009/05/adobe_reader_issue_update.html</ref>
      <ref url="http://blogs.adobe.com/psirt/2009/04/update_on_adobe_reader_issue.html" source="MISC" adv="1">http://blogs.adobe.com/psirt/2009/04/update_on_adobe_reader_issue.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="adobe" name="reader">
        <vers num="8.1.4" />
        <vers num="9.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1494" published="2009-04-30" name="CVE-2009-1494" modified="2009-05-16" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The process_stat function in Memcached 1.2.8 discloses memory-allocation statistics in response to a stats malloc command, which allows remote attackers to obtain potentially sensitive information by sending this command to the daemon's TCP port.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://groups.google.com/group/memcached/browse_thread/thread/ff96a9b88fb5d40e" source="MISC" patch="1">http://groups.google.com/group/memcached/browse_thread/thread/ff96a9b88fb5d40e</ref>
      <ref url="http://code.google.com/p/memcachedb/source/diff?spec=svn98&amp;r=98&amp;format=side&amp;path=/trunk/memcachedb.c" source="MISC" patch="1">http://code.google.com/p/memcachedb/source/diff?spec=svn98&amp;r=98&amp;format=side&amp;path=/trunk/memcachedb.c</ref>
      <ref url="http://code.google.com/p/memcachedb/source/detail?r=98" source="MISC" patch="1">http://code.google.com/p/memcachedb/source/detail?r=98</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/50444" source="XF">memcached-processstat-info-disclosure(50444)</ref>
      <ref url="http://memcached.googlecode.com/files/memcached-1.2.8.tar.gz" source="MISC">http://memcached.googlecode.com/files/memcached-1.2.8.tar.gz</ref>
      <ref url="http://code.google.com/p/memcachedb/source/browse/trunk/ChangeLog?spec=svn98&amp;r=98" source="MISC">http://code.google.com/p/memcachedb/source/browse/trunk/ChangeLog?spec=svn98&amp;r=98</ref>
    </refs>
    <vuln_soft>
      <prod vendor="memcachedb" name="memcached">
        <vers num="1.2.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1495" published="2009-05-01" name="CVE-2009-1495" modified="2009-05-01" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Web File Explorer 3.1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for data/db.mdb.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.milw0rm.com/exploits/8374" source="MILW0RM">8374</ref>
      <ref url="http://secunia.com/advisories/34648" source="SECUNIA" adv="1">34648</ref>
    </refs>
    <vuln_soft>
      <prod vendor="webfileexplorer" name="web_file_explorer">
        <vers num="3.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1496" published="2009-05-01" name="CVE-2009-1496" modified="2009-05-01" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in the Cmi Marketplace (com_cmimarketplace) component 0.1 for Joomla! allows remote attackers to list arbitrary directories via a .. (dot dot) in the viewit parameter to index.php.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/34431" source="BID">34431</ref>
      <ref url="http://www.milw0rm.com/exploits/8367" source="MILW0RM">8367</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ijobid" name="com_cmimarketplace">
        <vers num="0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1497" published="2009-05-01" name="CVE-2009-1497" modified="2009-05-01" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Stack-based buffer overflow in srt2smi.exe in Gretech Online Movie Player (GOM Player) 2.1.16.4635 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a long string in an SRT file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/34427" source="BID">34427</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/502552/100/0/threaded" source="BUGTRAQ">20090408 [Bkis-06-2009] GOM Player Subtitle Buffer Overflow Vulnerability</ref>
      <ref url="http://www.milw0rm.com/exploits/8370" source="MILW0RM">8370</ref>
      <ref url="http://security.bkis.vn/?p=501" source="MISC">http://security.bkis.vn/?p=501</ref>
      <ref url="http://secunia.com/advisories/34639" source="SECUNIA" adv="1">34639</ref>
      <ref url="http://osvdb.org/53361" source="OSVDB">53361</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gomlab" name="gom_player">
        <vers num="2.1.16" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1498" published="2009-05-01" name="CVE-2009-1498" modified="2009-05-02" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Directory traversal vulnerability in inc/profilemain.php in Game Maker 2k Internet Discussion Boards (iDB) 0.2.5 Pre-Alpha SVN 243 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the skin parameter in a settings action to profile.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/49697" source="XF">idb-profilemain-file-include(49697)</ref>
      <ref url="http://www.securityfocus.com/bid/34397" source="BID">34397</ref>
      <ref url="http://www.milw0rm.com/exploits/8357" source="MILW0RM">8357</ref>
    </refs>
    <vuln_soft>
      <prod vendor="idb" name="idb">
        <vers num="0.2.5_pre-alpha" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1499" published="2009-05-01" name="CVE-2009-1499" modified="2009-05-20" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in the MailTo (aka com_mailto) component in Joomla! allows remote attackers to execute arbitrary SQL commands via the article parameter in index.php.  NOTE: SecurityFocus states that this issue has been disputed by the vendor.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/34433" source="BID">34433</ref>
      <ref url="http://www.milw0rm.com/exploits/8366" source="MILW0RM">8366</ref>
    </refs>
    <vuln_soft>
      <prod vendor="joomla" name="com_mailto">
        <vers num="" />
      </prod>
      <prod vendor="joomla" name="joomla!">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1500" published="2009-05-01" name="CVE-2009-1500" modified="2009-07-29" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">SQL injection vulnerability in index.php in ProjectCMS 1.0 Beta allows remote attackers to execute arbitrary SQL commands via the sn parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/34767" source="BID">34767</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/503079/100/0/threaded" source="BUGTRAQ">20090429 SQL INJECTION (SQLi) VULNERABILITY--ProjectCMS v1.0 Beta Final--></ref>
      <ref url="http://www.milw0rm.com/exploits/8565" source="MILW0RM">8565</ref>
    </refs>
    <vuln_soft>
      <prod vendor="projectcms" name="projectcms">
        <vers num="1.0_beta" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1501" published="2009-05-01" name="CVE-2009-1501" modified="2009-05-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the Exif module 5.x-1.x before 5.x-1.2 and 6.x-1.x-dev before April 13, 2009, a module for Drupal, allows remote attackers to inject arbitrary web script or HTML via EXIF tags in an image.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/34774" source="BID" patch="1">34774</ref>
      <ref url="http://drupal.org/node/448958" source="CONFIRM" patch="1" adv="1">http://drupal.org/node/448958</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1213" source="VUPEN">ADV-2009-1213</ref>
      <ref url="http://secunia.com/advisories/34953" source="SECUNIA" adv="1">34953</ref>
    </refs>
    <vuln_soft>
      <prod vendor="exif" name="exif">
        <vers num="5.x-1.0" />
        <vers num="5.x-1.1" />
        <vers num="5.x-1.x" edition="" />
        <vers num="5.x-1.x" edition=":dev" />
        <vers num="6.x-1.x" edition="" />
        <vers num="6.x-1.x" edition=":dev" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1502" published="2009-05-01" name="CVE-2009-1502" modified="2009-05-02" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Directory traversal vulnerability in plugin.php in S-Cms 1.1 Stable and 1.5.2 allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the page parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/34771" source="BID">34771</ref>
      <ref url="http://www.milw0rm.com/exploits/8566" source="MILW0RM">8566</ref>
      <ref url="http://secunia.com/advisories/34940" source="SECUNIA" adv="1">34940</ref>
    </refs>
    <vuln_soft>
      <prod vendor="matteoiammarrone" name="s-cms">
        <vers num="1.1" />
        <vers num="1.5.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1503" published="2009-05-01" name="CVE-2009-1503" modified="2009-05-19" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in login.php in Tiger Document Management System (DMS) allow remote attackers to execute arbitrary SQL commands via the (1) username and (2) password parameters.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/34775" source="BID">34775</ref>
      <ref url="http://www.milw0rm.com/exploits/8571" source="MILW0RM">8571</ref>
      <ref url="http://secunia.com/advisories/34784" source="SECUNIA" adv="1">34784</ref>
    </refs>
    <vuln_soft>
      <prod vendor="tigerdms" name="tigerdms">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1504" published="2009-05-01" name="CVE-2009-1504" modified="2009-05-02" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Absolute Form Processor XE 1.5 allows remote attackers to bypass authentication and gain administrative access by setting the xlaAFPadmin cookie to "lvl=1&amp;userid=1."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.milw0rm.com/exploits/8529" source="MILW0RM">8529</ref>
    </refs>
    <vuln_soft>
      <prod vendor="xigla" name="absolute_control_panel_xe">
        <vers num="1.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1505" published="2009-05-01" name="CVE-2009-1505" modified="2010-03-31" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)" CVSS_score="6.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.0" CVSS_base_score="6.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in the News Page module 5.x before 5.x-1.2 for Drupal allows remote authenticated users, with News Page nodes create and edit privileges, to execute arbitrary SQL commands via the Include Words (aka keywords) field.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/34777" source="BID" patch="1">34777</ref>
      <ref url="http://drupal.org/node/449014" source="CONFIRM" patch="1" adv="1">http://drupal.org/node/449014</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/50248" source="XF">newspage-keywords-sql-injection(50248)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1214" source="VUPEN" adv="1">ADV-2009-1214</ref>
      <ref url="http://secunia.com/advisories/34954" source="SECUNIA" adv="1">34954</ref>
      <ref url="http://osvdb.org/54151" source="OSVDB">54151</ref>
    </refs>
    <vuln_soft>
      <prod vendor="drupal" name="news_page">
        <vers num="5.x-1.1" />
        <vers num="5.x-1.x" edition="" />
        <vers num="5.x-1.x" edition=":dev" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1506" published="2009-05-01" name="CVE-2009-1506" modified="2009-05-02" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">SQL injection vulnerability in classes/Xp.php in eLitius 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter to banner-details.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/34769" source="BID">34769</ref>
      <ref url="http://www.milw0rm.com/exploits/8563" source="MILW0RM">8563</ref>
    </refs>
    <vuln_soft>
      <prod vendor="intelliants" name="elitius">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1507" published="2009-05-01" name="CVE-2009-1507" modified="2009-05-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The Node Access User Reference module 5.x before 5.x-2.0-beta4 and 6.x before 6.x-2.0-beta6, a module for Drupal, interprets an empty CCK user reference as a reference to the anonymous user, which might allow remote attackers to bypass intended access restrictions to read or modify a node.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/34778" source="BID" patch="1">34778</ref>
      <ref url="http://drupal.org/node/449030" source="CONFIRM" patch="1" adv="1">http://drupal.org/node/449030</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1212" source="VUPEN">ADV-2009-1212</ref>
      <ref url="http://secunia.com/advisories/34955" source="SECUNIA" adv="1">34955</ref>
    </refs>
    <vuln_soft>
      <prod vendor="drupal" name="nodeaccess_userreference">
        <vers num="5.x-1.0" />
        <vers num="5.x-1.1" />
        <vers num="5.x-1.2" />
        <vers num="5.x-1.3" />
        <vers num="5.x-1.4" />
        <vers num="5.x-2.0" edition="beta1" />
        <vers num="5.x-2.0" edition="beta2" />
        <vers num="5.x-2.0" edition="beta3" />
        <vers num="6.x-1.0" />
        <vers num="6.x-1.1" />
        <vers num="6.x-1.2" />
        <vers num="6.x-1.4" />
        <vers num="6.x-1.5" />
        <vers num="6.x-1.6" />
        <vers num="6.x-1.7" />
        <vers num="6.x-2.0" edition="beta1" />
        <vers num="6.x-2.0" edition="beta2" />
        <vers num="6.x-2.0" edition="beta3" />
        <vers num="6.x-2.0" edition="beta4" />
        <vers num="6.x-2.0" edition="beta5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1508" published="2009-05-01" name="CVE-2009-1508" modified="2009-05-04" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in the xforum_validateUser function in Common.php in X-Forum 0.6.2 allows remote attackers to execute arbitrary SQL commands, as demonstrated via the cookie_username parameter to Configure.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/49537" source="XF">xforum-cookieusername-sql-injection(49537)</ref>
      <ref url="http://www.securityfocus.com/bid/34302" source="BID">34302</ref>
      <ref url="http://www.milw0rm.com/exploits/8317" source="MILW0RM">8317</ref>
    </refs>
    <vuln_soft>
      <prod vendor="keir_davis" name="x-forum">
        <vers num="0.6.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1509" published="2009-05-01" name="CVE-2009-1509" modified="2009-05-04" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in ajaxp_backend.php in MyioSoft AjaxPortal 3.0 allows remote attackers to execute arbitrary SQL commands via the page parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/34338" source="BID">34338</ref>
      <ref url="http://www.milw0rm.com/exploits/8341" source="MILW0RM">8341</ref>
      <ref url="http://secunia.com/advisories/34529" source="SECUNIA" adv="1">34529</ref>
    </refs>
    <vuln_soft>
      <prod vendor="myiosoft" name="ajaxportal">
        <vers num="3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1510" published="2009-05-01" name="CVE-2009-1510" modified="2009-05-04" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple directory traversal vulnerabilities in KoschtIT Image Gallery 1.82 allow remote attackers to include and execute arbitrary local files via directory traversal sequences in the file parameter to (1) ki_makepic.php and (2) ki_nojsdisplayimage.php in ki_base/.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/34335" source="BID">34335</ref>
      <ref url="http://www.milw0rm.com/exploits/8334" source="MILW0RM">8334</ref>
    </refs>
    <vuln_soft>
      <prod vendor="koschtit" name="koschtit_image_gallery">
        <vers num="1.82" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1511" published="2009-05-01" name="CVE-2009-1511" modified="2009-05-04" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">GDI+ in Microsoft Windows XP SP3 allows remote attackers to cause a denial of service (infinite loop) via a PNG file that contains a certain large btChunkLen value.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/34586" source="BID">34586</ref>
      <ref url="http://www.milw0rm.com/exploits/8466" source="MILW0RM">8466</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition="sp3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1512" published="2009-05-01" name="CVE-2009-1512" modified="2009-05-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)" CVSS_score="6.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.0" CVSS_base_score="6.5">
    <desc>
      <descript source="cve">Static code injection vulnerability in X-Forum 0.6.2 allows remote authenticated administrators to inject arbitrary PHP code into Config.php via the adminEMail parameter to SaveConfig.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/50390" source="XF">xforum-config-code-execution(50390)</ref>
      <ref url="http://www.milw0rm.com/exploits/8317" source="MILW0RM">8317</ref>
    </refs>
    <vuln_soft>
      <prod vendor="keir_davis" name="x-forum">
        <vers num="0.6.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1513" published="2009-05-04" name="CVE-2009-1513" modified="2009-08-08" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Buffer overflow in the PATinst function in src/load_pat.cpp in libmodplug before 0.8.7 allows user-assisted remote attackers to cause a denial of service and possibly execute arbitrary code via a long instrument name.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2009/1200" source="VUPEN" patch="1" adv="1">ADV-2009-1200</ref>
      <ref url="http://www.securityfocus.com/bid/34747" source="BID" patch="1">34747</ref>
      <ref url="http://sourceforge.net/tracker/?func=detail&amp;aid=2777467&amp;group_id=1275&amp;atid=301275" source="CONFIRM" patch="1">http://sourceforge.net/tracker/?func=detail&amp;aid=2777467&amp;group_id=1275&amp;atid=301275</ref>
      <ref url="http://sourceforge.net/project/shownotes.php?release_id=678622&amp;group_id=1275" source="CONFIRM" patch="1">http://sourceforge.net/project/shownotes.php?release_id=678622&amp;group_id=1275</ref>
      <ref url="http://modplug-xmms.git.sourceforge.net/git/gitweb.cgi?p=modplug-xmms;a=commitdiff;h=c4ebb701be6ee9a296a44fdac5a20b7739ff0595" source="CONFIRM" patch="1">http://modplug-xmms.git.sourceforge.net/git/gitweb.cgi?p=modplug-xmms;a=commitdiff;h=c4ebb701be6ee9a296a44fdac5a20b7739ff0595</ref>
      <ref url="http://www.ubuntu.com/usn/USN-771-1" source="UBUNTU">USN-771-1</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2009/04/29/5" source="MLIST">[oss-security] 20090429 Re: CVE Request -- libmodplug</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:128" source="MANDRIVA">MDVSA-2009:128</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1850" source="DEBIAN">DSA-1850</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200907-07.xml" source="GENTOO">GLSA-200907-07</ref>
      <ref url="http://secunia.com/advisories/36158" source="SECUNIA">36158</ref>
      <ref url="http://secunia.com/advisories/35736" source="SECUNIA">35736</ref>
      <ref url="http://secunia.com/advisories/35026" source="SECUNIA">35026</ref>
      <ref url="http://secunia.com/advisories/34927" source="SECUNIA" adv="1">34927</ref>
      <ref url="http://osvdb.org/54109" source="OSVDB">54109</ref>
      <ref url="http://modplug-xmms.cvs.sourceforge.net/viewvc/modplug-xmms/libmodplug/src/load_pat.cpp?r1=1.3&amp;r2=1.4" source="CONFIRM">http://modplug-xmms.cvs.sourceforge.net/viewvc/modplug-xmms/libmodplug/src/load_pat.cpp?r1=1.3&amp;r2=1.4</ref>
      <ref url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=526084" source="CONFIRM">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=526084</ref>
    </refs>
    <vuln_soft>
      <prod vendor="konstanty_bialkowski" name="libmodplug">
        <vers num="0.8" />
        <vers num="0.8.4" />
        <vers num="0.8.5" />
        <vers prev="1" num="0.8.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1514" published="2009-05-04" name="CVE-2009-1514" modified="2009-05-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Google Chrome 1.0.154.53 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a throw statement with a long exception value.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/34786" source="BID">34786</ref>
      <ref url="http://www.milw0rm.com/exploits/8573" source="MILW0RM">8573</ref>
    </refs>
    <vuln_soft>
      <prod vendor="google" name="chrome">
        <vers num="1.0.154.53" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1515" published="2009-05-04" name="CVE-2009-1515" modified="2009-11-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Heap-based buffer overflow in the cdf_read_sat function in src/cdf.c in Christos Zoulas file 5.00 allows user-assisted remote attackers to execute arbitrary code via a crafted compound document file, as demonstrated by a .msi, .doc, or .mpp file.  NOTE: some of these details are obtained from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/34745" source="BID">34745</ref>
      <ref url="http://www.osvdb.org/54100" source="OSVDB">54100</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:129" source="MANDRIVA">MDVSA-2009:129</ref>
      <ref url="http://secunia.com/advisories/34881" source="SECUNIA" adv="1">34881</ref>
      <ref url="http://mx.gw.com/pipermail/file/2009/000379.html" source="MLIST">[file] 20090501 file 5.01 is now available</ref>
      <ref url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=525820" source="MISC">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=525820</ref>
      <ref url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=515603" source="MISC">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=515603</ref>
      <ref url="ftp://ftp.astron.com/pub/file/file-5.01.tar.gz" source="CONFIRM">ftp://ftp.astron.com/pub/file/file-5.01.tar.gz</ref>
    </refs>
    <vuln_soft>
      <prod vendor="christos_zoulas" name="file">
        <vers num="5.00" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1516" published="2009-05-04" name="CVE-2009-1516" modified="2009-05-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Stack-based buffer overflow in the IceWarpServer.APIObject ActiveX control in api.dll in IceWarp Merak Mail Server 9.4.1 might allow context-dependent attackers to execute arbitrary code via a large value in the second argument to the Base64FileEncode method, as possibly demonstrated by a web application that accepts untrusted input for this method.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/34739" source="BID">34739</ref>
      <ref url="http://www.milw0rm.com/exploits/8542" source="MILW0RM">8542</ref>
    </refs>
    <vuln_soft>
      <prod vendor="icewarp" name="merak_mail_server">
        <vers num="9.4.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1517" published="2009-05-04" name="CVE-2009-1517" modified="2009-05-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple insecure method vulnerabilities in the Symantec.EasySetup.1 ActiveX control in EasySetupInt.dll 14.0.4.30167 in the EasySetup wizard in Symantec Norton Ghost 14.0 allow remote attackers to cause a denial of service (browser crash) and possibly execute arbitrary code via unspecified input to the (1) GetBackupLocationPath, (2) CallUninstall, (3) SetupDeleteVolume, (4) CanUseEasySetup, (5) CallAddInitialProtection, and (6) CallTour methods.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/50098" source="XF">nortonghost-easysetupint-dos(50098)</ref>
      <ref url="http://www.shinnai.net/xplits/TXT_Gl6RHStS23c9DANArcJE.html" source="MISC">http://www.shinnai.net/xplits/TXT_Gl6RHStS23c9DANArcJE.html</ref>
      <ref url="http://www.securitytracker.com/id?1022120" source="SECTRACK">1022120</ref>
      <ref url="http://www.securityfocus.com/bid/34696" source="BID">34696</ref>
      <ref url="http://www.milw0rm.com/exploits/8523" source="MILW0RM">8523</ref>
    </refs>
    <vuln_soft>
      <prod vendor="symantec" name="norton_ghost">
        <vers num="14.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1518" published="2009-05-04" name="CVE-2009-1518" modified="2009-05-05" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site request forgery (CSRF) vulnerability in Beltane before 2.3.11 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/34973" source="SECUNIA" adv="1">34973</ref>
      <ref url="http://osvdb.org/54167" source="OSVDB">54167</ref>
    </refs>
    <vuln_soft>
      <prod vendor="beltane" name="beltane">
        <vers num="1.0.15" />
        <vers num="1.0.16" />
        <vers num="2.3.8" />
        <vers prev="1" num="2.3.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1519" published="2009-05-04" name="CVE-2009-1519" modified="2009-05-16" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in index.php in Pecio CMS 1.1.5 allows remote attackers to read arbitrary files via a .. (dot dot) in the language parameter.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/34802" source="BID">34802</ref>
      <ref url="http://www.milw0rm.com/exploits/8593" source="MILW0RM">8593</ref>
    </refs>
    <vuln_soft>
      <prod vendor="pecio-cms" name="pecio_cms">
        <vers num="1.1.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1520" published="2009-05-05" name="CVE-2009-1520" modified="2009-05-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Buffer overflow in the Web GUI in the IBM Tivoli Storage Manager (TSM) client 5.1.0.0 through 5.1.8.2, 5.2.0.0 through 5.2.5.3, 5.3.0.0 through 5.3.6.4, 5.4.0.0 through 5.4.2.6, and 5.5.0.0 through 5.5.1.17 allows attackers to cause a denial of service (application crash) or execute arbitrary code via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/50328" source="XF">ibm-tsm-webgui-bo(50328)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1235" source="VUPEN">ADV-2009-1235</ref>
      <ref url="http://www-1.ibm.com/support/docview.wss?uid=swg1IC59994" source="AIXAPAR" adv="1">IC59994</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg21384389" source="CONFIRM" adv="1">http://www-01.ibm.com/support/docview.wss?uid=swg21384389</ref>
      <ref url="http://secunia.com/advisories/32604" source="SECUNIA">32604</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="tivoli_storage_manager_client">
        <vers num="5.1" />
        <vers num="5.1.8.0" />
        <vers num="5.1.8.2" />
        <vers num="5.2" />
        <vers num="5.2.5.1" />
        <vers num="5.2.5.2" />
        <vers num="5.2.5.3" />
        <vers num="5.3" />
        <vers num="5.3.5.2" />
        <vers num="5.3.5.3" />
        <vers num="5.3.6.3" />
        <vers num="5.3.6.4" />
        <vers num="5.4" />
        <vers num="5.4.1.1" />
        <vers num="5.4.1.2" />
        <vers num="5.4.1.96" />
      </prod>
      <prod vendor="ibm" name="tivoli_storage_manager_express">
        <vers num="5.3" />
        <vers num="5.3.3.0" />
        <vers num="5.3.6.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1521" published="2009-05-05" name="CVE-2009-1521" modified="2009-05-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Java GUI in the IBM Tivoli Storage Manager (TSM) client 5.2.0.0 through 5.2.5.3, 5.3.0.0 through 5.3.6.5, 5.4.0.0 through 5.4.2.6, and 5.5.0.0 through 5.5.1.17, and the TSM Express client 5.3.3.0 through 5.3.6.5, allows attackers to read or modify arbitrary files via unknown vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www-1.ibm.com/support/docview.wss?uid=swg1IC59779" source="AIXAPAR" patch="1" adv="1">IC59779</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg21384389" source="CONFIRM" patch="1" adv="1">http://www-01.ibm.com/support/docview.wss?uid=swg21384389</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/50329" source="XF">ibm-tsm-javagui-security-bypass(50329)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1235" source="VUPEN">ADV-2009-1235</ref>
      <ref url="http://secunia.com/advisories/32604" source="SECUNIA">32604</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="tivoli_storage_manager_client">
        <vers num="5.2.0" />
        <vers num="5.2.2" />
        <vers num="5.2.3" />
        <vers num="5.2.4" />
        <vers num="5.2.5" />
        <vers num="5.3.0" />
        <vers num="5.3.2" />
        <vers num="5.3.3" />
        <vers num="5.3.4" />
        <vers num="5.3.5" />
        <vers num="5.3.6" />
        <vers num="5.4.0" />
        <vers num="5.4.1" />
        <vers num="5.4.2" />
        <vers num="5.5.0" />
        <vers num="5.5.1" />
      </prod>
      <prod vendor="ibm" name="tivoli_storage_manager_express">
        <vers num="5.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1522" published="2009-05-05" name="CVE-2009-1522" modified="2009-05-19" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:N/A:N)" CVSS_score="7.1" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="8.6" CVSS_base_score="7.1">
    <desc>
      <descript source="cve">The IBM Tivoli Storage Manager (TSM) client 5.5.0.0 through 5.5.1.17 on AIX and Windows, when SSL is used, allows remote attackers to conduct unspecified man-in-the-middle attacks and read arbitrary files via unknown vectors.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www-1.ibm.com/support/docview.wss?uid=swg1IC59781" source="AIXAPAR" patch="1" adv="1">IC59781</ref>
      <ref url="http://www-01.ibm.com/support/docview.wss?uid=swg21384389" source="CONFIRM" patch="1" adv="1">http://www-01.ibm.com/support/docview.wss?uid=swg21384389</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/50330" source="XF">ibm-tsm-ssl-mitm(50330)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1235" source="VUPEN">ADV-2009-1235</ref>
      <ref url="http://secunia.com/advisories/32604" source="SECUNIA">32604</ref>
      <ref url="http://osvdb.org/54235" source="OSVDB">54235</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="tivoli_storage_manager_client">
        <vers num="5.5.0.0" />
        <vers num="5.5.0.91" />
        <vers num="5.5.1" />
        <vers num="5.5.1.17" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1523" published="2009-05-05" name="CVE-2009-1523" modified="2010-07-20" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in the HTTP server in Mort Bay Jetty 5.1.14, 6.x before 6.1.17, and 7.x through 7.0.0.M2 allows remote attackers to access arbitrary files via directory traversal sequences in the URI.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/402580" source="CERT-VN">VU#402580</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-May/msg01262.html" source="FEDORA">FEDORA-2009-5513</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-May/msg01259.html" source="FEDORA">FEDORA-2009-5509</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-May/msg01257.html" source="FEDORA">FEDORA-2009-5500</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=499867" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=499867</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1792" source="VUPEN" adv="1">ADV-2010-1792</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1900" source="VUPEN" adv="1">ADV-2009-1900</ref>
      <ref url="http://www.securitytracker.com/id?1022563" source="SECTRACK">1022563</ref>
      <ref url="http://www.securityfocus.com/bid/35675" source="BID">35675</ref>
      <ref url="http://www.securityfocus.com/bid/34800" source="BID">34800</ref>
      <ref url="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujul2009.html" source="CONFIRM">http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujul2009.html</ref>
      <ref url="http://www.kb.cert.org/vuls/id/CRDY-7RKQCY" source="CONFIRM">http://www.kb.cert.org/vuls/id/CRDY-7RKQCY</ref>
      <ref url="http://secunia.com/advisories/40553" source="SECUNIA" adv="1">40553</ref>
      <ref url="http://secunia.com/advisories/35776" source="SECUNIA" adv="1">35776</ref>
      <ref url="http://secunia.com/advisories/35225" source="SECUNIA" adv="1">35225</ref>
      <ref url="http://secunia.com/advisories/35143" source="SECUNIA" adv="1">35143</ref>
      <ref url="http://secunia.com/advisories/34975" source="SECUNIA" adv="1">34975</ref>
      <ref url="http://jira.codehaus.org/browse/JETTY-1004" source="CONFIRM">http://jira.codehaus.org/browse/JETTY-1004</ref>
      <ref url="http://itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c02282388" source="HP">HPSBMA02553</ref>
      <ref url="http://itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c02282388" source="HP">HPSBMA02553</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mortbay" name="jetty">
        <vers num="1.0" />
        <vers num="1.0.1" />
        <vers num="1.1" />
        <vers num="1.1.1" />
        <vers num="1.2.0" />
        <vers num="1.3.0" />
        <vers num="1.3.1" />
        <vers num="1.3.2" />
        <vers num="1.3.3" />
        <vers num="1.3.4" />
        <vers num="1.3.5" />
        <vers num="2.0" edition="alpha1" />
        <vers num="2.0" edition="alpha2" />
        <vers num="2.0" edition="beta1" />
        <vers num="2.0" edition="beta2" />
        <vers num="2.0.0" />
        <vers num="2.0.1" />
        <vers num="2.0.2" />
        <vers num="2.0.3" />
        <vers num="2.0.4" />
        <vers num="2.0.5" />
        <vers num="2.1.0" />
        <vers num="2.1.1" />
        <vers num="2.1.2" />
        <vers num="2.1.3" />
        <vers num="2.1.4" />
        <vers num="2.1.5" />
        <vers num="2.1.6" />
        <vers num="2.1.7" />
        <vers num="2.1.b0" />
        <vers num="2.1.b1" />
        <vers num="2.2" edition="alpha0" />
        <vers num="2.2" edition="alpha1" />
        <vers num="2.2" edition="beta0" />
        <vers num="2.2" edition="beta1" />
        <vers num="2.2" edition="beta2" />
        <vers num="2.2" edition="beta3" />
        <vers num="2.2" edition="beta4" />
        <vers num="2.2.0" />
        <vers num="2.2.1" />
        <vers num="2.2.2" />
        <vers num="2.2.3" />
        <vers num="2.2.4" />
        <vers num="2.2.5" />
        <vers num="2.2.6" />
        <vers num="2.2.7" />
        <vers num="2.2.8" />
        <vers num="2.3.0" />
        <vers num="2.3.0a" />
        <vers num="2.3.1" />
        <vers num="2.3.2" />
        <vers num="2.3.3" />
        <vers num="2.3.4" />
        <vers num="2.3.5" />
        <vers num="2.4.0" />
        <vers num="2.4.1" />
        <vers num="2.4.2" />
        <vers num="2.4.3" />
        <vers num="2.4.4" />
        <vers num="2.4.5" />
        <vers num="2.4.6" />
        <vers num="2.4.7" />
        <vers num="2.4.8" />
        <vers num="2.4.9" />
        <vers num="3.0.0" edition="rc1" />
        <vers num="3.0.0" edition="rc2" />
        <vers num="3.0.0" edition="rc3" />
        <vers num="3.0.0" edition="rc4" />
        <vers num="3.0.0" edition="rc5" />
        <vers num="3.0.0" edition="rc6" />
        <vers num="3.0.0" edition="rc7" />
        <vers num="3.0.0" edition="rc8" />
        <vers num="3.0.1" />
        <vers num="3.0.2" />
        <vers num="3.0.3" />
        <vers num="3.0.4" />
        <vers num="3.0.5" />
        <vers num="3.0.6" />
        <vers num="3.0.a0" />
        <vers num="3.0.a1" />
        <vers num="3.0.a2" />
        <vers num="3.0.a3" />
        <vers num="3.0.a4" />
        <vers num="3.0.a5" />
        <vers num="3.0.a6" />
        <vers num="3.0.a7" />
        <vers num="3.0.a8" />
        <vers num="3.0.a9" />
        <vers num="3.0.a90" />
        <vers num="3.0.a91" />
        <vers num="3.0.a92" />
        <vers num="3.0.a93" />
        <vers num="3.0.a94" />
        <vers num="3.0.a95" />
        <vers num="3.0.a96" />
        <vers num="3.0.a97" />
        <vers num="3.0.a98" />
        <vers num="3.0.a99" />
        <vers num="3.0.b01" />
        <vers num="3.0.b02" />
        <vers num="3.0.b03" />
        <vers num="3.0.b04" />
        <vers num="3.0.b05" />
        <vers num="3.1" edition="rc0" />
        <vers num="3.1" edition="rc1" />
        <vers num="3.1" edition="rc2" />
        <vers num="3.1" edition="rc3" />
        <vers num="3.1" edition="rc4" />
        <vers num="3.1" edition="rc5" />
        <vers num="3.1" edition="rc6" />
        <vers num="3.1" edition="rc7" />
        <vers num="3.1" edition="rc8" />
        <vers num="3.1" edition="rc9" />
        <vers num="3.1.0" />
        <vers num="3.1.1" />
        <vers num="3.1.2" />
        <vers num="3.1.3" />
        <vers num="3.1.4" />
        <vers num="3.1.5" />
        <vers num="3.1.6" />
        <vers num="3.1.7" />
        <vers num="3.1.8" />
        <vers num="3.1.9" />
        <vers num="4.0" edition="rc1" />
        <vers num="4.0" edition="rc2" />
        <vers num="4.0" edition="rc3" />
        <vers num="4.0.0" />
        <vers num="4.0.1" edition="rc0" />
        <vers num="4.0.1" edition="rc1" />
        <vers num="4.0.1" edition="rc2" />
        <vers num="4.0.2" />
        <vers num="4.0.3" />
        <vers num="4.0.4" />
        <vers num="4.0.5" />
        <vers num="4.0.6" />
        <vers num="4.0.b0" />
        <vers num="4.0.b1" />
        <vers num="4.0.b2" />
        <vers num="4.0.d0" />
        <vers num="4.0.d1" />
        <vers num="4.0.d2" />
        <vers num="4.0.d3" />
        <vers num="4.0.d4" />
        <vers num="4.1.0" edition="rc0" />
        <vers num="4.1.0" edition="rc1" />
        <vers num="4.1.0" edition="rc2" />
        <vers num="4.1.0" edition="rc3" />
        <vers num="4.1.0" edition="rc4" />
        <vers num="4.1.0" edition="rc5" />
        <vers num="4.1.0" edition="rc6" />
        <vers num="4.1.1" />
        <vers num="4.1.2" />
        <vers num="4.1.3" />
        <vers num="4.1.4" />
        <vers num="4.1.b0" />
        <vers num="4.1.b1" />
        <vers num="4.1.d0" />
        <vers num="4.1.d1" />
        <vers num="4.1.d2" />
        <vers num="4.2.0" edition="beta0" />
        <vers num="4.2.0" edition="rc0" />
        <vers num="4.2.0" edition="rc1" />
        <vers num="4.2.1" />
        <vers num="4.2.10" edition="pre0" />
        <vers num="4.2.10" edition="pre1" />
        <vers num="4.2.10" edition="pre2" />
        <vers num="4.2.12" />
        <vers num="4.2.14" edition="rc0" />
        <vers num="4.2.14" edition="rc1" />
        <vers num="4.2.15" edition="rc0" />
        <vers num="4.2.16" />
        <vers num="4.2.17" />
        <vers num="4.2.18" />
        <vers num="4.2.19" />
        <vers num="4.2.2" />
        <vers num="4.2.20" edition="rc0" />
        <vers num="4.2.21" />
        <vers num="4.2.22" />
        <vers num="4.2.23" edition="rc0" />
        <vers num="4.2.24" edition="rc0" />
        <vers num="4.2.24" edition="rc1" />
        <vers num="4.2.25" />
        <vers num="4.2.26" />
        <vers num="4.2.27" />
        <vers num="4.2.3" />
        <vers num="4.2.4" edition="rc0" />
        <vers num="4.2.5" />
        <vers num="4.2.6" />
        <vers num="4.2.7" />
        <vers num="4.2.8_01" />
        <vers num="4.2.9" edition="rc1" />
        <vers num="4.2.9" edition="rc2" />
        <vers num="5.0" edition="alpha0" />
        <vers num="5.0" edition="alpha1" />
        <vers num="5.0" edition="alpha2" />
        <vers num="5.0" edition="alpha3" />
        <vers num="5.0" edition="beta0" />
        <vers num="5.0" edition="beta1" />
        <vers num="5.0" edition="beta2" />
        <vers num="5.0" edition="rc1" />
        <vers num="5.0" edition="rc2" />
        <vers num="5.0" edition="rc3" />
        <vers num="5.0" edition="rc4" />
        <vers num="5.0.0" edition="rc0" />
        <vers num="5.1" edition="rc0" />
        <vers num="5.1" edition="rc1" />
        <vers num="5.1.0" />
        <vers num="5.1.1" edition="rc0" />
        <vers num="5.1.1" edition="rc1" />
        <vers num="5.1.10" />
        <vers num="5.1.11" edition="rc0" />
        <vers num="5.1.12" />
        <vers num="5.1.13" />
        <vers num="5.1.14" />
        <vers num="5.1.2" edition="pre0" />
        <vers num="5.1.3" edition="rc0" />
        <vers num="5.1.3" edition="rc1" />
        <vers num="5.1.3" edition="rc2" />
        <vers num="5.1.3" edition="rc3" />
        <vers num="5.1.3" edition="rc4" />
        <vers num="5.1.4" edition="rc0" />
        <vers num="5.1.5" edition="rc0" />
        <vers num="5.1.5" edition="rc1" />
        <vers num="5.1.5" edition="rc2" />
        <vers num="5.1.6" />
        <vers num="5.1.7" edition="rc0" />
        <vers num="5.1.8" />
        <vers num="5.1.9" />
        <vers num="6.0.0" edition="alpha0" />
        <vers num="6.0.0" edition="alpha1" />
        <vers num="6.0.0" edition="alpha2" />
        <vers num="6.0.0" edition="alpha3" />
        <vers num="6.0.0" edition="beta0" />
        <vers num="6.0.0" edition="beta1" />
        <vers num="6.0.0" edition="beta10" />
        <vers num="6.0.0" edition="beta11" />
        <vers num="6.0.0" edition="beta12" />
        <vers num="6.0.0" edition="beta14" />
        <vers num="6.0.0" edition="beta15" />
        <vers num="6.0.0" edition="beta16" />
        <vers num="6.0.0" edition="beta17" />
        <vers num="6.0.0" edition="beta2" />
        <vers num="6.0.0" edition="beta3" />
        <vers num="6.0.0" edition="beta4" />
        <vers num="6.0.0" edition="beta5" />
        <vers num="6.0.0" edition="beta6" />
        <vers num="6.0.0" edition="beta7" />
        <vers num="6.0.0" edition="beta8" />
        <vers num="6.0.0" edition="beta9" />
        <vers num="6.0.0" edition="betax" />
        <vers num="6.0.0" edition="rc0" />
        <vers num="6.0.0" edition="rc1" />
        <vers num="6.0.0" edition="rc2" />
        <vers num="6.0.0" edition="rc3" />
        <vers num="6.0.0" edition="rc4" />
        <vers num="6.0.1" />
        <vers num="6.0.2" />
        <vers num="6.1.0" edition="pre0" />
        <vers num="6.1.0" edition="pre1" />
        <vers num="6.1.0" edition="pre2" />
        <vers num="6.1.0" edition="pre3" />
        <vers num="6.1.0" edition="rc0" />
        <vers num="6.1.0" edition="rc1" />
        <vers num="6.1.0" edition="rc2" />
        <vers num="6.1.0" edition="rc3" />
        <vers num="6.1.1" edition="rc0" />
        <vers num="6.1.10" />
        <vers num="6.1.11" />
        <vers num="6.1.12" edition="rc1" />
        <vers num="6.1.12" edition="rc2" />
        <vers num="6.1.12" edition="rc3" />
        <vers num="6.1.12" edition="rc4" />
        <vers num="6.1.12" edition="rc5" />
        <vers num="6.1.14" />
        <vers num="6.1.15" edition="pre0" />
        <vers num="6.1.15" edition="rc2" />
        <vers num="6.1.15" edition="rc3" />
        <vers num="6.1.15" edition="rc4" />
        <vers num="6.1.15" edition="rc5" />
        <vers prev="1" num="6.1.16" />
        <vers num="6.1.2" edition="pre0" />
        <vers num="6.1.2" edition="pre1" />
        <vers num="6.1.2" edition="rc0" />
        <vers num="6.1.2" edition="rc1" />
        <vers num="6.1.2" edition="rc2" />
        <vers num="6.1.2" edition="rc3" />
        <vers num="6.1.2" edition="rc4" />
        <vers num="6.1.2" edition="rc5" />
        <vers num="6.1.3" />
        <vers num="6.1.4" edition="rc0" />
        <vers num="6.1.4" edition="rc1" />
        <vers num="6.1.5" edition="rc0" />
        <vers num="6.1.6" edition="rc0" />
        <vers num="6.1.6" edition="rc1" />
        <vers num="6.1.7" />
        <vers num="6.1.8" />
        <vers num="6.1.9" />
        <vers prev="1" num="7.0.0" edition="m1" />
        <vers prev="1" num="7.0.0" edition="m2" />
        <vers prev="1" num="7.0.0" edition="pre0" />
        <vers prev="1" num="7.0.0" edition="pre1" />
        <vers prev="1" num="7.0.0" edition="pre3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1524" published="2009-05-05" name="CVE-2009-1524" modified="2010-07-20" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Mort Bay Jetty before 6.1.17 allows remote attackers to inject arbitrary web script or HTML via a directory listing request containing a ; (semicolon) character.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://jira.codehaus.org/browse/JETTY-980" source="CONFIRM" patch="1">http://jira.codehaus.org/browse/JETTY-980</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=499867" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=499867</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1792" source="VUPEN">ADV-2010-1792</ref>
      <ref url="http://www.securityfocus.com/bid/34800" source="BID">34800</ref>
      <ref url="http://secunia.com/advisories/40553" source="SECUNIA">40553</ref>
      <ref url="http://secunia.com/advisories/34975" source="SECUNIA" adv="1">34975</ref>
      <ref url="http://itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c02282388" source="HP">HPSBMA02553</ref>
      <ref url="http://itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c02282388" source="HP">HPSBMA02553</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mortbay" name="jetty">
        <vers num="1.0" />
        <vers num="1.0.1" />
        <vers num="1.1" />
        <vers num="1.1.1" />
        <vers num="1.2.0" />
        <vers num="1.3.0" />
        <vers num="1.3.1" />
        <vers num="1.3.2" />
        <vers num="1.3.3" />
        <vers num="1.3.4" />
        <vers num="1.3.5" />
        <vers num="2.0" edition="alpha1" />
        <vers num="2.0" edition="alpha2" />
        <vers num="2.0" edition="beta1" />
        <vers num="2.0" edition="beta2" />
        <vers num="2.0.0" />
        <vers num="2.0.1" />
        <vers num="2.0.2" />
        <vers num="2.0.3" />
        <vers num="2.0.4" />
        <vers num="2.0.5" />
        <vers num="2.1.0" />
        <vers num="2.1.1" />
        <vers num="2.1.2" />
        <vers num="2.1.3" />
        <vers num="2.1.4" />
        <vers num="2.1.5" />
        <vers num="2.1.6" />
        <vers num="2.1.7" />
        <vers num="2.1.b0" />
        <vers num="2.1.b1" />
        <vers num="2.2" edition="alpha0" />
        <vers num="2.2" edition="alpha1" />
        <vers num="2.2" edition="beta0" />
        <vers num="2.2" edition="beta1" />
        <vers num="2.2" edition="beta2" />
        <vers num="2.2" edition="beta3" />
        <vers num="2.2" edition="beta4" />
        <vers num="2.2.0" />
        <vers num="2.2.1" />
        <vers num="2.2.2" />
        <vers num="2.2.3" />
        <vers num="2.2.4" />
        <vers num="2.2.5" />
        <vers num="2.2.6" />
        <vers num="2.2.7" />
        <vers num="2.2.8" />
        <vers num="2.3.0" />
        <vers num="2.3.0a" />
        <vers num="2.3.1" />
        <vers num="2.3.2" />
        <vers num="2.3.3" />
        <vers num="2.3.4" />
        <vers num="2.3.5" />
        <vers num="2.4.0" />
        <vers num="2.4.1" />
        <vers num="2.4.2" />
        <vers num="2.4.3" />
        <vers num="2.4.4" />
        <vers num="2.4.5" />
        <vers num="2.4.6" />
        <vers num="2.4.7" />
        <vers num="2.4.8" />
        <vers num="2.4.9" />
        <vers num="3.0.0" edition="rc1" />
        <vers num="3.0.0" edition="rc2" />
        <vers num="3.0.0" edition="rc3" />
        <vers num="3.0.0" edition="rc4" />
        <vers num="3.0.0" edition="rc5" />
        <vers num="3.0.0" edition="rc6" />
        <vers num="3.0.0" edition="rc7" />
        <vers num="3.0.0" edition="rc8" />
        <vers num="3.0.1" />
        <vers num="3.0.2" />
        <vers num="3.0.3" />
        <vers num="3.0.4" />
        <vers num="3.0.5" />
        <vers num="3.0.6" />
        <vers num="3.0.a0" />
        <vers num="3.0.a1" />
        <vers num="3.0.a2" />
        <vers num="3.0.a3" />
        <vers num="3.0.a4" />
        <vers num="3.0.a5" />
        <vers num="3.0.a6" />
        <vers num="3.0.a7" />
        <vers num="3.0.a8" />
        <vers num="3.0.a9" />
        <vers num="3.0.a90" />
        <vers num="3.0.a91" />
        <vers num="3.0.a92" />
        <vers num="3.0.a93" />
        <vers num="3.0.a94" />
        <vers num="3.0.a95" />
        <vers num="3.0.a96" />
        <vers num="3.0.a97" />
        <vers num="3.0.a98" />
        <vers num="3.0.a99" />
        <vers num="3.0.b01" />
        <vers num="3.0.b02" />
        <vers num="3.0.b03" />
        <vers num="3.0.b04" />
        <vers num="3.0.b05" />
        <vers num="3.1" edition="rc0" />
        <vers num="3.1" edition="rc1" />
        <vers num="3.1" edition="rc2" />
        <vers num="3.1" edition="rc3" />
        <vers num="3.1" edition="rc4" />
        <vers num="3.1" edition="rc5" />
        <vers num="3.1" edition="rc6" />
        <vers num="3.1" edition="rc7" />
        <vers num="3.1" edition="rc8" />
        <vers num="3.1" edition="rc9" />
        <vers num="3.1.0" />
        <vers num="3.1.1" />
        <vers num="3.1.2" />
        <vers num="3.1.3" />
        <vers num="3.1.4" />
        <vers num="3.1.5" />
        <vers num="3.1.6" />
        <vers num="3.1.7" />
        <vers num="3.1.8" />
        <vers num="3.1.9" />
        <vers num="4.0" edition="rc1" />
        <vers num="4.0" edition="rc2" />
        <vers num="4.0" edition="rc3" />
        <vers num="4.0.0" />
        <vers num="4.0.1" edition="rc0" />
        <vers num="4.0.1" edition="rc1" />
        <vers num="4.0.1" edition="rc2" />
        <vers num="4.0.2" />
        <vers num="4.0.3" />
        <vers num="4.0.4" />
        <vers num="4.0.5" />
        <vers num="4.0.6" />
        <vers num="4.0.b0" />
        <vers num="4.0.b1" />
        <vers num="4.0.b2" />
        <vers num="4.0.d0" />
        <vers num="4.0.d1" />
        <vers num="4.0.d2" />
        <vers num="4.0.d3" />
        <vers num="4.0.d4" />
        <vers num="4.1.0" edition="rc0" />
        <vers num="4.1.0" edition="rc1" />
        <vers num="4.1.0" edition="rc2" />
        <vers num="4.1.0" edition="rc3" />
        <vers num="4.1.0" edition="rc4" />
        <vers num="4.1.0" edition="rc5" />
        <vers num="4.1.0" edition="rc6" />
        <vers num="4.1.1" />
        <vers num="4.1.2" />
        <vers num="4.1.3" />
        <vers num="4.1.4" />
        <vers num="4.1.b0" />
        <vers num="4.1.b1" />
        <vers num="4.1.d0" />
        <vers num="4.1.d1" />
        <vers num="4.1.d2" />
        <vers num="4.2.0" edition="beta0" />
        <vers num="4.2.0" edition="rc0" />
        <vers num="4.2.0" edition="rc1" />
        <vers num="4.2.1" />
        <vers num="4.2.10" edition="pre0" />
        <vers num="4.2.10" edition="pre1" />
        <vers num="4.2.10" edition="pre2" />
        <vers num="4.2.12" />
        <vers num="4.2.14" edition="rc0" />
        <vers num="4.2.14" edition="rc1" />
        <vers num="4.2.15" edition="rc0" />
        <vers num="4.2.16" />
        <vers num="4.2.17" />
        <vers num="4.2.18" />
        <vers num="4.2.19" />
        <vers num="4.2.2" />
        <vers num="4.2.20" edition="rc0" />
        <vers num="4.2.21" />
        <vers num="4.2.22" />
        <vers num="4.2.23" edition="rc0" />
        <vers num="4.2.24" edition="rc0" />
        <vers num="4.2.24" edition="rc1" />
        <vers num="4.2.25" />
        <vers num="4.2.26" />
        <vers num="4.2.27" />
        <vers num="4.2.3" />
        <vers num="4.2.4" edition="rc0" />
        <vers num="4.2.5" />
        <vers num="4.2.6" />
        <vers num="4.2.7" />
        <vers num="4.2.8_01" />
        <vers num="4.2.9" edition="rc1" />
        <vers num="4.2.9" edition="rc2" />
        <vers num="5.0" edition="alpha0" />
        <vers num="5.0" edition="alpha1" />
        <vers num="5.0" edition="alpha2" />
        <vers num="5.0" edition="alpha3" />
        <vers num="5.0" edition="beta0" />
        <vers num="5.0" edition="beta1" />
        <vers num="5.0" edition="beta2" />
        <vers num="5.0" edition="rc1" />
        <vers num="5.0" edition="rc2" />
        <vers num="5.0" edition="rc3" />
        <vers num="5.0" edition="rc4" />
        <vers num="5.0.0" edition="rc0" />
        <vers num="5.1" edition="rc0" />
        <vers num="5.1" edition="rc1" />
        <vers num="5.1.0" />
        <vers num="5.1.1" edition="rc0" />
        <vers num="5.1.1" edition="rc1" />
        <vers num="5.1.10" />
        <vers num="5.1.11" edition="rc0" />
        <vers num="5.1.12" />
        <vers num="5.1.13" />
        <vers num="5.1.14" />
        <vers num="5.1.2" edition="pre0" />
        <vers num="5.1.3" edition="rc0" />
        <vers num="5.1.3" edition="rc1" />
        <vers num="5.1.3" edition="rc2" />
        <vers num="5.1.3" edition="rc3" />
        <vers num="5.1.3" edition="rc4" />
        <vers num="5.1.4" edition="rc0" />
        <vers num="5.1.5" edition="rc0" />
        <vers num="5.1.5" edition="rc1" />
        <vers num="5.1.5" edition="rc2" />
        <vers num="5.1.6" />
        <vers num="5.1.7" edition="rc0" />
        <vers num="5.1.8" />
        <vers num="5.1.9" />
        <vers num="6.0.0" edition="alpha0" />
        <vers num="6.0.0" edition="alpha1" />
        <vers num="6.0.0" edition="alpha2" />
        <vers num="6.0.0" edition="alpha3" />
        <vers num="6.0.0" edition="beta0" />
        <vers num="6.0.0" edition="beta1" />
        <vers num="6.0.0" edition="beta10" />
        <vers num="6.0.0" edition="beta11" />
        <vers num="6.0.0" edition="beta12" />
        <vers num="6.0.0" edition="beta14" />
        <vers num="6.0.0" edition="beta15" />
        <vers num="6.0.0" edition="beta16" />
        <vers num="6.0.0" edition="beta17" />
        <vers num="6.0.0" edition="beta2" />
        <vers num="6.0.0" edition="beta3" />
        <vers num="6.0.0" edition="beta4" />
        <vers num="6.0.0" edition="beta5" />
        <vers num="6.0.0" edition="beta6" />
        <vers num="6.0.0" edition="beta7" />
        <vers num="6.0.0" edition="beta8" />
        <vers num="6.0.0" edition="beta9" />
        <vers num="6.0.0" edition="betax" />
        <vers num="6.0.0" edition="rc0" />
        <vers num="6.0.0" edition="rc1" />
        <vers num="6.0.0" edition="rc2" />
        <vers num="6.0.0" edition="rc3" />
        <vers num="6.0.0" edition="rc4" />
        <vers num="6.0.1" />
        <vers num="6.0.2" />
        <vers num="6.1.0" edition="pre0" />
        <vers num="6.1.0" edition="pre1" />
        <vers num="6.1.0" edition="pre2" />
        <vers num="6.1.0" edition="pre3" />
        <vers num="6.1.0" edition="rc0" />
        <vers num="6.1.0" edition="rc1" />
        <vers num="6.1.0" edition="rc2" />
        <vers num="6.1.0" edition="rc3" />
        <vers num="6.1.1" edition="rc0" />
        <vers num="6.1.10" />
        <vers num="6.1.11" />
        <vers num="6.1.12" edition="rc1" />
        <vers num="6.1.12" edition="rc2" />
        <vers num="6.1.12" edition="rc3" />
        <vers num="6.1.12" edition="rc4" />
        <vers num="6.1.12" edition="rc5" />
        <vers num="6.1.14" />
        <vers num="6.1.15" edition="pre0" />
        <vers num="6.1.15" edition="rc2" />
        <vers num="6.1.15" edition="rc3" />
        <vers num="6.1.15" edition="rc4" />
        <vers num="6.1.15" edition="rc5" />
        <vers prev="1" num="6.1.16" />
        <vers num="6.1.2" edition="pre0" />
        <vers num="6.1.2" edition="pre1" />
        <vers num="6.1.2" edition="rc0" />
        <vers num="6.1.2" edition="rc1" />
        <vers num="6.1.2" edition="rc2" />
        <vers num="6.1.2" edition="rc3" />
        <vers num="6.1.2" edition="rc4" />
        <vers num="6.1.2" edition="rc5" />
        <vers num="6.1.3" />
        <vers num="6.1.4" edition="rc0" />
        <vers num="6.1.4" edition="rc1" />
        <vers num="6.1.5" edition="rc0" />
        <vers num="6.1.6" edition="rc0" />
        <vers num="6.1.6" edition="rc1" />
        <vers num="6.1.7" />
        <vers num="6.1.8" />
        <vers num="6.1.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1525" published="2009-05-05" name="CVE-2009-1525" modified="2009-05-08" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:S/C:C/I:C/A:C)" CVSS_score="8.5" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="6.8" CVSS_base_score="8.5">
    <desc>
      <descript source="cve">CMD_DB in JBMC Software DirectAdmin before 1.334 allows remote authenticated users to gain privileges via shell metacharacters in the name parameter during a restore action.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/50167" source="XF">directadmin-cmddb-command-execution(50167)</ref>
      <ref url="http://www.directadmin.com/features.php?id=968" source="CONFIRM" adv="1">http://www.directadmin.com/features.php?id=968</ref>
      <ref url="http://secunia.com/advisories/34861" source="SECUNIA" adv="1">34861</ref>
      <ref url="http://osvdb.org/54015" source="OSVDB">54015</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2009-04/0228.html" source="FULLDISC">20090422 DirectAdmin &lt; 1.33.4 Local file overwrite &amp; Local root escalation</ref>
    </refs>
    <vuln_soft>
      <prod vendor="jbmc-software" name="directadmin">
        <vers num="0.95" />
        <vers num="1" />
        <vers num="1.01" />
        <vers num="1.02" />
        <vers num="1.03" />
        <vers num="1.04" />
        <vers num="1.05" />
        <vers num="1.06" />
        <vers num="1.07" />
        <vers num="1.08" />
        <vers num="1.081" />
        <vers num="1.09" />
        <vers num="1.1" />
        <vers num="1.11" />
        <vers num="1.111" />
        <vers num="1.12" />
        <vers num="1.121" />
        <vers num="1.13" />
        <vers num="1.14" />
        <vers num="1.15" />
        <vers num="1.151" />
        <vers num="1.152" />
        <vers num="1.16" />
        <vers num="1.161" />
        <vers num="1.17" />
        <vers num="1.171" />
        <vers num="1.172" />
        <vers num="1.173" />
        <vers num="1.174" />
        <vers num="1.1741" />
        <vers num="1.18" />
        <vers num="1.181" />
        <vers num="1.19" />
        <vers num="1.192" />
        <vers num="1.193" />
        <vers num="1.1941" />
        <vers num="1.195" />
        <vers num="1.196" />
        <vers num="1.2" />
        <vers num="1.201" />
        <vers num="1.202" />
        <vers num="1.203" />
        <vers num="1.204" />
        <vers num="1.205" />
        <vers num="1.206" />
        <vers num="1.207" />
        <vers num="1.21" />
        <vers num="1.211" />
        <vers num="1.212" />
        <vers num="1.213" />
        <vers num="1.22" />
        <vers num="1.221" />
        <vers num="1.222" />
        <vers num="1.223" />
        <vers num="1.224" />
        <vers num="1.225" />
        <vers num="1.226" />
        <vers num="1.23" />
        <vers num="1.231" />
        <vers num="1.232" />
        <vers num="1.233" />
        <vers num="1.234" />
        <vers num="1.235" />
        <vers num="1.24" />
        <vers num="1.241" />
        <vers num="1.242" />
        <vers num="1.243" />
        <vers num="1.244" />
        <vers num="1.25" />
        <vers num="1.251" />
        <vers num="1.252" />
        <vers num="1.253" />
        <vers num="1.254" />
        <vers num="1.255" />
        <vers num="1.26" />
        <vers num="1.261" />
        <vers num="1.262" />
        <vers num="1.263" />
        <vers num="1.264" />
        <vers num="1.265" />
        <vers num="1.266" />
        <vers num="1.27" />
        <vers num="1.273" />
        <vers num="1.274" />
        <vers num="1.275" />
        <vers num="1.28" />
        <vers num="1.281" />
        <vers num="1.282" />
        <vers num="1.285" />
        <vers num="1.286" />
        <vers num="1.29" />
        <vers num="1.291" />
        <vers num="1.292" />
        <vers num="1.293" />
        <vers num="1.294" />
        <vers num="1.295" />
        <vers num="1.296" />
        <vers num="1.297" />
        <vers num="1.3" />
        <vers num="1.301" />
        <vers num="1.302" />
        <vers num="1.31" />
        <vers num="1.311" />
        <vers num="1.312" />
        <vers num="1.313" />
        <vers num="1.314" />
        <vers num="1.315" />
        <vers num="1.32" />
        <vers num="1.321" />
        <vers num="1.322" />
        <vers num="1.323" />
        <vers num="1.33" />
        <vers num="1.331" />
        <vers num="1.332" />
        <vers prev="1" num="1.333" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1526" published="2009-05-05" name="CVE-2009-1526" modified="2010-03-29" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="6.9" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.4" CVSS_base_score="6.9">
    <desc>
      <descript source="cve">JBMC Software DirectAdmin before 1.334 allows local users to create or overwrite any file via a symlink attack on an arbitrary file in a certain temporary directory, related to a request for this temporary file in the PATH_INFO to the CMD_DB script during a backup action.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.directadmin.com/features.php?id=968" source="CONFIRM" adv="1">http://www.directadmin.com/features.php?id=968</ref>
      <ref url="http://secunia.com/advisories/34861" source="SECUNIA" adv="1">34861</ref>
      <ref url="http://osvdb.org/54014" source="OSVDB">54014</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2009-04/0228.html" source="FULLDISC">20090422 DirectAdmin &lt; 1.33.4 Local file overwrite &amp; Local root escalation</ref>
    </refs>
    <vuln_soft>
      <prod vendor="jbmc-software" name="directadmin">
        <vers num="0.95" />
        <vers num="1" />
        <vers num="1.01" />
        <vers num="1.02" />
        <vers num="1.03" />
        <vers num="1.04" />
        <vers num="1.05" />
        <vers num="1.06" />
        <vers num="1.07" />
        <vers num="1.08" />
        <vers num="1.081" />
        <vers num="1.09" />
        <vers num="1.1" />
        <vers num="1.11" />
        <vers num="1.111" />
        <vers num="1.12" />
        <vers num="1.121" />
        <vers num="1.13" />
        <vers num="1.14" />
        <vers num="1.15" />
        <vers num="1.151" />
        <vers num="1.152" />
        <vers num="1.16" />
        <vers num="1.161" />
        <vers num="1.17" />
        <vers num="1.171" />
        <vers num="1.172" />
        <vers num="1.173" />
        <vers num="1.174" />
        <vers num="1.1741" />
        <vers num="1.18" />
        <vers num="1.181" />
        <vers num="1.19" />
        <vers num="1.192" />
        <vers num="1.193" />
        <vers num="1.1941" />
        <vers num="1.195" />
        <vers num="1.196" />
        <vers num="1.2" />
        <vers num="1.201" />
        <vers num="1.202" />
        <vers num="1.203" />
        <vers num="1.204" />
        <vers num="1.205" />
        <vers num="1.206" />
        <vers num="1.207" />
        <vers num="1.21" />
        <vers num="1.211" />
        <vers num="1.212" />
        <vers num="1.213" />
        <vers num="1.22" />
        <vers num="1.221" />
        <vers num="1.222" />
        <vers num="1.223" />
        <vers num="1.224" />
        <vers num="1.225" />
        <vers num="1.226" />
        <vers num="1.23" />
        <vers num="1.231" />
        <vers num="1.232" />
        <vers num="1.233" />
        <vers num="1.234" />
        <vers num="1.235" />
        <vers num="1.24" />
        <vers num="1.241" />
        <vers num="1.242" />
        <vers num="1.243" />
        <vers num="1.244" />
        <vers num="1.25" />
        <vers num="1.251" />
        <vers num="1.252" />
        <vers num="1.253" />
        <vers num="1.254" />
        <vers num="1.255" />
        <vers num="1.26" />
        <vers num="1.261" />
        <vers num="1.262" />
        <vers num="1.263" />
        <vers num="1.264" />
        <vers num="1.265" />
        <vers num="1.266" />
        <vers num="1.27" />
        <vers num="1.273" />
        <vers num="1.274" />
        <vers num="1.275" />
        <vers num="1.28" />
        <vers num="1.281" />
        <vers num="1.282" />
        <vers num="1.285" />
        <vers num="1.286" />
        <vers num="1.29" />
        <vers num="1.291" />
        <vers num="1.292" />
        <vers num="1.293" />
        <vers num="1.294" />
        <vers num="1.295" />
        <vers num="1.296" />
        <vers num="1.297" />
        <vers num="1.3" />
        <vers num="1.301" />
        <vers num="1.302" />
        <vers num="1.31" />
        <vers num="1.311" />
        <vers num="1.312" />
        <vers num="1.313" />
        <vers num="1.314" />
        <vers num="1.315" />
        <vers num="1.32" />
        <vers num="1.321" />
        <vers num="1.322" />
        <vers num="1.323" />
        <vers num="1.33" />
        <vers num="1.331" />
        <vers num="1.332" />
        <vers prev="1" num="1.333" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1527" published="2009-05-05" name="CVE-2009-1527" modified="2009-06-09" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="6.9" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.4" CVSS_base_score="6.9">
    <desc>
      <descript source="cve">Race condition in the ptrace_attach function in kernel/ptrace.c in the Linux kernel before 2.6.30-rc4 allows local users to gain privileges via a PTRACE_ATTACH ptrace call during an exec system call that is launching a setuid application, related to locking an incorrect cred_exec_mutex object.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2009/1236" source="VUPEN" patch="1" adv="1">ADV-2009-1236</ref>
      <ref url="http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=cad81bc2529ab8c62b6fdc83a1c0c7f4a87209eb" source="CONFIRM" patch="1" adv="1">http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=cad81bc2529ab8c62b6fdc83a1c0c7f4a87209eb</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/50293" source="XF">linux-kernel-ptraceattach-code-execution(50293)</ref>
      <ref url="http://www.securityfocus.com/bid/34799" source="BID">34799</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/503610/100/0/threaded" source="BUGTRAQ">20090516 rPSA-2009-0084-1 kernel</ref>
      <ref url="http://www.osvdb.org/54188" source="OSVDB">54188</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2009/05/04/2" source="MLIST">[oss-security] 20090504 CVE request: kernel: ptrace_attach: fix the usage of ->cred_exec_mutex</ref>
      <ref url="http://www.kernel.org/pub/linux/kernel/v2.6/testing/ChangeLog-2.6.30-rc4" source="CONFIRM" adv="1">http://www.kernel.org/pub/linux/kernel/v2.6/testing/ChangeLog-2.6.30-rc4</ref>
      <ref url="http://wiki.rpath.com/Advisories:rPSA-2009-0084" source="CONFIRM">http://wiki.rpath.com/Advisories:rPSA-2009-0084</ref>
      <ref url="http://secunia.com/advisories/35120" source="SECUNIA">35120</ref>
      <ref url="http://secunia.com/advisories/34977" source="SECUNIA" adv="1">34977</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="kernel">
        <vers num="2.2.27" />
        <vers num="2.4.36" />
        <vers num="2.4.36.1" />
        <vers num="2.4.36.2" />
        <vers num="2.4.36.3" />
        <vers num="2.4.36.4" />
        <vers num="2.4.36.5" />
        <vers num="2.4.36.6" />
        <vers num="2.6" />
        <vers num="2.6.0" />
        <vers num="2.6.1" />
        <vers num="2.6.10" />
        <vers num="2.6.11" />
        <vers num="2.6.11.1" />
        <vers num="2.6.11.10" />
        <vers num="2.6.11.11" />
        <vers num="2.6.11.12" />
        <vers num="2.6.11.2" />
        <vers num="2.6.11.3" />
        <vers num="2.6.11.4" />
        <vers num="2.6.11.5" />
        <vers num="2.6.11.6" />
        <vers num="2.6.11.7" />
        <vers num="2.6.11.8" />
        <vers num="2.6.11.9" />
        <vers num="2.6.12" />
        <vers num="2.6.12.1" />
        <vers num="2.6.12.2" />
        <vers num="2.6.12.3" />
        <vers num="2.6.12.4" />
        <vers num="2.6.12.5" />
        <vers num="2.6.12.6" />
        <vers num="2.6.13" />
        <vers num="2.6.13.1" />
        <vers num="2.6.13.2" />
        <vers num="2.6.13.3" />
        <vers num="2.6.13.4" />
        <vers num="2.6.13.5" />
        <vers num="2.6.14" />
        <vers num="2.6.14.1" />
        <vers num="2.6.14.2" />
        <vers num="2.6.14.3" />
        <vers num="2.6.14.4" />
        <vers num="2.6.14.5" />
        <vers num="2.6.14.6" />
        <vers num="2.6.14.7" />
        <vers num="2.6.15" />
        <vers num="2.6.15.1" />
        <vers num="2.6.15.2" />
        <vers num="2.6.15.3" />
        <vers num="2.6.15.4" />
        <vers num="2.6.15.5" />
        <vers num="2.6.15.6" />
        <vers num="2.6.15.7" />
        <vers num="2.6.16" />
        <vers num="2.6.16.1" />
        <vers num="2.6.16.10" />
        <vers num="2.6.16.11" />
        <vers num="2.6.16.12" />
        <vers num="2.6.16.13" />
        <vers num="2.6.16.14" />
        <vers num="2.6.16.15" />
        <vers num="2.6.16.16" />
        <vers num="2.6.16.17" />
        <vers num="2.6.16.18" />
        <vers num="2.6.16.19" />
        <vers num="2.6.16.2" />
        <vers num="2.6.16.20" />
        <vers num="2.6.16.21" />
        <vers num="2.6.16.22" />
        <vers num="2.6.16.23" />
        <vers num="2.6.16.24" />
        <vers num="2.6.16.25" />
        <vers num="2.6.16.26" />
        <vers num="2.6.16.27" />
        <vers num="2.6.16.28" />
        <vers num="2.6.16.29" />
        <vers num="2.6.16.3" />
        <vers num="2.6.16.30" />
        <vers num="2.6.16.31" />
        <vers num="2.6.16.32" />
        <vers num="2.6.16.33" />
        <vers num="2.6.16.34" />
        <vers num="2.6.16.35" />
        <vers num="2.6.16.36" />
        <vers num="2.6.16.37" />
        <vers num="2.6.16.38" />
        <vers num="2.6.16.39" />
        <vers num="2.6.16.4" />
        <vers num="2.6.16.40" />
        <vers num="2.6.16.41" />
        <vers num="2.6.16.42" />
        <vers num="2.6.16.43" />
        <vers num="2.6.16.44" />
        <vers num="2.6.16.45" />
        <vers num="2.6.16.46" />
        <vers num="2.6.16.47" />
        <vers num="2.6.16.48" />
        <vers num="2.6.16.49" />
        <vers num="2.6.16.5" />
        <vers num="2.6.16.50" />
        <vers num="2.6.16.51" />
        <vers num="2.6.16.52" />
        <vers num="2.6.16.53" />
        <vers num="2.6.16.54" />
        <vers num="2.6.16.55" />
        <vers num="2.6.16.56" />
        <vers num="2.6.16.57" />
        <vers num="2.6.16.58" />
        <vers num="2.6.16.59" />
        <vers num="2.6.16.6" />
        <vers num="2.6.16.60" />
        <vers num="2.6.16.61" />
        <vers num="2.6.16.62" />
        <vers num="2.6.16.7" />
        <vers num="2.6.16.8" />
        <vers num="2.6.16.9" />
        <vers num="2.6.17" />
        <vers num="2.6.17.1" />
        <vers num="2.6.17.10" />
        <vers num="2.6.17.11" />
        <vers num="2.6.17.12" />
        <vers num="2.6.17.13" />
        <vers num="2.6.17.14" />
        <vers num="2.6.17.2" />
        <vers num="2.6.17.3" />
        <vers num="2.6.17.4" />
        <vers num="2.6.17.5" />
        <vers num="2.6.17.6" />
        <vers num="2.6.17.7" />
        <vers num="2.6.17.8" />
        <vers num="2.6.17.9" />
        <vers num="2.6.18" edition="rc1" />
        <vers num="2.6.18" edition="rc2" />
        <vers num="2.6.18" edition="rc3" />
        <vers num="2.6.18" edition="rc4" />
        <vers num="2.6.18" edition="rc5" />
        <vers num="2.6.18" edition="rc6" />
        <vers num="2.6.18" edition="rc7" />
        <vers num="2.6.18.1" />
        <vers num="2.6.18.2" />
        <vers num="2.6.18.3" />
        <vers num="2.6.18.4" />
        <vers num="2.6.18.5" />
        <vers num="2.6.18.6" />
        <vers num="2.6.18.7" />
        <vers num="2.6.18.8" />
        <vers num="2.6.19" />
        <vers num="2.6.19.1" />
        <vers num="2.6.19.2" />
        <vers num="2.6.19.3" />
        <vers num="2.6.19.4" />
        <vers num="2.6.19.5" />
        <vers num="2.6.19.6" />
        <vers num="2.6.19.7" />
        <vers num="2.6.2" />
        <vers num="2.6.2.27.13" />
        <vers num="2.6.20" />
        <vers num="2.6.20.1" />
        <vers num="2.6.20.10" />
        <vers num="2.6.20.11" />
        <vers num="2.6.20.12" />
        <vers num="2.6.20.13" />
        <vers num="2.6.20.14" />
        <vers num="2.6.20.15" />
        <vers num="2.6.20.16" />
        <vers num="2.6.20.17" />
        <vers num="2.6.20.18" />
        <vers num="2.6.20.19" />
        <vers num="2.6.20.2" />
        <vers num="2.6.20.20" />
        <vers num="2.6.20.21" />
        <vers num="2.6.20.3" />
        <vers num="2.6.20.4" />
        <vers num="2.6.20.5" />
        <vers num="2.6.20.6" />
        <vers num="2.6.20.7" />
        <vers num="2.6.20.8" />
        <vers num="2.6.20.9" />
        <vers num="2.6.21" />
        <vers num="2.6.21.1" />
        <vers num="2.6.21.2" />
        <vers num="2.6.21.3" />
        <vers num="2.6.21.4" />
        <vers num="2.6.21.5" />
        <vers num="2.6.21.6" />
        <vers num="2.6.21.7" />
        <vers num="2.6.22" />
        <vers num="2.6.22.1" />
        <vers num="2.6.22.10" />
        <vers num="2.6.22.11" />
        <vers num="2.6.22.12" />
        <vers num="2.6.22.13" />
        <vers num="2.6.22.14" />
        <vers num="2.6.22.15" />
        <vers num="2.6.22.16" />
        <vers num="2.6.22.17" />
        <vers num="2.6.22.18" />
        <vers num="2.6.22.19" />
        <vers num="2.6.22.2" />
        <vers num="2.6.22.20" />
        <vers num="2.6.22.21" />
        <vers num="2.6.22.22" />
        <vers num="2.6.22.3" />
        <vers num="2.6.22.4" />
        <vers num="2.6.22.5" />
        <vers num="2.6.22.6" />
        <vers num="2.6.22.7" />
        <vers num="2.6.22.8" />
        <vers num="2.6.22.9" />
        <vers num="2.6.22_rc1" />
        <vers num="2.6.22_rc7" />
        <vers num="2.6.23" edition="rc1" />
        <vers num="2.6.23" edition="rc2" />
        <vers num="2.6.23.1" />
        <vers num="2.6.23.10" />
        <vers num="2.6.23.11" />
        <vers num="2.6.23.12" />
        <vers num="2.6.23.13" />
        <vers num="2.6.23.14" />
        <vers num="2.6.23.15" />
        <vers num="2.6.23.16" />
        <vers num="2.6.23.17" />
        <vers num="2.6.23.2" />
        <vers num="2.6.23.3" />
        <vers num="2.6.23.4" />
        <vers num="2.6.23.5" />
        <vers num="2.6.23.6" />
        <vers num="2.6.23.7" />
        <vers num="2.6.23.8" />
        <vers num="2.6.23.9" />
        <vers num="2.6.23_rc1" />
        <vers num="2.6.24" edition="rc1" />
        <vers num="2.6.24" edition="rc2" />
        <vers num="2.6.24" edition="rc3" />
        <vers num="2.6.24" edition="rc4" />
        <vers num="2.6.24" edition="rc5" />
        <vers num="2.6.24.1" />
        <vers num="2.6.24.2" />
        <vers num="2.6.24.3" />
        <vers num="2.6.24.4" />
        <vers num="2.6.24.5" />
        <vers num="2.6.24.6" />
        <vers num="2.6.24.7" />
        <vers num="2.6.24_rc1" />
        <vers num="2.6.24_rc4" />
        <vers num="2.6.24_rc5" />
        <vers num="2.6.25" edition="" />
        <vers num="2.6.25" edition=":x86_64" />
        <vers num="2.6.25.1" edition="" />
        <vers num="2.6.25.1" edition=":x86_64" />
        <vers num="2.6.25.10" edition="" />
        <vers num="2.6.25.10" edition=":x86_64" />
        <vers num="2.6.25.11" edition="" />
        <vers num="2.6.25.11" edition=":x86_64" />
        <vers num="2.6.25.12" edition="" />
        <vers num="2.6.25.12" edition=":x86_64" />
        <vers num="2.6.25.13" />
        <vers num="2.6.25.14" />
        <vers num="2.6.25.15" />
        <vers num="2.6.25.16" />
        <vers num="2.6.25.17" />
        <vers num="2.6.25.18" />
        <vers num="2.6.25.19" />
        <vers num="2.6.25.2" edition="" />
        <vers num="2.6.25.2" edition=":x86_64" />
        <vers num="2.6.25.20" />
        <vers num="2.6.25.3" edition="" />
        <vers num="2.6.25.3" edition=":x86_64" />
        <vers num="2.6.25.4" edition="" />
        <vers num="2.6.25.4" edition=":x86_64" />
        <vers num="2.6.25.5" edition="" />
        <vers num="2.6.25.5" edition=":x86_64" />
        <vers num="2.6.25.6" edition="" />
        <vers num="2.6.25.6" edition=":x86_64" />
        <vers num="2.6.25.7" edition="" />
        <vers num="2.6.25.7" edition=":x86_64" />
        <vers num="2.6.25.8" edition="" />
        <vers num="2.6.25.8" edition=":x86_64" />
        <vers num="2.6.25.9" edition="" />
        <vers num="2.6.25.9" edition=":x86_64" />
        <vers num="2.6.26" edition="rc4" />
        <vers num="2.6.26.1" />
        <vers num="2.6.26.2" />
        <vers num="2.6.26.3" />
        <vers num="2.6.26.4" />
        <vers num="2.6.26.5" />
        <vers num="2.6.26.6" />
        <vers num="2.6.26.7" />
        <vers num="2.6.26.8" />
        <vers num="2.6.27" edition="rc1" />
        <vers num="2.6.27" edition="rc2" />
        <vers num="2.6.27" edition="rc3" />
        <vers num="2.6.27" edition="rc4" />
        <vers num="2.6.27" edition="rc5" />
        <vers num="2.6.27" edition="rc6" />
        <vers num="2.6.27" edition="rc7" />
        <vers num="2.6.27" edition="rc8" />
        <vers num="2.6.27" edition="rc9" />
        <vers num="2.6.27.1" />
        <vers num="2.6.27.10" />
        <vers num="2.6.27.11" />
        <vers num="2.6.27.12" />
        <vers num="2.6.27.13" />
        <vers num="2.6.27.14" />
        <vers num="2.6.27.15" />
        <vers num="2.6.27.16" />
        <vers num="2.6.27.17" />
        <vers num="2.6.27.18" />
        <vers num="2.6.27.19" />
        <vers num="2.6.27.2" />
        <vers num="2.6.27.20" />
        <vers num="2.6.27.21" />
        <vers num="2.6.27.3" />
        <vers num="2.6.27.4" />
        <vers num="2.6.27.5" />
        <vers num="2.6.27.6" />
        <vers num="2.6.27.7" />
        <vers num="2.6.27.8" />
        <vers num="2.6.27.9" />
        <vers num="2.6.28" edition="git7" />
        <vers num="2.6.28" edition="rc1" />
        <vers num="2.6.28" edition="rc2" />
        <vers num="2.6.28" edition="rc3" />
        <vers num="2.6.28" edition="rc4" />
        <vers num="2.6.28" edition="rc5" />
        <vers num="2.6.28" edition="rc6" />
        <vers num="2.6.28" edition="rc7" />
        <vers num="2.6.28.1" />
        <vers num="2.6.28.2" />
        <vers num="2.6.28.3" />
        <vers num="2.6.28.4" />
        <vers num="2.6.28.5" />
        <vers num="2.6.28.6" />
        <vers num="2.6.28.7" />
        <vers num="2.6.28.8" />
        <vers num="2.6.28.9" />
        <vers num="2.6.29" edition="git1" />
        <vers num="2.6.29" edition="rc1" />
        <vers num="2.6.29" edition="rc2" />
        <vers num="2.6.29" edition="rc2_git7" />
        <vers num="2.6.29" edition="rc8-kk" />
        <vers num="2.6.29.rc1" />
        <vers num="2.6.29.rc2" />
        <vers num="2.6.29.rc2-git1" />
        <vers num="2.6.3" />
        <vers prev="1" num="2.6.30" edition="rc1" />
        <vers prev="1" num="2.6.30" edition="rc2" />
        <vers prev="1" num="2.6.30" edition="rc3" />
        <vers num="2.6.4" />
        <vers num="2.6.5" />
        <vers num="2.6.6" />
        <vers num="2.6.7" />
        <vers num="2.6.8" />
        <vers num="2.6.8.1" />
        <vers num="2.6.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1528" published="2009-06-10" name="CVE-2009-1528" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Microsoft Internet Explorer 6 and 7 for Windows XP SP2 and SP3; 6 and 7 for Server 2003 SP2; 7 for Vista Gold, SP1, and SP2; and 7 for Server 2008 SP2 does not properly synchronize AJAX requests, which allows allows remote attackers to execute arbitrary code via a large number of concurrent, asynchronous XMLHttpRequest calls, aka "HTML Object Memory Corruption Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-160A.html" source="CERT">TA09-160A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS09-019.mspx" source="MS" patch="1" adv="1">MS09-019</ref>
      <ref url="http://www.zerodayinitiative.com/advisories/ZDI-09-037" source="MISC">http://www.zerodayinitiative.com/advisories/ZDI-09-037</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1538" source="VUPEN" adv="1">ADV-2009-1538</ref>
      <ref url="http://www.securitytracker.com/id?1022350" source="SECTRACK">1022350</ref>
      <ref url="http://www.securityfocus.com/bid/35222" source="BID">35222</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/504206/100/0/threaded" source="BUGTRAQ">20090610 ZDI-09-037: Microsoft Internet Explorer Concurrent Ajax Request Memory Corruption Vulnerability</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6260" source="OVAL">oval:org.mitre.oval:def:6260</ref>
      <ref url="http://osvdb.org/54947" source="OSVDB">54947</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="6" />
        <vers num="7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1529" published="2009-06-10" name="CVE-2009-1529" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Microsoft Internet Explorer 7 for Windows XP SP2 and SP3; 7 for Server 2003 SP2; 7 for Vista Gold, SP1, and SP2; and 7 for Server 2008 SP2 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by calling the setCapture method on a collection of crafted objects, aka "Uninitialized Memory Corruption Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-160A.html" source="CERT">TA09-160A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS09-019.mspx" source="MS" patch="1" adv="1">MS09-019</ref>
      <ref url="http://www.zerodayinitiative.com/advisories/ZDI-09-036" source="MISC">http://www.zerodayinitiative.com/advisories/ZDI-09-036</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1538" source="VUPEN" adv="1">ADV-2009-1538</ref>
      <ref url="http://www.securitytracker.com/id?1022350" source="SECTRACK">1022350</ref>
      <ref url="http://www.securityfocus.com/bid/35223" source="BID">35223</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/504205/100/0/threaded" source="BUGTRAQ">20090610 ZDI-09-036: Microsoft Internet Explorer setCapture Memory Corruption Vulnerability</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6295" source="OVAL">oval:org.mitre.oval:def:6295</ref>
      <ref url="http://osvdb.org/54948" source="OSVDB">54948</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="5.01" edition="sp4" />
        <vers num="6" edition="sp1" />
        <vers num="7" />
        <vers num="8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1530" published="2009-06-10" name="CVE-2009-1530" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Use-after-free vulnerability in Microsoft Internet Explorer 7 for Windows XP SP2 and SP3; 7 for Server 2003 SP2; 7 for Vista Gold, SP1, and SP2; and 7 for Server 2008 SP2 allows remote attackers to execute arbitrary code by repeatedly adding HTML document nodes and calling event handlers, which triggers an access of an object that (1) was not properly initialized or (2) is deleted, aka "HTML Objects Memory Corruption Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-160A.html" source="CERT">TA09-160A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS09-019.mspx" source="MS" patch="1" adv="1">MS09-019</ref>
      <ref url="http://www.zerodayinitiative.com/advisories/ZDI-09-038" source="MISC">http://www.zerodayinitiative.com/advisories/ZDI-09-038</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1538" source="VUPEN" adv="1">ADV-2009-1538</ref>
      <ref url="http://www.securitytracker.com/id?1022350" source="SECTRACK">1022350</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/504209/100/0/threaded" source="BUGTRAQ">20090610 ZDI-09-038: Microsoft Internet Explorer Event Handler Memory Corruption Vulnerability</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6294" source="OVAL">oval:org.mitre.oval:def:6294</ref>
      <ref url="http://osvdb.org/54949" source="OSVDB">54949</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="5.01" edition="sp4" />
        <vers num="8" />
      </prod>
      <prod vendor="microsoft" name="internet_explorer">
        <vers num="6" edition="sp1" />
        <vers num="7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1531" published="2009-06-10" name="CVE-2009-1531" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Microsoft Internet Explorer 7 for Windows XP SP2 and SP3; 7 for Server 2003 SP2; 7 for Vista Gold, SP1, and SP2; and 7 for Server 2008 SP2 allows remote attackers to execute arbitrary code via frequent calls to the getElementsByTagName function combined with the creation of an object during reordering of elements, followed by an onreadystatechange event, which triggers an access of an object that (1) was not properly initialized or (2) is deleted, aka "HTML Object Memory Corruption Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-160A.html" source="CERT">TA09-160A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS09-019.mspx" source="MS" patch="1" adv="1">MS09-019</ref>
      <ref url="http://www.zerodayinitiative.com/advisories/ZDI-09-039" source="MISC">http://www.zerodayinitiative.com/advisories/ZDI-09-039</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1538" source="VUPEN" adv="1">ADV-2009-1538</ref>
      <ref url="http://www.securitytracker.com/id?1022350" source="SECTRACK">1022350</ref>
      <ref url="http://www.securityfocus.com/bid/35234" source="BID">35234</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/504216/100/0/threaded" source="BUGTRAQ">20090610 ZDI-09-039: Microsoft Internet Explorer onreadystatechange Memory Corruption Vulnerability</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6308" source="OVAL">oval:org.mitre.oval:def:6308</ref>
      <ref url="http://osvdb.org/54950" source="OSVDB">54950</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1532" published="2009-06-10" name="CVE-2009-1532" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Microsoft Internet Explorer 8 for Windows XP SP2 and SP3; 8 for Server 2003 SP2; 8 for Vista Gold, SP1, and SP2; and 8 for Server 2008 SP2 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code via "malformed row property references" that trigger an access of an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka "HTML Objects Memory Corruption Vulnerability" or "HTML Object Memory Corruption Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-160A.html" source="CERT">TA09-160A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS09-019.mspx" source="MS" patch="1" adv="1">MS09-019</ref>
      <ref url="http://www.zerodayinitiative.com/advisories/ZDI-09-041" source="MISC">http://www.zerodayinitiative.com/advisories/ZDI-09-041</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1538" source="VUPEN" adv="1">ADV-2009-1538</ref>
      <ref url="http://www.securitytracker.com/id?1022350" source="SECTRACK">1022350</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/504208/100/0/threaded" source="BUGTRAQ">20090610 ZDI-09-041: Microsoft Internet Explorer 8 Rows Property Dangling Pointer Code Execution Vulnerability</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6244" source="OVAL">oval:org.mitre.oval:def:6244</ref>
      <ref url="http://osvdb.org/54951" source="OSVDB">54951</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="ie">
        <vers num="8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1533" published="2009-06-10" name="CVE-2009-1533" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Buffer overflow in the Works for Windows document converters in Microsoft Office 2000 SP3, Office XP SP3, Office 2003 SP3, Office 2007 SP1, and Works 8.5 and 9 allows remote attackers to execute arbitrary code via a crafted Works .wps file that triggers memory corruption, aka "File Converter Buffer Overflow Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-160A.html" source="CERT">TA09-160A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS09-024.mspx" source="MS" patch="1" adv="1">MS09-024</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1543" source="VUPEN">ADV-2009-1543</ref>
      <ref url="http://www.securitytracker.com/id?1022355" source="SECTRACK">1022355</ref>
      <ref url="http://www.securitytracker.com/id?1022354" source="SECTRACK">1022354</ref>
      <ref url="http://www.securityfocus.com/bid/35184" source="BID">35184</ref>
      <ref url="http://secunia.com/advisories/35371" source="SECUNIA">35371</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6292" source="OVAL">oval:org.mitre.oval:def:6292</ref>
      <ref url="http://osvdb.org/54939" source="OSVDB">54939</ref>
      <ref url="http://jvn.jp/en/jp/JVN70858401/index.html" source="JVN">JVN#70858401</ref>
      <ref url="http://blogs.technet.com/srd/archive/2009/06/09/ms09-024.aspx" source="MISC">http://blogs.technet.com/srd/archive/2009/06/09/ms09-024.aspx</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="office">
        <vers num="2000" edition="sp3" />
        <vers num="2003" edition="sp3" />
      </prod>
      <prod vendor="microsoft" name="office_xp">
        <vers num="sp3" />
      </prod>
      <prod vendor="microsoft" name="works">
        <vers num="8.5" />
        <vers num="9.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1534" published="2009-08-12" name="CVE-2009-1534" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Buffer overflow in the Office Web Components ActiveX Control in Microsoft Office XP SP3, Office 2000 Web Components SP3, Office XP Web Components SP3, BizTalk Server 2002, and Visual Studio .NET 2003 SP1 allows remote attackers to execute arbitrary code via crafted property values, aka "Office Web Components Buffer Overflow Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-223A.html" source="CERT">TA09-223A</ref>
      <ref url="http://www.securityfocus.com/bid/35992" source="BID" patch="1">35992</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS09-043.mspx" source="MS" patch="1" adv="1">MS09-043</ref>
      <ref url="http://www.securitytracker.com/id?1022708" source="SECTRACK">1022708</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6326" source="OVAL">oval:org.mitre.oval:def:6326</ref>
      <ref url="http://osvdb.org/56916" source="OSVDB">56916</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="isa_server">
        <vers num="2004" edition="sp3" />
        <vers num="2004" edition="sp3:standard" />
        <vers num="2004" edition="sp3:enterprise" />
        <vers num="2006" edition="sp1" />
        <vers num="2006" edition="sp1:standard" />
        <vers num="2006" edition="sp1:enterprise" />
      </prod>
      <prod vendor="microsoft" name="office">
        <vers num="-" edition="" />
        <vers num="-" edition=":small_business_accounting_2006" />
        <vers num="2003" edition="sp3" />
        <vers num="xp" edition="sp3" />
      </prod>
      <prod vendor="microsoft" name="office_web_components">
        <vers num="2000" edition="sp3" />
        <vers num="2003" edition="sp1" />
        <vers num="2003" edition="sp1:2007_microsoft_office" />
        <vers num="2003" edition="sp3" />
        <vers num="xp" edition="sp3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1535" published="2009-06-10" name="CVE-2009-1535" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)" CVSS_score="7.6" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="4.9" CVSS_base_score="7.6">
    <desc>
      <descript source="cve">The WebDAV extension in Microsoft Internet Information Services (IIS) 5.1 and 6.0 allows remote attackers to bypass URI-based protection mechanisms, and list folders or read, create, or modify files, via a %c0%af (Unicode / character) at an arbitrary position in the URI, as demonstrated by inserting %c0%af into a "/protected/" initial pathname component to bypass the password protection on the protected\ folder, aka "IIS 5.1 and 6.0 WebDAV Authentication Bypass Vulnerability," a different vulnerability than CVE-2009-1122.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-160A.html" source="CERT">TA09-160A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS09-020.mspx" source="MS">MS09-020</ref>
      <ref url="http://www.attrition.org/pipermail/vim/2009-June/002192.html" source="VIM">20090616 IIS WebDav Vulnerability CVE ID</ref>
      <ref url="http://view.samurajdata.se/psview.php?id=023287d6&amp;page=1" source="MISC">http://view.samurajdata.se/psview.php?id=023287d6&amp;page=1</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6029" source="OVAL">oval:org.mitre.oval:def:6029</ref>
      <ref url="http://isc.sans.org/diary.html?n&amp;storyid=6397" source="MISC">http://isc.sans.org/diary.html?n&amp;storyid=6397</ref>
      <ref url="http://blog.zoller.lu/2009/05/iis-6-webdac-auth-bypass-and-data.html" source="MISC">http://blog.zoller.lu/2009/05/iis-6-webdac-auth-bypass-and-data.html</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2009-05/att-0135/IIS_Advisory.pdf" source="MISC">http://archives.neohapsis.com/archives/fulldisclosure/2009-05/att-0135/IIS_Advisory.pdf</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2009-05/0144.html" source="FULLDISC">20090515 Re: IIS6 + webdav and unicode rides again in 2009</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2009-05/0139.html" source="FULLDISC">20090515 Re: IIS6 + webdav and unicode rides again in 2009</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2009-05/0135.html" source="FULLDISC">20090515 IIS6 + webdav and unicode rides again in 2009</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="iis">
        <vers num="5.0" />
        <vers num="5.1" />
        <vers num="6.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2009-1536" published="2009-08-12" name="CVE-2009-1536" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:N/A:P)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">ASP.NET in Microsoft .NET Framework 2.0 SP1 and SP2 and 3.5 Gold and SP1, when ASP 2.0 is used in integrated mode on IIS 7.0, does not properly manage request scheduling, which allows remote attackers to cause a denial of service (daemon outage) via a series of crafted HTTP requests, aka "Remote Unauthenticated Denial of Service in ASP.NET Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-223A.html" source="CERT">TA09-223A</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/2231" source="VUPEN" patch="1" adv="1">ADV-2009-2231</ref>
      <ref url="http://www.securityfocus.com/bid/35985" source="BID" patch="1">35985</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS09-036.mspx" source="MS" patch="1" adv="1">MS09-036</ref>
      <ref url="http://www.securitytracker.com/id?1022715" source="SECTRACK">1022715</ref>
      <ref url="http://secunia.com/advisories/36127" source="SECUNIA" adv="1">36127</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6393" source="OVAL">oval:org.mitre.oval:def:6393</ref>
      <ref url="http://osvdb.org/56905" source="OSVDB">56905</ref>
      <ref url="http://blogs.technet.com/srd/archive/2009/08/11/ms09-035-asp-net-denial-of-service-vulnerability.aspx" source="MISC">http://blogs.technet.com/srd/archive/2009/08/11/ms09-035-asp-net-denial-of-service-vulnerability.aspx</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_server">
        <vers num="2008" edition="" />
        <vers num="2008" edition=":" />
        <vers num="2008" edition="::itanium" />
        <vers num="2008" edition="-" />
        <vers num="2008" edition="-:x32" />
        <vers num="2008" edition="-:x64" />
      </prod>
      <prod vendor="microsoft" name="windows_vista">
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:x64" />
        <vers num="-" edition="-" />
        <vers num="-" edition="-:x64" />
        <vers num="-" edition="sp1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1537" published="2009-05-29" name="CVE-2009-1537" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Unspecified vulnerability in the QuickTime Movie Parser Filter in quartz.dll in DirectShow in Microsoft DirectX 7.0 through 9.0c on Windows 2000 SP4, Windows XP SP2 and SP3, and Windows Server 2003 SP2 allows remote attackers to execute arbitrary code via a crafted QuickTime media file, as exploited in the wild in May 2009, aka "DirectX NULL Byte Overwrite Vulnerability."</descript>
    </desc>
    <impacts>
      <impact source="nvd">Per: http://www.microsoft.com/technet/security/advisory/971778.mspx

"Microsoft is aware of limited, active attacks that use this exploit code. While our investigation is ongoing, our investigation so far has shown that Windows 2000 Service Pack 4, Windows XP, and Windows Server 2003 are vulnerable; all versions of Windows Vista and Windows Server 2008 are not vulnerable."</impact>
    </impacts>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-195A.html" source="CERT">TA09-195A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS09-028.mspx" source="MS" patch="1" adv="1">MS09-028</ref>
      <ref url="http://www.microsoft.com/technet/security/advisory/971778.mspx" source="CONFIRM" patch="1" adv="1">http://www.microsoft.com/technet/security/advisory/971778.mspx</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1886" source="VUPEN" adv="1">ADV-2009-1886</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1445" source="VUPEN" adv="1">ADV-2009-1445</ref>
      <ref url="http://www.securitytracker.com/id?1022299" source="SECTRACK">1022299</ref>
      <ref url="http://www.securityfocus.com/bid/35139" source="BID">35139</ref>
      <ref url="http://secunia.com/advisories/35268" source="SECUNIA" adv="1">35268</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6237" source="OVAL">oval:org.mitre.oval:def:6237</ref>
      <ref url="http://osvdb.org/54797" source="OSVDB">54797</ref>
      <ref url="http://isc.sans.org/diary.html?storyid=6481" source="MISC">http://isc.sans.org/diary.html?storyid=6481</ref>
      <ref url="http://blogs.technet.com/srd/archive/2009/05/28/new-vulnerability-in-quicktime-parsing.aspx" source="CONFIRM">http://blogs.technet.com/srd/archive/2009/05/28/new-vulnerability-in-quicktime-parsing.aspx</ref>
      <ref url="http://blogs.technet.com/msrc/archive/2009/05/28/microsoft-security-advisory-971778-vulnerability-in-microsoft-directshow-released.aspx" source="CONFIRM" adv="1">http://blogs.technet.com/msrc/archive/2009/05/28/microsoft-security-advisory-971778-vulnerability-in-microsoft-directshow-released.aspx</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="directx">
        <vers num="7.0" />
        <vers num="7.0a" />
        <vers num="7.1" />
        <vers num="8.1" />
        <vers num="8.1b" />
        <vers num="9.0" />
        <vers num="9.0a" />
        <vers num="9.0b" />
        <vers num="9.0c" />
      </prod>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition="sp4" />
      </prod>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:itanium" />
        <vers num="" edition="sp2:x64" />
      </prod>
      <prod vendor="microsoft" name="windows_server_2003">
        <vers num="" edition="sp2" />
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:professional_x64" />
        <vers num="" edition="sp3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1538" published="2009-07-15" name="CVE-2009-1538" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">The QuickTime Movie Parser Filter in quartz.dll in DirectShow in Microsoft DirectX 7.0 through 9.0c on Windows 2000 SP4, Windows XP SP2 and SP3, and Windows Server 2003 SP2 performs updates to pointers without properly validating unspecified data values, which allows remote attackers to execute arbitrary code via a crafted QuickTime media file, aka "DirectX Pointer Validation Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-195A.html" source="CERT">TA09-195A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS09-028.mspx" source="MS" patch="1" adv="1">MS09-028</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1886" source="VUPEN">ADV-2009-1886</ref>
      <ref url="http://www.securityfocus.com/bid/35600" source="BID">35600</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5963" source="OVAL">oval:org.mitre.oval:def:5963</ref>
      <ref url="http://osvdb.org/55844" source="OSVDB">55844</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="directx">
        <vers num="7.0" />
        <vers num="8.1" />
        <vers num="9.0" />
      </prod>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="-" edition="sp4" />
      </prod>
      <prod vendor="microsoft" name="windows_server_2003">
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:itanium" />
        <vers num="" edition="sp2:x64" />
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="-" edition="sp2" />
        <vers num="-" edition="sp2:x64" />
        <vers num="-" edition="sp3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1539" published="2009-07-15" name="CVE-2009-1539" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">The QuickTime Movie Parser Filter in quartz.dll in DirectShow in Microsoft DirectX 7.0 through 9.0c on Windows 2000 SP4, Windows XP SP2 and SP3, and Windows Server 2003 SP2 does not properly validate unspecified size fields in QuickTime media files, which allows remote attackers to execute arbitrary code via a crafted file, aka "DirectX Size Validation Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-195A.html" source="CERT">TA09-195A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS09-028.mspx" source="MS" patch="1" adv="1">MS09-028</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1886" source="VUPEN">ADV-2009-1886</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6341" source="OVAL">oval:org.mitre.oval:def:6341</ref>
      <ref url="http://osvdb.org/55845" source="OSVDB">55845</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="directx">
        <vers num="7.0" />
        <vers num="8.1" />
        <vers num="9.0" />
      </prod>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="-" edition="sp4" />
      </prod>
      <prod vendor="microsoft" name="windows_server_2003">
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:itanium" />
        <vers num="" edition="sp2:x64" />
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="-" edition="sp2" />
        <vers num="-" edition="sp2:x64" />
        <vers num="-" edition="sp3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1542" published="2009-07-15" name="CVE-2009-1542" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:C/I:C/A:C)" CVSS_score="9.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.0" CVSS_base_score="9.0">
    <desc>
      <descript source="cve">The Virtual Machine Monitor (VMM) in Microsoft Virtual PC 2004 SP1, 2007, and 2007 SP1, and Microsoft Virtual Server 2005 R2 SP1, does not enforce CPU privilege-level requirements for all machine instructions, which allows guest OS users to execute arbitrary kernel-mode code and gain privileges within the guest OS via a crafted application, aka "Virtual PC and Virtual Server Privileged Instruction Decoding Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-195A.html" source="CERT">TA09-195A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS09-033.mspx" source="MS" patch="1" adv="1">MS09-033</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1890" source="VUPEN">ADV-2009-1890</ref>
      <ref url="http://www.securitytracker.com/id?1022544" source="SECTRACK">1022544</ref>
      <ref url="http://secunia.com/advisories/35808" source="SECUNIA">35808</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6166" source="OVAL">oval:org.mitre.oval:def:6166</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="virtual_pc">
        <vers num="2004" edition="sp1" />
        <vers num="2007" edition="" />
        <vers num="2007" edition=":x64" />
        <vers num="2007" edition="sp1" />
      </prod>
      <prod vendor="microsoft" name="virtual_server">
        <vers num="2005" edition="r2_sp1" />
        <vers num="2005" edition="r2_sp1:x64" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1544" published="2009-08-12" name="CVE-2009-1544" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:C/I:C/A:C)" CVSS_score="9.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.0" CVSS_base_score="9.0">
    <desc>
      <descript source="cve">Double free vulnerability in the Workstation service in Microsoft Windows allows remote authenticated users to gain privileges via a crafted RPC message to a Windows XP SP2 or SP3 or Server 2003 SP2 system, or cause a denial of service via a crafted RPC message to a Vista Gold, SP1, or SP2 or Server 2008 Gold or SP2 system, aka "Workstation Service Memory Corruption Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-223A.html" source="CERT">TA09-223A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS09-041.mspx" source="MS" adv="1">MS09-041</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6286" source="OVAL">oval:org.mitre.oval:def:6286</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="sp2" edition="" />
        <vers num="sp2" edition=":itanium" />
        <vers num="sp2" edition=":x64" />
      </prod>
      <prod vendor="microsoft" name="windows_server_2008">
        <vers num="" edition=":itanium" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:x64" />
        <vers num="-" edition="-" />
        <vers num="-" edition="-:x32" />
        <vers num="-" edition="-:x64" />
        <vers num="-" edition="sp2" />
        <vers num="-" edition="sp2:x32" />
        <vers num="-" edition="sp2:itanium" />
      </prod>
      <prod vendor="microsoft" name="windows_vista">
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:x64" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:x64" />
        <vers num="-" edition="-" />
        <vers num="-" edition="-:x64" />
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:x64" />
        <vers num="-" edition="sp2" />
        <vers num="-" edition="sp3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1545" published="2009-08-12" name="CVE-2009-1545" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Unspecified vulnerability in Avifil32.dll in the Windows Media file handling functionality in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 allows remote attackers to execute arbitrary code via a malformed header in a crafted AVI file, aka "Malformed AVI Header Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-223A.html" source="CERT">TA09-223A</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/2233" source="VUPEN" patch="1" adv="1">ADV-2009-2233</ref>
      <ref url="http://www.securityfocus.com/bid/35967" source="BID" patch="1">35967</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS09-038.mspx" source="MS" patch="1" adv="1">MS09-038</ref>
      <ref url="http://www.securitytracker.com/id?1022711" source="SECTRACK">1022711</ref>
      <ref url="http://secunia.com/advisories/36206" source="SECUNIA" adv="1">36206</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5412" source="OVAL">oval:org.mitre.oval:def:5412</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="sp2" edition="" />
        <vers num="sp2" edition=":itanium" />
        <vers num="sp2" edition=":x64" />
      </prod>
      <prod vendor="microsoft" name="windows_server_2008">
        <vers num="" edition=":itanium" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:x64" />
        <vers num="-" edition="-" />
        <vers num="-" edition="-:x32" />
        <vers num="-" edition="-:x64" />
        <vers num="-" edition="sp2" />
        <vers num="-" edition="sp2:x32" />
        <vers num="-" edition="sp2:itanium" />
      </prod>
      <prod vendor="microsoft" name="windows_vista">
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:x64" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:x64" />
        <vers num="-" edition="-" />
        <vers num="-" edition="-:x64" />
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:x64" />
        <vers num="-" edition="sp2" />
        <vers num="-" edition="sp3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1546" published="2009-08-12" name="CVE-2009-1546" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:S/C:C/I:C/A:C)" CVSS_score="8.5" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="6.8" CVSS_base_score="8.5">
    <desc>
      <descript source="cve">Integer overflow in Avifil32.dll in the Windows Media file handling functionality in Microsoft Windows allows remote attackers to execute arbitrary code on a Windows 2000 SP4 system via a crafted AVI file, or cause a denial of service on a Windows XP SP2 or SP3, Server 2003 SP2, Vista Gold, SP1, or SP2, or Server 2008 Gold or SP2 system via a crafted AVI file, aka "AVI Integer Overflow Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-223A.html" source="CERT">TA09-223A</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/2233" source="VUPEN" patch="1" adv="1">ADV-2009-2233</ref>
      <ref url="http://www.securityfocus.com/bid/35970" source="BID" patch="1">35970</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS09-038.mspx" source="MS" patch="1" adv="1">MS09-038</ref>
      <ref url="http://www.securitytracker.com/id?1022711" source="SECTRACK">1022711</ref>
      <ref url="http://secunia.com/advisories/36206" source="SECUNIA" adv="1">36206</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5930" source="OVAL">oval:org.mitre.oval:def:5930</ref>
      <ref url="http://osvdb.org/56909" source="OSVDB">56909</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="windows_2003_server">
        <vers num="sp2" edition="" />
        <vers num="sp2" edition=":itanium" />
        <vers num="sp2" edition=":x64" />
      </prod>
      <prod vendor="microsoft" name="windows_server_2008">
        <vers num="" edition=":itanium" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:x64" />
        <vers num="-" edition="-" />
        <vers num="-" edition="-:x32" />
        <vers num="-" edition="-:x64" />
        <vers num="-" edition="sp2" />
        <vers num="-" edition="sp2:x32" />
        <vers num="-" edition="sp2:itanium" />
      </prod>
      <prod vendor="microsoft" name="windows_vista">
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:x64" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:x64" />
        <vers num="-" edition="-" />
        <vers num="-" edition="-:x64" />
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:x64" />
        <vers num="-" edition="sp2" />
        <vers num="-" edition="sp3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1547" published="2009-10-14" name="CVE-2009-1547" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Unspecified vulnerability in Microsoft Internet Explorer 5.01 SP4, 6, 6 SP1, and 7 allows remote attackers to execute arbitrary code via a crafted data stream header that triggers memory corruption, aka "Data Stream Header Corruption Vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-286A.html" source="CERT">TA09-286A</ref>
      <ref url="http://www.microsoft.com/technet/security/Bulletin/MS09-054.mspx" source="MS" patch="1" adv="1">MS09-054</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6454" source="OVAL">oval:org.mitre.oval:def:6454</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microsoft" name="internet_explorer">
        <vers num="5.01" edition="sp4" />
        <vers num="6" edition="sp1" />
        <vers num="7" />
        <vers num="8" />
      </prod>
      <prod vendor="microsoft" name="windows_2000">
        <vers num="" edition="sp4" />
      </prod>
      <prod vendor="microsoft" name="windows_7">
        <vers num="-" edition="-" />
        <vers num="-" edition="-:x32" />
        <vers num="-" edition="-:x64" />
      </prod>
      <prod vendor="microsoft" name="windows_server_2003">
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:itanium" />
        <vers num="" edition="sp2:x64" />
      </prod>
      <prod vendor="microsoft" name="windows_server_2008">
        <vers num="" edition=":x32" />
        <vers num="" edition=":itanium" />
        <vers num="" edition=":x64" />
        <vers num="" edition="r2" />
        <vers num="" edition="r2:x64" />
        <vers num="" edition="r2:itanium" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:x64" />
        <vers num="-" edition="sp2" />
        <vers num="-" edition="sp2:itanium" />
        <vers num="-" edition="sp2:x32" />
      </prod>
      <prod vendor="microsoft" name="windows_vista">
        <vers num="" edition="sp1" />
        <vers num="" edition="sp1:x64" />
        <vers num="" edition="sp2" />
        <vers num="" edition="sp2:x64" />
        <vers num="-" edition="-" />
        <vers num="-" edition="-:x64" />
        <vers num="-" edition="sp1" />
        <vers num="-" edition="sp2" />
      </prod>
      <prod vendor="microsoft" name="windows_xp">
        <vers num="" edition="sp3" />
        <vers num="-" edition="sp2" />
        <vers num="-" edition="sp2:x64" />
        <vers num="-" edition="sp2:home" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1548" published="2009-05-06" name="CVE-2009-1548" modified="2009-05-23" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in index.php in BluSky CMS allows remote attackers to execute arbitrary SQL commands via the news_id parameter in a read action.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2009/1246" source="VUPEN">ADV-2009-1246</ref>
      <ref url="http://www.securityfocus.com/bid/34811" source="BID">34811</ref>
      <ref url="http://www.milw0rm.com/exploits/8600" source="MILW0RM">8600</ref>
      <ref url="http://secunia.com/advisories/34998" source="SECUNIA">34998</ref>
      <ref url="http://osvdb.org/54221" source="OSVDB">54221</ref>
    </refs>
    <vuln_soft>
      <prod vendor="qsix" name="blusky_cms">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1549" published="2009-05-06" name="CVE-2009-1549" modified="2009-05-23" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">AGTC MyShop 3.2b allows remote attackers to bypass authentication and obtain administrative access setting the log_accept cookie to "correcto."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2009/1245" source="VUPEN">ADV-2009-1245</ref>
      <ref url="http://www.securityfocus.com/bid/34808" source="BID">34808</ref>
      <ref url="http://www.milw0rm.com/exploits/8599" source="MILW0RM">8599</ref>
      <ref url="http://secunia.com/advisories/34968" source="SECUNIA">34968</ref>
      <ref url="http://osvdb.org/54216" source="OSVDB">54216</ref>
    </refs>
    <vuln_soft>
      <prod vendor="agtc" name="agtc_myshop">
        <vers num="3.2b" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1550" published="2009-05-06" name="CVE-2009-1550" modified="2009-05-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Zakkis Technology ABC Advertise 1.0 does not properly restrict access to admin.inc.php, which allows remote attackers to obtain the administrator login name and password via a direct request.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/50183" source="XF">abcadvertise-admininc-info-disclosure(50183)</ref>
      <ref url="http://www.milw0rm.com/exploits/8555" source="MILW0RM">8555</ref>
    </refs>
    <vuln_soft>
      <prod vendor="zakkis" name="abc_advertise">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1551" published="2009-05-06" name="CVE-2009-1551" modified="2009-05-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple PHP remote file inclusion vulnerabilities in Qt quickteam 2 allow remote attackers to execute arbitrary PHP code via a URL in the (1) qte_web_path parameter to qte_web.php and the (2) qte_root parameter to bin/qte_init.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2009/1247" source="VUPEN">ADV-2009-1247</ref>
      <ref url="http://www.milw0rm.com/exploits/8602" source="MILW0RM">8602</ref>
      <ref url="http://secunia.com/advisories/34997" source="SECUNIA">34997</ref>
      <ref url="http://osvdb.org/54218" source="OSVDB">54218</ref>
      <ref url="http://osvdb.org/54217" source="OSVDB">54217</ref>
    </refs>
    <vuln_soft>
      <prod vendor="qt-cute" name="quickteam">
        <vers num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1552" published="2009-05-06" name="CVE-2009-1552" modified="2009-05-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Unspecified vulnerability in the IGMP driver in SCO Unixware Release 7.1.4 Maintenance Pack 4 allows attackers to cause a denial of service (system panic) via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/50255" source="XF" patch="1">unixware-igmp-unspecified-dos(50255)</ref>
      <ref url="http://www.securityfocus.com/bid/34781" source="BID" patch="1">34781</ref>
      <ref url="ftp://ftp.sco.com/pub/unixware7/714/security/p535283/p535283.txt" source="CONFIRM" patch="1" adv="1">ftp://ftp.sco.com/pub/unixware7/714/security/p535283/p535283.txt</ref>
      <ref url="http://secunia.com/advisories/34951" source="SECUNIA" adv="1">34951</ref>
      <ref url="http://osvdb.org/54168" source="OSVDB">54168</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sco" name="unixware">
        <vers num="7.1.4" edition="mp4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1553" published="2009-05-06" name="CVE-2009-1553" modified="2011-04-22" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in the Admin Console in Sun GlassFish Enterprise Server 2.1 allow remote attackers to inject arbitrary web script or HTML via the query string to (1) applications/applications.jsf, (2) configuration/configuration.jsf, (3) customMBeans/customMBeans.jsf, (4) resourceNode/resources.jsf, (5) sysnet/registration.jsf, or (6) webService/webServicesGeneral.jsf; or the name parameter to (7) configuration/auditModuleEdit.jsf, (8) configuration/httpListenerEdit.jsf, or (9) resourceNode/jdbcResourceEdit.jsf.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="https://glassfish.dev.java.net/servlets/ReadMsg?list=cvs&amp;msgNo=29675" source="MLIST" patch="1" adv="1">[cvs] 20090322 CVS update [SJSAS91_FCS_BRANCH]: /glassfish/admin-gui/src/docroot/configuration/</ref>
      <ref url="https://glassfish.dev.java.net/servlets/ReadMsg?list=cvs&amp;msgNo=29669" source="MLIST" patch="1" adv="1">[cvs] 20090320 CVS update [SJSAS91_FCS_BRANCH]: /glassfish/admin-gui/src/docroot/</ref>
      <ref url="https://glassfish.dev.java.net/servlets/ReadMsg?list=cvs&amp;msgNo=29668" source="MLIST" patch="1" adv="1">[cvs] 20090320 CVS update [SJSAS91_FCS_BRANCH]: /glassfish/admin-gui/src/java/com/sun/enterprise/tools/admingui/handlers/CommonHandlers.java</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/50453" source="XF">glassfish-jsa-admininterface-xss(50453)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1255" source="VUPEN">ADV-2009-1255</ref>
      <ref url="http://www.securityfocus.com/bid/34914" source="BID">34914</ref>
      <ref url="http://www.securityfocus.com/bid/34824" source="BID">34824</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/503236/100/0/threaded" source="BUGTRAQ">20090505 [DSECRG-09-034] Sun Glassfish Enterprise Server - Multiple Linked XSS vulnerabilies</ref>
      <ref url="http://www.nabble.com/Re:--DSECRG--Sun-Glassfish-Multiple-Security-Vulnerabilities-p23002524.html" source="MLIST">[dev] 20090411 Re: [DSECRG] Sun Glassfish Multiple Security Vulnerabilities</ref>
      <ref url="http://www.nabble.com/-DSECRG--Sun-Glassfish-Multiple-Security-Vulnerabilities-p22595435.html" source="MLIST">[dev] 20090319 [DSECRG] Sun Glassfish Multiple Security Vulnerabilities</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-258528-1" source="SUNALERT">258528</ref>
      <ref url="http://osvdb.org/54257" source="OSVDB">54257</ref>
      <ref url="http://osvdb.org/54256" source="OSVDB">54256</ref>
      <ref url="http://osvdb.org/54255" source="OSVDB">54255</ref>
      <ref url="http://osvdb.org/54254" source="OSVDB">54254</ref>
      <ref url="http://osvdb.org/54253" source="OSVDB">54253</ref>
      <ref url="http://osvdb.org/54252" source="OSVDB">54252</ref>
      <ref url="http://osvdb.org/54251" source="OSVDB">54251</ref>
      <ref url="http://osvdb.org/54250" source="OSVDB">54250</ref>
      <ref url="http://osvdb.org/54249" source="OSVDB">54249</ref>
      <ref url="http://jvndb.jvn.jp/en/contents/2009/JVNDB-2009-000027.html" source="JVNDB">JVNDB-2009-000027</ref>
      <ref url="http://jvn.jp/en/jp/JVN73653977/index.html" source="JVN">JVN#73653977</ref>
      <ref url="http://dsecrg.com/pages/vul/show.php?id=134" source="MISC">http://dsecrg.com/pages/vul/show.php?id=134</ref>
    </refs>
    <vuln_soft>
      <prod vendor="oracle" name="glassfish_server">
        <vers num="2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1554" published="2009-05-06" name="CVE-2009-1554" modified="2011-04-22" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in ThemeServlet.java in Sun Woodstock 4.2, as used in Sun GlassFish Enterprise Server and other products, allows remote attackers to inject arbitrary web script or HTML via a UTF-7 string in the PATH_INFO, which is displayed on the 404 error page, as demonstrated by the PATH_INFO to theme/META-INF.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="https://woodstock.dev.java.net/servlets/ReadMsg?list=cvs&amp;msgNo=4041" source="MLIST" patch="1" adv="1">[cvs] 20090321 CVS update: /woodstock/webui/src/runtime/com/sun/webui/theme/ThemeServlet.java</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/50336" source="XF">woodstock-404page-xss(50336)</ref>
      <ref url="http://www.securityfocus.com/bid/34829" source="BID">34829</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/503239/100/0/threaded" source="BUGTRAQ">20090505 [DSECRG-09-038] Sun Glassfish Woodstock Project - Linked XSS Vulnerability</ref>
      <ref url="http://www.nabble.com/Re:--DSECRG--Sun-Glassfish-Multiple-Security-Vulnerabilities-p23002524.html" source="MLIST">[dev] 20090411 Re: [DSECRG] Sun Glassfish Multiple Security Vulnerabilities</ref>
      <ref url="http://www.nabble.com/-DSECRG--Sun-Glassfish-Multiple-Security-Vulnerabilities-p22595435.html" source="MLIST">[dev] 20090319 [DSECRG] Sun Glassfish Multiple Security Vulnerabilities</ref>
      <ref url="http://secunia.com/advisories/35006" source="SECUNIA">35006</ref>
      <ref url="http://osvdb.org/54220" source="OSVDB">54220</ref>
      <ref url="http://dsecrg.com/pages/vul/show.php?id=138" source="MISC">http://dsecrg.com/pages/vul/show.php?id=138</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="woodstock">
        <vers num="4.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1555" published="2009-05-06" name="CVE-2009-1555" modified="2009-05-23" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The Cisco Linksys WVC54GCA wireless video camera with firmware 1.00R22 and 1.00R24 sends configuration data in response to a Setup Wizard remote-management command, which allows remote attackers to obtain sensitive information such as passwords by reading the SetupWizard.exe process memory, a related issue to CVE-2008-4390.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2009/1173" source="VUPEN" adv="1">ADV-2009-1173</ref>
      <ref url="http://www.securityfocus.com/bid/34596" source="BID">34596</ref>
      <ref url="http://www.gnucitizen.org/blog/hacking-linksys-ip-cameras-pt-1/" source="MISC">http://www.gnucitizen.org/blog/hacking-linksys-ip-cameras-pt-1/</ref>
      <ref url="http://secunia.com/advisories/34767" source="SECUNIA" adv="1">34767</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="wvc54gca">
        <vers num="1.00r22" />
        <vers num="1.00r24" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2009-1556" published="2009-05-06" name="CVE-2009-1556" modified="2009-05-23" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:S/C:P/I:N/A:N)" CVSS_score="3.5" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="6.8" CVSS_base_score="3.5">
    <desc>
      <descript source="cve">img/main.cgi on the Cisco Linksys WVC54GCA wireless video camera with firmware 1.00R22 and 1.00R24 allows remote authenticated users to read arbitrary files in img/ via a filename in the next_file parameter, as demonstrated by reading .htpasswd to obtain the admin password, a different vulnerability than CVE-2004-2507.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2009/1173" source="VUPEN" adv="1">ADV-2009-1173</ref>
      <ref url="http://www.securityfocus.com/bid/34629" source="BID">34629</ref>
      <ref url="http://www.gnucitizen.org/blog/hacking-linksys-ip-cameras-pt-2/" source="MISC">http://www.gnucitizen.org/blog/hacking-linksys-ip-cameras-pt-2/</ref>
      <ref url="http://secunia.com/advisories/34767" source="SECUNIA" adv="1">34767</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="wvc54gca">
        <vers num="1.00r22" />
        <vers num="1.00r24" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1557" published="2009-05-06" name="CVE-2009-1557" modified="2009-05-23" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities on the Cisco Linksys WVC54GCA wireless video camera with firmware 1.00R22 and 1.00R24 allow remote attackers to inject arbitrary web script or HTML via the next_file parameter to (1) main.cgi, (2) img/main.cgi, or (3) adm/file.cgi; or (4) the this_file parameter to adm/file.cgi.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/50224" source="XF">wvc54gca-nextfile-xss(50224)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1173" source="VUPEN" adv="1">ADV-2009-1173</ref>
      <ref url="http://www.securityfocus.com/bid/34714" source="BID">34714</ref>
      <ref url="http://www.gnucitizen.org/blog/hacking-linksys-ip-cameras-pt-4/" source="MISC">http://www.gnucitizen.org/blog/hacking-linksys-ip-cameras-pt-4/</ref>
      <ref url="http://secunia.com/advisories/34767" source="SECUNIA" adv="1">34767</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="wvc54gca">
        <vers num="1.00r22" />
        <vers num="1.00r24" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1558" published="2009-05-06" name="CVE-2009-1558" modified="2009-05-08" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:N/A:N)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Directory traversal vulnerability in adm/file.cgi on the Cisco Linksys WVC54GCA wireless video camera with firmware 1.00R22 and 1.00R24 allows remote attackers to read arbitrary files via a %2e. (encoded dot dot) or an absolute pathname in the next_file parameter.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/50231" source="XF">wvc54gca-admfile-dir-traversal(50231)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1173" source="VUPEN" adv="1">ADV-2009-1173</ref>
      <ref url="http://www.securityfocus.com/bid/34713" source="BID">34713</ref>
      <ref url="http://www.gnucitizen.org/blog/hacking-linksys-ip-cameras-pt-3/" source="MISC">http://www.gnucitizen.org/blog/hacking-linksys-ip-cameras-pt-3/</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="wvc54gca">
        <vers num="1.00r22" />
        <vers num="1.00r24" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1559" published="2009-05-06" name="CVE-2009-1559" modified="2009-05-08" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:N/A:N)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Absolute path traversal vulnerability in adm/file.cgi on the Cisco Linksys WVC54GCA wireless video camera with firmware 1.00R24 and possibly 1.00R22 allows remote attackers to read arbitrary files via an absolute pathname in the this_file parameter.  NOTE: traversal via a .. (dot dot) is probably also possible.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/50231" source="XF">wvc54gca-admfile-dir-traversal(50231)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1173" source="VUPEN" adv="1">ADV-2009-1173</ref>
      <ref url="http://www.securityfocus.com/bid/34713" source="BID">34713</ref>
      <ref url="http://www.gnucitizen.org/blog/hacking-linksys-ip-cameras-pt-3/" source="MISC">http://www.gnucitizen.org/blog/hacking-linksys-ip-cameras-pt-3/</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="wvc54gca">
        <vers num="1.00r22" />
        <vers num="1.00r24" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1560" published="2009-05-06" name="CVE-2009-1560" modified="2009-05-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:N/A:N)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">The Cisco Linksys WVC54GCA wireless video camera with firmware 1.00R22 and 1.00R24 stores passwords and wireless-network keys in cleartext in (1) pass_wd.htm and (2) Wsecurity.htm, which allows remote attackers to obtain sensitive information by reading the HTML source code.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/50410" source="XF">wvc54gca-pass-wsecurity-info-disclosure(50410)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1173" source="VUPEN" adv="1">ADV-2009-1173</ref>
      <ref url="http://www.gnucitizen.org/blog/hacking-linksys-ip-cameras-pt-4/" source="MISC">http://www.gnucitizen.org/blog/hacking-linksys-ip-cameras-pt-4/</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="wvc54gc">
        <vers num="1.00r22" />
        <vers num="1.00r24" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1561" published="2009-05-06" name="CVE-2009-1561" modified="2009-05-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site request forgery (CSRF) vulnerability in administration.cgi on the Cisco Linksys WRT54GC router with firmware 1.05.7 allows remote attackers to hijack the intranet connectivity of arbitrary users for requests that change the administrator password via the sysPasswd and sysConfirmPasswd parameters.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2009/1172" source="VUPEN" adv="1">ADV-2009-1172</ref>
      <ref url="http://www.securityfocus.com/bid/34616" source="BID">34616</ref>
      <ref url="http://www.falandodeseguranca.com/?p=17" source="MISC">http://www.falandodeseguranca.com/?p=17</ref>
      <ref url="http://secunia.com/advisories/34805" source="SECUNIA" adv="1">34805</ref>
      <ref url="http://packetstormsecurity.org/0904-exploits/linksysadmin-passwd.txt" source="MISC">http://packetstormsecurity.org/0904-exploits/linksysadmin-passwd.txt</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2009-04/0198.html" source="BUGTRAQ">20090418 Linksys WRT54GC - Admin Password Change (POC)</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cisco" name="wrt54gc">
        <vers num="1.05.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" seq="2009-1563" reject="1" published="2009-10-29" name="CVE-2009-1563" modified="2009-12-19">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2009-0689.  Reason: This candidate is a duplicate of CVE-2009-0689.  Certain codebase relationships were not originally clear.  Notes: All CVE users should reference CVE-2009-0689 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript>
    </desc>
    <refs />
  </entry>
  <entry type="CVE" severity="High" seq="2009-1564" published="2010-04-12" name="CVE-2009-1564" modified="2010-04-22" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Heap-based buffer overflow in vmnc.dll in the VMnc media codec in VMware Movie Decoder before 6.5.4 Build 246459 on Windows, and the movie decoder in VMware Workstation 6.5.x before 6.5.4 build 246459, VMware Player 2.5.x before 2.5.4 build 246459, and VMware Server 2.x on Windows, allows remote attackers to execute arbitrary code via an AVI file with crafted video chunks that use HexTile encoding.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vmware.com/security/advisories/VMSA-2010-0007.html" source="CONFIRM" adv="1">http://www.vmware.com/security/advisories/VMSA-2010-0007.html</ref>
      <ref url="http://www.securitytracker.com/id?1023838" source="SECTRACK">1023838</ref>
      <ref url="http://www.securityfocus.com/bid/39363" source="BID">39363</ref>
      <ref url="http://secunia.com/secunia_research/2009-36/" source="MISC" adv="1">http://secunia.com/secunia_research/2009-36/</ref>
      <ref url="http://secunia.com/advisories/39215" source="SECUNIA" adv="1">39215</ref>
      <ref url="http://secunia.com/advisories/39206" source="SECUNIA" adv="1">39206</ref>
      <ref url="http://secunia.com/advisories/36712" source="SECUNIA" adv="1">36712</ref>
      <ref url="http://osvdb.org/63614" source="OSVDB">63614</ref>
      <ref url="http://lists.vmware.com/pipermail/security-announce/2010/000090.html" source="MLIST">[security-announce] 20100409 VMSA-2010-0007 VMware hosted products, vCenter Server and ESX patches resolve multiple security issues</ref>
      <ref url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=866" source="IDEFENSE">20100409 VMware VMnc Codec Heap Overflow Vulnerability</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2010-04/0121.html" source="FULLDISC">20100409 VMSA-2010-0007 VMware hosted products, vCenter Server and ESX patches resolve multiple security issues</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2010-04/0077.html" source="BUGTRAQ">20100409 VMSA-2010-0007 VMware hosted products, vCenter Server and ESX patches resolve multiple security issues</ref>
    </refs>
    <vuln_soft>
      <prod vendor="vmware" name="movie_decoder">
        <vers num="6.5.3" />
      </prod>
      <prod vendor="vmware" name="player">
        <vers num="2.5" />
        <vers num="2.5.1" />
        <vers num="2.5.2" />
        <vers num="2.5.3" />
      </prod>
      <prod vendor="vmware" name="server">
        <vers num="2.0.0" />
        <vers num="2.0.1" />
        <vers num="2.0.2" />
      </prod>
      <prod vendor="vmware" name="workstation">
        <vers num="6.5.0" />
        <vers num="6.5.1" />
        <vers num="6.5.2" />
        <vers num="6.5.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1565" published="2010-04-12" name="CVE-2009-1565" modified="2010-04-22" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">vmnc.dll in the VMnc media codec in VMware Movie Decoder before 6.5.4 Build 246459 on Windows, and the movie decoder in VMware Workstation 6.5.x before 6.5.4 build 246459, VMware Player 2.5.x before 2.5.4 build 246459, and VMware Server 2.x on Windows, allows remote attackers to execute arbitrary code via an AVI file with crafted HexTile-encoded video chunks that trigger heap-based buffer overflows, related to "integer truncation errors."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vmware.com/security/advisories/VMSA-2010-0007.html" source="CONFIRM" patch="1">http://www.vmware.com/security/advisories/VMSA-2010-0007.html</ref>
      <ref url="http://lists.vmware.com/pipermail/security-announce/2010/000090.html" source="MLIST" patch="1">[security-announce] 20100409 VMSA-2010-0007 VMware hosted products, vCenter Server and ESX patches resolve multiple security issues</ref>
      <ref url="http://www.securitytracker.com/id?1023838" source="SECTRACK">1023838</ref>
      <ref url="http://www.securityfocus.com/bid/39364" source="BID">39364</ref>
      <ref url="http://www.osvdb.org/63615" source="OSVDB">63615</ref>
      <ref url="http://secunia.com/secunia_research/2009-37/" source="MISC" adv="1">http://secunia.com/secunia_research/2009-37/</ref>
      <ref url="http://secunia.com/advisories/39215" source="SECUNIA" adv="1">39215</ref>
      <ref url="http://secunia.com/advisories/39206" source="SECUNIA" adv="1">39206</ref>
      <ref url="http://secunia.com/advisories/36712" source="SECUNIA" adv="1">36712</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2010-04/0121.html" source="FULLDISC">20100409 VMSA-2010-0007 VMware hosted products, vCenter Server and ESX patches resolve multiple security issues</ref>
      <ref url="http://archives.neohapsis.com/archives/bugtraq/2010-04/0077.html" source="BUGTRAQ">20100409 VMSA-2010-0007 VMware hosted products, vCenter Server and ESX patches resolve multiple security issues</ref>
    </refs>
    <vuln_soft>
      <prod vendor="vmware" name="movie_decoder">
        <vers num="6.5.3" />
      </prod>
      <prod vendor="vmware" name="player">
        <vers num="2.5" />
        <vers num="2.5.1" />
        <vers num="2.5.2" />
        <vers num="2.5.3" />
      </prod>
      <prod vendor="vmware" name="server">
        <vers num="2.0.0" />
        <vers num="2.0.1" />
        <vers num="2.0.2" />
      </prod>
      <prod vendor="vmware" name="workstation">
        <vers num="6.5.0" />
        <vers num="6.5.1" />
        <vers num="6.5.2" />
        <vers num="6.5.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1566" published="2009-12-03" name="CVE-2009-1566" modified="2009-12-04" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Integer overflow in Roxio Easy Media Creator 9.0.136, and Roxio Creator 2010 before SP1, might allow remote attackers to execute arbitrary code via an image with crafted dimensions.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/54496" source="XF">roxio-image-code-execution(54496)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/3375" source="VUPEN">ADV-2009-3375</ref>
      <ref url="http://www.securityfocus.com/bid/37183" source="BID">37183</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/508165/100/0/threaded" source="BUGTRAQ">20091202 Secunia Research: Roxio Creator Image Rendering Integer Overflow Vulnerability</ref>
      <ref url="http://secunia.com/secunia_research/2009-38/" source="MISC" adv="1">http://secunia.com/secunia_research/2009-38/</ref>
      <ref url="http://secunia.com/advisories/36069" source="SECUNIA" adv="1">36069</ref>
    </refs>
    <vuln_soft>
      <prod vendor="roxio" name="creator">
        <vers prev="1" num="9.0.136" />
      </prod>
      <prod vendor="roxio" name="easy_media_creator">
        <vers num="9.0.136" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1567" published="2009-12-03" name="CVE-2009-1567" modified="2009-12-07" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Multiple stack-based buffer overflows in the Lateral Arts Photobox uploader ActiveX control 1.x before 1.3, and 2.2.0.6, allow remote attackers to execute arbitrary code via a long URL string for the (1) LogURL, (2) ConnectURL, (3) SkinURL, (4) AlbumCreateURL, (5) ErrorURL, or (6) httpsinglehost property value.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2009/3377" source="VUPEN">ADV-2009-3377</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/3376" source="VUPEN" adv="1">ADV-2009-3376</ref>
      <ref url="http://www.securityfocus.com/bid/37187" source="BID">37187</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/508169/100/0/threaded" source="BUGTRAQ">20091202 Secunia Research: Lateral Arts Photobox uploader ActiveX Control Buffer Overflow</ref>
      <ref url="http://secunia.com/secunia_research/2009-41/" source="MISC" adv="1">http://secunia.com/secunia_research/2009-41/</ref>
      <ref url="http://secunia.com/advisories/37492" source="SECUNIA" adv="1">37492</ref>
      <ref url="http://secunia.com/advisories/37138" source="SECUNIA" adv="1">37138</ref>
    </refs>
    <vuln_soft>
      <prod vendor="larts" name="uploader_activex_control">
        <vers num="2.2.0.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1568" published="2009-12-08" name="CVE-2009-1568" modified="2009-12-09" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Stack-based buffer overflow in ienipp.ocx in Novell iPrint Client 5.30, and possibly other versions before 5.32, allows remote attackers to execute arbitrary code via a long target-frame parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2009/3429" source="VUPEN" patch="1" adv="1">ADV-2009-3429</ref>
      <ref url="http://www.securityfocus.com/bid/37242" source="BID" patch="1">37242</ref>
      <ref url="http://download.novell.com/Download?buildid=29T3EFRky18~" source="CONFIRM" patch="1">http://download.novell.com/Download?buildid=29T3EFRky18~</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/508289/100/0/threaded" source="BUGTRAQ">20091208 Secunia Research: Novell iPrint Client "target-frame" Parameter Buffer Overflow</ref>
      <ref url="http://secunia.com/secunia_research/2009-40/" source="MISC" adv="1">http://secunia.com/secunia_research/2009-40/</ref>
      <ref url="http://secunia.com/advisories/37169" source="SECUNIA" adv="1">37169</ref>
    </refs>
    <vuln_soft>
      <prod vendor="novell" name="iprint_client">
        <vers num="5.30" />
        <vers num="5.31" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1569" published="2009-12-08" name="CVE-2009-1569" modified="2010-12-29" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Multiple stack-based buffer overflows in Novell iPrint Client 4.38, 5.30, and possibly other versions before 5.32 allow remote attackers to execute arbitrary code via vectors related to (1) Date and (2) Time.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2009/3429" source="VUPEN" patch="1" adv="1">ADV-2009-3429</ref>
      <ref url="http://www.securityfocus.com/bid/37242" source="BID" patch="1">37242</ref>
      <ref url="http://download.novell.com/Download?buildid=29T3EFRky18~" source="CONFIRM" patch="1">http://download.novell.com/Download?buildid=29T3EFRky18~</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/508288/100/0/threaded" source="BUGTRAQ">20091208 Secunia Research: Novell iPrint Client Date/Time Parsing Buffer Overflow</ref>
      <ref url="http://secunia.com/secunia_research/2009-44/" source="MISC" adv="1">http://secunia.com/secunia_research/2009-44/</ref>
      <ref url="http://secunia.com/advisories/37169" source="SECUNIA" adv="1">37169</ref>
      <ref url="http://secunia.com/advisories/35004" source="SECUNIA" adv="1">35004</ref>
    </refs>
    <vuln_soft>
      <prod vendor="novell" name="iprint">
        <vers num="4.38" edition="" />
        <vers num="4.38" edition=":client" />
        <vers num="5.30" edition="" />
        <vers num="5.30" edition=":client" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1570" published="2009-11-13" name="CVE-2009-1570" modified="2011-08-23" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Integer overflow in the ReadImage function in plug-ins/file-bmp/bmp-read.c in GIMP 2.6.7 might allow remote attackers to execute arbitrary code via a BMP file with crafted width and height values that trigger a heap-based buffer overflow.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2009/3228" source="VUPEN" patch="1" adv="1">ADV-2009-3228</ref>
      <ref url="http://git.gnome.org/cgit/gimp/commit/?h=gimp-2-6&amp;id=df2b0aca2e7cdb95ebfd3454c65aaba0a83e9bbe" source="CONFIRM" patch="1">http://git.gnome.org/cgit/gimp/commit/?h=gimp-2-6&amp;id=df2b0aca2e7cdb95ebfd3454c65aaba0a83e9bbe</ref>
      <ref url="https://bugzilla.gnome.org/show_bug.cgi?id=600484" source="MISC">https://bugzilla.gnome.org/show_bug.cgi?id=600484</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/54254" source="XF">gimp-readimage-bo(54254)</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1021" source="VUPEN">ADV-2010-1021</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/3564" source="VUPEN">ADV-2009-3564</ref>
      <ref url="http://www.securityfocus.com/bid/37006" source="BID">37006</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/507813/100/0/threaded" source="BUGTRAQ">20091112 Secunia Research: Gimp BMP Image Parsing Integer Overflow Vulnerability</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2011-0838.html" source="REDHAT">RHSA-2011:0838</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2011-0837.html" source="REDHAT">RHSA-2011:0837</ref>
      <ref url="http://www.osvdb.org/59930" source="OSVDB">59930</ref>
      <ref url="http://secunia.com/secunia_research/2009-42/" source="MISC" adv="1">http://secunia.com/secunia_research/2009-42/</ref>
      <ref url="http://secunia.com/advisories/37232" source="SECUNIA" adv="1">37232</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:8290" source="OVAL">oval:org.mitre.oval:def:8290</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-04/msg00002.html" source="SUSE">SUSE-SR:2010:009</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gimp" name="gimp">
        <vers num="2.6.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1571" published="2010-02-22" name="CVE-2009-1571" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Use-after-free vulnerability in the HTML parser in Mozilla Firefox 3.0.x before 3.0.18 and 3.5.x before 3.5.8, Thunderbird before 3.0.2, and SeaMonkey before 2.0.3 allows remote attackers to execute arbitrary code via unspecified method calls that attempt to access freed objects in low-memory situations.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="https://bugzilla.mozilla.org/show_bug.cgi?id=526500" source="CONFIRM">https://bugzilla.mozilla.org/show_bug.cgi?id=526500</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/56361" source="XF">mozilla-htmlparser-code-exec(56361)</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0650" source="VUPEN">ADV-2010-0650</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/0405" source="VUPEN" adv="1">ADV-2010-0405</ref>
      <ref url="http://www.ubuntu.com/usn/USN-896-1" source="UBUNTU">USN-896-1</ref>
      <ref url="http://www.ubuntu.com/usn/USN-895-1" source="UBUNTU">USN-895-1</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/509585/100/0/threaded" source="BUGTRAQ">20100218 Secunia Research: Mozilla Firefox Memory Corruption Vulnerability</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0154.html" source="REDHAT">RHSA-2010:0154</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0153.html" source="REDHAT">RHSA-2010:0153</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0113.html" source="REDHAT">RHSA-2010:0113</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2010-0112.html" source="REDHAT">RHSA-2010:0112</ref>
      <ref url="http://www.mozilla.org/security/announce/2010/mfsa2010-03.html" source="CONFIRM" adv="1">http://www.mozilla.org/security/announce/2010/mfsa2010-03.html</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2010:051" source="MANDRIVA">MDVSA-2010:051</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2010:042" source="MANDRIVA">MDVSA-2010:042</ref>
      <ref url="http://www.debian.org/security/2010/dsa-1999" source="DEBIAN">DSA-1999</ref>
      <ref url="http://secunia.com/secunia_research/2009-45/" source="MISC" adv="1">http://secunia.com/secunia_research/2009-45/</ref>
      <ref url="http://secunia.com/advisories/38847" source="SECUNIA">38847</ref>
      <ref url="http://secunia.com/advisories/38772" source="SECUNIA">38772</ref>
      <ref url="http://secunia.com/advisories/38770" source="SECUNIA">38770</ref>
      <ref url="http://secunia.com/advisories/37242" source="SECUNIA" adv="1">37242</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:8615" source="OVAL">oval:org.mitre.oval:def:8615</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11227" source="OVAL">oval:org.mitre.oval:def:11227</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-03/msg00001.html" source="SUSE">SUSE-SA:2010:015</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2010-March/036132.html" source="FEDORA">FEDORA-2010-3267</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2010-March/036097.html" source="FEDORA">FEDORA-2010-3230</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2010-February/035426.html" source="FEDORA">FEDORA-2010-1727</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2010-February/035367.html" source="FEDORA">FEDORA-2010-1936</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2010-February/035346.html" source="FEDORA">FEDORA-2010-1932</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="3.0" edition="alpha" />
        <vers num="3.0" edition="beta2" />
        <vers num="3.0" edition="beta5" />
        <vers num="3.0.1" />
        <vers num="3.0.10" />
        <vers num="3.0.11" />
        <vers num="3.0.12" />
        <vers num="3.0.13" />
        <vers num="3.0.14" />
        <vers num="3.0.15" />
        <vers num="3.0.17" />
        <vers num="3.0.2" />
        <vers num="3.0.3" />
        <vers num="3.0.4" />
        <vers num="3.0.5" />
        <vers num="3.0.6" />
        <vers num="3.0.7" />
        <vers num="3.0.8" />
        <vers num="3.0.9" />
        <vers num="3.5" />
        <vers num="3.5.1" />
        <vers num="3.5.2" />
        <vers num="3.5.3" />
        <vers num="3.5.4" />
        <vers num="3.5.5" />
        <vers num="3.5.6" />
        <vers num="3.5.7" />
      </prod>
      <prod vendor="mozilla" name="seamonkey">
        <vers num="1.0" edition="alpha" />
        <vers num="1.0" edition="beta" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.5" />
        <vers num="1.0.6" />
        <vers num="1.0.7" />
        <vers num="1.0.8" />
        <vers num="1.0.9" />
        <vers num="1.1" />
        <vers num="1.1.1" />
        <vers num="1.1.10" />
        <vers num="1.1.11" />
        <vers num="1.1.12" />
        <vers num="1.1.13" />
        <vers num="1.1.14" />
        <vers num="1.1.15" />
        <vers num="1.1.16" />
        <vers num="1.1.17" />
        <vers num="1.1.2" />
        <vers num="1.1.3" />
        <vers num="1.1.4" />
        <vers num="1.1.5" />
        <vers num="1.1.6" />
        <vers num="1.1.7" />
        <vers num="1.1.8" />
        <vers num="1.1.9" />
        <vers num="2.0" edition="alpha_2" />
        <vers num="2.0" edition="alpha_3" />
        <vers num="2.0" edition="beta_1" />
        <vers num="2.0" edition="beta_2" />
        <vers num="2.0" edition="rc1" />
        <vers num="2.0" edition="rc2" />
        <vers num="2.0.1" />
        <vers num="2.0.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1572" published="2009-05-06" name="CVE-2009-1572" modified="2011-03-31" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The BGP daemon (bgpd) in Quagga 0.99.11 and earlier allows remote attackers to cause a denial of service (crash) via an AS path containing ASN elements whose string representation is longer than expected, which triggers an assert error.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.debian.org/security/2009/dsa-1788" source="DEBIAN" patch="1">DSA-1788</ref>
      <ref url="http://marc.info/?l=quagga-dev&amp;m=123364779626078&amp;w=2" source="MLIST" patch="1">[quagga-dev] 20090203 [quagga-dev 6391]  [PATCH] BGP 4-byte ASN bug fixes</ref>
      <ref url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=526311" source="CONFIRM" patch="1">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=526311</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-May/msg01107.html" source="FEDORA">FEDORA-2009-5324</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-May/msg01037.html" source="FEDORA">FEDORA-2009-5284</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/50317" source="XF">quagga-systemnumber-dos(50317)</ref>
      <ref url="http://www.ubuntu.com/usn/usn-775-1" source="UBUNTU">USN-775-1</ref>
      <ref url="http://www.securitytracker.com/id?1022164" source="SECTRACK">1022164</ref>
      <ref url="http://www.securityfocus.com/bid/34817" source="BID">34817</ref>
      <ref url="http://www.osvdb.org/54200" source="OSVDB">54200</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2009/05/01/2" source="MLIST">[oss-security] 20090501 Re: CVE request (sort of): Quagga BGP crasher</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2009/05/01/1" source="MLIST">[oss-security] 20090501 CVE request (sort of): Quagga BGP crasher</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:109" source="MANDRIVA">MDVSA-2009:109</ref>
      <ref url="http://thread.gmane.org/gmane.network.quagga.devel/6513" source="MISC">http://thread.gmane.org/gmane.network.quagga.devel/6513</ref>
      <ref url="http://secunia.com/advisories/35685" source="SECUNIA" adv="1">35685</ref>
      <ref url="http://secunia.com/advisories/35203" source="SECUNIA" adv="1">35203</ref>
      <ref url="http://secunia.com/advisories/35061" source="SECUNIA" adv="1">35061</ref>
      <ref url="http://secunia.com/advisories/34999" source="SECUNIA" adv="1">34999</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-07/msg00002.html" source="SUSE">SUSE-SR:2009:012</ref>
    </refs>
    <vuln_soft>
      <prod vendor="quagga" name="quagga">
        <vers num="0.95" />
        <vers num="0.96" />
        <vers num="0.96.1" />
        <vers num="0.96.2" />
        <vers num="0.96.3" />
        <vers num="0.96.4" />
        <vers num="0.96.5" />
        <vers num="0.97.0" />
        <vers num="0.97.1" />
        <vers num="0.97.2" />
        <vers num="0.97.3" />
        <vers num="0.97.4" />
        <vers num="0.97.5" />
        <vers num="0.98.0" />
        <vers num="0.98.1" />
        <vers num="0.98.2" />
        <vers num="0.98.3" />
        <vers num="0.98.4" />
        <vers num="0.98.5" />
        <vers num="0.98.6" />
        <vers num="0.99.1" />
        <vers num="0.99.10" />
        <vers prev="1" num="0.99.11" />
        <vers num="0.99.2" />
        <vers num="0.99.3" />
        <vers num="0.99.4" />
        <vers num="0.99.5" />
        <vers num="0.99.6" />
        <vers num="0.99.7" />
        <vers num="0.99.8" />
        <vers num="0.99.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1573" published="2009-05-06" name="CVE-2009-1573" modified="2010-05-27" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="4.6" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.9" CVSS_base_score="4.6">
    <desc>
      <descript source="cve">xvfb-run 1.6.1 in Debian GNU/Linux, Ubuntu, Fedora 10, and possibly other operating systems place the magic cookie (MCOOKIE) on the command line, which allows local users to gain privileges by listing the process and its arguments.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/50348" source="XF">xvfbrun-magiccookie-info-disclosure(50348)</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1185" source="VUPEN">ADV-2010-1185</ref>
      <ref url="http://www.ubuntu.com/usn/USN-939-1" source="UBUNTU">USN-939-1</ref>
      <ref url="http://www.securityfocus.com/bid/34828" source="BID">34828</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2009/05/05/4" source="MLIST">[oss-security] 20090505 Re: CVE id request: Debian/Ubuntu specific issue in xvfb-run (xorg)</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2009/05/05/2" source="MLIST">[oss-security] 20090505 CVE id request: Debian/Ubuntu specific issue in xvfb-run (xorg)</ref>
      <ref url="http://secunia.com/advisories/39834" source="SECUNIA">39834</ref>
      <ref url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=526678" source="CONFIRM" adv="1">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=526678</ref>
    </refs>
    <vuln_soft>
      <prod vendor="branden_robinson" name="xvfb-run">
        <vers num="1.6.1" />
      </prod>
      <prod vendor="debian" name="debian_linux">
        <vers num="" />
      </prod>
      <prod vendor="redhat" name="fedora">
        <vers num="10" />
      </prod>
      <prod vendor="ubuntu" name="linux">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1574" published="2009-05-06" name="CVE-2009-1574" modified="2010-12-23" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">racoon/isakmp_frag.c in ipsec-tools before 0.7.2 allows remote attackers to cause a denial of service (crash) via crafted fragmented packets without a payload, which triggers a NULL pointer dereference.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=497990" source="CONFIRM" patch="1">https://bugzilla.redhat.com/show_bug.cgi?id=497990</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2009/05/04/3" source="MLIST" patch="1">[oss-security] 20090504 Re: ipsec-tools 0.7.2</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2009/04/29/6" source="MLIST" patch="1">[oss-security] 20090429 ipsec-tools 0.7.2</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-May/msg00789.html" source="FEDORA">FEDORA-2009-4394</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-May/msg00746.html" source="FEDORA">FEDORA-2009-4298</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-May/msg00725.html" source="FEDORA">FEDORA-2009-4291</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/50412" source="XF">ipsectools-isakmpfrag-dos(50412)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/3184" source="VUPEN">ADV-2009-3184</ref>
      <ref url="http://www.ubuntu.com/usn/USN-785-1" source="UBUNTU">USN-785-1</ref>
      <ref url="http://www.securityfocus.com/bid/34765" source="BID">34765</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-1036.html" source="REDHAT">RHSA-2009:1036</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:112" source="MANDRIVA">MDVSA-2009:112</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1804" source="DEBIAN">DSA-1804</ref>
      <ref url="http://support.apple.com/kb/HT4298" source="CONFIRM">http://support.apple.com/kb/HT4298</ref>
      <ref url="http://support.apple.com/kb/HT3937" source="CONFIRM">http://support.apple.com/kb/HT3937</ref>
      <ref url="http://sourceforge.net/project/shownotes.php?group_id=74601&amp;release_id=677611" source="CONFIRM">http://sourceforge.net/project/shownotes.php?group_id=74601&amp;release_id=677611</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200905-03.xml" source="GENTOO">GLSA-200905-03</ref>
      <ref url="http://secunia.com/advisories/35685" source="SECUNIA">35685</ref>
      <ref url="http://secunia.com/advisories/35404" source="SECUNIA">35404</ref>
      <ref url="http://secunia.com/advisories/35212" source="SECUNIA">35212</ref>
      <ref url="http://secunia.com/advisories/35159" source="SECUNIA">35159</ref>
      <ref url="http://secunia.com/advisories/35153" source="SECUNIA">35153</ref>
      <ref url="http://secunia.com/advisories/35113" source="SECUNIA">35113</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9624" source="OVAL">oval:org.mitre.oval:def:9624</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-07/msg00002.html" source="SUSE">SUSE-SR:2009:012</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Dec/msg00001.html" source="APPLE">APPLE-SA-2010-12-16-1</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2009/Nov/msg00000.html" source="APPLE">APPLE-SA-2009-11-09-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ipsec-tools" name="ipsec-tools">
        <vers num="0.1" />
        <vers num="0.2" />
        <vers num="0.2.1" />
        <vers num="0.2.2" />
        <vers num="0.2.3" />
        <vers num="0.2.4" />
        <vers num="0.3" edition="rc1" />
        <vers num="0.3" edition="rc2" />
        <vers num="0.3" edition="rc3" />
        <vers num="0.3" edition="rc4" />
        <vers num="0.3" edition="rc5" />
        <vers num="0.3.1" />
        <vers num="0.3.2" />
        <vers num="0.3.3" />
        <vers num="0.4" edition="rc1" />
        <vers num="0.5" />
        <vers num="0.6.1" />
        <vers num="0.6.2" />
        <vers num="0.6.3" />
        <vers num="0.6.4" />
        <vers num="0.6.5" />
        <vers num="0.6.6" />
        <vers num="0.7" />
        <vers prev="1" num="0.7.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1575" published="2009-05-06" name="CVE-2009-1575" modified="2009-05-20" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Drupal 5.x before 5.17 and 6.x before 6.11, as used in vbDrupal before 5.17.0, allows remote attackers to inject arbitrary web script or HTML via crafted UTF-8 byte sequences before the Content-Type meta tag, which are treated as UTF-7 by Internet Explorer 6 and 7.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2009/1216" source="VUPEN" patch="1" adv="1">ADV-2009-1216</ref>
      <ref url="http://www.vbdrupal.org/forum/showthread.php?p=9953#post9953" source="CONFIRM" patch="1" adv="1">http://www.vbdrupal.org/forum/showthread.php?p=9953#post9953</ref>
      <ref url="http://www.osvdb.org/54152" source="OSVDB" patch="1">54152</ref>
      <ref url="http://drupal.org/node/449078" source="CONFIRM" patch="1" adv="1">http://drupal.org/node/449078</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-May/msg00133.html" source="FEDORA">FEDORA-2009-4203</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-May/msg00108.html" source="FEDORA">FEDORA-2009-4175</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/50250" source="XF">drupal-utf7-xss(50250)</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1792" source="DEBIAN">DSA-1792</ref>
      <ref url="http://secunia.com/advisories/34980" source="SECUNIA">34980</ref>
      <ref url="http://secunia.com/advisories/34950" source="SECUNIA" adv="1">34950</ref>
      <ref url="http://secunia.com/advisories/34948" source="SECUNIA" adv="1">34948</ref>
    </refs>
    <vuln_soft>
      <prod vendor="drupal" name="drupal">
        <vers num="5.0" edition="beta1" />
        <vers num="5.0" edition="beta2" />
        <vers num="5.0" edition="rc1" />
        <vers num="5.0" edition="rc2" />
        <vers num="5.1" />
        <vers num="5.10" />
        <vers num="5.11" />
        <vers num="5.12" />
        <vers num="5.13" />
        <vers num="5.14" />
        <vers num="5.15" />
        <vers num="5.16" />
        <vers num="5.1_rev1.1" />
        <vers num="5.2" />
        <vers num="5.3" />
        <vers num="5.4" />
        <vers num="5.5" />
        <vers num="5.5." />
        <vers num="5.6" />
        <vers num="5.7" />
        <vers num="5.8" />
        <vers num="5.9" />
        <vers num="6" edition="beta1" />
        <vers num="6.0" edition="beta1" />
        <vers num="6.0" edition="beta2" />
        <vers num="6.0" edition="beta3" />
        <vers num="6.0" edition="beta4" />
        <vers num="6.0" edition="rc-1" />
        <vers num="6.0" edition="rc-2" />
        <vers num="6.0" edition="rc-3" />
        <vers num="6.0" edition="rc-4" />
        <vers num="6.1" />
        <vers num="6.10" />
        <vers num="6.2" />
        <vers num="6.3" />
        <vers num="6.4" />
        <vers num="6.5" />
        <vers num="6.6" />
        <vers num="6.7" />
        <vers num="6.8" />
        <vers num="6.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1576" published="2009-05-06" name="CVE-2009-1576" modified="2009-05-20" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Unspecified vulnerability in Drupal 5.x before 5.17 and 6.x before 6.11, as used in vbDrupal before 5.17.0, allows user-assisted remote attackers to obtain sensitive information by tricking victims into visiting the front page of the site with a crafted URL and causing form data to be sent to an attacker-controlled site, possibly related to multiple / (slash) characters that are not properly handled by includes/bootstrap.inc, as demonstrated using the search box.  NOTE: this vulnerability can be leveraged to conduct cross-site request forgery (CSRF) attacks.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-May/msg00133.html" source="FEDORA" patch="1">FEDORA-2009-4203</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-May/msg00108.html" source="FEDORA" patch="1">FEDORA-2009-4175</ref>
      <ref url="http://www.vbdrupal.org/forum/showthread.php?p=9953#post9953" source="CONFIRM" patch="1">http://www.vbdrupal.org/forum/showthread.php?p=9953#post9953</ref>
      <ref url="http://drupal.org/node/449078" source="CONFIRM" patch="1" adv="1">http://drupal.org/node/449078</ref>
      <ref url="http://drupal.org/files/sa-core-2009-005/SA-CORE-2009-005-5.16.patch" source="MISC" patch="1">http://drupal.org/files/sa-core-2009-005/SA-CORE-2009-005-5.16.patch</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1216" source="VUPEN" adv="1">ADV-2009-1216</ref>
      <ref url="http://www.osvdb.org/54153" source="OSVDB">54153</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1792" source="DEBIAN">DSA-1792</ref>
      <ref url="http://secunia.com/advisories/34980" source="SECUNIA">34980</ref>
      <ref url="http://secunia.com/advisories/34950" source="SECUNIA" adv="1">34950</ref>
      <ref url="http://secunia.com/advisories/34948" source="SECUNIA" adv="1">34948</ref>
    </refs>
    <vuln_soft>
      <prod vendor="drupal" name="drupal">
        <vers num="5.0" edition="beta1" />
        <vers num="5.0" edition="beta2" />
        <vers num="5.0" edition="rc1" />
        <vers num="5.0" edition="rc2" />
        <vers num="5.1" />
        <vers num="5.10" />
        <vers num="5.11" />
        <vers num="5.12" />
        <vers num="5.13" />
        <vers num="5.14" />
        <vers num="5.15" />
        <vers num="5.16" />
        <vers num="5.1_rev1.1" />
        <vers num="6.0" edition="beta1" />
        <vers num="6.0" edition="beta2" />
        <vers num="6.0" edition="beta3" />
        <vers num="6.0" edition="beta4" />
        <vers num="6.0" edition="rc-1" />
        <vers num="6.0" edition="rc-2" />
        <vers num="6.0" edition="rc-3" />
        <vers num="6.0" edition="rc-4" />
        <vers num="6.1" />
        <vers num="6.10" />
        <vers num="6.2" />
        <vers num="6.3" />
        <vers num="6.4" />
        <vers num="6.5" />
        <vers num="6.6" />
        <vers num="6.7" />
        <vers num="6.8" />
        <vers num="6.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1577" published="2009-05-07" name="CVE-2009-1577" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Multiple stack-based buffer overflows in the putstring function in find.c in Cscope before 15.6 allow user-assisted remote attackers to execute arbitrary code via a long (1) function name or (2) symbol in a source-code file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=499174" source="CONFIRM" patch="1">https://bugzilla.redhat.com/show_bug.cgi?id=499174</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=189666" source="CONFIRM" patch="1">https://bugzilla.redhat.com/show_bug.cgi?id=189666</ref>
      <ref url="http://cscope.cvs.sourceforge.net/viewvc/cscope/cscope/src/find.c?r1=1.18&amp;r2=1.19" source="CONFIRM" patch="1">http://cscope.cvs.sourceforge.net/viewvc/cscope/cscope/src/find.c?r1=1.18&amp;r2=1.19</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/50366" source="XF">cscope-findc-bo(50366)</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-1101.html" source="REDHAT">RHSA-2009:1101</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2009/05/06/9" source="MLIST">[oss-security] 20090506 Re: Old cscope buffer overflow</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2009/05/06/10" source="MLIST">[oss-security] 20090506 Re: Old cscope buffer overflow</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2009/05/05/1" source="MLIST">[oss-security] 20090505 Old cscope buffer overflow</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200905-02.xml" source="GENTOO">GLSA-200905-02</ref>
      <ref url="http://secunia.com/advisories/35213" source="SECUNIA">35213</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9837" source="OVAL">oval:org.mitre.oval:def:9837</ref>
      <ref url="http://cvs.fedoraproject.org/viewvc/rpms/cscope/devel/cscope-15.5-putstring-overflow.patch" source="CONFIRM">http://cvs.fedoraproject.org/viewvc/rpms/cscope/devel/cscope-15.5-putstring-overflow.patch</ref>
      <ref url="http://cscope.cvs.sourceforge.net/viewvc/cscope/cscope/src/find.c?view=log#rev1.19" source="CONFIRM">http://cscope.cvs.sourceforge.net/viewvc/cscope/cscope/src/find.c?view=log#rev1.19</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cscope" name="cscope">
        <vers num="13.0" />
        <vers num="15.0bl2" />
        <vers num="15.1" />
        <vers num="15.3" />
        <vers num="15.4" />
        <vers prev="1" num="15.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1578" published="2009-05-14" name="CVE-2009-1578" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in SquirrelMail before 1.4.18 and NaSMail before 1.7 allow remote attackers to inject arbitrary web script or HTML via vectors involving (1) certain encrypted strings in e-mail headers, related to contrib/decrypt_headers.php; (2) PHP_SELF; and (3) the query string (aka QUERY_STRING).</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-May/msg00577.html" source="FEDORA" patch="1">FEDORA-2009-4880</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-May/msg00566.html" source="FEDORA" patch="1">FEDORA-2009-4870</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/50460" source="XF" patch="1">squirrelmail-decryptheaders-xss(50460)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1296" source="VUPEN" patch="1" adv="1">ADV-2009-1296</ref>
      <ref url="http://www.squirrelmail.org/security/issue/2009-05-09" source="CONFIRM" patch="1" adv="1">http://www.squirrelmail.org/security/issue/2009-05-09</ref>
      <ref url="http://www.squirrelmail.org/security/issue/2009-05-08" source="CONFIRM" patch="1" adv="1">http://www.squirrelmail.org/security/issue/2009-05-08</ref>
      <ref url="http://www.securityfocus.com/bid/34916" source="BID" patch="1">34916</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:110" source="MANDRIVA" patch="1">MDVSA-2009:110</ref>
      <ref url="http://squirrelmail.svn.sourceforge.net/viewvc/squirrelmail?view=rev&amp;revision=13672" source="CONFIRM" patch="1">http://squirrelmail.svn.sourceforge.net/viewvc/squirrelmail?view=rev&amp;revision=13672</ref>
      <ref url="http://squirrelmail.svn.sourceforge.net/viewvc/squirrelmail?view=rev&amp;revision=13670" source="CONFIRM" patch="1">http://squirrelmail.svn.sourceforge.net/viewvc/squirrelmail?view=rev&amp;revision=13670</ref>
      <ref url="http://squirrelmail.svn.sourceforge.net/viewvc/squirrelmail/branches/SM-1_4-STABLE/squirrelmail/functions/global.php?r1=13670&amp;r2=13669&amp;pathrev=13670" source="CONFIRM" patch="1">http://squirrelmail.svn.sourceforge.net/viewvc/squirrelmail/branches/SM-1_4-STABLE/squirrelmail/functions/global.php?r1=13670&amp;r2=13669&amp;pathrev=13670</ref>
      <ref url="http://squirrelmail.svn.sourceforge.net/viewvc/squirrelmail/branches/SM-1_4-STABLE/squirrelmail/doc/ChangeLog" source="CONFIRM" patch="1">http://squirrelmail.svn.sourceforge.net/viewvc/squirrelmail/branches/SM-1_4-STABLE/squirrelmail/doc/ChangeLog</ref>
      <ref url="http://squirrelmail.svn.sourceforge.net/viewvc/squirrelmail/branches/SM-1_4-STABLE/squirrelmail/contrib/decrypt_headers.php?r1=13672&amp;r2=13671&amp;pathrev=13672" source="CONFIRM" patch="1">http://squirrelmail.svn.sourceforge.net/viewvc/squirrelmail/branches/SM-1_4-STABLE/squirrelmail/contrib/decrypt_headers.php?r1=13672&amp;r2=13671&amp;pathrev=13672</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-May/msg00572.html" source="FEDORA">FEDORA-2009-4875</ref>
      <ref url="https://gna.org/forum/forum.php?forum_id=2146" source="CONFIRM">https://gna.org/forum/forum.php?forum_id=2146</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=500363" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=500363</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/50459" source="XF">squirrelmail-phpself-xss(50459)</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1481" source="VUPEN">ADV-2010-1481</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/3315" source="VUPEN">ADV-2009-3315</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-1066.html" source="REDHAT">RHSA-2009:1066</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1802" source="DEBIAN">DSA-1802</ref>
      <ref url="http://support.apple.com/kb/HT4188" source="CONFIRM">http://support.apple.com/kb/HT4188</ref>
      <ref url="http://secunia.com/advisories/40220" source="SECUNIA">40220</ref>
      <ref url="http://secunia.com/advisories/37415" source="SECUNIA">37415</ref>
      <ref url="http://secunia.com/advisories/35259" source="SECUNIA">35259</ref>
      <ref url="http://secunia.com/advisories/35140" source="SECUNIA">35140</ref>
      <ref url="http://secunia.com/advisories/35073" source="SECUNIA" adv="1">35073</ref>
      <ref url="http://secunia.com/advisories/35052" source="SECUNIA" adv="1">35052</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11624" source="OVAL">oval:org.mitre.oval:def:11624</ref>
      <ref url="http://osvdb.org/60468" source="OSVDB">60468</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Jun/msg00001.html" source="APPLE">APPLE-SA-2010-06-15-1</ref>
      <ref url="http://download.gna.org/nasmail/nasmail-1.7.zip" source="CONFIRM">http://download.gna.org/nasmail/nasmail-1.7.zip</ref>
    </refs>
    <vuln_soft>
      <prod vendor="squirrelmail" name="squirrelmail">
        <vers num="0.1" />
        <vers num="0.1.1" />
        <vers num="0.1.2" />
        <vers num="0.2" />
        <vers num="0.2.1" />
        <vers num="0.3" />
        <vers num="0.3.1" />
        <vers num="0.3pre1" />
        <vers num="0.3pre2" />
        <vers num="0.4" />
        <vers num="0.4pre1" />
        <vers num="0.4pre2" />
        <vers num="0.5" />
        <vers num="0.5pre1" />
        <vers num="0.5pre2" />
        <vers num="1.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.5" />
        <vers num="1.0.6" />
        <vers num="1.0pre1" />
        <vers num="1.0pre2" />
        <vers num="1.0pre3" />
        <vers num="1.1.0" />
        <vers num="1.1.1" />
        <vers num="1.1.2" />
        <vers num="1.1.3" />
        <vers num="1.2" />
        <vers num="1.2.0" />
        <vers num="1.2.0_rc3" />
        <vers num="1.2.1" />
        <vers num="1.2.10" />
        <vers num="1.2.11" />
        <vers num="1.2.2" />
        <vers num="1.2.3" />
        <vers num="1.2.4" />
        <vers num="1.2.5" />
        <vers num="1.2.6" />
        <vers num="1.2.7" />
        <vers num="1.2.8" />
        <vers num="1.2.9" />
        <vers num="1.3.0" />
        <vers num="1.3.1" />
        <vers num="1.3.2" />
        <vers num="1.4" />
        <vers num="1.4.0" />
        <vers num="1.4.0_rc1" />
        <vers num="1.4.0_rc2a" />
        <vers num="1.4.1" />
        <vers num="1.4.10" />
        <vers num="1.4.10a" />
        <vers num="1.4.11" />
        <vers num="1.4.12" />
        <vers num="1.4.15" />
        <vers num="1.4.15_rc1" />
        <vers num="1.4.16" />
        <vers prev="1" num="1.4.17" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1579" published="2009-05-14" name="CVE-2009-1579" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">The map_yp_alias function in functions/imap_general.php in SquirrelMail before 1.4.18 and NaSMail before 1.7 allows remote attackers to execute arbitrary commands via shell metacharacters in a username string that is used by the ypmatch program.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-May/msg00577.html" source="FEDORA" patch="1">FEDORA-2009-4880</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-May/msg00566.html" source="FEDORA" patch="1">FEDORA-2009-4870</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1296" source="VUPEN" patch="1" adv="1">ADV-2009-1296</ref>
      <ref url="http://www.squirrelmail.org/security/issue/2009-05-10" source="CONFIRM" patch="1" adv="1">http://www.squirrelmail.org/security/issue/2009-05-10</ref>
      <ref url="http://www.securityfocus.com/bid/34916" source="BID" patch="1">34916</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:110" source="MANDRIVA" patch="1">MDVSA-2009:110</ref>
      <ref url="http://squirrelmail.svn.sourceforge.net/viewvc/squirrelmail?view=rev&amp;revision=13674" source="CONFIRM" patch="1">http://squirrelmail.svn.sourceforge.net/viewvc/squirrelmail?view=rev&amp;revision=13674</ref>
      <ref url="http://squirrelmail.svn.sourceforge.net/viewvc/squirrelmail/branches/SM-1_4-STABLE/squirrelmail/functions/imap_general.php?r1=13674&amp;r2=13673&amp;pathrev=13674" source="CONFIRM" patch="1">http://squirrelmail.svn.sourceforge.net/viewvc/squirrelmail/branches/SM-1_4-STABLE/squirrelmail/functions/imap_general.php?r1=13674&amp;r2=13673&amp;pathrev=13674</ref>
      <ref url="http://squirrelmail.svn.sourceforge.net/viewvc/squirrelmail/branches/SM-1_4-STABLE/squirrelmail/doc/ChangeLog" source="CONFIRM" patch="1">http://squirrelmail.svn.sourceforge.net/viewvc/squirrelmail/branches/SM-1_4-STABLE/squirrelmail/doc/ChangeLog</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-May/msg00572.html" source="FEDORA">FEDORA-2009-4875</ref>
      <ref url="https://gna.org/forum/forum.php?forum_id=2146" source="CONFIRM">https://gna.org/forum/forum.php?forum_id=2146</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=500360" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=500360</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/50461" source="XF">squirrelmail-mapypalias-code-execution(50461)</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1481" source="VUPEN">ADV-2010-1481</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/3315" source="VUPEN">ADV-2009-3315</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-1066.html" source="REDHAT">RHSA-2009:1066</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1802" source="DEBIAN">DSA-1802</ref>
      <ref url="http://support.apple.com/kb/HT4188" source="CONFIRM">http://support.apple.com/kb/HT4188</ref>
      <ref url="http://secunia.com/advisories/40220" source="SECUNIA">40220</ref>
      <ref url="http://secunia.com/advisories/37415" source="SECUNIA">37415</ref>
      <ref url="http://secunia.com/advisories/35259" source="SECUNIA">35259</ref>
      <ref url="http://secunia.com/advisories/35140" source="SECUNIA">35140</ref>
      <ref url="http://secunia.com/advisories/35073" source="SECUNIA" adv="1">35073</ref>
      <ref url="http://secunia.com/advisories/35052" source="SECUNIA" adv="1">35052</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10986" source="OVAL">oval:org.mitre.oval:def:10986</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Jun/msg00001.html" source="APPLE">APPLE-SA-2010-06-15-1</ref>
      <ref url="http://download.gna.org/nasmail/nasmail-1.7.zip" source="CONFIRM">http://download.gna.org/nasmail/nasmail-1.7.zip</ref>
    </refs>
    <vuln_soft>
      <prod vendor="squirrelmail" name="squirrelmail">
        <vers num="0.1" />
        <vers num="0.1.1" />
        <vers num="0.1.2" />
        <vers num="0.2" />
        <vers num="0.2.1" />
        <vers num="0.3" />
        <vers num="0.3.1" />
        <vers num="0.3pre1" />
        <vers num="0.3pre2" />
        <vers num="0.4" />
        <vers num="0.4pre1" />
        <vers num="0.4pre2" />
        <vers num="0.5" />
        <vers num="0.5pre1" />
        <vers num="0.5pre2" />
        <vers num="1.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.5" />
        <vers num="1.0.6" />
        <vers num="1.0pre1" />
        <vers num="1.0pre2" />
        <vers num="1.0pre3" />
        <vers num="1.1.0" />
        <vers num="1.1.1" />
        <vers num="1.1.2" />
        <vers num="1.1.3" />
        <vers num="1.2" />
        <vers num="1.2.0" />
        <vers num="1.2.0_rc3" />
        <vers num="1.2.1" />
        <vers num="1.2.10" />
        <vers num="1.2.11" />
        <vers num="1.2.2" />
        <vers num="1.2.3" />
        <vers num="1.2.4" />
        <vers num="1.2.5" />
        <vers num="1.2.6" />
        <vers num="1.2.7" />
        <vers num="1.2.8" />
        <vers num="1.2.9" />
        <vers num="1.3.0" />
        <vers num="1.3.1" />
        <vers num="1.3.2" />
        <vers num="1.4" />
        <vers num="1.4.0" />
        <vers num="1.4.0_rc1" />
        <vers num="1.4.0_rc2a" />
        <vers num="1.4.1" />
        <vers num="1.4.10" />
        <vers num="1.4.10a" />
        <vers num="1.4.11" />
        <vers num="1.4.12" />
        <vers num="1.4.15" />
        <vers num="1.4.15_rc1" />
        <vers num="1.4.16" />
        <vers prev="1" num="1.4.17" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1580" published="2009-05-14" name="CVE-2009-1580" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)" CVSS_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_base_score="5.8">
    <desc>
      <descript source="cve">Session fixation vulnerability in SquirrelMail before 1.4.18 allows remote attackers to hijack web sessions via a crafted cookie.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2009/1296" source="VUPEN" patch="1" adv="1">ADV-2009-1296</ref>
      <ref url="http://www.squirrelmail.org/security/issue/2009-05-11" source="CONFIRM" patch="1" adv="1">http://www.squirrelmail.org/security/issue/2009-05-11</ref>
      <ref url="http://www.securityfocus.com/bid/34916" source="BID" patch="1">34916</ref>
      <ref url="http://squirrelmail.svn.sourceforge.net/viewvc/squirrelmail?view=rev&amp;revision=13676" source="CONFIRM" patch="1" adv="1">http://squirrelmail.svn.sourceforge.net/viewvc/squirrelmail?view=rev&amp;revision=13676</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-May/msg00577.html" source="FEDORA">FEDORA-2009-4880</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-May/msg00572.html" source="FEDORA">FEDORA-2009-4875</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-May/msg00566.html" source="FEDORA">FEDORA-2009-4870</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=500358" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=500358</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/50462" source="XF">squirrelmail-baseuri-session-hijacking(50462)</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1481" source="VUPEN">ADV-2010-1481</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:110" source="MANDRIVA">MDVSA-2009:110</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1802" source="DEBIAN">DSA-1802</ref>
      <ref url="http://support.apple.com/kb/HT4188" source="CONFIRM">http://support.apple.com/kb/HT4188</ref>
      <ref url="http://squirrelmail.svn.sourceforge.net/viewvc/squirrelmail/branches/SM-1_4-STABLE/squirrelmail/doc/ChangeLog" source="CONFIRM">http://squirrelmail.svn.sourceforge.net/viewvc/squirrelmail/branches/SM-1_4-STABLE/squirrelmail/doc/ChangeLog</ref>
      <ref url="http://secunia.com/advisories/40220" source="SECUNIA">40220</ref>
      <ref url="http://secunia.com/advisories/35140" source="SECUNIA">35140</ref>
      <ref url="http://secunia.com/advisories/35073" source="SECUNIA" adv="1">35073</ref>
      <ref url="http://secunia.com/advisories/35052" source="SECUNIA" adv="1">35052</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10107" source="OVAL">oval:org.mitre.oval:def:10107</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Jun/msg00001.html" source="APPLE">APPLE-SA-2010-06-15-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="squirrelmail" name="squirrelmail">
        <vers num="0.1" />
        <vers num="0.1.1" />
        <vers num="0.1.2" />
        <vers num="0.2" />
        <vers num="0.2.1" />
        <vers num="0.3" />
        <vers num="0.3.1" />
        <vers num="0.3pre1" />
        <vers num="0.3pre2" />
        <vers num="0.4" />
        <vers num="0.4pre1" />
        <vers num="0.4pre2" />
        <vers num="0.5" />
        <vers num="0.5pre1" />
        <vers num="0.5pre2" />
        <vers num="1.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.5" />
        <vers num="1.0.6" />
        <vers num="1.0pre1" />
        <vers num="1.0pre2" />
        <vers num="1.0pre3" />
        <vers num="1.1.0" />
        <vers num="1.1.2" />
        <vers num="1.1.3" />
        <vers num="1.2" />
        <vers num="1.2.0" edition="rc3" />
        <vers num="1.2.1" />
        <vers num="1.2.10" />
        <vers num="1.2.11" />
        <vers num="1.2.2" />
        <vers num="1.2.3" />
        <vers num="1.2.4" />
        <vers num="1.2.5" />
        <vers num="1.2.6" />
        <vers num="1.2.7" />
        <vers num="1.2.8" />
        <vers num="1.2.9" />
        <vers num="1.3.0" />
        <vers num="1.4" edition="rc1" />
        <vers num="1.4.0" edition="rc1" />
        <vers num="1.4.0" edition="rc2a" />
        <vers num="1.4.1" />
        <vers num="1.4.10a" />
        <vers num="1.4.11" />
        <vers num="1.4.12" />
        <vers num="1.4.15" edition="rc1" />
        <vers num="1.4.16" />
        <vers prev="1" num="1.4.17" />
        <vers num="1.4.2" />
        <vers num="1.4.3" edition="r3" />
        <vers num="1.4.3" edition="rc1" />
        <vers num="1.4.3a" />
        <vers num="1.4.3aa" />
        <vers num="1.4.4" edition="rc1" />
        <vers num="1.4.5" />
        <vers num="1.4.6" edition="rc1" />
        <vers num="1.4.7" />
        <vers num="1.4.8.4fc6" />
        <vers num="1.4.9" />
        <vers num="1.4.9a" />
        <vers num="1.44" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1581" published="2009-05-14" name="CVE-2009-1581" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">functions/mime.php in SquirrelMail before 1.4.18 does not protect the application's content from Cascading Style Sheets (CSS) positioning in HTML e-mail messages, which allows remote attackers to spoof the user interface, and conduct cross-site scripting (XSS) and phishing attacks, via a crafted message.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=500356" source="CONFIRM" patch="1">https://bugzilla.redhat.com/show_bug.cgi?id=500356</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-May/msg00577.html" source="FEDORA">FEDORA-2009-4880</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-May/msg00572.html" source="FEDORA">FEDORA-2009-4875</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-May/msg00566.html" source="FEDORA">FEDORA-2009-4870</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/50463" source="XF">squirrelmail-css-xss(50463)</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1481" source="VUPEN">ADV-2010-1481</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1296" source="VUPEN" adv="1">ADV-2009-1296</ref>
      <ref url="http://www.squirrelmail.org/security/issue/2009-05-12" source="CONFIRM">http://www.squirrelmail.org/security/issue/2009-05-12</ref>
      <ref url="http://www.securityfocus.com/bid/34916" source="BID">34916</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-1066.html" source="REDHAT">RHSA-2009:1066</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:110" source="MANDRIVA">MDVSA-2009:110</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1802" source="DEBIAN">DSA-1802</ref>
      <ref url="http://support.apple.com/kb/HT4188" source="CONFIRM">http://support.apple.com/kb/HT4188</ref>
      <ref url="http://squirrelmail.svn.sourceforge.net/viewvc/squirrelmail?view=rev&amp;revision=13667" source="CONFIRM">http://squirrelmail.svn.sourceforge.net/viewvc/squirrelmail?view=rev&amp;revision=13667</ref>
      <ref url="http://squirrelmail.svn.sourceforge.net/viewvc/squirrelmail/branches/SM-1_4-STABLE/squirrelmail/functions/mime.php?r1=13667&amp;r2=13666&amp;pathrev=13667" source="CONFIRM">http://squirrelmail.svn.sourceforge.net/viewvc/squirrelmail/branches/SM-1_4-STABLE/squirrelmail/functions/mime.php?r1=13667&amp;r2=13666&amp;pathrev=13667</ref>
      <ref url="http://squirrelmail.svn.sourceforge.net/viewvc/squirrelmail/branches/SM-1_4-STABLE/squirrelmail/doc/ChangeLog" source="CONFIRM">http://squirrelmail.svn.sourceforge.net/viewvc/squirrelmail/branches/SM-1_4-STABLE/squirrelmail/doc/ChangeLog</ref>
      <ref url="http://secunia.com/advisories/40220" source="SECUNIA">40220</ref>
      <ref url="http://secunia.com/advisories/35259" source="SECUNIA">35259</ref>
      <ref url="http://secunia.com/advisories/35140" source="SECUNIA">35140</ref>
      <ref url="http://secunia.com/advisories/35073" source="SECUNIA" adv="1">35073</ref>
      <ref url="http://secunia.com/advisories/35052" source="SECUNIA" adv="1">35052</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10441" source="OVAL">oval:org.mitre.oval:def:10441</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Jun/msg00001.html" source="APPLE">APPLE-SA-2010-06-15-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="squirrelmail" name="squirrelmail">
        <vers num="0.1" />
        <vers num="0.1.1" />
        <vers num="0.1.2" />
        <vers num="0.2" />
        <vers num="0.2.1" />
        <vers num="0.3" />
        <vers num="0.3.1" />
        <vers num="0.3pre1" />
        <vers num="0.3pre2" />
        <vers num="0.4" />
        <vers num="0.4pre1" />
        <vers num="0.4pre2" />
        <vers num="0.5" />
        <vers num="0.5pre1" />
        <vers num="0.5pre2" />
        <vers num="1.0" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" />
        <vers num="1.0.4" />
        <vers num="1.0.5" />
        <vers num="1.0.6" />
        <vers num="1.0pre1" />
        <vers num="1.0pre2" />
        <vers num="1.0pre3" />
        <vers num="1.1.0" />
        <vers num="1.1.1" />
        <vers num="1.1.2" />
        <vers num="1.1.3" />
        <vers num="1.2" />
        <vers num="1.2.0" />
        <vers num="1.2.0_rc3" />
        <vers num="1.2.1" />
        <vers num="1.2.10" />
        <vers num="1.2.11" />
        <vers num="1.2.2" />
        <vers num="1.2.3" />
        <vers num="1.2.4" />
        <vers num="1.2.5" />
        <vers num="1.2.6" />
        <vers num="1.2.7" />
        <vers num="1.2.8" />
        <vers num="1.2.9" />
        <vers num="1.3.0" />
        <vers num="1.3.1" />
        <vers num="1.3.2" />
        <vers num="1.4" />
        <vers num="1.4.0" />
        <vers num="1.4.0_rc1" />
        <vers num="1.4.0_rc2a" />
        <vers num="1.4.1" />
        <vers num="1.4.10" />
        <vers num="1.4.10a" />
        <vers num="1.4.11" />
        <vers num="1.4.12" />
        <vers num="1.4.15" />
        <vers num="1.4.15_rc1" />
        <vers num="1.4.16" />
        <vers prev="1" num="1.4.17" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1582" published="2009-05-07" name="CVE-2009-1582" modified="2009-05-08" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Million Dollar Text Links 1.0 does not properly restrict administrator access to admin.home.php, which allows remote attackers to bypass intended restrictions and gain privileges via a direct request to admin.home.php after visiting admin.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/50306" source="XF">milliondollar-adminhome-auth-bypass(50306)</ref>
      <ref url="http://www.securityfocus.com/bid/34809" source="BID">34809</ref>
      <ref url="http://www.milw0rm.com/exploits/8605" source="MILW0RM">8605</ref>
      <ref url="http://secunia.com/advisories/34994" source="SECUNIA" adv="1">34994</ref>
      <ref url="http://osvdb.org/54204" source="OSVDB">54204</ref>
    </refs>
    <vuln_soft>
      <prod vendor="kalptarudemos" name="million_dollar_text_links">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1583" published="2009-05-07" name="CVE-2009-1583" modified="2010-12-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in TemaTres 1.0.3 and 1.031 allow remote attackers to inject arbitrary web script or HTML via the (1) search form; (2) _expresion_de_busqueda, (3) letra, (4) estado_id, and (5) tema parameters to index.php; the (6) PATH_INFO to index.php; (7) unspecified parameters when editing a term as specified by the edit_id and tema parameters to index.php; and the (7) y, (8) ord, and (9) m parameters to sobre.php.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/50343" source="XF">tematres-term-xss(50343)</ref>
      <ref url="http://www.securityfocus.com/bid/34830" source="BID">34830</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/503252/100/0/threaded" source="BUGTRAQ">20090505 MULTIPLE REMOTE VULNERABILITIES--TemaTres 1.0.3--></ref>
      <ref url="http://www.milw0rm.com/exploits/8615" source="MILW0RM">8615</ref>
      <ref url="http://secunia.com/advisories/34990" source="SECUNIA" adv="1">34990</ref>
      <ref url="http://secunia.com/advisories/34983" source="SECUNIA" adv="1">34983</ref>
      <ref url="http://osvdb.org/54247" source="OSVDB">54247</ref>
    </refs>
    <vuln_soft>
      <prod vendor="r020" name="tematres">
        <vers num="1.0.3" />
        <vers num="1.031" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1584" published="2009-05-07" name="CVE-2009-1584" modified="2009-05-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:S/C:P/I:P/A:P)" CVSS_score="6.0" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="6.8" CVSS_base_score="6.0">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in TemaTres 1.0.3 and 1.031, when magic_quotes_gpc is disabled, allow remote attackers or remote authenticated users to execute arbitrary SQL commands via the (1) mail, (2) password, and (3) letra parameters to index.php; (4) y and (5) m parameters to sobre.php; and the (6) dcTema, (7) madsTema, (8) zthesTema, (9) skosTema, and (10) xtmTema parameters to xml.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/34830" source="BID">34830</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/503252/100/0/threaded" source="BUGTRAQ">20090505 MULTIPLE REMOTE VULNERABILITIES--TemaTres 1.0.3--></ref>
      <ref url="http://www.securityfocus.com/archive/1/503256" source="BUGTRAQ">20090505 BLIND SQL INJECTION EXPLOIT--TemaTres 1.0.3--></ref>
      <ref url="http://www.milw0rm.com/exploits/8616" source="MILW0RM">8616</ref>
      <ref url="http://www.milw0rm.com/exploits/8615" source="MILW0RM">8615</ref>
      <ref url="http://secunia.com/advisories/34983" source="SECUNIA" adv="1">34983</ref>
      <ref url="http://osvdb.org/54246" source="OSVDB">54246</ref>
      <ref url="http://osvdb.org/54245" source="OSVDB">54245</ref>
    </refs>
    <vuln_soft>
      <prod vendor="r020" name="tematres">
        <vers num="1.0.3" />
        <vers num="1.031" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1585" published="2009-05-07" name="CVE-2009-1585" modified="2009-05-13" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="4.4" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.4" CVSS_base_score="4.4">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in TemaTres 1.031, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) id_correo_electronico and (2) id_password parameters to login.php.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/34983" source="SECUNIA" adv="1">34983</ref>
      <ref url="http://osvdb.org/54244" source="OSVDB">54244</ref>
    </refs>
    <vuln_soft>
      <prod vendor="r020" name="tematres">
        <vers num="1.031" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1586" published="2009-05-07" name="CVE-2009-1586" modified="2009-05-08" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Stack-based buffer overflow in the NZB importer feature in GrabIt 1.7.2 Beta 3 and earlier allows remote attackers to execute arbitrary code via a crafted DTD reference in a DOCTYPE element in an NZB file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.shemes.com/index.php?p=whatsnew" source="CONFIRM" patch="1" adv="1">http://www.shemes.com/index.php?p=whatsnew</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/50310" source="XF">grabit-nzb-bo(50310)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1243" source="VUPEN" adv="1">ADV-2009-1243</ref>
      <ref url="http://www.securitytracker.com/id?1022161" source="SECTRACK">1022161</ref>
      <ref url="http://www.securityfocus.com/bid/34807" source="BID">34807</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/503184/100/0/threaded" source="BUGTRAQ">20090503 Grabit &lt;= 1.7.2 beta 3 NZB file parsing stack overflow</ref>
      <ref url="http://www.milw0rm.com/exploits/8612" source="MILW0RM">8612</ref>
      <ref url="http://secunia.com/advisories/34893" source="SECUNIA" adv="1">34893</ref>
      <ref url="http://osvdb.org/54205" source="OSVDB">54205</ref>
      <ref url="http://blog.teusink.net/2009/05/grabit-172-beta-3-nzb-file-parsing.html" source="MISC">http://blog.teusink.net/2009/05/grabit-172-beta-3-nzb-file-parsing.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="shemes" name="grabit">
        <vers num="1.5.0" edition="beta" />
        <vers num="1.5.1" edition="beta" />
        <vers num="1.5.2" edition="beta" />
        <vers num="1.5.3" edition="beta" />
        <vers num="1.6.1" edition="beta" />
        <vers num="1.6.2" edition="beta" />
        <vers num="1.7.1" edition="beta" />
        <vers prev="1" num="1.7.2" edition="beta" />
        <vers prev="1" num="1.7.2" edition="beta2" />
        <vers prev="1" num="1.7.2" edition="beta3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1587" published="2009-05-07" name="CVE-2009-1587" modified="2009-05-08" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">index.php in PHP Site Lock 2.0 allows remote attackers to bypass authentication and obtain administrative access by setting the login_id, group_id, login_name, user_id, and user_type cookies to certain values.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/50304" source="XF">phpsitelock-index-security-bypass(50304)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1249" source="VUPEN" adv="1">ADV-2009-1249</ref>
      <ref url="http://www.milw0rm.com/exploits/8604" source="MILW0RM">8604</ref>
      <ref url="http://secunia.com/advisories/34995" source="SECUNIA" adv="1">34995</ref>
      <ref url="http://osvdb.org/54203" source="OSVDB">54203</ref>
    </refs>
    <vuln_soft>
      <prod vendor="kalptarudemos" name="php_site_lock">
        <vers num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1588" published="2009-05-08" name="CVE-2009-1588" modified="2009-05-12" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in CGI RESCUE MiniBBS 8t before 8.95t, 8 before 8.95, 9 before 9.08, and 10 before 10.32 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://jvndb.jvn.jp/en/contents/2009/JVNDB-2009-000022.html" source="JVNDB" patch="1">JVNDB-2009-000022</ref>
      <ref url="http://jvn.jp/en/jp/JVN11396739/index.html" source="JVN" patch="1">JVN#11396739</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/50219" source="XF">minibbs-unspecified-xss(50219)</ref>
      <ref url="http://www.securityfocus.com/bid/34718" source="BID">34718</ref>
      <ref url="http://www.rescue.ne.jp/whatsnew/blog.cgi/permalink/20081213132937" source="CONFIRM" adv="1">http://www.rescue.ne.jp/whatsnew/blog.cgi/permalink/20081213132937</ref>
      <ref url="http://secunia.com/advisories/34887" source="SECUNIA" adv="1">34887</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cgi_rescue" name="cgi_rescue_minibbs">
        <vers num="10.0" />
        <vers num="8.0" />
        <vers num="9.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1589" published="2009-05-08" name="CVE-2009-1589" modified="2009-06-10" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in CGI RESCUE MiniBBS22 before 1.01 allows remote attackers to send email to arbitrary recipients via unknown vectors.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.rescue.ne.jp/whatsnew/blog.cgi/permalink/20081213132937" source="CONFIRM" adv="1">http://www.rescue.ne.jp/whatsnew/blog.cgi/permalink/20081213132937</ref>
      <ref url="http://jvndb.jvn.jp/en/contents/2009/JVNDB-2009-000021.html" source="JVNDB">JVNDB-2009-000021</ref>
      <ref url="http://jvn.jp/en/jp/JVN36982346/index.html" source="JVN">JVN#36982346</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cgi_rescue" name="cgi_rescue_minibbs22">
        <vers prev="1" num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1590" published="2009-05-08" name="CVE-2009-1590" modified="2009-05-11" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in CGI RESCUE FORM2MAIL before 1.42 allows remote attackers to send email to arbitrary recipients via a web form.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://osvdb.org/54097" source="OSVDB" patch="1">54097</ref>
      <ref url="http://jvn.jp/en/jp/JVN76370393/index.html" source="JVN" patch="1">JVN#76370393</ref>
      <ref url="http://www.rescue.ne.jp/whatsnew/blog.cgi/permalink/20081213132937" source="CONFIRM" adv="1">http://www.rescue.ne.jp/whatsnew/blog.cgi/permalink/20081213132937</ref>
      <ref url="http://secunia.com/advisories/34869" source="SECUNIA" adv="1">34869</ref>
      <ref url="http://jvndb.jvn.jp/en/contents/2009/JVNDB-2009-000023.html" source="JVNDB">JVNDB-2009-000023</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cgi_rescue" name="form2mail">
        <vers num="1.21" />
        <vers prev="1" num="1.41" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1591" published="2009-05-08" name="CVE-2009-1591" modified="2009-05-23" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">CRLF injection vulnerability in CGI RESCUE Web Mailer before 1.04 allows remote attackers to inject arbitrary HTTP headers, and conduct cross-site scripting (XSS) or HTTP response splitting attacks, via CRLF sequences in an unspecified web form.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.rescue.ne.jp/whatsnew/blog.cgi/permalink/20090209180123" source="CONFIRM" patch="1" adv="1">http://www.rescue.ne.jp/whatsnew/blog.cgi/permalink/20090209180123</ref>
      <ref url="http://jvn.jp/en/jp/JVN28020230/index.html" source="JVN" patch="1">JVN#28020230</ref>
      <ref url="http://www.securityfocus.com/bid/35047" source="BID">35047</ref>
      <ref url="http://secunia.com/advisories/34862" source="SECUNIA" adv="1">34862</ref>
      <ref url="http://jvndb.jvn.jp/en/contents/2009/JVNDB-2009-000024.html" source="JVNDB">JVNDB-2009-000024</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cgi_rescue" name="cgi_web_mailer">
        <vers prev="1" num="1.03" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1592" published="2009-05-08" name="CVE-2009-1592" modified="2009-05-20" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Stack-based buffer overflow in ElectraSoft 32bit FTP 09.04.24 allows remote FTP servers to execute arbitrary code via a long banner.  NOTE: this might overlap CVE-2003-1368.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/50337" source="XF">32bit-cwd-banner-bo(50337)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1263" source="VUPEN">ADV-2009-1263</ref>
      <ref url="http://www.securityfocus.com/bid/34822" source="BID">34822</ref>
      <ref url="http://www.milw0rm.com/exploits/8614" source="MILW0RM">8614</ref>
      <ref url="http://www.milw0rm.com/exploits/8611" source="MILW0RM">8611</ref>
      <ref url="http://secunia.com/advisories/34993" source="SECUNIA">34993</ref>
      <ref url="http://osvdb.org/54219" source="OSVDB">54219</ref>
    </refs>
    <vuln_soft>
      <prod vendor="electrasoft" name="32bit_ftp">
        <vers num="09.04.24" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1593" published="2009-05-21" name="CVE-2009-1593" modified="2009-05-23" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Armorlogic Profense Web Application Firewall before 2.2.22, and 2.4.x before 2.4.4, does not properly implement the "negative model," which allows remote attackers to conduct cross-site scripting (XSS) attacks via a modified end tag of a SCRIPT element.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/50663" source="XF">profense-blacklist-security-bypass(50663)</ref>
      <ref url="http://www.webappsec.org/lists/websecurity/archive/2009-05/msg00040.html" source="MLIST">[websecurity] 20090519 [WEB SECURITY] Trustwave's SpiderLabs Security Advisory TWSL2009-001 and EnableSecurity Advisory ES-20090500</ref>
      <ref url="http://www.securityfocus.com/bid/35053" source="BID">35053</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/503649/100/0/threaded" source="BUGTRAQ">20090520 Armorlogic Profense Web Application Firewall 2.4 multiple vulnerabilities.</ref>
    </refs>
    <vuln_soft>
      <prod vendor="armorlogic" name="profense_web_application_firewall">
        <vers prev="1" num="2.2.21" />
        <vers num="2.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1594" published="2009-05-21" name="CVE-2009-1594" modified="2010-08-30" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Armorlogic Profense Web Application Firewall before 2.2.22, and 2.4.x before 2.4.4, does not properly implement the "positive model," which allows remote attackers to bypass certain protection mechanisms via a %0A (encoded newline), as demonstrated by a %0A in a cross-site scripting (XSS) attack URL.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/50662" source="XF">profense-whitelist-security-bypass(50662)</ref>
      <ref url="http://www.webappsec.org/lists/websecurity/archive/2009-05/msg00040.html" source="MLIST">[websecurity] 20090519 [WEB SECURITY] Trustwave's SpiderLabs Security Advisory TWSL2009-001 and EnableSecurity Advisory ES-20090500</ref>
      <ref url="http://www.securityfocus.com/bid/35053" source="BID">35053</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/503649/100/0/threaded" source="BUGTRAQ">20090520 Armorlogic Profense Web Application Firewall 2.4 multiple vulnerabilities.</ref>
      <ref url="http://resources.enablesecurity.com/advisories/ES-20090500-profense.txt" source="MISC">http://resources.enablesecurity.com/advisories/ES-20090500-profense.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="armorlogic" name="profense_web_application_firewall">
        <vers prev="1" num="2.2.21" />
        <vers num="2.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1595" published="2009-05-11" name="CVE-2009-1595" modified="2009-05-11" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:N/I:P/A:N)" CVSS_score="4.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.0" CVSS_base_score="4.0">
    <desc>
      <descript source="cve">The jabber:iq:auth implementation in IQAuthHandler.java in Ignite Realtime Openfire before 3.6.4 allows remote authenticated users to change the passwords of arbitrary accounts via a modified username element in a passwd_change action.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2009/1237" source="VUPEN" patch="1" adv="1">ADV-2009-1237</ref>
      <ref url="http://www.securityfocus.com/bid/34804" source="BID" patch="1">34804</ref>
      <ref url="http://www.igniterealtime.org/issues/browse/JM-1531" source="CONFIRM" patch="1" adv="1">http://www.igniterealtime.org/issues/browse/JM-1531</ref>
      <ref url="http://www.igniterealtime.org/community/message/190280" source="CONFIRM" patch="1" adv="1">http://www.igniterealtime.org/community/message/190280</ref>
      <ref url="http://www.igniterealtime.org/builds/openfire/docs/latest/changelog.html" source="CONFIRM" patch="1">http://www.igniterealtime.org/builds/openfire/docs/latest/changelog.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/50292" source="XF">openfire-jabberiqauth-security-bypass(50292)</ref>
      <ref url="http://secunia.com/advisories/34976" source="SECUNIA" adv="1">34976</ref>
      <ref url="http://osvdb.org/54189" source="OSVDB">54189</ref>
    </refs>
    <vuln_soft>
      <prod vendor="igniterealtime" name="openfire">
        <vers num="2.6.0" />
        <vers num="2.6.1" />
        <vers num="2.6.2" />
        <vers num="3.0.0" />
        <vers num="3.0.1" />
        <vers num="3.1.0" />
        <vers num="3.1.1" />
        <vers num="3.2.0" />
        <vers num="3.2.1" />
        <vers num="3.2.2" />
        <vers num="3.2.3" />
        <vers num="3.2.4" />
        <vers num="3.3.0" />
        <vers num="3.3.2" />
        <vers num="3.3.3" />
        <vers num="3.4.0" />
        <vers num="3.4.1" />
        <vers num="3.4.2" />
        <vers num="3.4.3" />
        <vers num="3.4.4" />
        <vers num="3.4.5" />
        <vers num="3.5.0" />
        <vers num="3.5.1" />
        <vers num="3.5.2" />
        <vers num="3.6.0" />
        <vers num="3.6.0a" />
        <vers num="3.6.1" />
        <vers num="3.6.2" />
        <vers prev="1" num="3.6.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1596" published="2009-05-11" name="CVE-2009-1596" modified="2009-05-11" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:N/I:P/A:N)" CVSS_score="4.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.0" CVSS_base_score="4.0">
    <desc>
      <descript source="cve">Ignite Realtime Openfire before 3.6.5 does not properly implement the register.password (aka canChangePassword) console configuration setting, which allows remote authenticated users to bypass intended policy and change their own passwords via a passwd_change IQ packet.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/34804" source="BID" patch="1">34804</ref>
      <ref url="http://www.igniterealtime.org/issues/browse/JM-1532" source="CONFIRM" patch="1" adv="1">http://www.igniterealtime.org/issues/browse/JM-1532</ref>
      <ref url="http://www.igniterealtime.org/community/message/190280" source="CONFIRM" patch="1" adv="1">http://www.igniterealtime.org/community/message/190280</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/50291" source="XF">openfire-nopassword-security-bypass(50291)</ref>
      <ref url="http://www.osvdb.org/54189" source="OSVDB">54189</ref>
      <ref url="http://secunia.com/advisories/34984" source="SECUNIA" adv="1">34984</ref>
    </refs>
    <vuln_soft>
      <prod vendor="igniterealtime" name="openfire">
        <vers num="2.6.0" />
        <vers num="2.6.1" />
        <vers num="2.6.2" />
        <vers num="3.0.0" />
        <vers num="3.0.1" />
        <vers num="3.1.0" />
        <vers num="3.1.1" />
        <vers num="3.2.0" />
        <vers num="3.2.1" />
        <vers num="3.2.2" />
        <vers num="3.2.3" />
        <vers num="3.2.4" />
        <vers num="3.3.0" />
        <vers num="3.3.2" />
        <vers num="3.3.3" />
        <vers num="3.4.0" />
        <vers num="3.4.1" />
        <vers num="3.4.2" />
        <vers num="3.4.3" />
        <vers num="3.4.4" />
        <vers num="3.4.5" />
        <vers num="3.5.0" />
        <vers num="3.5.1" />
        <vers num="3.5.2" />
        <vers num="3.6.0" />
        <vers num="3.6.0a" />
        <vers num="3.6.1" />
        <vers num="3.6.2" />
        <vers num="3.6.3" />
        <vers prev="1" num="3.6.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1597" published="2009-05-11" name="CVE-2009-1597" modified="2009-05-12" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Mozilla Firefox executes DOM calls in response to a javascript: URI in the target attribute of a submit element within a form contained in an inline PDF file, which might allow remote attackers to bypass intended Adobe Acrobat JavaScript restrictions on accessing the document object, as demonstrated by a web site that permits PDF uploads by untrusted users, and therefore has a shared document.domain between the web site and this javascript: URI.  NOTE: the researcher reports that Adobe's position is "a PDF file is active content."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/503183/100/0/threaded" source="BUGTRAQ">20090503 [SecNiche WhitePaper ] - PDF Silent HTTP Form Repurposing Attacks</ref>
      <ref url="http://secniche.org/papers/SNS_09_03_PDF_Silent_Form_Re_Purp_Attack.pdf" source="MISC">http://secniche.org/papers/SNS_09_03_PDF_Silent_Form_Re_Purp_Attack.pdf</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mozilla" name="firefox">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1598" published="2009-05-11" name="CVE-2009-1598" modified="2009-05-12" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Google Chrome executes DOM calls in response to a javascript: URI in the target attribute of a submit element within a form contained in an inline PDF file, which might allow remote attackers to bypass intended Adobe Acrobat JavaScript restrictions on accessing the document object, as demonstrated by a web site that permits PDF uploads by untrusted users, and therefore has a shared document.domain between the web site and this javascript: URI.  NOTE: the researcher reports that Adobe's position is "a PDF file is active content."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/503183/100/0/threaded" source="BUGTRAQ">20090503 [SecNiche WhitePaper ] - PDF Silent HTTP Form Repurposing Attacks</ref>
      <ref url="http://secniche.org/papers/SNS_09_03_PDF_Silent_Form_Re_Purp_Attack.pdf" source="MISC">http://secniche.org/papers/SNS_09_03_PDF_Silent_Form_Re_Purp_Attack.pdf</ref>
    </refs>
    <vuln_soft>
      <prod vendor="google" name="chrome">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1599" published="2009-05-11" name="CVE-2009-1599" modified="2009-05-12" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Opera executes DOM calls in response to a javascript: URI in the target attribute of a submit element within a form contained in an inline PDF file, which might allow remote attackers to bypass intended Adobe Acrobat JavaScript restrictions on accessing the document object, as demonstrated by a web site that permits PDF uploads by untrusted users, and therefore has a shared document.domain between the web site and this javascript: URI.  NOTE: the researcher reports that Adobe's position is "a PDF file is active content."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/503183/100/0/threaded" source="BUGTRAQ">20090503 [SecNiche WhitePaper ] - PDF Silent HTTP Form Repurposing Attacks</ref>
      <ref url="http://secniche.org/papers/SNS_09_03_PDF_Silent_Form_Re_Purp_Attack.pdf" source="MISC">http://secniche.org/papers/SNS_09_03_PDF_Silent_Form_Re_Purp_Attack.pdf</ref>
    </refs>
    <vuln_soft>
      <prod vendor="opera" name="opera_browser">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1600" published="2009-05-11" name="CVE-2009-1600" modified="2009-05-14" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Apple Safari executes DOM calls in response to a javascript: URI in the target attribute of a submit element within a form contained in an inline PDF file, which might allow remote attackers to bypass intended Adobe Acrobat JavaScript restrictions on accessing the document object, as demonstrated by a web site that permits PDF uploads by untrusted users, and therefore has a shared document.domain between the web site and this javascript: URI.  NOTE: the researcher reports that Adobe's position is "a PDF file is active content."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/503183/100/0/threaded" source="BUGTRAQ">20090503 [SecNiche WhitePaper ] - PDF Silent HTTP Form Repurposing Attacks</ref>
      <ref url="http://secniche.org/papers/SNS_09_03_PDF_Silent_Form_Re_Purp_Attack.pdf" source="MISC">http://secniche.org/papers/SNS_09_03_PDF_Silent_Form_Re_Purp_Attack.pdf</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="safari">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1601" published="2009-05-11" name="CVE-2009-1601" modified="2009-05-12" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:S/C:C/I:C/A:C)" CVSS_score="6.8" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.1" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">The Ubuntu clamav-milter.init script in clamav-milter before 0.95.1+dfsg-1ubuntu1.2 in Ubuntu 9.04 sets the ownership of the current working directory to the clamav account, which might allow local users to bypass intended access restrictions via read or write operations involving this directory.</descript>
    </desc>
    <impacts>
      <impact source="nvd">Per https://bugs.launchpad.net/ubuntu/+source/clamav/+bug/365823

A clean install of clamav-milter (0.95.1+dfsg-1ubuntu1.1) causes the root directory to become owned by the clamav user.

This was witnessed breaking ssh chroot environment.

TEST CASE:
- purge any existing clamav-milter installation, make sure you don't have any old /etc/init.d/clamav-milter init script around
- check root directory's owner (should be root:root)
- sudo apt-get install clamav-milter (the last one in Jaunty is 0.95.1+dfsg-1ubuntu1.1)
- after installing the package, clamav-milter will start automatically (at least 'init.d/clamav-milter start' will execute)
- check the root directory's owner:</impact>
    </impacts>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/50311" source="XF" patch="1">clamav-clamavmilter-security-bypass(50311)</ref>
      <ref url="http://www.securityfocus.com/bid/34818" source="BID" patch="1">34818</ref>
      <ref url="https://launchpad.net/bugs/365823" source="CONFIRM">https://launchpad.net/bugs/365823</ref>
      <ref url="http://www.ubuntu.com/usn/USN-770-1" source="UBUNTU" adv="1">USN-770-1</ref>
      <ref url="http://secunia.com/advisories/35000" source="SECUNIA" adv="1">35000</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ubuntu" name="linux">
        <vers num="9.04" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1602" published="2009-05-11" name="CVE-2009-1602" modified="2009-05-12" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Pablo Software Solutions Quick 'n Easy Mail Server 3.3 allows remote attackers to cause a denial of service (daemon outage or CPU consumption) via multiple long SMTP commands, as demonstrated by HELO commands.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/50299" source="XF">quickneasymailserver-helo-dos(50299)</ref>
      <ref url="http://www.securityfocus.com/bid/34814" source="BID">34814</ref>
      <ref url="http://www.milw0rm.com/exploits/8606" source="MILW0RM">8606</ref>
      <ref url="http://secunia.com/advisories/34992" source="SECUNIA" adv="1">34992</ref>
      <ref url="http://osvdb.org/54215" source="OSVDB">54215</ref>
    </refs>
    <vuln_soft>
      <prod vendor="pablosoftwaresolutions" name="quick'n_easy_mail_server">
        <vers num="3.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1603" published="2009-05-11" name="CVE-2009-1603" modified="2009-08-08" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">src/tools/pkcs11-tool.c in pkcs11-tool in OpenSC 0.11.7, when used with unspecified third-party PKCS#11 modules, generates RSA keys with incorrect public exponents, which allows attackers to read the cleartext form of messages that were intended to be encrypted.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.openwall.com/lists/oss-security/2009/05/08/1" source="MLIST" patch="1">[oss-security] 20090508 OpenSC 0.11.8 released with security update</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-May/msg01432.html" source="FEDORA">FEDORA-2009-4883</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-May/msg01420.html" source="FEDORA">FEDORA-2009-4919</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-June/msg00097.html" source="FEDORA">FEDORA-2009-4967</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-June/msg00095.html" source="FEDORA">FEDORA-2009-4928</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1295" source="VUPEN">ADV-2009-1295</ref>
      <ref url="http://www.opensc-project.org/pipermail/opensc-announce/2009-May/000025.html" source="MLIST">[opensc-announce] 20090508 OpenSC 0.11.8 released with security update</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:123" source="MANDRIVA">MDVSA-2009:123</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200908-01.xml" source="GENTOO">GLSA-200908-01</ref>
      <ref url="http://secunia.com/advisories/36074" source="SECUNIA">36074</ref>
      <ref url="http://secunia.com/advisories/35309" source="SECUNIA">35309</ref>
      <ref url="http://secunia.com/advisories/35293" source="SECUNIA">35293</ref>
      <ref url="http://secunia.com/advisories/35035" source="SECUNIA">35035</ref>
    </refs>
    <vuln_soft>
      <prod vendor="opensc-project" name="opensc">
        <vers num="0.11.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1604" published="2009-05-11" name="CVE-2009-1604" modified="2009-05-23" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Unspecified vulnerability in LimeSurvey before 1.82 allows remote attackers to execute commands and obtain sensitive data via unknown attack vectors related to /admin/remotecontrol/.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2009/1219" source="VUPEN" patch="1" adv="1">ADV-2009-1219</ref>
      <ref url="http://www.limesurvey.org/content/view/169/1/lang,en/" source="CONFIRM" patch="1" adv="1">http://www.limesurvey.org/content/view/169/1/lang,en/</ref>
      <ref url="http://www.securityfocus.com/bid/34785" source="BID">34785</ref>
      <ref url="http://secunia.com/advisories/34946" source="SECUNIA" adv="1">34946</ref>
    </refs>
    <vuln_soft>
      <prod vendor="limesurvey" name="limesurvey">
        <vers num="1.80" edition="rc4" />
        <vers num="1.80+" />
        <vers num="1.81" />
        <vers num="1.81+" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1605" published="2009-05-11" name="CVE-2009-1605" modified="2009-05-12" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Heap-based buffer overflow in the loadexponentialfunc function in mupdf/pdf_function.c in MuPDF in the mupdf-20090223-win32 package, as used in SumatraPDF 0.9.3 and earlier, allows remote attackers to execute arbitrary code via a crafted PDF file.  NOTE: some of these details are obtained from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2009/1186" source="VUPEN" adv="1">ADV-2009-1186</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1185" source="VUPEN" adv="1">ADV-2009-1185</ref>
      <ref url="http://secunia.com/advisories/34916" source="SECUNIA" adv="1">34916</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2009-04/0258.html" source="FULLDISC">20090424 SumatraPDF &lt;= 0.9.3 Heap Overflow PoC</ref>
    </refs>
    <vuln_soft>
      <prod vendor="kowalczyk" name="sumatrapdf">
        <vers num="0.1" />
        <vers num="0.2" />
        <vers num="0.3" />
        <vers num="0.4" />
        <vers num="0.5" />
        <vers num="0.6" />
        <vers num="0.7" />
        <vers num="0.8" />
        <vers num="0.8.1" />
        <vers num="0.9" />
        <vers prev="1" num="0.9.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1606" published="2009-05-11" name="CVE-2009-1606" modified="2009-05-12" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Multiple stack-based and heap-based buffer overflows in Dafolo DafoloControl ActiveX control (DafoloFFControl.dll) 1.108.6.195 allow remote attackers to execute arbitrary code via long (1) baseurl, (2) kommune, (3) felter, (4) afdeling, (5) Flags, (6) HelpURL, (7) caburl, or (8) filename properties; or (9) a long argument to the Open method. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/50423" source="XF">dafolo-filenames-bo(50423)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/50422" source="XF">dafolo-helpurl-caburl-bo(50422)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/50421" source="XF">dafolo-stringparsing-bo(50421)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/50420" source="XF">dafolo-baseurl-bo(50420)</ref>
      <ref url="http://www.securityfocus.com/bid/34900" source="BID">34900</ref>
      <ref url="http://secunia.com/advisories/35017" source="SECUNIA" adv="1">35017</ref>
    </refs>
    <vuln_soft>
      <prod vendor="dafolo" name="dafolocontrol">
        <vers num="1.108.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1607" published="2009-05-11" name="CVE-2009-1607" modified="2009-05-12" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in the administrator panel in phpForm.net LinkBase 2.0 allows remote attackers to inject arbitrary web script or HTML via the username in a registration, which is not properly handled when the administrator accesses the Users menu.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/50338" source="XF">linkbase-usersmenu-xss(50338)</ref>
      <ref url="http://www.securityfocus.com/bid/34844" source="BID">34844</ref>
      <ref url="http://www.milw0rm.com/exploits/8618" source="MILW0RM">8618</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linkbase" name="linkbase">
        <vers num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1608" published="2009-05-11" name="CVE-2009-1608" modified="2009-05-20" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Multiple buffer overflows in Microchip MPLAB IDE 8.30 and possibly earlier versions allow user-assisted remote attackers to execute arbitrary code via a .MCP project file with long (1) FILE_INFO, (2) CAT_FILTERS, and possibly other fields.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/50419" source="XF">mplabide-catfilters-bo(50419)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/50418" source="XF">mplabide-fileinfo-bo(50418)</ref>
      <ref url="http://www.securityfocus.com/bid/34897" source="BID">34897</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/503400/100/0/threaded" source="BUGTRAQ">20090511 [Bkis-08-2009] Microchip MPLAB IDE Buffer Overflow Vulnerability</ref>
      <ref url="http://security.bkis.vn/?p=654" source="MISC">http://security.bkis.vn/?p=654</ref>
      <ref url="http://secunia.com/advisories/35054" source="SECUNIA" adv="1">35054</ref>
      <ref url="http://osvdb.org/54370" source="OSVDB">54370</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microchip" name="mplab_ide">
        <vers num="8.30" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1609" published="2009-05-11" name="CVE-2009-1609" modified="2009-05-23" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Unrestricted file upload vulnerability in admin/uploadform.asp in Battle Blog 1.25 allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/50400" source="XF">battleblog-uploadform-file-upload(50400)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1280" source="VUPEN">ADV-2009-1280</ref>
      <ref url="http://www.securityfocus.com/bid/34887" source="BID">34887</ref>
      <ref url="http://www.milw0rm.com/exploits/8647" source="MILW0RM">8647</ref>
      <ref url="http://secunia.com/advisories/35023" source="SECUNIA" adv="1">35023</ref>
    </refs>
    <vuln_soft>
      <prod vendor="battleblog" name="battle_blog">
        <vers num="1.25" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1610" published="2009-05-11" name="CVE-2009-1610" modified="2009-05-12" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">admin/changepassword.php in Job Script Job Board Software 2.0 allows remote attackers to change the administrator password and gain administrator privileges via a direct request.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/50380" source="XF">jobscript-changepassword-security-bypass(50380)</ref>
      <ref url="http://www.securityfocus.com/bid/34874" source="BID">34874</ref>
      <ref url="http://www.milw0rm.com/exploits/8639" source="MILW0RM">8639</ref>
      <ref url="http://secunia.com/advisories/35029" source="SECUNIA" adv="1">35029</ref>
      <ref url="http://osvdb.org/54281" source="OSVDB">54281</ref>
    </refs>
    <vuln_soft>
      <prod vendor="jobscript" name="job_script_job_board_software">
        <vers num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1611" published="2009-05-11" name="CVE-2009-1611" modified="2009-05-20" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Stack-based buffer overflow in ElectraSoft 32bit FTP 09.04.24 allows remote FTP servers to execute arbitrary code via a long 257 reply to a CWD command.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2009/1263" source="VUPEN">ADV-2009-1263</ref>
      <ref url="http://www.securityfocus.com/bid/34838" source="BID">34838</ref>
      <ref url="http://www.securityfocus.com/bid/34822" source="BID">34822</ref>
      <ref url="http://www.milw0rm.com/exploits/8621" source="MILW0RM">8621</ref>
      <ref url="http://www.milw0rm.com/exploits/8613" source="MILW0RM">8613</ref>
    </refs>
    <vuln_soft>
      <prod vendor="electrasoft" name="32bit_ftp">
        <vers num="09.04.24" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1612" published="2009-05-11" name="CVE-2009-1612" modified="2009-05-30" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Stack-based buffer overflow in the MPS.StormPlayer.1 ActiveX control in mps.dll 3.9.4.27 in Baofeng Storm allows remote attackers to execute arbitrary code via a long argument to the OnBeforeVideoDownload method, as exploited in the wild in April and May 2009. NOTE: some of these details are obtained from third party information. NOTE: it was later reported that 3.09.04.17 and earlier are also affected.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/34789" source="BID" patch="1">34789</ref>
      <ref url="http://www.milw0rm.com/exploits/8579" source="MILW0RM">8579</ref>
      <ref url="http://www.cisrt.org/enblog/read.php?245" source="MISC">http://www.cisrt.org/enblog/read.php?245</ref>
      <ref url="http://secunia.com/advisories/34944" source="SECUNIA" adv="1">34944</ref>
    </refs>
    <vuln_soft>
      <prod vendor="baofeng" name="storm">
        <vers num="2.7.9_10" />
        <vers num="2.7.9_8" />
        <vers num="2.8" />
        <vers num="2.9" />
        <vers num="3.9.3_25" />
        <vers num="3.9.3_30" />
        <vers num="3.9.4_17" />
        <vers num="3.9.4_27" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1613" published="2009-05-11" name="CVE-2009-1613" modified="2009-05-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in leap.php in Leap CMS 0.1.4, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) searchterm or (2) email parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.milw0rm.com/exploits/8577" source="MILW0RM">8577</ref>
      <ref url="http://www.milw0rm.com/exploits/8576" source="MILW0RM">8576</ref>
      <ref url="http://secunia.com/advisories/34943" source="SECUNIA" adv="1">34943</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gowondesigns" name="leap">
        <vers num="0.1.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2009-1614" published="2009-05-11" name="CVE-2009-1614" modified="2009-05-12" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Leap CMS 0.1.4 allow remote attackers to inject arbitrary web script or HTML via (1) the msg parameter (aka the message in an article comment) or (2) the searchterm parameter (aka the search post form).  NOTE: some of these details are obtained from third party information.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.milw0rm.com/exploits/8577" source="MILW0RM">8577</ref>
      <ref url="http://secunia.com/advisories/34943" source="SECUNIA" adv="1">34943</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gowondesigns" name="leap">
        <vers num="0.1.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1615" published="2009-05-11" name="CVE-2009-1615" modified="2009-05-12" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Unrestricted file upload vulnerability in Leap CMS 0.1.4 allows remote attackers to execute arbitrary code by uploading a file with an executable extension via an admin.system.files (aka Manage Files) request to the default URI, then accessing the file via a direct request.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.milw0rm.com/exploits/8577" source="MILW0RM">8577</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gowondesigns" name="leap">
        <vers num="0.1.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1616" published="2009-05-11" name="CVE-2009-1616" modified="2009-05-12" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in docs/showdoc.php in Coppermine Photo Gallery (CPG) before 1.4.22 allows remote attackers to inject arbitrary web script or HTML via the css parameter, a different vector than CVE-2008-0505.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://forum.coppermine-gallery.net/index.php/topic,59247.0.html" source="CONFIRM" patch="1">http://forum.coppermine-gallery.net/index.php/topic,59247.0.html</ref>
      <ref url="http://www.securityfocus.com/bid/34782" source="BID">34782</ref>
      <ref url="http://secunia.com/advisories/34961" source="SECUNIA" adv="1">34961</ref>
      <ref url="http://osvdb.org/54145" source="OSVDB">54145</ref>
      <ref url="http://forum.coppermine-gallery.net/index.php/topic,59237.0.html" source="CONFIRM">http://forum.coppermine-gallery.net/index.php/topic,59237.0.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="coppermine" name="coppermine_photo_gallery">
        <vers num="1.4.22" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1617" published="2009-05-12" name="CVE-2009-1617" modified="2009-05-12" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Teraway LinkTracker 1.0 allows remote attackers to bypass authentication and gain administrative access via a userid=1&amp;lvl=1 value for the twLTadmin cookie.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/34735" source="BID">34735</ref>
      <ref url="http://www.milw0rm.com/exploits/8550" source="MILW0RM">8550</ref>
      <ref url="http://secunia.com/advisories/34903" source="SECUNIA" adv="1">34903</ref>
    </refs>
    <vuln_soft>
      <prod vendor="teraway" name="linktracker">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1618" published="2009-05-12" name="CVE-2009-1618" modified="2009-05-12" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Teraway LiveHelp 2.0 allows remote attackers to bypass authentication and gain administrative access via a pwd=&amp;lvl=1&amp;usr=&amp;alias=admin&amp;userid=1 value for the TWLHadmin cookie.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/34735" source="BID">34735</ref>
      <ref url="http://www.milw0rm.com/exploits/8552" source="MILW0RM">8552</ref>
      <ref url="http://secunia.com/advisories/34802" source="SECUNIA" adv="1">34802</ref>
    </refs>
    <vuln_soft>
      <prod vendor="teraway" name="livehelp">
        <vers num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1619" published="2009-05-12" name="CVE-2009-1619" modified="2009-05-12" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Teraway FileStream 1.0 allows remote attackers to bypass authentication and gain administrative access by setting the twFSadmin cookie to 1.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/34735" source="BID">34735</ref>
      <ref url="http://www.milw0rm.com/exploits/8551" source="MILW0RM">8551</ref>
      <ref url="http://secunia.com/advisories/34818" source="SECUNIA" adv="1">34818</ref>
    </refs>
    <vuln_soft>
      <prod vendor="teraway" name="filestream">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1620" published="2009-05-12" name="CVE-2009-1620" modified="2009-05-12" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in input.php in MataChat allow remote attackers to inject arbitrary web script or HTML via the (1) nickname and (2) color parameters.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/34722" source="BID">34722</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/503014/100/0/threaded" source="BUGTRAQ">20090425 MataChat Cross-Site Scripting Vulnerabilities</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mata" name="matachat">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1621" published="2009-05-12" name="CVE-2009-1621" modified="2009-05-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in index.php in OpenCart 1.1.8 allows remote attackers to read arbitrary files via a .. (dot dot) in the route parameter.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/34724" source="BID">34724</ref>
      <ref url="http://www.milw0rm.com/exploits/8539" source="MILW0RM">8539</ref>
      <ref url="http://secunia.com/advisories/34313" source="SECUNIA" adv="1">34313</ref>
    </refs>
    <vuln_soft>
      <prod vendor="opencart" name="opencart">
        <vers num="1.1.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1622" published="2009-05-12" name="CVE-2009-1622" modified="2009-05-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in user.php in EcShop 2.5.0 allows remote attackers to execute arbitrary SQL commands via the order_sn parameter in an order_query action.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/34733" source="BID">34733</ref>
      <ref url="http://www.milw0rm.com/exploits/8548" source="MILW0RM">8548</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ecshop" name="ecshop">
        <vers num="2.5.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1623" published="2009-05-12" name="CVE-2009-1623" modified="2009-05-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in index.php in Dew-NewPHPLinks 2.0 allows remote attackers to inject arbitrary web script or HTML via the PID parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/34732" source="BID">34732</ref>
      <ref url="http://www.milw0rm.com/exploits/8545" source="MILW0RM">8545</ref>
    </refs>
    <vuln_soft>
      <prod vendor="dew-code" name="dew-newphplinks">
        <vers num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1624" published="2009-05-12" name="CVE-2009-1624" modified="2009-05-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in index.php in Dew-NewPHPLinks 2.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the show parameter.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/34732" source="BID">34732</ref>
      <ref url="http://www.milw0rm.com/exploits/8545" source="MILW0RM">8545</ref>
    </refs>
    <vuln_soft>
      <prod vendor="dew-code" name="dew-newphplinks">
        <vers num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1625" published="2009-05-12" name="CVE-2009-1625" modified="2009-05-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Directory traversal vulnerability in index.php in Thickbox Gallery 2 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the ln parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/34741" source="BID">34741</ref>
      <ref url="http://www.milw0rm.com/exploits/8546" source="MILW0RM">8546</ref>
      <ref url="http://secunia.com/advisories/34906" source="SECUNIA" adv="1">34906</ref>
    </refs>
    <vuln_soft>
      <prod vendor="davlin" name="thickbox_gallery">
        <vers num="2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1626" published="2009-05-12" name="CVE-2009-1626" modified="2009-05-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in public/specific.php in EZ-Blog before Beta 2 20090427, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the category parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/34729" source="BID">34729</ref>
      <ref url="http://www.milw0rm.com/exploits/8547" source="MILW0RM">8547</ref>
      <ref url="http://sourceforge.net/project/shownotes.php?release_id=678562&amp;group_id=243152" source="CONFIRM">http://sourceforge.net/project/shownotes.php?release_id=678562&amp;group_id=243152</ref>
    </refs>
    <vuln_soft>
      <prod vendor="will_kraft" name="ez-blog">
        <vers prev="1" num="-" edition="beta1" />
        <vers prev="1" num="-" edition="beta2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1627" published="2009-05-12" name="CVE-2009-1627" modified="2009-05-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Stack-based buffer overflow in Streaming Download Project (SDP) Downloader 2.3.0 allows remote attackers to execute arbitrary code via a long .asf URL in the HREF attribute of a REF element in a .asx file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2009/1171" source="VUPEN" adv="1">ADV-2009-1171</ref>
      <ref url="http://www.securityfocus.com/bid/34712" source="BID">34712</ref>
      <ref url="http://www.milw0rm.com/exploits/8536" source="MILW0RM">8536</ref>
      <ref url="http://www.milw0rm.com/exploits/8531" source="MILW0RM">8531</ref>
      <ref url="http://secunia.com/advisories/34883" source="SECUNIA" adv="1">34883</ref>
      <ref url="http://osvdb.org/54090" source="OSVDB">54090</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sdp_multimedia" name="streaming_download_project">
        <vers num="2.3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1628" published="2009-06-26" name="CVE-2009-1628" modified="2009-06-29" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Stack-based buffer overflow in mnet.exe in Unisys Business Information Server (BIS) 10 and 10.1 on Windows allows remote attackers to execute arbitrary code via a crafted TCP packet.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=808" source="IDEFENSE">20090625 Unisys Business Information Server Stack Buffer Overflow</ref>
      <ref url="ftp://ftp.support.unisys.com/pub/mapper/NT/BIS10.1/Readme.txt" source="CONFIRM" adv="1">ftp://ftp.support.unisys.com/pub/mapper/NT/BIS10.1/Readme.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="unisys" name="business_information_server">
        <vers num="10" />
        <vers num="10.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1629" published="2009-05-14" name="CVE-2009-1629" modified="2011-01-19" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">ajaxterm.js in AjaxTerm 0.10 and earlier generates session IDs with predictable random numbers based on certain JavaScript functions, which makes it easier for remote attackers to (1) hijack a session or (2) cause a denial of service (session ID exhaustion) via a brute-force attack.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/50464" source="XF">ajaxterm-ajaxterm-session-hijacking(50464)</ref>
      <ref url="http://www.securityfocus.com/bid/34903" source="BID">34903</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/503421/100/0/threaded" source="BUGTRAQ">20090511 [oCERT-2009-004] AjaxTerm session id collision</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2009/05/11/1" source="MLIST">[oss-security] 20090511 [oCERT-2009-004] AjaxTerm session id collision</ref>
      <ref url="http://www.ocert.org/advisories/ocert-2009-004.html" source="MISC">http://www.ocert.org/advisories/ocert-2009-004.html</ref>
      <ref url="http://secunia.com/advisories/42784" source="SECUNIA">42784</ref>
      <ref url="http://lists.fedoraproject.org/pipermail/package-announce/2010-December/052655.html" source="FEDORA">FEDORA-2010-18867</ref>
    </refs>
    <vuln_soft>
      <prod vendor="antony_lesuisse" name="ajaxterm">
        <vers prev="1" num="0.10" />
        <vers num="0.6" />
        <vers num="0.7" />
        <vers num="0.8" />
        <vers num="0.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1630" published="2009-05-14" name="CVE-2009-1630" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="4.4" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="3.4" CVSS_base_score="4.4">
    <desc>
      <descript source="cve">The nfs_permission function in fs/nfs/dir.c in the NFS client implementation in the Linux kernel 2.6.29.3 and earlier, when atomic_open is available, does not check execute (aka EXEC or MAY_EXEC) permission bits, which allows local users to bypass permissions and execute files, as demonstrated by files on an NFSv4 fileserver.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://linux-nfs.org/pipermail/nfsv4/2006-November/005323.html" source="MLIST" patch="1">[nfsv4] 20061117 [Patch] Re: Status of execute permissions in NFSv4 ACLs ?</ref>
      <ref url="http://bugzilla.linux-nfs.org/show_bug.cgi?id=131" source="CONFIRM" patch="1">http://bugzilla.linux-nfs.org/show_bug.cgi?id=131</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=500297" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=500297</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/3316" source="VUPEN">ADV-2009-3316</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1331" source="VUPEN">ADV-2009-1331</ref>
      <ref url="http://www.vmware.com/security/advisories/VMSA-2009-0016.html" source="CONFIRM">http://www.vmware.com/security/advisories/VMSA-2009-0016.html</ref>
      <ref url="http://www.ubuntu.com/usn/usn-793-1" source="UBUNTU">USN-793-1</ref>
      <ref url="http://www.securityfocus.com/bid/34934" source="BID">34934</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/507985/100/0/threaded" source="BUGTRAQ">20091120 VMSA-2009-0016 VMware vCenter and ESX update release and vMA patch release address multiple security issue in third party components</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/505254/100/0/threaded" source="BUGTRAQ">20090724 rPSA-2009-0111-1 kernel</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-1157.html" source="REDHAT">RHSA-2009:1157</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2009/05/13/2" source="MLIST">[oss-security] 20090513 CVE request: kernel: problem with NFS v4 client handling of MAY_EXEC in nfs_permission</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:148" source="MANDRIVA">MDVSA-2009:148</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:135" source="MANDRIVA">MDVSA-2009:135</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1865" source="DEBIAN">DSA-1865</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1844" source="DEBIAN">DSA-1844</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1809" source="DEBIAN">DSA-1809</ref>
      <ref url="http://wiki.rpath.com/Advisories:rPSA-2009-0111" source="CONFIRM">http://wiki.rpath.com/Advisories:rPSA-2009-0111</ref>
      <ref url="http://secunia.com/advisories/37471" source="SECUNIA">37471</ref>
      <ref url="http://secunia.com/advisories/36327" source="SECUNIA">36327</ref>
      <ref url="http://secunia.com/advisories/36051" source="SECUNIA">36051</ref>
      <ref url="http://secunia.com/advisories/35847" source="SECUNIA">35847</ref>
      <ref url="http://secunia.com/advisories/35656" source="SECUNIA">35656</ref>
      <ref url="http://secunia.com/advisories/35394" source="SECUNIA">35394</ref>
      <ref url="http://secunia.com/advisories/35298" source="SECUNIA">35298</ref>
      <ref url="http://secunia.com/advisories/35106" source="SECUNIA">35106</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9990" source="OVAL">oval:org.mitre.oval:def:9990</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:8543" source="OVAL">oval:org.mitre.oval:def:8543</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-07/msg00004.html" source="SUSE">SUSE-SA:2009:038</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-06/msg00001.html" source="SUSE">SUSE-SA:2009:031</ref>
      <ref url="http://linux-nfs.org/pipermail/nfsv4/2006-November/005313.html" source="MLIST">[nfsv4] 20061116 Status of execute permissions in NFSv4 ACLs ?</ref>
      <ref url="http://article.gmane.org/gmane.linux.nfs/26592" source="MLIST">[linux-nfs] 20090509 [NFS] [PATCH] nfs: Fix NFS v4 client handling of MAY_EXEC in nfs_permission.</ref>
    </refs>
    <vuln_soft>
      <prod vendor="linux" name="kernel">
        <vers num="2.2.27" />
        <vers num="2.4.36" />
        <vers num="2.4.36.1" />
        <vers num="2.4.36.2" />
        <vers num="2.4.36.3" />
        <vers num="2.4.36.4" />
        <vers num="2.4.36.5" />
        <vers num="2.4.36.6" />
        <vers num="2.6.0" />
        <vers num="2.6.1" />
        <vers num="2.6.10" />
        <vers num="2.6.11" />
        <vers num="2.6.11.1" />
        <vers num="2.6.11.10" />
        <vers num="2.6.11.11" />
        <vers num="2.6.11.12" />
        <vers num="2.6.11.2" />
        <vers num="2.6.11.3" />
        <vers num="2.6.11.4" />
        <vers num="2.6.11.5" />
        <vers num="2.6.11.6" />
        <vers num="2.6.11.7" />
        <vers num="2.6.11.8" />
        <vers num="2.6.11.9" />
        <vers num="2.6.12" />
        <vers num="2.6.12.1" />
        <vers num="2.6.12.2" />
        <vers num="2.6.12.3" />
        <vers num="2.6.12.4" />
        <vers num="2.6.12.5" />
        <vers num="2.6.12.6" />
        <vers num="2.6.13" />
        <vers num="2.6.13.1" />
        <vers num="2.6.13.2" />
        <vers num="2.6.13.3" />
        <vers num="2.6.13.4" />
        <vers num="2.6.13.5" />
        <vers num="2.6.14" />
        <vers num="2.6.14.1" />
        <vers num="2.6.14.2" />
        <vers num="2.6.14.3" />
        <vers num="2.6.14.4" />
        <vers num="2.6.14.5" />
        <vers num="2.6.14.6" />
        <vers num="2.6.14.7" />
        <vers num="2.6.15" />
        <vers num="2.6.15.1" />
        <vers num="2.6.15.2" />
        <vers num="2.6.15.3" />
        <vers num="2.6.15.4" />
        <vers num="2.6.15.5" />
        <vers num="2.6.15.6" />
        <vers num="2.6.15.7" />
        <vers num="2.6.16" />
        <vers num="2.6.16.1" />
        <vers num="2.6.16.10" />
        <vers num="2.6.16.11" />
        <vers num="2.6.16.12" />
        <vers num="2.6.16.13" />
        <vers num="2.6.16.14" />
        <vers num="2.6.16.15" />
        <vers num="2.6.16.16" />
        <vers num="2.6.16.17" />
        <vers num="2.6.16.18" />
        <vers num="2.6.16.19" />
        <vers num="2.6.16.2" />
        <vers num="2.6.16.20" />
        <vers num="2.6.16.21" />
        <vers num="2.6.16.22" />
        <vers num="2.6.16.23" />
        <vers num="2.6.16.24" />
        <vers num="2.6.16.25" />
        <vers num="2.6.16.26" />
        <vers num="2.6.16.27" />
        <vers num="2.6.16.28" />
        <vers num="2.6.16.29" />
        <vers num="2.6.16.3" />
        <vers num="2.6.16.30" />
        <vers num="2.6.16.31" />
        <vers num="2.6.16.32" />
        <vers num="2.6.16.33" />
        <vers num="2.6.16.34" />
        <vers num="2.6.16.35" />
        <vers num="2.6.16.36" />
        <vers num="2.6.16.37" />
        <vers num="2.6.16.38" />
        <vers num="2.6.16.39" />
        <vers num="2.6.16.4" />
        <vers num="2.6.16.40" />
        <vers num="2.6.16.41" />
        <vers num="2.6.16.42" />
        <vers num="2.6.16.43" />
        <vers num="2.6.16.44" />
        <vers num="2.6.16.45" />
        <vers num="2.6.16.46" />
        <vers num="2.6.16.47" />
        <vers num="2.6.16.48" />
        <vers num="2.6.16.49" />
        <vers num="2.6.16.5" />
        <vers num="2.6.16.50" />
        <vers num="2.6.16.51" />
        <vers num="2.6.16.52" />
        <vers num="2.6.16.53" />
        <vers num="2.6.16.54" />
        <vers num="2.6.16.55" />
        <vers num="2.6.16.56" />
        <vers num="2.6.16.57" />
        <vers num="2.6.16.58" />
        <vers num="2.6.16.59" />
        <vers num="2.6.16.6" />
        <vers num="2.6.16.60" />
        <vers num="2.6.16.61" />
        <vers num="2.6.16.62" />
        <vers num="2.6.16.7" />
        <vers num="2.6.16.8" />
        <vers num="2.6.16.9" />
        <vers num="2.6.17" />
        <vers num="2.6.17.1" />
        <vers num="2.6.17.10" />
        <vers num="2.6.17.11" />
        <vers num="2.6.17.12" />
        <vers num="2.6.17.13" />
        <vers num="2.6.17.14" />
        <vers num="2.6.17.2" />
        <vers num="2.6.17.3" />
        <vers num="2.6.17.4" />
        <vers num="2.6.17.5" />
        <vers num="2.6.17.6" />
        <vers num="2.6.17.7" />
        <vers num="2.6.17.8" />
        <vers num="2.6.17.9" />
        <vers num="2.6.18" edition="rc1" />
        <vers num="2.6.18" edition="rc2" />
        <vers num="2.6.18" edition="rc3" />
        <vers num="2.6.18" edition="rc4" />
        <vers num="2.6.18" edition="rc5" />
        <vers num="2.6.18" edition="rc6" />
        <vers num="2.6.18" edition="rc7" />
        <vers num="2.6.18.1" />
        <vers num="2.6.18.2" />
        <vers num="2.6.18.3" />
        <vers num="2.6.18.4" />
        <vers num="2.6.18.5" />
        <vers num="2.6.18.6" />
        <vers num="2.6.18.7" />
        <vers num="2.6.18.8" />
        <vers num="2.6.19" />
        <vers num="2.6.19.1" />
        <vers num="2.6.19.2" />
        <vers num="2.6.19.3" />
        <vers num="2.6.19.4" />
        <vers num="2.6.19.5" />
        <vers num="2.6.19.6" />
        <vers num="2.6.19.7" />
        <vers num="2.6.2" />
        <vers num="2.6.2.27.13" />
        <vers num="2.6.20" />
        <vers num="2.6.20.1" />
        <vers num="2.6.20.10" />
        <vers num="2.6.20.11" />
        <vers num="2.6.20.12" />
        <vers num="2.6.20.13" />
        <vers num="2.6.20.14" />
        <vers num="2.6.20.15" />
        <vers num="2.6.20.16" />
        <vers num="2.6.20.17" />
        <vers num="2.6.20.18" />
        <vers num="2.6.20.19" />
        <vers num="2.6.20.2" />
        <vers num="2.6.20.20" />
        <vers num="2.6.20.21" />
        <vers num="2.6.20.3" />
        <vers num="2.6.20.4" />
        <vers num="2.6.20.5" />
        <vers num="2.6.20.6" />
        <vers num="2.6.20.7" />
        <vers num="2.6.20.8" />
        <vers num="2.6.20.9" />
        <vers num="2.6.21" />
        <vers num="2.6.21.1" />
        <vers num="2.6.21.2" />
        <vers num="2.6.21.3" />
        <vers num="2.6.21.4" />
        <vers num="2.6.21.5" />
        <vers num="2.6.21.6" />
        <vers num="2.6.21.7" />
        <vers num="2.6.22" />
        <vers num="2.6.22.1" />
        <vers num="2.6.22.10" />
        <vers num="2.6.22.11" />
        <vers num="2.6.22.12" />
        <vers num="2.6.22.13" />
        <vers num="2.6.22.14" />
        <vers num="2.6.22.15" />
        <vers num="2.6.22.16" />
        <vers num="2.6.22.17" />
        <vers num="2.6.22.18" />
        <vers num="2.6.22.19" />
        <vers num="2.6.22.2" />
        <vers num="2.6.22.20" />
        <vers num="2.6.22.21" />
        <vers num="2.6.22.22" />
        <vers num="2.6.22.3" />
        <vers num="2.6.22.4" />
        <vers num="2.6.22.5" />
        <vers num="2.6.22.6" />
        <vers num="2.6.22.7" />
        <vers num="2.6.22.8" />
        <vers num="2.6.22.9" />
        <vers num="2.6.22_rc1" />
        <vers num="2.6.22_rc7" />
        <vers num="2.6.23" edition="rc1" />
        <vers num="2.6.23" edition="rc2" />
        <vers num="2.6.23.1" />
        <vers num="2.6.23.10" />
        <vers num="2.6.23.11" />
        <vers num="2.6.23.12" />
        <vers num="2.6.23.13" />
        <vers num="2.6.23.14" />
        <vers num="2.6.23.15" />
        <vers num="2.6.23.16" />
        <vers num="2.6.23.17" />
        <vers num="2.6.23.2" />
        <vers num="2.6.23.3" />
        <vers num="2.6.23.4" />
        <vers num="2.6.23.5" />
        <vers num="2.6.23.6" />
        <vers num="2.6.23.7" />
        <vers num="2.6.23.8" />
        <vers num="2.6.23.9" />
        <vers num="2.6.23_rc1" />
        <vers num="2.6.24" edition="rc1" />
        <vers num="2.6.24" edition="rc2" />
        <vers num="2.6.24" edition="rc3" />
        <vers num="2.6.24" edition="rc4" />
        <vers num="2.6.24" edition="rc5" />
        <vers num="2.6.24.1" />
        <vers num="2.6.24.2" />
        <vers num="2.6.24.3" />
        <vers num="2.6.24.4" />
        <vers num="2.6.24.5" />
        <vers num="2.6.24.6" />
        <vers num="2.6.24.7" />
        <vers num="2.6.24_rc1" />
        <vers num="2.6.24_rc4" />
        <vers num="2.6.24_rc5" />
        <vers num="2.6.25" edition="" />
        <vers num="2.6.25" edition=":x86_64" />
        <vers num="2.6.25.1" edition="" />
        <vers num="2.6.25.1" edition=":x86_64" />
        <vers num="2.6.25.10" edition="" />
        <vers num="2.6.25.10" edition=":x86_64" />
        <vers num="2.6.25.11" edition="" />
        <vers num="2.6.25.11" edition=":x86_64" />
        <vers num="2.6.25.12" edition="" />
        <vers num="2.6.25.12" edition=":x86_64" />
        <vers num="2.6.25.13" />
        <vers num="2.6.25.14" />
        <vers num="2.6.25.15" />
        <vers num="2.6.25.16" />
        <vers num="2.6.25.17" />
        <vers num="2.6.25.18" />
        <vers num="2.6.25.19" />
        <vers num="2.6.25.2" edition="" />
        <vers num="2.6.25.2" edition=":x86_64" />
        <vers num="2.6.25.20" />
        <vers num="2.6.25.3" edition="" />
        <vers num="2.6.25.3" edition=":x86_64" />
        <vers num="2.6.25.4" edition="" />
        <vers num="2.6.25.4" edition=":x86_64" />
        <vers num="2.6.25.5" edition="" />
        <vers num="2.6.25.5" edition=":x86_64" />
        <vers num="2.6.25.6" edition="" />
        <vers num="2.6.25.6" edition=":x86_64" />
        <vers num="2.6.25.7" edition="" />
        <vers num="2.6.25.7" edition=":x86_64" />
        <vers num="2.6.25.8" edition="" />
        <vers num="2.6.25.8" edition=":x86_64" />
        <vers num="2.6.25.9" edition="" />
        <vers num="2.6.25.9" edition=":x86_64" />
        <vers num="2.6.26" edition="rc4" />
        <vers num="2.6.26.1" />
        <vers num="2.6.26.2" />
        <vers num="2.6.26.3" />
        <vers num="2.6.26.4" />
        <vers num="2.6.26.5" />
        <vers num="2.6.26.6" />
        <vers num="2.6.26.7" />
        <vers num="2.6.26.8" />
        <vers num="2.6.27" edition="rc1" />
        <vers num="2.6.27" edition="rc2" />
        <vers num="2.6.27" edition="rc3" />
        <vers num="2.6.27" edition="rc4" />
        <vers num="2.6.27" edition="rc5" />
        <vers num="2.6.27" edition="rc6" />
        <vers num="2.6.27" edition="rc7" />
        <vers num="2.6.27" edition="rc8" />
        <vers num="2.6.27" edition="rc9" />
        <vers num="2.6.27.1" />
        <vers num="2.6.27.10" />
        <vers num="2.6.27.11" />
        <vers num="2.6.27.12" />
        <vers num="2.6.27.13" />
        <vers num="2.6.27.14" />
        <vers num="2.6.27.15" />
        <vers num="2.6.27.16" />
        <vers num="2.6.27.17" />
        <vers num="2.6.27.18" />
        <vers num="2.6.27.19" />
        <vers num="2.6.27.2" />
        <vers num="2.6.27.20" />
        <vers num="2.6.27.21" />
        <vers num="2.6.27.3" />
        <vers num="2.6.27.4" />
        <vers num="2.6.27.5" />
        <vers num="2.6.27.6" />
        <vers num="2.6.27.7" />
        <vers num="2.6.27.8" />
        <vers num="2.6.27.9" />
        <vers num="2.6.28" edition="git7" />
        <vers num="2.6.28" edition="rc1" />
        <vers num="2.6.28" edition="rc2" />
        <vers num="2.6.28" edition="rc3" />
        <vers num="2.6.28" edition="rc4" />
        <vers num="2.6.28" edition="rc5" />
        <vers num="2.6.28" edition="rc6" />
        <vers num="2.6.28" edition="rc7" />
        <vers num="2.6.28.1" />
        <vers num="2.6.28.2" />
        <vers num="2.6.28.3" />
        <vers num="2.6.28.4" />
        <vers num="2.6.28.5" />
        <vers num="2.6.28.6" />
        <vers num="2.6.28.7" />
        <vers num="2.6.28.8" />
        <vers num="2.6.28.9" />
        <vers num="2.6.29" edition="git1" />
        <vers num="2.6.29" edition="rc1" />
        <vers num="2.6.29" edition="rc2" />
        <vers num="2.6.29" edition="rc2_git7" />
        <vers num="2.6.29" edition="rc8-kk" />
        <vers prev="1" num="2.6.29.3" />
        <vers num="2.6.29.rc1" />
        <vers num="2.6.29.rc2" />
        <vers num="2.6.29.rc2-git1" />
        <vers num="2.6.3" />
        <vers num="2.6.30" edition="rc1" />
        <vers num="2.6.30" edition="rc2" />
        <vers num="2.6.30" edition="rc3" />
        <vers num="2.6.4" />
        <vers num="2.6.5" />
        <vers num="2.6.6" />
        <vers num="2.6.7" />
        <vers num="2.6.8" />
        <vers num="2.6.8.1" />
        <vers num="2.6.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2009-1631" published="2009-05-14" name="CVE-2009-1631" modified="2009-05-23" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">The Mailer component in Evolution 2.26.1 and earlier uses world-readable permissions for the .evolution directory, and certain directories and files under .evolution/ related to local mail, which allows local users to obtain sensitive information by reading these files.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=498648" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=498648</ref>
      <ref url="http://www.securityfocus.com/bid/34921" source="BID">34921</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2009/05/12/6" source="MLIST">[oss-security] 20090512 CVE Request (evolution)</ref>
      <ref url="http://bugzilla.gnome.org/show_bug.cgi?id=581604" source="MISC">http://bugzilla.gnome.org/show_bug.cgi?id=581604</ref>
      <ref url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=526409" source="MISC">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=526409</ref>
    </refs>
    <vuln_soft>
      <prod vendor="gnome" name="evolution">
        <vers num="1.0.8" />
        <vers num="1.2" />
        <vers num="1.2.1" />
        <vers num="1.2.2" />
        <vers num="1.2.3" />
        <vers num="1.2.4" />
        <vers num="1.4" />
        <vers num="1.4.3" />
        <vers num="1.4.4" />
        <vers num="1.4.5" />
        <vers num="1.4.6" />
        <vers num="2.0.0" />
        <vers num="2.0.1" />
        <vers num="2.0.2" />
        <vers num="2.12" />
        <vers num="2.24" />
        <vers prev="1" num="2.26.1" />
        <vers num="2.4" />
        <vers num="2.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1632" published="2009-05-14" name="CVE-2009-1632" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Multiple memory leaks in Ipsec-tools before 0.7.2 allow remote attackers to cause a denial of service (memory consumption) via vectors involving (1) signature verification during user authentication with X.509 certificates, related to the eay_check_x509sign function in src/racoon/crypto_openssl.c; and (2) the NAT-Traversal (aka NAT-T) keepalive implementation, related to src/racoon/nattraversal.c.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://sourceforge.net/mailarchive/forum.php?thread_name=20090422151825.GB46988%40zeninc.net&amp;forum_name=ipsec-tools-announce" source="MLIST" patch="1">[ipsec-tools-announce] 20090422 Ipsec-tools 0.7.2 released</ref>
      <ref url="https://trac.ipsec-tools.net/ticket/303" source="CONFIRM">https://trac.ipsec-tools.net/ticket/303</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/3184" source="VUPEN">ADV-2009-3184</ref>
      <ref url="http://www.ubuntu.com/usn/USN-785-1" source="UBUNTU">USN-785-1</ref>
      <ref url="http://www.securityfocus.com/bid/34765" source="BID">34765</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-1036.html" source="REDHAT">RHSA-2009:1036</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2009/05/12/3" source="MLIST">[oss-security] 20090512 Re: ipsec-tools 0.7.2</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:114" source="MANDRIVA">MDVSA-2009:114</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1804" source="DEBIAN">DSA-1804</ref>
      <ref url="http://support.apple.com/kb/HT3937" source="CONFIRM">http://support.apple.com/kb/HT3937</ref>
      <ref url="http://sourceforge.net/project/shownotes.php?group_id=74601&amp;release_id=677611" source="CONFIRM">http://sourceforge.net/project/shownotes.php?group_id=74601&amp;release_id=677611</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200905-03.xml" source="GENTOO">GLSA-200905-03</ref>
      <ref url="http://secunia.com/advisories/35685" source="SECUNIA">35685</ref>
      <ref url="http://secunia.com/advisories/35404" source="SECUNIA">35404</ref>
      <ref url="http://secunia.com/advisories/35212" source="SECUNIA">35212</ref>
      <ref url="http://secunia.com/advisories/35159" source="SECUNIA">35159</ref>
      <ref url="http://secunia.com/advisories/35153" source="SECUNIA">35153</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10581" source="OVAL">oval:org.mitre.oval:def:10581</ref>
      <ref url="http://marc.info/?l=oss-security&amp;m=124101704828036&amp;w=2" source="MLIST">[oss-security] 20090429 ipsec-tools 0.7.2</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-07/msg00002.html" source="SUSE">SUSE-SR:2009:012</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2009/Nov/msg00000.html" source="APPLE">APPLE-SA-2009-11-09-1</ref>
      <ref url="http://cvsweb.netbsd.org/bsdweb.cgi/src/crypto/dist/ipsec-tools/src/racoon/nattraversal.c.diff?r1=1.6&amp;r2=1.6.6.1&amp;f=h" source="CONFIRM">http://cvsweb.netbsd.org/bsdweb.cgi/src/crypto/dist/ipsec-tools/src/racoon/nattraversal.c.diff?r1=1.6&amp;r2=1.6.6.1&amp;f=h</ref>
      <ref url="http://cvsweb.netbsd.org/bsdweb.cgi/src/crypto/dist/ipsec-tools/src/racoon/nattraversal.c" source="CONFIRM">http://cvsweb.netbsd.org/bsdweb.cgi/src/crypto/dist/ipsec-tools/src/racoon/nattraversal.c</ref>
      <ref url="http://cvsweb.netbsd.org/bsdweb.cgi/src/crypto/dist/ipsec-tools/src/racoon/crypto_openssl.c.diff?r1=1.11.6.4&amp;r2=1.11.6.5&amp;f=h" source="CONFIRM">http://cvsweb.netbsd.org/bsdweb.cgi/src/crypto/dist/ipsec-tools/src/racoon/crypto_openssl.c.diff?r1=1.11.6.4&amp;r2=1.11.6.5&amp;f=h</ref>
      <ref url="http://cvsweb.netbsd.org/bsdweb.cgi/src/crypto/dist/ipsec-tools/src/racoon/crypto_openssl.c" source="CONFIRM">http://cvsweb.netbsd.org/bsdweb.cgi/src/crypto/dist/ipsec-tools/src/racoon/crypto_openssl.c</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ipsec-tools" name="ipsec-tools">
        <vers num="0.1" />
        <vers num="0.2" />
        <vers num="0.2.1" />
        <vers num="0.2.2" />
        <vers num="0.2.3" />
        <vers num="0.2.4" />
        <vers num="0.3" edition="rc1" />
        <vers num="0.3" edition="rc2" />
        <vers num="0.3" edition="rc3" />
        <vers num="0.3" edition="rc4" />
        <vers num="0.3" edition="rc5" />
        <vers num="0.3.1" />
        <vers num="0.3.2" />
        <vers num="0.3.3" />
        <vers num="0.3_rc1" />
        <vers num="0.3_rc2" />
        <vers num="0.3_rc3" />
        <vers num="0.3_rc4" />
        <vers num="0.3_rc5" />
        <vers num="0.4" edition="rc1" />
        <vers num="0.5" />
        <vers num="0.5.1" />
        <vers num="0.5.2" />
        <vers num="0.6" />
        <vers num="0.6.1" />
        <vers num="0.6.2" />
        <vers num="0.6.3" />
        <vers num="0.6.4" />
        <vers num="0.6.5" />
        <vers num="0.6.6" />
        <vers num="0.6.7" />
        <vers num="0.7" />
        <vers prev="1" num="0.7.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1633" published="2009-05-28" name="CVE-2009-1633" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Multiple buffer overflows in the cifs subsystem in the Linux kernel before 2.6.29.4 allow remote CIFS servers to cause a denial of service (memory corruption) and possibly have unspecified other impact via (1) a malformed Unicode string, related to Unicode string area alignment in fs/cifs/sess.c; or (2) long Unicode characters, related to fs/cifs/cifssmb.c and the cifs_readdir function in fs/cifs/readdir.c.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-May/msg01126.html" source="FEDORA" patch="1">FEDORA-2009-5356</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=496572" source="CONFIRM" patch="1">https://bugzilla.redhat.com/show_bug.cgi?id=496572</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2009/05/15/2" source="MLIST" patch="1">[oss-security] 20090515 Re: Re: Update - Re: CVE request? buffer overflow in CIFS in 2.6.*</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2009/05/14/4" source="MLIST" patch="1">[oss-security] 20090514 Re: Update - Re: CVE request? buffer overflow in CIFS in 2.6.*</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2009/05/14/1" source="MLIST" patch="1">[oss-security] 20090514 Update - Re: CVE request? buffer overflow in CIFS in 2.6.*</ref>
      <ref url="http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=27b87fe52baba0a55e9723030e76fce94fabcea4" source="CONFIRM" patch="1">http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=27b87fe52baba0a55e9723030e76fce94fabcea4</ref>
      <ref url="http://git.kernel.org/?p=linux/kernel/git/sfrench/cifs-2.6.git;a=commit;h=968460ebd8006d55661dec0fb86712b40d71c413" source="CONFIRM" patch="1">http://git.kernel.org/?p=linux/kernel/git/sfrench/cifs-2.6.git;a=commit;h=968460ebd8006d55661dec0fb86712b40d71c413</ref>
      <ref url="http://git.kernel.org/?p=linux/kernel/git/sfrench/cifs-2.6.git;a=commit;h=7b0c8fcff47a885743125dd843db64af41af5a61" source="CONFIRM" patch="1">http://git.kernel.org/?p=linux/kernel/git/sfrench/cifs-2.6.git;a=commit;h=7b0c8fcff47a885743125dd843db64af41af5a61</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-May/msg01271.html" source="FEDORA">FEDORA-2009-5383</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/3316" source="VUPEN">ADV-2009-3316</ref>
      <ref url="http://www.vmware.com/security/advisories/VMSA-2009-0016.html" source="CONFIRM">http://www.vmware.com/security/advisories/VMSA-2009-0016.html</ref>
      <ref url="http://www.ubuntu.com/usn/usn-793-1" source="UBUNTU">USN-793-1</ref>
      <ref url="http://www.securityfocus.com/bid/34612" source="BID">34612</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/507985/100/0/threaded" source="BUGTRAQ">20091120 VMSA-2009-0016 VMware vCenter and ESX update release and vMA patch release address multiple security issue in third party components</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/505254/100/0/threaded" source="BUGTRAQ">20090724 rPSA-2009-0111-1 kernel</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-1157.html" source="REDHAT">RHSA-2009:1157</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:148" source="MANDRIVA">MDVSA-2009:148</ref>
      <ref url="http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.29.4" source="CONFIRM">http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.29.4</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1865" source="DEBIAN">DSA-1865</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1844" source="DEBIAN">DSA-1844</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1809" source="DEBIAN">DSA-1809</ref>
      <ref url="http://wiki.rpath.com/Advisories:rPSA-2009-0111" source="CONFIRM">http://wiki.rpath.com/Advisories:rPSA-2009-0111</ref>
      <ref url="http://secunia.com/advisories/37471" source="SECUNIA">37471</ref>
      <ref url="http://secunia.com/advisories/37351" source="SECUNIA">37351</ref>
      <ref url="http://secunia.com/advisories/36327" source="SECUNIA">36327</ref>
      <ref url="http://secunia.com/advisories/36051" source="SECUNIA">36051</ref>
      <ref url="http://secunia.com/advisories/35847" source="SECUNIA">35847</ref>
      <ref url="http://secunia.com/advisories/35656" source="SECUNIA">35656</ref>
      <ref url="http://secunia.com/advisories/35298" source="SECUNIA">35298</ref>
      <ref url="http://secunia.com/advisories/35226" source="SECUNIA" adv="1">35226</ref>
      <ref url="http://secunia.com/advisories/35217" source="SECUNIA">35217</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9525" source="OVAL">oval:org.mitre.oval:def:9525</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:8588" source="OVAL">oval:org.mitre.oval:def:8588</ref>
      <ref url="http://marc.info/?l=oss-security&amp;m=124099371726547&amp;w=2" source="MLIST">[oss-security] 20090429 Re: CVE request? buffer overflow in CIFS in 2.6.*</ref>
      <ref url="http://marc.info/?l=oss-security&amp;m=124099284225229&amp;w=2" source="MLIST">[oss-security] 20090429 Re: CVE request? buffer overflow in CIFS in 2.6.*</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2010-02/msg00005.html" source="SUSE">SUSE-SA:2010:012</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-11/msg00007.html" source="SUSE">SUSE-SA:2009:056</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-11/msg00005.html" source="SUSE">SUSE-SA:2009:054</ref>
    </refs>
    <vuln_soft>
      <prod vendor="kernel" name="linux">
        <vers num="2.6.0" />
        <vers num="2.6.1" />
        <vers num="2.6.10" />
        <vers num="2.6.11" />
        <vers num="2.6.11.1" />
        <vers num="2.6.11.10" />
        <vers num="2.6.11.12" />
        <vers num="2.6.11.2" />
        <vers num="2.6.11.3" />
        <vers num="2.6.11.4" />
        <vers num="2.6.11.5" />
        <vers num="2.6.11.6" />
        <vers num="2.6.11.7" />
        <vers num="2.6.11.8" />
        <vers num="2.6.11.9" />
        <vers num="2.6.12" />
        <vers num="2.6.12.1" />
        <vers num="2.6.12.2" />
        <vers num="2.6.12.3" />
        <vers num="2.6.12.4" />
        <vers num="2.6.12.5" />
        <vers num="2.6.12.6" />
        <vers num="2.6.13" />
        <vers num="2.6.13.1" />
        <vers num="2.6.13.2" />
        <vers num="2.6.13.3" />
        <vers num="2.6.13.4" />
        <vers num="2.6.13.5" />
        <vers num="2.6.14" />
        <vers num="2.6.14.1" />
        <vers num="2.6.14.2" />
        <vers num="2.6.14.3" />
        <vers num="2.6.14.4" />
        <vers num="2.6.14.5" />
        <vers num="2.6.14.6" />
        <vers num="2.6.14.7" />
        <vers num="2.6.15" />
        <vers num="2.6.15.1" />
        <vers num="2.6.15.2" />
        <vers num="2.6.15.3" />
        <vers num="2.6.15.4" />
        <vers num="2.6.15.5" />
        <vers num="2.6.15.6" />
        <vers num="2.6.15.7" />
        <vers num="2.6.16" />
        <vers num="2.6.16.20" />
        <vers num="2.6.16.21" />
        <vers num="2.6.16.22" />
        <vers num="2.6.16.23" />
        <vers num="2.6.16.24" />
        <vers num="2.6.16.25" />
        <vers num="2.6.16.26" />
        <vers num="2.6.16.27" />
        <vers num="2.6.16.28" />
        <vers num="2.6.16.29" />
        <vers num="2.6.16.30" />
        <vers num="2.6.16.31" />
        <vers num="2.6.16.32" />
        <vers num="2.6.16.33" />
        <vers num="2.6.16.34" />
        <vers num="2.6.16.35" />
        <vers num="2.6.16.36" />
        <vers num="2.6.16.37" />
        <vers num="2.6.16.38" />
        <vers num="2.6.16.39" />
        <vers num="2.6.16.40" />
        <vers num="2.6.16.41" />
        <vers num="2.6.16.42" />
        <vers num="2.6.16.43" />
        <vers num="2.6.16.44" />
        <vers num="2.6.16.45" />
        <vers num="2.6.16.46" />
        <vers num="2.6.16.47" />
        <vers num="2.6.16.48" />
        <vers num="2.6.16.49" />
        <vers num="2.6.16.50" />
        <vers num="2.6.16.51" />
        <vers num="2.6.16.52" />
        <vers num="2.6.16.53" />
        <vers num="2.6.16.54" />
        <vers num="2.6.16.55" />
        <vers num="2.6.16.56" />
        <vers num="2.6.16.57" />
        <vers num="2.6.16.58" />
        <vers num="2.6.16.59" />
        <vers num="2.6.16.60" />
        <vers num="2.6.16.61" />
        <vers num="2.6.16.62" />
        <vers num="2.6.17" />
        <vers num="2.6.17.1" />
        <vers num="2.6.17.10" />
        <vers num="2.6.17.11" />
        <vers num="2.6.17.12" />
        <vers num="2.6.17.13" />
        <vers num="2.6.17.14" />
        <vers num="2.6.17.2" />
        <vers num="2.6.17.3" />
        <vers num="2.6.17.4" />
        <vers num="2.6.17.5" />
        <vers num="2.6.17.6" />
        <vers num="2.6.17.7" />
        <vers num="2.6.17.8" />
        <vers num="2.6.17.9" />
        <vers num="2.6.18" />
        <vers num="2.6.18.1" />
        <vers num="2.6.18.2" />
        <vers num="2.6.18.3" />
        <vers num="2.6.18.4" />
        <vers num="2.6.18.5" />
        <vers num="2.6.18.6" />
        <vers num="2.6.18.7" />
        <vers num="2.6.18.8" />
        <vers num="2.6.19" />
        <vers num="2.6.19.1" />
        <vers num="2.6.19.2" />
        <vers num="2.6.19.3" />
        <vers num="2.6.19.4" />
        <vers num="2.6.19.5" />
        <vers num="2.6.19.6" />
        <vers num="2.6.19.7" />
        <vers num="2.6.2" />
        <vers num="2.6.20" />
        <vers num="2.6.20.1" />
        <vers num="2.6.20.10" />
        <vers num="2.6.20.11" />
        <vers num="2.6.20.12" />
        <vers num="2.6.20.13" />
        <vers num="2.6.20.14" />
        <vers num="2.6.20.15" />
        <vers num="2.6.20.16" />
        <vers num="2.6.20.17" />
        <vers num="2.6.20.18" />
        <vers num="2.6.20.19" />
        <vers num="2.6.20.2" />
        <vers num="2.6.20.20" />
        <vers num="2.6.20.21" />
        <vers num="2.6.20.3" />
        <vers num="2.6.20.4" />
        <vers num="2.6.20.5" />
        <vers num="2.6.20.6" />
        <vers num="2.6.20.7" />
        <vers num="2.6.20.8" />
        <vers num="2.6.20.9" />
        <vers num="2.6.21" />
        <vers num="2.6.21.1" />
        <vers num="2.6.21.2" />
        <vers num="2.6.21.3" />
        <vers num="2.6.21.4" />
        <vers num="2.6.21.5" />
        <vers num="2.6.21.6" />
        <vers num="2.6.21.7" />
        <vers num="2.6.22" />
        <vers num="2.6.22.1" />
        <vers num="2.6.22.10" />
        <vers num="2.6.22.11" />
        <vers num="2.6.22.12" />
        <vers num="2.6.22.13" />
        <vers num="2.6.22.14" />
        <vers num="2.6.22.15" />
        <vers num="2.6.22.16" />
        <vers num="2.6.22.17" />
        <vers num="2.6.22.18" />
        <vers num="2.6.22.19" />
        <vers num="2.6.22.2" />
        <vers num="2.6.22.3" />
        <vers num="2.6.22.4" />
        <vers num="2.6.22.5" />
        <vers num="2.6.22.6" />
        <vers num="2.6.22.7" />
        <vers num="2.6.22.8" />
        <vers num="2.6.22.9" />
        <vers num="2.6.23" />
        <vers num="2.6.23.1" />
        <vers num="2.6.23.10" />
        <vers num="2.6.23.11" />
        <vers num="2.6.23.12" />
        <vers num="2.6.23.13" />
        <vers num="2.6.23.14" />
        <vers num="2.6.23.15" />
        <vers num="2.6.23.16" />
        <vers num="2.6.23.17" />
        <vers num="2.6.23.2" />
        <vers num="2.6.23.3" />
        <vers num="2.6.23.4" />
        <vers num="2.6.23.5" />
        <vers num="2.6.23.6" />
        <vers num="2.6.23.7" />
        <vers num="2.6.23.8" />
        <vers num="2.6.23.9" />
        <vers num="2.6.24" />
        <vers num="2.6.24.1" />
        <vers num="2.6.24.2" />
        <vers num="2.6.24.3" />
        <vers num="2.6.24.4" />
        <vers num="2.6.24.5" />
        <vers num="2.6.24.6" />
        <vers num="2.6.24.7" />
        <vers num="2.6.25" />
        <vers num="2.6.25.1" />
        <vers num="2.6.25.10" />
        <vers num="2.6.25.11" />
        <vers num="2.6.25.12" />
        <vers num="2.6.25.13" />
        <vers num="2.6.25.14" />
        <vers num="2.6.25.15" />
        <vers num="2.6.25.16" />
        <vers num="2.6.25.17" />
        <vers num="2.6.25.18" />
        <vers num="2.6.25.19" />
        <vers num="2.6.25.2" />
        <vers num="2.6.25.20" />
        <vers num="2.6.25.3" />
        <vers num="2.6.25.4" />
        <vers num="2.6.25.5" />
        <vers num="2.6.25.6" />
        <vers num="2.6.25.7" />
        <vers num="2.6.25.8" />
        <vers num="2.6.25.9" />
        <vers num="2.6.26" />
        <vers num="2.6.26.1" />
        <vers num="2.6.26.2" />
        <vers num="2.6.26.3" />
        <vers num="2.6.26.4" />
        <vers num="2.6.26.5" />
        <vers num="2.6.26.6" />
        <vers num="2.6.26.7" />
        <vers num="2.6.26.8" />
        <vers num="2.6.27" />
        <vers num="2.6.27.1" />
        <vers num="2.6.27.10" />
        <vers num="2.6.27.11" />
        <vers num="2.6.27.12" />
        <vers num="2.6.27.13" />
        <vers num="2.6.27.14" />
        <vers num="2.6.27.15" />
        <vers num="2.6.27.16" />
        <vers num="2.6.27.17" />
        <vers num="2.6.27.18" />
        <vers num="2.6.27.19" />
        <vers num="2.6.27.2" />
        <vers num="2.6.27.3" />
        <vers num="2.6.27.4" />
        <vers num="2.6.27.5" />
        <vers num="2.6.27.6" />
        <vers num="2.6.27.7" />
        <vers num="2.6.27.8" />
        <vers num="2.6.27.9" />
        <vers num="2.6.28" />
        <vers num="2.6.28.1" />
        <vers num="2.6.28.2" />
        <vers num="2.6.28.3" />
        <vers num="2.6.28.4" />
        <vers num="2.6.29" />
        <vers num="2.6.29.1" />
        <vers num="2.6.29.2" />
        <vers prev="1" num="2.6.29.3" />
        <vers num="2.6.3" />
        <vers num="2.6.4" />
        <vers num="2.6.5" />
        <vers num="2.6.6" />
        <vers num="2.6.7" />
        <vers num="2.6.8" />
        <vers num="2.6.8.1" />
        <vers num="2.6.9" />
      </prod>
      <prod vendor="linux" name="kernel">
        <vers num="2.6.29" edition="rc2_git7" />
        <vers num="2.6.29" edition="rc8-kk" />
        <vers prev="1" num="2.6.29.3" />
        <vers num="2.6.29.rc1" />
        <vers num="2.6.29.rc2" />
        <vers num="2.6.29.rc2-git1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1634" published="2009-05-26" name="CVE-2009-1634" modified="2009-06-09" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The WebAccess component in Novell GroupWise 7.x before 7.03 HP3 and 8.x before 8.0 HP2 does not properly implement session management mechanisms, which allows remote attackers to gain access to user accounts via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="https://bugzilla.novell.com/show_bug.cgi?id=472979" source="MISC" adv="1">https://bugzilla.novell.com/show_bug.cgi?id=472979</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/50688" source="XF">groupwise-session-unauth-access(50688)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1393" source="VUPEN" adv="1">ADV-2009-1393</ref>
      <ref url="http://www.securityfocus.com/bid/35066" source="BID">35066</ref>
      <ref url="http://www.novell.com/support/viewContent.do?externalId=7003266&amp;sliceId=1" source="CONFIRM" adv="1">http://www.novell.com/support/viewContent.do?externalId=7003266&amp;sliceId=1</ref>
      <ref url="http://secunia.com/advisories/35177" source="SECUNIA" adv="1">35177</ref>
    </refs>
    <vuln_soft>
      <prod vendor="novell" name="groupwise">
        <vers num="7.0" />
        <vers num="7.0.0" edition="sp1" />
        <vers num="7.0.0" edition="sp2" />
        <vers num="7.0.2" />
        <vers num="7.0.3" />
        <vers num="7.03" edition="hp1a" />
        <vers num="7.03" edition="hp2" />
        <vers num="8.0" edition="hp1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1635" published="2009-05-22" name="CVE-2009-1635" modified="2009-06-09" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in the WebAccess component in Novell GroupWise 7.x before 7.03 HP3 and 8.x before 8.0 HP2 allow remote attackers to inject arbitrary web script or HTML via (1) the User.lang parameter to the login page (aka gw/webacc), (2) style expressions in a message that contains an HTML file, or (3) vectors associated with incorrect protection mechanisms against scripting, as demonstrated using whitespace between JavaScript event names and values.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.novell.com/support/search.do?cmd=displayKC&amp;externalId=7003271" source="CONFIRM" patch="1" adv="1">http://www.novell.com/support/search.do?cmd=displayKC&amp;externalId=7003271</ref>
      <ref url="https://bugzilla.novell.com/show_bug.cgi?id=484942" source="MISC">https://bugzilla.novell.com/show_bug.cgi?id=484942</ref>
      <ref url="https://bugzilla.novell.com/show_bug.cgi?id=474500" source="MISC">https://bugzilla.novell.com/show_bug.cgi?id=474500</ref>
      <ref url="https://bugzilla.novell.com/show_bug.cgi?id=472987" source="MISC">https://bugzilla.novell.com/show_bug.cgi?id=472987</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/50691" source="XF">groupwise-unspecified-xss(50691)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/50689" source="XF">groupwise-styleexpressions-xss(50689)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/50672" source="XF">groupwise-webaccess-loginpage-xss(50672)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1393" source="VUPEN">ADV-2009-1393</ref>
      <ref url="http://www.securityfocus.com/bid/35066" source="BID">35066</ref>
      <ref url="http://www.securityfocus.com/bid/35061" source="BID">35061</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/503885/100/0/threaded" source="BUGTRAQ">20090528 Novell Groupwise fails to properly sanitize emails.</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/503700/100/0/threaded" source="BUGTRAQ">20090521 Novell GroupWise Web Access Multiple XSS</ref>
      <ref url="http://www.novell.com/support/viewContent.do?externalId=7003268&amp;sliceId=1" source="CONFIRM">http://www.novell.com/support/viewContent.do?externalId=7003268&amp;sliceId=1</ref>
      <ref url="http://www.novell.com/support/viewContent.do?externalId=7003267&amp;sliceId=1" source="CONFIRM">http://www.novell.com/support/viewContent.do?externalId=7003267&amp;sliceId=1</ref>
      <ref url="http://securitytracker.com/id?1022267" source="SECTRACK">1022267</ref>
      <ref url="http://secunia.com/advisories/35177" source="SECUNIA">35177</ref>
      <ref url="http://packetstorm.linuxsecurity.com/0905-exploits/groupwise-xss.txt" source="MISC">http://packetstorm.linuxsecurity.com/0905-exploits/groupwise-xss.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="novell" name="groupwise">
        <vers num="7.0" edition="sp1" />
        <vers num="7.0" edition="sp2" />
        <vers num="7.0" edition="sp3" />
        <vers num="7.0.0" edition="sp1" />
        <vers num="7.0.0" edition="sp2" />
        <vers num="7.0.2" />
        <vers num="7.0.3" />
        <vers num="7.01" />
        <vers num="7.02x" />
        <vers num="7.03" edition="hp1a" />
        <vers num="7.03" edition="hp2" />
        <vers num="8.0" edition="hp1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1636" published="2009-05-26" name="CVE-2009-1636" modified="2009-06-09" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Multiple buffer overflows in the Internet Agent (aka GWIA) component in Novell GroupWise 7.x before 7.03 HP3 and 8.x before 8.0 HP2 allow remote attackers to execute arbitrary code via (1) a crafted e-mail address in an SMTP session or (2) an SMTP command.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="https://bugzilla.novell.com/show_bug.cgi?id=482914" source="MISC">https://bugzilla.novell.com/show_bug.cgi?id=482914</ref>
      <ref url="https://bugzilla.novell.com/show_bug.cgi?id=478892" source="MISC">https://bugzilla.novell.com/show_bug.cgi?id=478892</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/50693" source="XF">gia-email-code-execution(50693)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/50692" source="XF">gia-smtp-code-execution(50692)</ref>
      <ref url="http://www.vupen.com/exploits/Novell_GroupWise_GWIA_SMTP_Command_Remote_Buffer_Overflow_PoC_Exploit_1393140.php" source="MISC" adv="1">http://www.vupen.com/exploits/Novell_GroupWise_GWIA_SMTP_Command_Remote_Buffer_Overflow_PoC_Exploit_1393140.php</ref>
      <ref url="http://www.vupen.com/exploits/Novell_GroupWise_GWIA_Email_Address_Remote_Buffer_Overflow_Exploit_1393141.php" source="MISC" adv="1">http://www.vupen.com/exploits/Novell_GroupWise_GWIA_Email_Address_Remote_Buffer_Overflow_Exploit_1393141.php</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1393" source="VUPEN" adv="1">ADV-2009-1393</ref>
      <ref url="http://www.securitytracker.com/id?1022276" source="SECTRACK">1022276</ref>
      <ref url="http://www.securityfocus.com/bid/35065" source="BID">35065</ref>
      <ref url="http://www.securityfocus.com/bid/35064" source="BID">35064</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/503724/100/0/threaded" source="BUGTRAQ">20090522 Novell GroupWise Internet Agent Remote Buffer Overflow Vulnerabilities</ref>
      <ref url="http://www.novell.com/support/viewContent.do?externalId=7003273&amp;sliceId=1" source="CONFIRM" adv="1">http://www.novell.com/support/viewContent.do?externalId=7003273&amp;sliceId=1</ref>
      <ref url="http://www.novell.com/support/viewContent.do?externalId=7003272&amp;sliceId=1" source="CONFIRM">http://www.novell.com/support/viewContent.do?externalId=7003272&amp;sliceId=1</ref>
      <ref url="http://secunia.com/advisories/35177" source="SECUNIA" adv="1">35177</ref>
      <ref url="http://osvdb.org/54645" source="OSVDB">54645</ref>
      <ref url="http://osvdb.org/54644" source="OSVDB">54644</ref>
    </refs>
    <vuln_soft>
      <prod vendor="novell" name="groupwise">
        <vers num="7.0" edition="sp1" />
        <vers num="7.0" edition="sp2" />
        <vers num="7.0" edition="sp3" />
        <vers num="7.0.0" edition="sp1" />
        <vers num="7.0.0" edition="sp2" />
        <vers num="7.0.2" />
        <vers num="7.0.3" />
        <vers num="7.01" />
        <vers num="7.03" edition="hp1a" />
        <vers num="7.03" edition="hp2" />
        <vers num="8.0" edition="hp1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1637" published="2009-05-15" name="CVE-2009-1637" modified="2009-05-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">profile.php in Simple Customer 1.3 does not require administrative authentication, which allows remote attackers to change the admin e-mail address and password via the email and password parameters.</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/50379" source="XF">simplecustomer-profile-security-bypass(50379)</ref>
      <ref url="http://www.securityfocus.com/bid/34872" source="BID">34872</ref>
      <ref url="http://www.milw0rm.com/exploits/8638" source="MILW0RM">8638</ref>
      <ref url="http://secunia.com/advisories/35030" source="SECUNIA" adv="1">35030</ref>
      <ref url="http://osvdb.org/54280" source="OSVDB">54280</ref>
    </refs>
    <vuln_soft>
      <prod vendor="simplecustomer" name="simple_customer">
        <vers num="1.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1638" published="2009-05-15" name="CVE-2009-1638" modified="2009-05-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Techno Dreams Job Career Package 3.0 allows remote attackers to bypass authentication and obtain administrative access by setting the JobCareerAdmin cookie to Login.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/50370" source="XF">jcp-jobcareeradmin-sec-bypass(50370)</ref>
      <ref url="http://www.securityfocus.com/bid/34865" source="BID">34865</ref>
      <ref url="http://www.milw0rm.com/exploits/8627" source="MILW0RM">8627</ref>
      <ref url="http://secunia.com/advisories/34996" source="SECUNIA" adv="1">34996</ref>
      <ref url="http://osvdb.org/54278" source="OSVDB">54278</ref>
    </refs>
    <vuln_soft>
      <prod vendor="t-dreams" name="job_career_package">
        <vers num="3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1639" published="2009-05-15" name="CVE-2009-1639" modified="2009-05-19" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Stack-based buffer overflow in Nucleus Data Recovery Kernel Recovery for Novell 4.03 allows user-assisted attackers to execute arbitrary code via a crafted .NKNT file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/34846" source="BID">34846</ref>
      <ref url="http://www.insight-tech.org/xploits/KernelrecoveryforNovell%28Traditionalvolumes%29v.4.03CodeExecutionandDoS.py" source="MISC">http://www.insight-tech.org/xploits/KernelrecoveryforNovell(Traditionalvolumes)v.4.03CodeExecutionandDoS.py</ref>
      <ref url="http://www.insight-tech.org/index.php?p=Kernel-recovery-for-Novell-Traditional-volumes-v-4-03-Code-Execution-and-DoS" source="MISC">http://www.insight-tech.org/index.php?p=Kernel-recovery-for-Novell-Traditional-volumes-v-4-03-Code-Execution-and-DoS</ref>
      <ref url="http://secunia.com/advisories/34798" source="SECUNIA" adv="1">34798</ref>
    </refs>
    <vuln_soft>
      <prod vendor="nucleustechnologies" name="kernel_recovery">
        <vers num="4.03" edition="novell" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1640" published="2009-05-15" name="CVE-2009-1640" modified="2009-05-18" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Stack-based buffer overflow in Nucleus Data Recovery Kernel Recovery for Macintosh 4.04 allows user-assisted attackers to execute arbitrary code via a crafted .AMHH file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/50345" source="XF">nucleus-amhh-bo(50345)</ref>
      <ref url="http://www.securityfocus.com/bid/34846" source="BID">34846</ref>
      <ref url="http://www.insight-tech.org/xploits/KernelrecoveryforMacintoshv.4.04BufferOverflow.py" source="MISC">http://www.insight-tech.org/xploits/KernelrecoveryforMacintoshv.4.04BufferOverflow.py</ref>
      <ref url="http://www.insight-tech.org/index.php?p=Kernel-recovery-for-Macintosh-v-4-04-Buffer-Overflow" source="MISC">http://www.insight-tech.org/index.php?p=Kernel-recovery-for-Macintosh-v-4-04-Buffer-Overflow</ref>
      <ref url="http://secunia.com/advisories/34860" source="SECUNIA" adv="1">34860</ref>
      <ref url="http://osvdb.org/54224" source="OSVDB">54224</ref>
    </refs>
    <vuln_soft>
      <prod vendor="nucleustechnologies" name="kernel_recovery">
        <vers num="4.04" edition="" />
        <vers num="4.04" edition=":macintosh" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1641" published="2009-05-15" name="CVE-2009-1641" modified="2009-05-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Multiple stack-based buffer overflows in Mini-stream Ripper 3.0.1.1 allow remote attackers to execute arbitrary code via (1) a long rtsp URL in a .ram file and (2) a long string in the HREF attribute of a REF element in a .asx file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/50375" source="XF">ripper-ram-asx-bo(50375)</ref>
      <ref url="http://www.securityfocus.com/bid/34864" source="BID">34864</ref>
      <ref url="http://www.securityfocus.com/bid/34860" source="BID">34860</ref>
      <ref url="http://www.milw0rm.com/exploits/8632" source="MILW0RM">8632</ref>
      <ref url="http://www.milw0rm.com/exploits/8631" source="MILW0RM">8631</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mini-stream" name="ripper">
        <vers num="3.0.1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1642" published="2009-05-15" name="CVE-2009-1642" modified="2009-05-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Multiple stack-based buffer overflows in Mini-stream ASX to MP3 Converter 3.0.0.7 allow remote attackers to execute arbitrary code via (1) a long rtsp URL in a .ram file and (2) a long string in the HREF attribute of a REF element in a .asx file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/50374" source="XF">asxmp3-ram-asxf-bo(50374)</ref>
      <ref url="http://www.securityfocus.com/bid/34864" source="BID">34864</ref>
      <ref url="http://www.securityfocus.com/bid/34860" source="BID">34860</ref>
      <ref url="http://www.milw0rm.com/exploits/8630" source="MILW0RM">8630</ref>
      <ref url="http://www.milw0rm.com/exploits/8629" source="MILW0RM">8629</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mini-stream" name="mini-stream_to_mp3_converter">
        <vers num="3.0.0.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1643" published="2009-05-15" name="CVE-2009-1643" modified="2009-05-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Stack-based buffer overflow in Sorinara Soritong MP3 Player 1.0 allows remote attackers to execute arbitrary code via a crafted .m3u file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/50398" source="XF">soritong-m3u-bo(50398)</ref>
      <ref url="http://www.securityfocus.com/bid/34863" source="BID">34863</ref>
      <ref url="http://www.milw0rm.com/exploits/8624" source="MILW0RM">8624</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sorinara" name="soritong_mp3_player">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1644" published="2009-05-15" name="CVE-2009-1644" modified="2009-05-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Stack-based buffer overflow in Sorinara Streaming Audio Player 0.9 allows remote attackers to execute arbitrary code via a crafted .pla file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/50369" source="XF">sorinara-pla-bo(50369)</ref>
      <ref url="http://www.securityfocus.com/bid/34861" source="BID">34861</ref>
      <ref url="http://www.milw0rm.com/exploits/8640" source="MILW0RM">8640</ref>
      <ref url="http://www.milw0rm.com/exploits/8625" source="MILW0RM">8625</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sorinara" name="streaming_audio_player">
        <vers num="0.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1645" published="2009-05-15" name="CVE-2009-1645" modified="2009-05-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Multiple stack-based buffer overflows in Mini-stream Easy RM-MP3 Converter 3.0.0.7 allow remote attackers to execute arbitrary code via (1) a long rtsp URL in a .ram file and (2) a long string in the HREF attribute of a REF element in a .asx file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/50376" source="XF">easyrmmp3-ram-asx-bo(50376)</ref>
      <ref url="http://www.securityfocus.com/bid/34864" source="BID">34864</ref>
      <ref url="http://www.securityfocus.com/bid/34860" source="BID">34860</ref>
      <ref url="http://www.milw0rm.com/exploits/8634" source="MILW0RM">8634</ref>
      <ref url="http://www.milw0rm.com/exploits/8633" source="MILW0RM">8633</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mini-stream" name="easy_rm-mp3_converter">
        <vers num="3.0.0.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1646" published="2009-05-15" name="CVE-2009-1646" modified="2009-05-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Stack-based buffer overflow in Mini-stream RM Downloader 3.0.0.9 allows remote attackers to execute arbitrary code via a long rtsp URL in a .ram file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/34860" source="BID">34860</ref>
      <ref url="http://www.milw0rm.com/exploits/8628" source="MILW0RM">8628</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mini-stream" name="mini-stream_rm_downloader">
        <vers num="3.0.0.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1647" published="2009-05-15" name="CVE-2009-1647" modified="2009-05-15" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Heap-based buffer overflow in popcorn.exe in Ultrafunk Popcorn 1.87 allows remote POP3 servers to cause a denial of service (application crash) via a long string in a +OK response.  NOTE: some of these details are obtained from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2009/1170" source="VUPEN" adv="1">ADV-2009-1170</ref>
      <ref url="http://www.securityfocus.com/bid/34699" source="BID">34699</ref>
      <ref url="http://www.milw0rm.com/exploits/8526" source="MILW0RM">8526</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ultrafunk" name="popcorn">
        <vers num="1.87" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1648" published="2009-07-05" name="CVE-2009-1648" modified="2009-07-06" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The YaST2 LDAP module in yast2-ldap-server on SUSE Linux Enterprise Server 11 (aka SLE11) does not enable the firewall in certain circumstances involving reboots during online updates, which makes it easier for remote attackers to access network services.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://secunia.com/advisories/35685" source="SECUNIA">35685</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2009-07/msg00002.html" source="SUSE" adv="1">SUSE-SR:2009:012</ref>
    </refs>
    <vuln_soft>
      <prod vendor="suse" name="suse_linux">
        <vers num="11" edition="" />
        <vers num="11" edition=":enterprise_server" />
        <vers num="11" edition=":enterprise_desktop" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1649" published="2009-05-16" name="CVE-2009-1649" modified="2009-05-18" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Directory traversal vulnerability in arch.php in beLive 0.2.3 allows remote attackers to read arbitrary files via a .. (dot dot) in the arch parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/34968" source="BID">34968</ref>
      <ref url="http://www.milw0rm.com/exploits/8680" source="MILW0RM">8680</ref>
      <ref url="http://secunia.com/advisories/35059" source="SECUNIA" adv="1">35059</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bicluc" name="belive">
        <vers num="0.2.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1650" published="2009-05-16" name="CVE-2009-1650" modified="2009-05-18" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in photos.php in Shutter 0.1.1 allow remote attackers to execute arbitrary SQL commands via the (1) albumID, (2) tagID, and (3) photoID parameters to index.html.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/34967" source="BID">34967</ref>
      <ref url="http://www.securityfocus.com/archive/1/503493" source="BUGTRAQ">20090514 MULTIPLE SQL INJECTION VULNERABILITIES --Shutter v-0.1.1--></ref>
      <ref url="http://www.milw0rm.com/exploits/8679" source="MILW0RM">8679</ref>
      <ref url="http://secunia.com/advisories/35049" source="SECUNIA" adv="1">35049</ref>
    </refs>
    <vuln_soft>
      <prod vendor="tenfourzero" name="shutter">
        <vers num="0.1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1651" published="2009-05-16" name="CVE-2009-1651" modified="2009-05-23" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in admin/member_details.php in 2daybiz Business Community Script allows remote attackers to execute arbitrary SQL commands via the mid parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/34976" source="BID">34976</ref>
      <ref url="http://www.milw0rm.com/exploits/8689" source="MILW0RM">8689</ref>
      <ref url="http://secunia.com/advisories/35071" source="SECUNIA" adv="1">35071</ref>
      <ref url="http://osvdb.org/54494" source="OSVDB">54494</ref>
    </refs>
    <vuln_soft>
      <prod vendor="2daybiz" name="business_community_script">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1652" published="2009-05-16" name="CVE-2009-1652" modified="2009-05-23" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">admin/adminaddeditdetails.php in Business Community Script does not properly restrict access, which allows remote attackers to gain privileges and add administrators via a direct request.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/34976" source="BID">34976</ref>
      <ref url="http://www.milw0rm.com/exploits/8689" source="MILW0RM">8689</ref>
      <ref url="http://secunia.com/advisories/35071" source="SECUNIA" adv="1">35071</ref>
      <ref url="http://osvdb.org/54493" source="OSVDB">54493</ref>
    </refs>
    <vuln_soft>
      <prod vendor="2daybiz" name="business_community_script">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1653" published="2009-05-16" name="CVE-2009-1653" modified="2009-05-18" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:N/A:N)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Directory traversal vulnerability in examples/tbs_us_examples_0view.php in TinyButStrong 3.4.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the script parameter.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/50506" source="XF">tinybutstrong-script-file-include(50506)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1304" source="VUPEN" adv="1">ADV-2009-1304</ref>
      <ref url="http://www.milw0rm.com/exploits/8667" source="MILW0RM">8667</ref>
    </refs>
    <vuln_soft>
      <prod vendor="tinybutstrong" name="tinybutstrong">
        <vers num="3.4.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1654" published="2009-05-16" name="CVE-2009-1654" modified="2009-05-23" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in questiondetail.php in Easy Scripts Answer and Question Script allows remote attackers to inject arbitrary web script or HTML via the questionid parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/34975" source="BID">34975</ref>
      <ref url="http://www.milw0rm.com/exploits/8690" source="MILW0RM">8690</ref>
      <ref url="http://secunia.com/advisories/35067" source="SECUNIA" adv="1">35067</ref>
      <ref url="http://osvdb.org/54501" source="OSVDB">54501</ref>
    </refs>
    <vuln_soft>
      <prod vendor="easy-scripts" name="answer_and_question_script">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1655" published="2009-05-16" name="CVE-2009-1655" modified="2009-05-23" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)" CVSS_score="6.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.0" CVSS_base_score="6.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in myaccount.php in Easy Scripts Answer and Question Script allow remote authenticated users to execute arbitrary SQL commands via the (1) user name (userid parameter) and (2) password.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/34975" source="BID">34975</ref>
      <ref url="http://www.milw0rm.com/exploits/8690" source="MILW0RM">8690</ref>
      <ref url="http://secunia.com/advisories/35067" source="SECUNIA" adv="1">35067</ref>
      <ref url="http://osvdb.org/54502" source="OSVDB">54502</ref>
    </refs>
    <vuln_soft>
      <prod vendor="easy-scripts" name="answer_and_question_script">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1656" published="2009-05-16" name="CVE-2009-1656" modified="2009-06-09" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Xerox WorkCentre and WorkCentre Pro 232, 238, 245, 255, 265, 275; and WorkCentre 5632, 5638, 5645, 5655, 5665, 5675, 5687, 7655, 7656, and 7675 allows remote attackers to execute arbitrary commands via unknown attack vectors, aka "command injection vulnerability."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.xerox.com/downloads/usa/en/c/cert_XRX09-02_v1.0.pdf" source="CONFIRM" patch="1" adv="1">http://www.xerox.com/downloads/usa/en/c/cert_XRX09-02_v1.0.pdf</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1328" source="VUPEN" patch="1" adv="1">ADV-2009-1328</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/50558" source="XF">workcentre-unspecified-cmd-execution(50558)</ref>
      <ref url="http://www.securitytracker.com/id?1022238" source="SECTRACK">1022238</ref>
      <ref url="http://www.securityfocus.com/bid/34984" source="BID">34984</ref>
      <ref url="http://secunia.com/advisories/35101" source="SECUNIA" adv="1">35101</ref>
      <ref url="http://osvdb.org/54457" source="OSVDB">54457</ref>
    </refs>
    <vuln_soft>
      <prod vendor="xerox" name="workcentre">
        <vers num="232" edition="" />
        <vers num="232" edition=":pro" />
        <vers num="238" edition="" />
        <vers num="238" edition=":pro" />
        <vers num="245" edition="" />
        <vers num="245" edition=":pro" />
        <vers num="255" edition="" />
        <vers num="255" edition=":pro" />
        <vers num="265" edition="" />
        <vers num="265" edition=":pro" />
        <vers num="275" edition="pro" />
        <vers num="5632" />
        <vers num="5638" />
        <vers num="5645" />
        <vers num="5655" />
        <vers num="5665" />
        <vers num="5675" />
        <vers num="5687" />
        <vers num="7655" />
        <vers num="7665" />
        <vers num="7675" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1657" published="2009-05-18" name="CVE-2009-1657" modified="2009-05-18" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in the Starrating plugin before 0.7.7 for b2evolution allow remote attackers to execute arbitrary SQL commands via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://sourceforge.net/project/shownotes.php?release_id=681352&amp;group_id=160495" source="CONFIRM" patch="1">http://sourceforge.net/project/shownotes.php?release_id=681352&amp;group_id=160495</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/50417" source="XF">starrating-unspecified-sql-injection(50417)</ref>
      <ref url="http://www.securityfocus.com/bid/34899" source="BID">34899</ref>
      <ref url="http://secunia.com/advisories/35053" source="SECUNIA" adv="1">35053</ref>
      <ref url="http://osvdb.org/54369" source="OSVDB">54369</ref>
    </refs>
    <vuln_soft>
      <prod vendor="b2evolution" name="starrating_plugin">
        <vers num="0.6" />
        <vers num="0.7" />
        <vers num="0.7.5" />
        <vers prev="1" num="0.7.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1658" published="2009-05-18" name="CVE-2009-1658" modified="2009-05-18" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in admin/admin.php in Realty Webware Technologies Realty Web-Base 1.0 allow remote attackers to execute arbitrary SQL commands via the (1) user (username) and (2) password parameters.  NOTE: some of these details are obtained from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/50399" source="XF">webbase-admin-sql-injection(50399)</ref>
      <ref url="http://www.securityfocus.com/bid/34886" source="BID">34886</ref>
      <ref url="http://www.milw0rm.com/exploits/8643" source="MILW0RM">8643</ref>
      <ref url="http://secunia.com/advisories/35033" source="SECUNIA" adv="1">35033</ref>
      <ref url="http://osvdb.org/54372" source="OSVDB">54372</ref>
    </refs>
    <vuln_soft>
      <prod vendor="realtywebware" name="realty_web-base">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1659" published="2009-05-18" name="CVE-2009-1659" modified="2009-05-18" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Unrestricted file upload vulnerability in admin/uploadimage.php in eLitius 1.0 allows remote attackers to bypass intended access restrictions and upload and execute arbitrary files via an avatar file with an accepted Content-Type such as image/gif, then requesting the file in admin/banners/.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/50305" source="XF">elitius-uploadimage-file-upload(50305)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1248" source="VUPEN" adv="1">ADV-2009-1248</ref>
      <ref url="http://www.securityfocus.com/bid/34813" source="BID">34813</ref>
      <ref url="http://www.milw0rm.com/exploits/8603" source="MILW0RM">8603</ref>
    </refs>
    <vuln_soft>
      <prod vendor="intelliants" name="elitius">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1660" published="2009-05-18" name="CVE-2009-1660" modified="2009-05-18" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Stack-based buffer overflow in URUWorks ViPlay3 3.0 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long file entry in a .vpl file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/50403" source="XF">viplay3-vpl-bo(50403)</ref>
      <ref url="http://www.securityfocus.com/bid/34877" source="BID">34877</ref>
      <ref url="http://www.milw0rm.com/exploits/8644" source="MILW0RM">8644</ref>
    </refs>
    <vuln_soft>
      <prod vendor="urusoft" name="viplay3">
        <vers num="3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1661" published="2009-05-18" name="CVE-2009-1661" modified="2009-05-19" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">SQL injection vulnerability in admin/utopic.php in uTopic 1.0, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the rating parameter to index.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2009/1288" source="VUPEN" patch="1" adv="1">ADV-2009-1288</ref>
      <ref url="http://www.securityfocus.com/bid/34907" source="BID" patch="1">34907</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/50428" source="XF">microtopic-rating-sql-injection(50428)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/503422/100/0/threaded" source="BUGTRAQ">20090511 (POST var 'rating') BLIND SQL INJECTION--microTopic v1 Initial Release--></ref>
      <ref url="http://www.milw0rm.com/exploits/8655" source="MILW0RM">8655</ref>
      <ref url="http://sourceforge.net/project/shownotes.php?group_id=261386&amp;release_id=680474" source="CONFIRM">http://sourceforge.net/project/shownotes.php?group_id=261386&amp;release_id=680474</ref>
      <ref url="http://secunia.com/advisories/35051" source="SECUNIA" adv="1">35051</ref>
    </refs>
    <vuln_soft>
      <prod vendor="anoldman" name="utopic">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1662" published="2009-05-18" name="CVE-2009-1662" modified="2009-05-18" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in admin/login.php in Wright Way Services Recipe Script 5 allow remote attackers to execute arbitrary SQL commands via the (1) username and (2) Password fields, as reachable from admin/index.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/50407" source="XF">recipescript-login-sql-injection(50407)</ref>
      <ref url="http://www.securityfocus.com/bid/34885" source="BID">34885</ref>
      <ref url="http://www.milw0rm.com/exploits/8642" source="MILW0RM">8642</ref>
    </refs>
    <vuln_soft>
      <prod vendor="recipescript" name="recipe_script">
        <vers num="5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1663" published="2009-05-18" name="CVE-2009-1663" modified="2009-05-18" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Unrestricted file upload vulnerability in myaccount.php in Easy Scripts Answer and Question Script allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in the uploads/[username] directory.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.milw0rm.com/exploits/8690" source="MILW0RM">8690</ref>
    </refs>
    <vuln_soft>
      <prod vendor="easy-scripts" name="answer_and_question_script">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1664" published="2009-05-18" name="CVE-2009-1664" modified="2009-05-18" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">myaccount.php in Easy Scripts Answer and Question Script does not verify the original password before changing passwords, which allows remote attackers to change the password of other users and gain privileges via modified userid, txtpassword, and txtRpassword parameters.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.milw0rm.com/exploits/8690" source="MILW0RM">8690</ref>
    </refs>
    <vuln_soft>
      <prod vendor="easy-scripts" name="answer_and_question_script">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1665" published="2009-05-18" name="CVE-2009-1665" modified="2009-05-23" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:P)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">myaccount.php in Easy Scripts Answer and Question Script allows remote attackers to remove arbitrary user accounts via a modified userid parameter without specifying any additional fields.</descript>
    </desc>
    <loss_types>
      <avail />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/50627" source="XF">answerquestion-userid-security-bypass(50627)</ref>
      <ref url="http://www.milw0rm.com/exploits/8690" source="MILW0RM">8690</ref>
      <ref url="http://osvdb.org/54586" source="OSVDB">54586</ref>
    </refs>
    <vuln_soft>
      <prod vendor="easy-scripts" name="answer_and_question_script">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1666" published="2009-05-18" name="CVE-2009-1666" modified="2009-05-19" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Multiple unspecified vulnerabilities in CycloMedia CycloScopeLite 2.50.3.0 allow remote attackers to execute arbitrary code via the ReturnConnection method in (1) CM_ADOConnection.dll, (2) CM_AddressInfoDBC.dll, and (3) CM_RecordingLocationDBC.dll, related to improper dereferencing.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/34912" source="BID">34912</ref>
      <ref url="http://secunia.com/advisories/35046" source="SECUNIA" adv="1">35046</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cyclomedia" name="cycloscopelite">
        <vers num="2.50.3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1667" published="2009-05-18" name="CVE-2009-1667" modified="2009-05-19" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Stack-based buffer overflow in Mini-stream CastRipper 2.50.70 allows remote attackers to execute arbitrary code via a crafted .m3u file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.milw0rm.com/exploits/8662" source="MILW0RM">8662</ref>
      <ref url="http://www.milw0rm.com/exploits/8661" source="MILW0RM">8661</ref>
      <ref url="http://www.milw0rm.com/exploits/8660" source="MILW0RM">8660</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mini-stream" name="castripper">
        <vers num="2.50.70" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1668" published="2009-05-18" name="CVE-2009-1668" modified="2009-06-10" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:N/I:N/A:P)" CVSS_score="4.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.0" CVSS_base_score="4.0">
    <desc>
      <descript source="cve">TYPSoft FTP Server 1.11 allows remote attackers to cause a denial of service (CPU consumption) by sending an ABOR (abort) command without an active file transfer.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securitytracker.com/id?1022202" source="SECTRACK">1022202</ref>
      <ref url="http://www.securityfocus.com/bid/34901" source="BID">34901</ref>
      <ref url="http://www.milw0rm.com/exploits/8650" source="MILW0RM">8650</ref>
    </refs>
    <vuln_soft>
      <prod vendor="typsoft" name="typsoft_ftp_server">
        <vers num="1.11" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1669" published="2009-05-18" name="CVE-2009-1669" modified="2009-07-01" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">The smarty_function_math function in libs/plugins/function.math.php in Smarty 2.6.22 allows context-dependent attackers to execute arbitrary commands via shell metacharacters in the equation attribute of the math function.  NOTE: some of these details are obtained from third party information.</descript>
    </desc>
    <impacts>
      <impact source="nvd">Per http://secunia.com/advisories/35072
"The vulnerability is confirmed in version 2.6.22 on Windows. Other versions may also be affected."</impact>
    </impacts>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-May/msg01287.html" source="FEDORA">FEDORA-2009-5520</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-May/msg01283.html" source="FEDORA">FEDORA-2009-5516</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-May/msg01274.html" source="FEDORA">FEDORA-2009-5525</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/50457" source="XF">smarty-smartyfunctionmath-cmd-execution(50457)</ref>
      <ref url="http://www.ubuntu.com/usn/usn-791-3" source="UBUNTU">USN-791-3</ref>
      <ref url="http://www.securityfocus.com/bid/34918" source="BID">34918</ref>
      <ref url="http://www.milw0rm.com/exploits/8659" source="MILW0RM">8659</ref>
      <ref url="http://secunia.com/advisories/35219" source="SECUNIA">35219</ref>
      <ref url="http://secunia.com/advisories/35072" source="SECUNIA" adv="1">35072</ref>
      <ref url="http://osvdb.org/54380" source="OSVDB">54380</ref>
    </refs>
    <vuln_soft>
      <prod vendor="smarty" name="smarty">
        <vers num="2.6.22" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1670" published="2009-05-18" name="CVE-2009-1670" modified="2009-06-09" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">user/index.php in TCPDB 3.8 does not require administrative authentication, which allows remote attackers to add admin accounts via unspecified vectors.  NOTE: some of these details are obtained from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/50371" source="XF">tcpdb-userpage-security-bypass(50371)</ref>
      <ref url="http://www.securityfocus.com/bid/34866" source="BID">34866</ref>
      <ref url="http://www.milw0rm.com/exploits/8626" source="MILW0RM">8626</ref>
      <ref url="http://secunia.com/advisories/34966" source="SECUNIA" adv="1">34966</ref>
      <ref url="http://osvdb.org/54282" source="OSVDB">54282</ref>
    </refs>
    <vuln_soft>
      <prod vendor="tcpdb" name="tcpdb">
        <vers num="3.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1671" published="2009-05-18" name="CVE-2009-1671" modified="2009-05-19" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Multiple buffer overflows in the Deployment Toolkit ActiveX control in deploytk.dll 6.0.130.3 in Sun Java SE Runtime Environment (aka JRE) 6 Update 13 allow remote attackers to execute arbitrary code via a long string argument to the (1) setInstallerType, (2) setAdditionalPackages, (3) compareVersion, (4) getStaticCLSID, or (5) launch method.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.shinnai.net/xplits/TXT_mhxRKrtrPLyAHRFNm7QR.html" source="MISC">http://www.shinnai.net/xplits/TXT_mhxRKrtrPLyAHRFNm7QR.html</ref>
      <ref url="http://www.securityfocus.com/bid/34931" source="BID">34931</ref>
      <ref url="http://www.milw0rm.com/exploits/8665" source="MILW0RM">8665</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="jre">
        <vers num="6" edition="update_13" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1672" published="2009-05-18" name="CVE-2009-1672" modified="2009-05-23" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">The Deployment Toolkit ActiveX control in deploytk.dll 6.0.130.3 in Sun Java SE Runtime Environment (aka JRE) 6 Update 13 allows remote attackers to (1) execute arbitrary code via a .jnlp URL in the argument to the launch method, and might allow remote attackers to launch JRE installation processes via the (2) installLatestJRE or (3) installJRE method.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/50629" source="XF">sun-jre-activex-code-execution(50629)</ref>
      <ref url="http://www.shinnai.net/xplits/TXT_mhxRKrtrPLyAHRFNm7QR.html" source="MISC">http://www.shinnai.net/xplits/TXT_mhxRKrtrPLyAHRFNm7QR.html</ref>
      <ref url="http://www.securityfocus.com/bid/34931" source="BID">34931</ref>
      <ref url="http://www.milw0rm.com/exploits/8665" source="MILW0RM">8665</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="jre">
        <vers num="6" edition="update_13" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1673" published="2009-05-18" name="CVE-2009-1673" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="4.9" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="3.9" CVSS_base_score="4.9">
    <desc>
      <descript source="cve">The kernel in Sun Solaris 9 allows local users to cause a denial of service (panic) by calling fstat with a first argument of AT_FDCWD.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2009/1315" source="VUPEN" patch="1" adv="1">ADV-2009-1315</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-257988-1" source="SUNALERT" patch="1" adv="1">257988</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-21-122300-40-1" source="CONFIRM" patch="1">http://sunsolve.sun.com/search/document.do?assetkey=1-21-122300-40-1</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/50557" source="XF">solaris-fstat-dos(50557)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1388" source="VUPEN">ADV-2009-1388</ref>
      <ref url="http://www.securitytracker.com/id?1022232" source="SECTRACK">1022232</ref>
      <ref url="http://www.securityfocus.com/bid/34979" source="BID">34979</ref>
      <ref url="http://support.avaya.com/elmodocs2/security/ASA-2009-188.htm" source="CONFIRM">http://support.avaya.com/elmodocs2/security/ASA-2009-188.htm</ref>
      <ref url="http://secunia.com/advisories/35119" source="SECUNIA">35119</ref>
      <ref url="http://secunia.com/advisories/35103" source="SECUNIA">35103</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6256" source="OVAL">oval:org.mitre.oval:def:6256</ref>
      <ref url="http://osvdb.org/54464" source="OSVDB">54464</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="solaris">
        <vers num="9" edition="" />
        <vers num="9" edition=":sparc" />
        <vers num="9" edition=":x86" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1674" published="2009-05-18" name="CVE-2009-1674" modified="2009-05-19" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Stack-based buffer overflow in Microchip MPLAB IDE 8.30 allows user-assisted remote attackers to execute arbitrary code via a long .cof pathname in a [TOOL_SETTINGS] section in a .mcp file, possibly a related issue to CVE-2009-1608.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.milw0rm.com/exploits/8656" source="MILW0RM">8656</ref>
      <ref url="http://secunia.com/advisories/35054" source="SECUNIA" adv="1">35054</ref>
    </refs>
    <vuln_soft>
      <prod vendor="microchip" name="mplab_ide">
        <vers num="8.30" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1675" published="2009-05-18" name="CVE-2009-1675" modified="2009-05-23" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Stack-based buffer overflow in ElectraSoft 32bit FTP 09.04.24 allows remote FTP servers to execute arbitrary code via a long 227 reply to a PASV command.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/50644" source="XF">32bit-pasv-bo(50644)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/50337" source="XF">32bit-cwd-banner-bo(50337)</ref>
      <ref url="http://www.securityfocus.com/bid/34838" source="BID">34838</ref>
      <ref url="http://www.milw0rm.com/exploits/8623" source="MILW0RM">8623</ref>
    </refs>
    <vuln_soft>
      <prod vendor="electrasoft" name="32bit_ftp">
        <vers num="09.04.24" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" seq="2009-1676" reject="1" published="2009-05-18" name="CVE-2009-1676" modified="2009-06-12">
    <desc>
      <descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-2009-1535.  Reason: This candidate is a duplicate of CVE-2009-1535.  Notes: All CVE users should reference CVE-2009-1535 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript>
    </desc>
    <impacts>
      <impact source="nvd">Per http://www.microsoft.com/technet/security/advisory/971492.mspx

Affected Software

Microsoft Internet Information Services 5.0

Microsoft Internet Information Services 5.1

Microsoft Internet Information Services 6.0</impact>
    </impacts>
    <refs />
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1677" published="2009-05-18" name="CVE-2009-1677" modified="2009-06-09" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:S/C:P/I:P/A:P)" CVSS_score="6.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.0" CVSS_base_score="6.5">
    <desc>
      <descript source="cve">Multiple static code injection vulnerabilities in the saveFeed function in rss/feedcreator.class.php in Bitweaver 2.6 and earlier allow (1) remote authenticated users to inject arbitrary PHP code into files by placing PHP sequences into the account's "display name" setting and then invoking boards/boards_rss.php, and might allow (2) remote attackers to inject arbitrary PHP code into files via the HTTP Host header in a request to boards/boards_rss.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/50631" source="XF">bitweaver-savefeed-code-execution(50631)</ref>
      <ref url="http://www.securityfocus.com/bid/34910" source="BID">34910</ref>
      <ref url="http://www.securityfocus.com/archive/1/503435" source="BUGTRAQ">20090512 Bitweaver &lt;= 2.6 /boards/boards_rss.php / saveFeed() remote code execution exploit</ref>
      <ref url="http://www.milw0rm.com/exploits/8659" source="MILW0RM">8659</ref>
      <ref url="http://secunia.com/advisories/35057" source="SECUNIA" adv="1">35057</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bitweaver" name="bitweaver">
        <vers num="1.1" />
        <vers num="1.1.1_beta" />
        <vers num="1.2.1" />
        <vers num="1.3" />
        <vers num="1.3.1" />
        <vers num="2.0.0" />
        <vers num="2.0.2" />
        <vers num="2.5" />
        <vers prev="1" num="2.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1678" published="2009-05-18" name="CVE-2009-1678" modified="2009-06-09" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Directory traversal vulnerability in the saveFeed function in rss/feedcreator.class.php in Bitweaver 2.6 and earlier allows remote attackers to create or overwrite arbitrary files via a .. (dot dot) in the version parameter to boards/boards_rss.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/34910" source="BID">34910</ref>
      <ref url="http://www.securityfocus.com/archive/1/503435" source="BUGTRAQ">20090512 Bitweaver &lt;= 2.6 /boards/boards_rss.php / saveFeed() remote code execution exploit</ref>
      <ref url="http://www.milw0rm.com/exploits/8659" source="MILW0RM">8659</ref>
      <ref url="http://secunia.com/advisories/35057" source="SECUNIA" adv="1">35057</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bitweaver" name="bitweaver">
        <vers num="1.1" />
        <vers num="1.1.1_beta" />
        <vers num="1.2.1" />
        <vers num="1.3" />
        <vers num="1.3.1" />
        <vers num="2.0.0" />
        <vers num="2.0.2" />
        <vers num="2.5" />
        <vers prev="1" num="2.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1679" published="2009-06-19" name="CVE-2009-1679" modified="2009-06-24" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="6.9" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.4" CVSS_base_score="6.9">
    <desc>
      <descript source="cve">The Profiles component in Apple iPhone OS 1.0 through 2.2.1 and iPhone OS for iPod touch 1.1 through 2.2.1, when installing a configuration profile, can replace the password policy from Exchange ActiveSync with a weaker password policy, which allows physically proximate attackers to bypass the intended policy.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://support.apple.com/kb/HT3639" source="CONFIRM" patch="1" adv="1">http://support.apple.com/kb/HT3639</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/51212" source="XF">ipod-iphone-profile-security-bypass(51212)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1621" source="VUPEN">ADV-2009-1621</ref>
      <ref url="http://www.securityfocus.com/bid/35436" source="BID">35436</ref>
      <ref url="http://www.securityfocus.com/bid/35414" source="BID">35414</ref>
      <ref url="http://osvdb.org/55239" source="OSVDB">55239</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2009/Jun/msg00005.html" source="APPLE" adv="1">APPLE-SA-2009-06-17-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="iphone_os">
        <vers num="1.0.0" edition="-" />
        <vers num="1.0.0" edition="-:iphone" />
        <vers num="1.0.1" edition="-" />
        <vers num="1.0.1" edition="-:iphone" />
        <vers num="1.0.2" edition="-" />
        <vers num="1.0.2" edition="-:iphone" />
        <vers num="1.1.0" edition="-" />
        <vers num="1.1.0" edition="-:ipodtouch" />
        <vers num="1.1.0" edition="-:iphone" />
        <vers num="1.1.1" edition="-" />
        <vers num="1.1.1" edition="-:ipodtouch" />
        <vers num="1.1.1" edition="-:iphone" />
        <vers num="1.1.2" edition="-" />
        <vers num="1.1.2" edition="-:ipodtouch" />
        <vers num="1.1.2" edition="-:iphone" />
        <vers num="1.1.3" edition="-" />
        <vers num="1.1.3" edition="-:iphone" />
        <vers num="1.1.3" edition="-:ipodtouch" />
        <vers num="1.1.4" edition="-" />
        <vers num="1.1.4" edition="-:ipodtouch" />
        <vers num="1.1.4" edition="-:iphone" />
        <vers num="1.1.5" edition="-" />
        <vers num="1.1.5" edition="-:iphone" />
        <vers num="1.1.5" edition="-:ipodtouch" />
        <vers num="2.0.0" edition="-" />
        <vers num="2.0.0" edition="-:ipodtouch" />
        <vers num="2.0.0" edition="-:iphone" />
        <vers num="2.0.1" edition="-" />
        <vers num="2.0.1" edition="-:ipodtouch" />
        <vers num="2.0.1" edition="-:iphone" />
        <vers num="2.0.2" edition="-" />
        <vers num="2.0.2" edition="-:iphone" />
        <vers num="2.1" edition="-" />
        <vers num="2.1" edition="-:ipodtouch" />
        <vers num="2.1" edition="-:iphone" />
        <vers num="2.2" edition="-" />
        <vers num="2.2" edition="-:ipodtouch" />
        <vers num="2.2" edition="-:iphone" />
        <vers num="2.2.1" edition="-" />
        <vers num="2.2.1" edition="-:iphone" />
        <vers num="2.2.1" edition="-:ipodtouch" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2009-1680" published="2009-06-19" name="CVE-2009-1680" modified="2009-06-24" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">Safari in Apple iPhone OS 1.0 through 2.2.1 and iPhone OS for iPod touch 1.1 through 2.2.1 does not properly clear the search history when it is cleared from the Settings application, which allows physically proximate attackers to obtain the search history.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://support.apple.com/kb/HT3639" source="CONFIRM" patch="1" adv="1">http://support.apple.com/kb/HT3639</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1621" source="VUPEN">ADV-2009-1621</ref>
      <ref url="http://www.securityfocus.com/bid/35448" source="BID">35448</ref>
      <ref url="http://www.securityfocus.com/bid/35414" source="BID">35414</ref>
      <ref url="http://osvdb.org/55240" source="OSVDB">55240</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2009/Jun/msg00005.html" source="APPLE" adv="1">APPLE-SA-2009-06-17-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="iphone_os">
        <vers num="1.0.0" edition="-" />
        <vers num="1.0.0" edition="-:iphone" />
        <vers num="1.0.1" edition="-" />
        <vers num="1.0.1" edition="-:iphone" />
        <vers num="1.0.2" edition="-" />
        <vers num="1.0.2" edition="-:iphone" />
        <vers num="1.1.0" edition="-" />
        <vers num="1.1.0" edition="-:ipodtouch" />
        <vers num="1.1.0" edition="-:iphone" />
        <vers num="1.1.1" edition="-" />
        <vers num="1.1.1" edition="-:ipodtouch" />
        <vers num="1.1.1" edition="-:iphone" />
        <vers num="1.1.2" edition="-" />
        <vers num="1.1.2" edition="-:ipodtouch" />
        <vers num="1.1.2" edition="-:iphone" />
        <vers num="1.1.3" edition="-" />
        <vers num="1.1.3" edition="-:iphone" />
        <vers num="1.1.3" edition="-:ipodtouch" />
        <vers num="1.1.4" edition="-" />
        <vers num="1.1.4" edition="-:ipodtouch" />
        <vers num="1.1.4" edition="-:iphone" />
        <vers num="1.1.5" edition="-" />
        <vers num="1.1.5" edition="-:iphone" />
        <vers num="1.1.5" edition="-:ipodtouch" />
        <vers num="2.0.0" edition="-" />
        <vers num="2.0.0" edition="-:ipodtouch" />
        <vers num="2.0.0" edition="-:iphone" />
        <vers num="2.0.1" edition="-" />
        <vers num="2.0.1" edition="-:ipodtouch" />
        <vers num="2.0.1" edition="-:iphone" />
        <vers num="2.0.2" edition="-" />
        <vers num="2.0.2" edition="-:iphone" />
        <vers num="2.1" edition="-" />
        <vers num="2.1" edition="-:ipodtouch" />
        <vers num="2.1" edition="-:iphone" />
        <vers num="2.2" edition="-" />
        <vers num="2.2" edition="-:ipodtouch" />
        <vers num="2.2" edition="-:iphone" />
        <vers num="2.2.1" edition="-" />
        <vers num="2.2.1" edition="-:iphone" />
        <vers num="2.2.1" edition="-:ipodtouch" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1681" published="2009-06-10" name="CVE-2009-1681" modified="2011-02-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">WebKit in Apple Safari before 4.0, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch 1.1 through 2.2.1 does not prevent web sites from loading third-party content into a subframe, which allows remote attackers to bypass the Same Origin Policy and conduct "clickjacking" attacks via a crafted HTML document.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2009/1522" source="VUPEN" patch="1" adv="1">ADV-2009-1522</ref>
      <ref url="http://support.apple.com/kb/HT3613" source="CONFIRM" patch="1" adv="1">http://support.apple.com/kb/HT3613</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2009/jun/msg00002.html" source="APPLE" patch="1" adv="1">APPLE-SA-2009-06-08-1</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0212" source="VUPEN">ADV-2011-0212</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1621" source="VUPEN">ADV-2009-1621</ref>
      <ref url="http://www.securityfocus.com/bid/35317" source="BID">35317</ref>
      <ref url="http://www.securityfocus.com/bid/35260" source="BID">35260</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1950" source="DEBIAN">DSA-1950</ref>
      <ref url="http://support.apple.com/kb/HT3639" source="CONFIRM">http://support.apple.com/kb/HT3639</ref>
      <ref url="http://secunia.com/advisories/43068" source="SECUNIA">43068</ref>
      <ref url="http://secunia.com/advisories/37746" source="SECUNIA">37746</ref>
      <ref url="http://secunia.com/advisories/35379" source="SECUNIA" adv="1">35379</ref>
      <ref url="http://osvdb.org/54981" source="OSVDB">54981</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.html" source="SUSE">SUSE-SR:2011:002</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2009/Jun/msg00005.html" source="APPLE">APPLE-SA-2009-06-17-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="safari">
        <vers num="0.8" edition="" />
        <vers num="0.8" edition=":mac" />
        <vers num="0.9" edition="" />
        <vers num="0.9" edition=":mac" />
        <vers num="1.0" edition="" />
        <vers num="1.0" edition=":mac" />
        <vers num="1.0.3" edition="" />
        <vers num="1.0.3" edition=":mac" />
        <vers num="1.1" edition="" />
        <vers num="1.1" edition=":mac" />
        <vers num="1.2" edition="" />
        <vers num="1.2" edition=":mac" />
        <vers num="1.3" edition="" />
        <vers num="1.3" edition=":mac" />
        <vers num="1.3.1" edition="" />
        <vers num="1.3.1" edition=":mac" />
        <vers num="1.3.2" edition="" />
        <vers num="1.3.2" edition=":mac" />
        <vers num="2.0" edition="" />
        <vers num="2.0" edition=":mac" />
        <vers num="2.0.2" edition="" />
        <vers num="2.0.2" edition=":mac" />
        <vers num="2.0.4" edition="" />
        <vers num="2.0.4" edition=":mac" />
        <vers num="3.0" edition="" />
        <vers num="3.0" edition=":windows" />
        <vers num="3.0" edition=":mac" />
        <vers num="3.0.1" edition="" />
        <vers num="3.0.1" edition=":windows" />
        <vers num="3.0.2" edition="" />
        <vers num="3.0.2" edition=":windows" />
        <vers num="3.0.2" edition="-" />
        <vers num="3.0.2" edition="-:mac" />
        <vers num="3.0.3" edition="" />
        <vers num="3.0.3" edition=":windows" />
        <vers num="3.0.3" edition=":mac" />
        <vers num="3.0.4" edition="" />
        <vers num="3.0.4" edition=":windows" />
        <vers num="3.0.4" edition=":mac" />
        <vers num="3.1" edition="" />
        <vers num="3.1" edition=":windows" />
        <vers num="3.1" edition=":mac" />
        <vers num="3.1.1" edition="" />
        <vers num="3.1.1" edition=":windows" />
        <vers num="3.1.1" edition=":mac" />
        <vers num="3.1.2" edition="" />
        <vers num="3.1.2" edition=":mac" />
        <vers num="3.1.2" edition=":windows" />
        <vers num="3.2" edition="-" />
        <vers num="3.2" edition="-:windows" />
        <vers num="3.2.1" edition="" />
        <vers num="3.2.1" edition=":mac" />
        <vers num="3.2.1" edition=":windows" />
        <vers num="3.2.2" edition="" />
        <vers num="3.2.2" edition=":windows" />
        <vers prev="1" num="3.2.3" edition="" />
        <vers prev="1" num="3.2.3" edition=":windows" />
        <vers prev="1" num="3.2.3" edition=":mac" />
        <vers prev="1" num="4.0_beta" edition="" />
        <vers prev="1" num="4.0_beta" edition=":mac" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1682" published="2009-06-10" name="CVE-2009-1682" modified="2009-06-19" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Apple Safari before 4.0 does not properly check for revoked Extended Validation (EV) certificates, which makes it easier for remote attackers to trick a user into accepting an invalid certificate.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2009/1522" source="VUPEN" patch="1" adv="1">ADV-2009-1522</ref>
      <ref url="http://www.securityfocus.com/bid/35260" source="BID" patch="1">35260</ref>
      <ref url="http://support.apple.com/kb/HT3613" source="CONFIRM" patch="1" adv="1">http://support.apple.com/kb/HT3613</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2009/jun/msg00002.html" source="APPLE" patch="1" adv="1">APPLE-SA-2009-06-08-1</ref>
      <ref url="http://www.securitytracker.com/id?1022346" source="SECTRACK">1022346</ref>
      <ref url="http://www.securityfocus.com/bid/35353" source="BID">35353</ref>
      <ref url="http://secunia.com/advisories/35379" source="SECUNIA" adv="1">35379</ref>
      <ref url="http://osvdb.org/54982" source="OSVDB">54982</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="safari">
        <vers num="0.8" edition="-" />
        <vers num="0.8" edition="-:mac" />
        <vers num="0.9" edition="-" />
        <vers num="0.9" edition="-:mac" />
        <vers num="1.0" edition="-" />
        <vers num="1.0" edition="-:mac" />
        <vers num="1.0.3" edition="-" />
        <vers num="1.0.3" edition="-:mac" />
        <vers num="1.1" edition="-" />
        <vers num="1.1" edition="-:mac" />
        <vers num="1.2" edition="-" />
        <vers num="1.2" edition="-:mac" />
        <vers num="1.3" edition="-" />
        <vers num="1.3" edition="-:mac" />
        <vers num="1.3.1" edition="-" />
        <vers num="1.3.1" edition="-:mac" />
        <vers num="1.3.2" edition="-" />
        <vers num="1.3.2" edition="-:mac" />
        <vers num="2.0" edition="-" />
        <vers num="2.0" edition="-:mac" />
        <vers num="2.0.2" edition="-" />
        <vers num="2.0.2" edition="-:mac" />
        <vers num="2.0.4" edition="-" />
        <vers num="2.0.4" edition="-:mac" />
        <vers num="3.0" edition="-" />
        <vers num="3.0" edition="-:windows" />
        <vers num="3.0" edition="-:mac" />
        <vers num="3.0.1" edition="-" />
        <vers num="3.0.1" edition="-:windows" />
        <vers num="3.0.2" edition="-" />
        <vers num="3.0.2" edition="-:mac" />
        <vers num="3.0.2" edition="-:windows" />
        <vers num="3.0.3" edition="-" />
        <vers num="3.0.3" edition="-:windows" />
        <vers num="3.0.3" edition="-:mac" />
        <vers num="3.0.4" edition="-" />
        <vers num="3.0.4" edition="-:mac" />
        <vers num="3.0.4" edition="-:windows" />
        <vers num="3.1" edition="-" />
        <vers num="3.1" edition="-:mac" />
        <vers num="3.1" edition="-:windows" />
        <vers num="3.1.1" edition="-" />
        <vers num="3.1.1" edition="-:windows" />
        <vers num="3.1.1" edition="-:mac" />
        <vers num="3.1.2" edition="-" />
        <vers num="3.1.2" edition="-:mac" />
        <vers num="3.1.2" edition="-:windows" />
        <vers num="3.2" edition="-" />
        <vers num="3.2" edition="-:windows" />
        <vers num="3.2.1" edition="-" />
        <vers num="3.2.1" edition="-:mac" />
        <vers num="3.2.1" edition="-:windows" />
        <vers num="3.2.2" edition="-" />
        <vers num="3.2.2" edition="-:windows" />
        <vers prev="1" num="3.2.3" edition="-" />
        <vers prev="1" num="3.2.3" edition="-:windows" />
        <vers prev="1" num="3.2.3" edition="-:mac" />
        <vers prev="1" num="4.0_beta" edition="-" />
        <vers prev="1" num="4.0_beta" edition="-:mac" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1683" published="2009-06-19" name="CVE-2009-1683" modified="2009-06-23" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">The Telephony component in Apple iPhone OS 1.0 through 2.2.1 and iPhone OS for iPod touch 1.1 through 2.2.1 allows remote attackers to cause a denial of service (device reset) via a crafted ICMP echo request, which triggers an assertion error related to a "logic issue."</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://support.apple.com/kb/HT3639" source="CONFIRM" patch="1" adv="1">http://support.apple.com/kb/HT3639</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1621" source="VUPEN">ADV-2009-1621</ref>
      <ref url="http://www.securityfocus.com/bid/35414" source="BID">35414</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2009/Jun/msg00005.html" source="APPLE" adv="1">APPLE-SA-2009-06-17-1</ref>
      <ref url="http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-000040.html" source="JVNDB">JVNDB-2009-000040</ref>
      <ref url="http://jvn.jp/en/jp/JVN87239696/index.html" source="JVN">JVN#87239696</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="iphone_os">
        <vers num="1.0.0" edition="-" />
        <vers num="1.0.0" edition="-:iphone" />
        <vers num="1.0.1" edition="-" />
        <vers num="1.0.1" edition="-:iphone" />
        <vers num="1.0.2" edition="-" />
        <vers num="1.0.2" edition="-:iphone" />
        <vers num="1.1.0" edition="-" />
        <vers num="1.1.0" edition="-:ipodtouch" />
        <vers num="1.1.0" edition="-:iphone" />
        <vers num="1.1.1" edition="-" />
        <vers num="1.1.1" edition="-:ipodtouch" />
        <vers num="1.1.1" edition="-:iphone" />
        <vers num="1.1.2" edition="-" />
        <vers num="1.1.2" edition="-:ipodtouch" />
        <vers num="1.1.2" edition="-:iphone" />
        <vers num="1.1.3" edition="-" />
        <vers num="1.1.3" edition="-:iphone" />
        <vers num="1.1.3" edition="-:ipodtouch" />
        <vers num="1.1.4" edition="-" />
        <vers num="1.1.4" edition="-:ipodtouch" />
        <vers num="1.1.4" edition="-:iphone" />
        <vers num="1.1.5" edition="-" />
        <vers num="1.1.5" edition="-:iphone" />
        <vers num="1.1.5" edition="-:ipodtouch" />
        <vers num="2.0.0" edition="-" />
        <vers num="2.0.0" edition="-:ipodtouch" />
        <vers num="2.0.0" edition="-:iphone" />
        <vers num="2.0.1" edition="-" />
        <vers num="2.0.1" edition="-:ipodtouch" />
        <vers num="2.0.1" edition="-:iphone" />
        <vers num="2.0.2" edition="-" />
        <vers num="2.0.2" edition="-:iphone" />
        <vers num="2.1" edition="-" />
        <vers num="2.1" edition="-:ipodtouch" />
        <vers num="2.1" edition="-:iphone" />
        <vers num="2.2" edition="-" />
        <vers num="2.2" edition="-:ipodtouch" />
        <vers num="2.2" edition="-:iphone" />
        <vers num="2.2.1" edition="-" />
        <vers num="2.2.1" edition="-:iphone" />
        <vers num="2.2.1" edition="-:ipodtouch" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1684" published="2009-06-10" name="CVE-2009-1684" modified="2011-02-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in WebKit in Apple Safari before 4.0, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch 1.1 through 2.2.1 allows remote attackers to inject arbitrary web script or HTML via an event handler that triggers script execution in the context of the next loaded document.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2009/1522" source="VUPEN" patch="1" adv="1">ADV-2009-1522</ref>
      <ref url="http://support.apple.com/kb/HT3613" source="CONFIRM" patch="1" adv="1">http://support.apple.com/kb/HT3613</ref>
      <ref url="http://securitytracker.com/id?1022344" source="SECTRACK" patch="1">1022344</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2009/jun/msg00002.html" source="APPLE" patch="1" adv="1">APPLE-SA-2009-06-08-1</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0212" source="VUPEN">ADV-2011-0212</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1621" source="VUPEN">ADV-2009-1621</ref>
      <ref url="http://www.securityfocus.com/bid/35260" source="BID">35260</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1950" source="DEBIAN">DSA-1950</ref>
      <ref url="http://support.apple.com/kb/HT3639" source="CONFIRM">http://support.apple.com/kb/HT3639</ref>
      <ref url="http://secunia.com/advisories/43068" source="SECUNIA">43068</ref>
      <ref url="http://secunia.com/advisories/37746" source="SECUNIA">37746</ref>
      <ref url="http://secunia.com/advisories/35379" source="SECUNIA" adv="1">35379</ref>
      <ref url="http://osvdb.org/54987" source="OSVDB">54987</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.html" source="SUSE">SUSE-SR:2011:002</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2009/Jun/msg00005.html" source="APPLE">APPLE-SA-2009-06-17-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="safari">
        <vers num="0.8" edition="" />
        <vers num="0.8" edition=":mac" />
        <vers num="0.9" edition="" />
        <vers num="0.9" edition=":mac" />
        <vers num="1.0" edition="" />
        <vers num="1.0" edition=":mac" />
        <vers num="1.0.3" edition="" />
        <vers num="1.0.3" edition=":mac" />
        <vers num="1.1" edition="" />
        <vers num="1.1" edition=":mac" />
        <vers num="1.2" edition="" />
        <vers num="1.2" edition=":mac" />
        <vers num="1.3" edition="" />
        <vers num="1.3" edition=":mac" />
        <vers num="1.3.1" edition="" />
        <vers num="1.3.1" edition=":mac" />
        <vers num="1.3.2" edition="" />
        <vers num="1.3.2" edition=":mac" />
        <vers num="2.0" edition="" />
        <vers num="2.0" edition=":mac" />
        <vers num="2.0.2" edition="" />
        <vers num="2.0.2" edition=":mac" />
        <vers num="2.0.4" edition="" />
        <vers num="2.0.4" edition=":mac" />
        <vers num="3.0" edition="" />
        <vers num="3.0" edition=":windows" />
        <vers num="3.0" edition=":mac" />
        <vers num="3.0.1" edition="" />
        <vers num="3.0.1" edition=":windows" />
        <vers num="3.0.2" edition="" />
        <vers num="3.0.2" edition=":windows" />
        <vers num="3.0.2" edition="-" />
        <vers num="3.0.2" edition="-:mac" />
        <vers num="3.0.3" edition="" />
        <vers num="3.0.3" edition=":windows" />
        <vers num="3.0.3" edition=":mac" />
        <vers num="3.0.4" edition="" />
        <vers num="3.0.4" edition=":windows" />
        <vers num="3.0.4" edition=":mac" />
        <vers num="3.1" edition="" />
        <vers num="3.1" edition=":windows" />
        <vers num="3.1" edition=":mac" />
        <vers num="3.1.1" edition="" />
        <vers num="3.1.1" edition=":windows" />
        <vers num="3.1.1" edition=":mac" />
        <vers num="3.1.2" edition="" />
        <vers num="3.1.2" edition=":mac" />
        <vers num="3.1.2" edition=":windows" />
        <vers num="3.2" edition="-" />
        <vers num="3.2" edition="-:windows" />
        <vers num="3.2.1" edition="" />
        <vers num="3.2.1" edition=":mac" />
        <vers num="3.2.1" edition=":windows" />
        <vers num="3.2.2" edition="" />
        <vers num="3.2.2" edition=":windows" />
        <vers prev="1" num="3.2.3" edition="" />
        <vers prev="1" num="3.2.3" edition=":windows" />
        <vers prev="1" num="3.2.3" edition=":mac" />
        <vers prev="1" num="4.0_beta" edition="" />
        <vers prev="1" num="4.0_beta" edition=":mac" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1685" published="2009-06-10" name="CVE-2009-1685" modified="2011-02-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in WebKit in Apple Safari before 4.0, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch 1.1 through 2.2.1 allows remote attackers to inject arbitrary web script or HTML by overwriting the document.implementation property of (1) an embedded document or (2) a parent document.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2009/1522" source="VUPEN" patch="1" adv="1">ADV-2009-1522</ref>
      <ref url="http://support.apple.com/kb/HT3613" source="CONFIRM" patch="1" adv="1">http://support.apple.com/kb/HT3613</ref>
      <ref url="http://securitytracker.com/id?1022344" source="SECTRACK" patch="1">1022344</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2009/jun/msg00002.html" source="APPLE" patch="1" adv="1">APPLE-SA-2009-06-08-1</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0212" source="VUPEN">ADV-2011-0212</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1621" source="VUPEN">ADV-2009-1621</ref>
      <ref url="http://www.securityfocus.com/bid/35319" source="BID">35319</ref>
      <ref url="http://www.securityfocus.com/bid/35260" source="BID">35260</ref>
      <ref url="http://support.apple.com/kb/HT3639" source="CONFIRM">http://support.apple.com/kb/HT3639</ref>
      <ref url="http://secunia.com/advisories/43068" source="SECUNIA">43068</ref>
      <ref url="http://secunia.com/advisories/35379" source="SECUNIA" adv="1">35379</ref>
      <ref url="http://osvdb.org/54983" source="OSVDB">54983</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.html" source="SUSE">SUSE-SR:2011:002</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2009/Jun/msg00005.html" source="APPLE">APPLE-SA-2009-06-17-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="safari">
        <vers num="0.8" edition="" />
        <vers num="0.8" edition=":mac" />
        <vers num="0.9" edition="" />
        <vers num="0.9" edition=":mac" />
        <vers num="1.0" edition="" />
        <vers num="1.0" edition=":mac" />
        <vers num="1.0.3" edition="" />
        <vers num="1.0.3" edition=":mac" />
        <vers num="1.1" edition="" />
        <vers num="1.1" edition=":mac" />
        <vers num="1.2" edition="" />
        <vers num="1.2" edition=":mac" />
        <vers num="1.3" edition="" />
        <vers num="1.3" edition=":mac" />
        <vers num="1.3.1" edition="" />
        <vers num="1.3.1" edition=":mac" />
        <vers num="1.3.2" edition="" />
        <vers num="1.3.2" edition=":mac" />
        <vers num="2.0" edition="" />
        <vers num="2.0" edition=":mac" />
        <vers num="2.0.2" edition="" />
        <vers num="2.0.2" edition=":mac" />
        <vers num="2.0.4" edition="" />
        <vers num="2.0.4" edition=":mac" />
        <vers num="3.0" edition="" />
        <vers num="3.0" edition=":windows" />
        <vers num="3.0" edition=":mac" />
        <vers num="3.0.1" edition="" />
        <vers num="3.0.1" edition=":windows" />
        <vers num="3.0.2" edition="" />
        <vers num="3.0.2" edition=":windows" />
        <vers num="3.0.2" edition="-" />
        <vers num="3.0.2" edition="-:mac" />
        <vers num="3.0.3" edition="" />
        <vers num="3.0.3" edition=":windows" />
        <vers num="3.0.3" edition=":mac" />
        <vers num="3.0.4" edition="" />
        <vers num="3.0.4" edition=":windows" />
        <vers num="3.0.4" edition=":mac" />
        <vers num="3.1" edition="" />
        <vers num="3.1" edition=":windows" />
        <vers num="3.1" edition=":mac" />
        <vers num="3.1.1" edition="" />
        <vers num="3.1.1" edition=":windows" />
        <vers num="3.1.1" edition=":mac" />
        <vers num="3.1.2" edition="" />
        <vers num="3.1.2" edition=":mac" />
        <vers num="3.1.2" edition=":windows" />
        <vers num="3.2" edition="-" />
        <vers num="3.2" edition="-:windows" />
        <vers num="3.2.1" edition="" />
        <vers num="3.2.1" edition=":mac" />
        <vers num="3.2.1" edition=":windows" />
        <vers num="3.2.2" edition="" />
        <vers num="3.2.2" edition=":windows" />
        <vers prev="1" num="3.2.3" edition="" />
        <vers prev="1" num="3.2.3" edition=":windows" />
        <vers prev="1" num="3.2.3" edition=":mac" />
        <vers prev="1" num="4.0_beta" edition="" />
        <vers prev="1" num="4.0_beta" edition=":mac" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1686" published="2009-06-10" name="CVE-2009-1686" modified="2011-02-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">WebKit in Apple Safari before 4.0, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch 1.1 through 2.2.1 does not properly handle constant (aka const) declarations in a type-conversion operation during JavaScript exception handling, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted HTML document.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2009/1522" source="VUPEN" patch="1" adv="1">ADV-2009-1522</ref>
      <ref url="http://support.apple.com/kb/HT3613" source="CONFIRM" patch="1" adv="1">http://support.apple.com/kb/HT3613</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2009/jun/msg00002.html" source="APPLE" patch="1" adv="1">APPLE-SA-2009-06-08-1</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0212" source="VUPEN">ADV-2011-0212</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1621" source="VUPEN">ADV-2009-1621</ref>
      <ref url="http://www.securityfocus.com/bid/35311" source="BID">35311</ref>
      <ref url="http://www.securityfocus.com/bid/35260" source="BID">35260</ref>
      <ref url="http://support.apple.com/kb/HT3639" source="CONFIRM">http://support.apple.com/kb/HT3639</ref>
      <ref url="http://securitytracker.com/id?1022345" source="SECTRACK">1022345</ref>
      <ref url="http://secunia.com/advisories/43068" source="SECUNIA">43068</ref>
      <ref url="http://secunia.com/advisories/35379" source="SECUNIA" adv="1">35379</ref>
      <ref url="http://osvdb.org/54984" source="OSVDB">54984</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.html" source="SUSE">SUSE-SR:2011:002</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2009/Jun/msg00005.html" source="APPLE">APPLE-SA-2009-06-17-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="safari">
        <vers num="0.8" edition="-" />
        <vers num="0.8" edition="-:mac" />
        <vers num="0.9" edition="-" />
        <vers num="0.9" edition="-:mac" />
        <vers num="1.0" edition="-" />
        <vers num="1.0" edition="-:mac" />
        <vers num="1.0.3" edition="-" />
        <vers num="1.0.3" edition="-:mac" />
        <vers num="1.1" edition="-" />
        <vers num="1.1" edition="-:mac" />
        <vers num="1.2" edition="-" />
        <vers num="1.2" edition="-:mac" />
        <vers num="1.3" edition="-" />
        <vers num="1.3" edition="-:mac" />
        <vers num="1.3.1" edition="-" />
        <vers num="1.3.1" edition="-:mac" />
        <vers num="1.3.2" edition="-" />
        <vers num="1.3.2" edition="-:mac" />
        <vers num="2.0" edition="-" />
        <vers num="2.0" edition="-:mac" />
        <vers num="2.0.2" edition="-" />
        <vers num="2.0.2" edition="-:mac" />
        <vers num="2.0.4" edition="-" />
        <vers num="2.0.4" edition="-:mac" />
        <vers num="3.0" edition="-" />
        <vers num="3.0" edition="-:windows" />
        <vers num="3.0" edition="-:mac" />
        <vers num="3.0.1" edition="-" />
        <vers num="3.0.1" edition="-:windows" />
        <vers num="3.0.2" edition="-" />
        <vers num="3.0.2" edition="-:mac" />
        <vers num="3.0.2" edition="-:windows" />
        <vers num="3.0.3" edition="-" />
        <vers num="3.0.3" edition="-:windows" />
        <vers num="3.0.3" edition="-:mac" />
        <vers num="3.0.4" edition="-" />
        <vers num="3.0.4" edition="-:mac" />
        <vers num="3.0.4" edition="-:windows" />
        <vers num="3.1" edition="-" />
        <vers num="3.1" edition="-:mac" />
        <vers num="3.1" edition="-:windows" />
        <vers num="3.1.1" edition="-" />
        <vers num="3.1.1" edition="-:windows" />
        <vers num="3.1.1" edition="-:mac" />
        <vers num="3.1.2" edition="-" />
        <vers num="3.1.2" edition="-:mac" />
        <vers num="3.1.2" edition="-:windows" />
        <vers num="3.2" edition="-" />
        <vers num="3.2" edition="-:windows" />
        <vers num="3.2.1" edition="-" />
        <vers num="3.2.1" edition="-:mac" />
        <vers num="3.2.1" edition="-:windows" />
        <vers num="3.2.2" edition="-" />
        <vers num="3.2.2" edition="-:windows" />
        <vers prev="1" num="3.2.3" edition="-" />
        <vers prev="1" num="3.2.3" edition="-:windows" />
        <vers prev="1" num="3.2.3" edition="-:mac" />
        <vers prev="1" num="4.0_beta" edition="-" />
        <vers prev="1" num="4.0_beta" edition="-:mac" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1687" published="2009-06-10" name="CVE-2009-1687" modified="2011-02-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">The JavaScript garbage collector in WebKit in Apple Safari before 4.0, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch 1.1 through 2.2.1 does not properly handle allocation failures, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted HTML document that triggers write access to an "offset of a NULL pointer."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2009/1522" source="VUPEN" patch="1" adv="1">ADV-2009-1522</ref>
      <ref url="http://securitytracker.com/id?1022345" source="SECTRACK" patch="1">1022345</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-July/msg01200.html" source="FEDORA">FEDORA-2009-8020</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-July/msg01199.html" source="FEDORA">FEDORA-2009-8046</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-July/msg01196.html" source="FEDORA">FEDORA-2009-8049</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-July/msg01177.html" source="FEDORA">FEDORA-2009-8039</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0212" source="VUPEN">ADV-2011-0212</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1621" source="VUPEN">ADV-2009-1621</ref>
      <ref url="http://www.ubuntu.com/usn/USN-857-1" source="UBUNTU">USN-857-1</ref>
      <ref url="http://www.ubuntu.com/usn/USN-836-1" source="UBUNTU">USN-836-1</ref>
      <ref url="http://www.ubuntu.com/usn/USN-822-1" source="UBUNTU">USN-822-1</ref>
      <ref url="http://www.securityfocus.com/bid/35309" source="BID">35309</ref>
      <ref url="http://www.securityfocus.com/bid/35260" source="BID">35260</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:330" source="MANDRIVA">MDVSA-2009:330</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1950" source="DEBIAN">DSA-1950</ref>
      <ref url="http://support.apple.com/kb/HT3639" source="CONFIRM">http://support.apple.com/kb/HT3639</ref>
      <ref url="http://support.apple.com/kb/HT3613" source="CONFIRM" adv="1">http://support.apple.com/kb/HT3613</ref>
      <ref url="http://secunia.com/advisories/43068" source="SECUNIA">43068</ref>
      <ref url="http://secunia.com/advisories/37746" source="SECUNIA">37746</ref>
      <ref url="http://secunia.com/advisories/36790" source="SECUNIA">36790</ref>
      <ref url="http://secunia.com/advisories/36062" source="SECUNIA">36062</ref>
      <ref url="http://secunia.com/advisories/36057" source="SECUNIA">36057</ref>
      <ref url="http://secunia.com/advisories/35379" source="SECUNIA" adv="1">35379</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10260" source="OVAL">oval:org.mitre.oval:def:10260</ref>
      <ref url="http://osvdb.org/54985" source="OSVDB">54985</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.html" source="SUSE">SUSE-SR:2011:002</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2009/Jun/msg00005.html" source="APPLE">APPLE-SA-2009-06-17-1</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2009/jun/msg00002.html" source="APPLE" adv="1">APPLE-SA-2009-06-08-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="safari">
        <vers num="0.8" edition="" />
        <vers num="0.8" edition=":mac" />
        <vers num="0.9" edition="" />
        <vers num="0.9" edition=":mac" />
        <vers num="1.0" edition="" />
        <vers num="1.0" edition=":mac" />
        <vers num="1.0.3" edition="" />
        <vers num="1.0.3" edition=":mac" />
        <vers num="1.1" edition="" />
        <vers num="1.1" edition=":mac" />
        <vers num="1.2" edition="" />
        <vers num="1.2" edition=":mac" />
        <vers num="1.3" edition="" />
        <vers num="1.3" edition=":mac" />
        <vers num="1.3.1" edition="" />
        <vers num="1.3.1" edition=":mac" />
        <vers num="1.3.2" edition="" />
        <vers num="1.3.2" edition=":mac" />
        <vers num="2.0" edition="" />
        <vers num="2.0" edition=":mac" />
        <vers num="2.0.2" edition="" />
        <vers num="2.0.2" edition=":mac" />
        <vers num="2.0.4" edition="" />
        <vers num="2.0.4" edition=":mac" />
        <vers num="3.0" edition="" />
        <vers num="3.0" edition=":windows" />
        <vers num="3.0" edition=":mac" />
        <vers num="3.0.1" edition="" />
        <vers num="3.0.1" edition=":windows" />
        <vers num="3.0.2" edition="" />
        <vers num="3.0.2" edition=":windows" />
        <vers num="3.0.2" edition="-" />
        <vers num="3.0.2" edition="-:mac" />
        <vers num="3.0.3" edition="" />
        <vers num="3.0.3" edition=":windows" />
        <vers num="3.0.3" edition=":mac" />
        <vers num="3.0.4" edition="" />
        <vers num="3.0.4" edition=":windows" />
        <vers num="3.0.4" edition=":mac" />
        <vers num="3.1" edition="" />
        <vers num="3.1" edition=":windows" />
        <vers num="3.1" edition=":mac" />
        <vers num="3.1.1" edition="" />
        <vers num="3.1.1" edition=":windows" />
        <vers num="3.1.1" edition=":mac" />
        <vers num="3.1.2" edition="" />
        <vers num="3.1.2" edition=":mac" />
        <vers num="3.1.2" edition=":windows" />
        <vers num="3.2" edition="-" />
        <vers num="3.2" edition="-:windows" />
        <vers num="3.2.1" edition="" />
        <vers num="3.2.1" edition=":mac" />
        <vers num="3.2.1" edition=":windows" />
        <vers num="3.2.2" edition="" />
        <vers num="3.2.2" edition=":windows" />
        <vers prev="1" num="3.2.3" edition="" />
        <vers prev="1" num="3.2.3" edition=":windows" />
        <vers prev="1" num="3.2.3" edition=":mac" />
        <vers prev="1" num="4.0_beta" edition="" />
        <vers prev="1" num="4.0_beta" edition=":mac" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1688" published="2009-06-10" name="CVE-2009-1688" modified="2011-02-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in WebKit in Apple Safari before 4.0, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch 1.1 through 2.2.1 allows remote attackers to inject arbitrary web script or HTML via vectors related to determining a security context through an approach that is not the "HTML 5 standard method."</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2009/1522" source="VUPEN" patch="1" adv="1">ADV-2009-1522</ref>
      <ref url="http://support.apple.com/kb/HT3613" source="CONFIRM" patch="1">http://support.apple.com/kb/HT3613</ref>
      <ref url="http://securitytracker.com/id?1022344" source="SECTRACK" patch="1">1022344</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2009/jun/msg00002.html" source="APPLE" patch="1" adv="1">APPLE-SA-2009-06-08-1</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0212" source="VUPEN">ADV-2011-0212</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1621" source="VUPEN">ADV-2009-1621</ref>
      <ref url="http://www.securityfocus.com/bid/35320" source="BID">35320</ref>
      <ref url="http://www.securityfocus.com/bid/35260" source="BID">35260</ref>
      <ref url="http://support.apple.com/kb/HT3639" source="CONFIRM">http://support.apple.com/kb/HT3639</ref>
      <ref url="http://secunia.com/advisories/43068" source="SECUNIA">43068</ref>
      <ref url="http://secunia.com/advisories/35379" source="SECUNIA" adv="1">35379</ref>
      <ref url="http://osvdb.org/54986" source="OSVDB">54986</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.html" source="SUSE">SUSE-SR:2011:002</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2009/Jun/msg00005.html" source="APPLE">APPLE-SA-2009-06-17-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="safari">
        <vers num="0.8" edition="" />
        <vers num="0.8" edition=":mac" />
        <vers num="0.9" edition="" />
        <vers num="0.9" edition=":mac" />
        <vers num="1.0" edition="" />
        <vers num="1.0" edition=":mac" />
        <vers num="1.0.3" edition="" />
        <vers num="1.0.3" edition=":mac" />
        <vers num="1.1" edition="" />
        <vers num="1.1" edition=":mac" />
        <vers num="1.2" edition="" />
        <vers num="1.2" edition=":mac" />
        <vers num="1.3" edition="" />
        <vers num="1.3" edition=":mac" />
        <vers num="1.3.1" edition="" />
        <vers num="1.3.1" edition=":mac" />
        <vers num="1.3.2" edition="" />
        <vers num="1.3.2" edition=":mac" />
        <vers num="2.0" edition="" />
        <vers num="2.0" edition=":mac" />
        <vers num="2.0.2" edition="" />
        <vers num="2.0.2" edition=":mac" />
        <vers num="2.0.4" edition="" />
        <vers num="2.0.4" edition=":mac" />
        <vers num="3.0" edition="" />
        <vers num="3.0" edition=":windows" />
        <vers num="3.0" edition=":mac" />
        <vers num="3.0.1" edition="" />
        <vers num="3.0.1" edition=":windows" />
        <vers num="3.0.2" edition="" />
        <vers num="3.0.2" edition=":windows" />
        <vers num="3.0.2" edition="-" />
        <vers num="3.0.2" edition="-:mac" />
        <vers num="3.0.3" edition="" />
        <vers num="3.0.3" edition=":windows" />
        <vers num="3.0.3" edition=":mac" />
        <vers num="3.0.4" edition="" />
        <vers num="3.0.4" edition=":windows" />
        <vers num="3.0.4" edition=":mac" />
        <vers num="3.1" edition="" />
        <vers num="3.1" edition=":windows" />
        <vers num="3.1" edition=":mac" />
        <vers num="3.1.1" edition="" />
        <vers num="3.1.1" edition=":windows" />
        <vers num="3.1.1" edition=":mac" />
        <vers num="3.1.2" edition="" />
        <vers num="3.1.2" edition=":mac" />
        <vers num="3.1.2" edition=":windows" />
        <vers num="3.2" edition="-" />
        <vers num="3.2" edition="-:windows" />
        <vers num="3.2.1" edition="" />
        <vers num="3.2.1" edition=":mac" />
        <vers num="3.2.1" edition=":windows" />
        <vers num="3.2.2" edition="" />
        <vers num="3.2.2" edition=":windows" />
        <vers prev="1" num="3.2.3" edition="" />
        <vers prev="1" num="3.2.3" edition=":windows" />
        <vers prev="1" num="3.2.3" edition=":mac" />
        <vers prev="1" num="4.0_beta" edition="" />
        <vers prev="1" num="4.0_beta" edition=":mac" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1689" published="2009-06-10" name="CVE-2009-1689" modified="2011-02-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in WebKit in Apple Safari before 4.0, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch 1.1 through 2.2.1 allows remote attackers to inject arbitrary web script or HTML via vectors involving submission of a form to the about:blank URL, leading to security-context replacement.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2009/1522" source="VUPEN" patch="1" adv="1">ADV-2009-1522</ref>
      <ref url="http://www.securityfocus.com/bid/35260" source="BID" patch="1">35260</ref>
      <ref url="http://support.apple.com/kb/HT3613" source="CONFIRM" patch="1" adv="1">http://support.apple.com/kb/HT3613</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2009/jun/msg00002.html" source="APPLE" patch="1" adv="1">APPLE-SA-2009-06-08-1</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0212" source="VUPEN">ADV-2011-0212</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1621" source="VUPEN">ADV-2009-1621</ref>
      <ref url="http://www.securityfocus.com/bid/35332" source="BID">35332</ref>
      <ref url="http://support.apple.com/kb/HT3639" source="CONFIRM">http://support.apple.com/kb/HT3639</ref>
      <ref url="http://securitytracker.com/id?1022344" source="SECTRACK">1022344</ref>
      <ref url="http://secunia.com/advisories/43068" source="SECUNIA">43068</ref>
      <ref url="http://secunia.com/advisories/35379" source="SECUNIA" adv="1">35379</ref>
      <ref url="http://osvdb.org/54988" source="OSVDB">54988</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.html" source="SUSE">SUSE-SR:2011:002</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2009/Jun/msg00005.html" source="APPLE">APPLE-SA-2009-06-17-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="safari">
        <vers num="0.8" edition="-" />
        <vers num="0.8" edition="-:mac" />
        <vers num="0.9" edition="-" />
        <vers num="0.9" edition="-:mac" />
        <vers num="1.0" edition="-" />
        <vers num="1.0" edition="-:mac" />
        <vers num="1.0.3" edition="-" />
        <vers num="1.0.3" edition="-:mac" />
        <vers num="1.1" edition="-" />
        <vers num="1.1" edition="-:mac" />
        <vers num="1.2" edition="-" />
        <vers num="1.2" edition="-:mac" />
        <vers num="1.3" edition="-" />
        <vers num="1.3" edition="-:mac" />
        <vers num="1.3.1" edition="-" />
        <vers num="1.3.1" edition="-:mac" />
        <vers num="1.3.2" edition="-" />
        <vers num="1.3.2" edition="-:mac" />
        <vers num="2.0" edition="-" />
        <vers num="2.0" edition="-:mac" />
        <vers num="2.0.2" edition="-" />
        <vers num="2.0.2" edition="-:mac" />
        <vers num="2.0.4" edition="-" />
        <vers num="2.0.4" edition="-:mac" />
        <vers num="3.0" edition="-" />
        <vers num="3.0" edition="-:windows" />
        <vers num="3.0" edition="-:mac" />
        <vers num="3.0.1" edition="-" />
        <vers num="3.0.1" edition="-:windows" />
        <vers num="3.0.2" edition="-" />
        <vers num="3.0.2" edition="-:mac" />
        <vers num="3.0.2" edition="-:windows" />
        <vers num="3.0.3" edition="-" />
        <vers num="3.0.3" edition="-:windows" />
        <vers num="3.0.3" edition="-:mac" />
        <vers num="3.0.4" edition="-" />
        <vers num="3.0.4" edition="-:mac" />
        <vers num="3.0.4" edition="-:windows" />
        <vers num="3.1" edition="-" />
        <vers num="3.1" edition="-:mac" />
        <vers num="3.1" edition="-:windows" />
        <vers num="3.1.1" edition="-" />
        <vers num="3.1.1" edition="-:windows" />
        <vers num="3.1.1" edition="-:mac" />
        <vers num="3.1.2" edition="-" />
        <vers num="3.1.2" edition="-:mac" />
        <vers num="3.1.2" edition="-:windows" />
        <vers num="3.2" edition="-" />
        <vers num="3.2" edition="-:windows" />
        <vers num="3.2.1" edition="-" />
        <vers num="3.2.1" edition="-:mac" />
        <vers num="3.2.1" edition="-:windows" />
        <vers num="3.2.2" edition="-" />
        <vers num="3.2.2" edition="-:windows" />
        <vers prev="1" num="3.2.3" edition="-" />
        <vers prev="1" num="3.2.3" edition="-:windows" />
        <vers prev="1" num="3.2.3" edition="-:mac" />
        <vers prev="1" num="4.0_beta" edition="-" />
        <vers prev="1" num="4.0_beta" edition="-:mac" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1690" published="2009-06-10" name="CVE-2009-1690" modified="2011-02-24" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Use-after-free vulnerability in WebKit, as used in Apple Safari before 4.0, iPhone OS 1.0 through 2.2.1, iPhone OS for iPod touch 1.1 through 2.2.1, Google Chrome 1.0.154.53, and possibly other products, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) by setting an unspecified property of an HTML tag that causes child elements to be freed and later accessed when an HTML error occurs, related to "recursion in certain DOM event handlers."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2009/1522" source="VUPEN" patch="1" adv="1">ADV-2009-1522</ref>
      <ref url="http://www.securityfocus.com/bid/35260" source="BID" patch="1">35260</ref>
      <ref url="http://support.apple.com/kb/HT3639" source="CONFIRM" patch="1" adv="1">http://support.apple.com/kb/HT3639</ref>
      <ref url="http://support.apple.com/kb/HT3613" source="CONFIRM" patch="1" adv="1">http://support.apple.com/kb/HT3613</ref>
      <ref url="http://securitytracker.com/id?1022345" source="SECTRACK" patch="1">1022345</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2009/Jun/msg00005.html" source="APPLE" patch="1" adv="1">APPLE-SA-2009-06-17-1</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2009/jun/msg00002.html" source="APPLE" patch="1" adv="1">APPLE-SA-2009-06-08-1</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-July/msg01200.html" source="FEDORA">FEDORA-2009-8020</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-July/msg01199.html" source="FEDORA">FEDORA-2009-8046</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-July/msg01196.html" source="FEDORA">FEDORA-2009-8049</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-July/msg01177.html" source="FEDORA">FEDORA-2009-8039</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0212" source="VUPEN" adv="1">ADV-2011-0212</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1621" source="VUPEN" adv="1">ADV-2009-1621</ref>
      <ref url="http://www.ubuntu.com/usn/USN-857-1" source="UBUNTU">USN-857-1</ref>
      <ref url="http://www.ubuntu.com/usn/USN-836-1" source="UBUNTU">USN-836-1</ref>
      <ref url="http://www.ubuntu.com/usn/USN-822-1" source="UBUNTU">USN-822-1</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:330" source="MANDRIVA">MDVSA-2009:330</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1950" source="DEBIAN">DSA-1950</ref>
      <ref url="http://secunia.com/advisories/43068" source="SECUNIA" adv="1">43068</ref>
      <ref url="http://secunia.com/advisories/37746" source="SECUNIA" adv="1">37746</ref>
      <ref url="http://secunia.com/advisories/36790" source="SECUNIA" adv="1">36790</ref>
      <ref url="http://secunia.com/advisories/36062" source="SECUNIA" adv="1">36062</ref>
      <ref url="http://secunia.com/advisories/36057" source="SECUNIA" adv="1">36057</ref>
      <ref url="http://secunia.com/advisories/35379" source="SECUNIA" adv="1">35379</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:11009" source="OVAL">oval:org.mitre.oval:def:11009</ref>
      <ref url="http://osvdb.org/54990" source="OSVDB">54990</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.html" source="SUSE">SUSE-SR:2011:002</ref>
      <ref url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=803" source="IDEFENSE">20090608 Multiple Vendor WebKit Error Handling Use After Free Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="safari">
        <vers num="0.8" edition="" />
        <vers num="0.8" edition=":mac" />
        <vers num="0.9" edition="" />
        <vers num="0.9" edition=":mac" />
        <vers num="1.0" edition="" />
        <vers num="1.0" edition=":mac" />
        <vers num="1.0.3" edition="" />
        <vers num="1.0.3" edition=":mac" />
        <vers num="1.1" edition="" />
        <vers num="1.1" edition=":mac" />
        <vers num="1.2" edition="" />
        <vers num="1.2" edition=":mac" />
        <vers num="1.3" edition="" />
        <vers num="1.3" edition=":mac" />
        <vers num="1.3.1" edition="" />
        <vers num="1.3.1" edition=":mac" />
        <vers num="1.3.2" edition="" />
        <vers num="1.3.2" edition=":mac" />
        <vers num="2.0" edition="" />
        <vers num="2.0" edition=":mac" />
        <vers num="2.0.2" edition="" />
        <vers num="2.0.2" edition=":mac" />
        <vers num="2.0.4" edition="" />
        <vers num="2.0.4" edition=":mac" />
        <vers num="3.0" edition="" />
        <vers num="3.0" edition=":windows" />
        <vers num="3.0" edition=":mac" />
        <vers num="3.0.1" edition="" />
        <vers num="3.0.1" edition=":windows" />
        <vers num="3.0.2" edition="" />
        <vers num="3.0.2" edition=":windows" />
        <vers num="3.0.2" edition="-" />
        <vers num="3.0.2" edition="-:mac" />
        <vers num="3.0.3" edition="" />
        <vers num="3.0.3" edition=":mac" />
        <vers num="3.0.3" edition=":windows" />
        <vers num="3.0.4" edition="" />
        <vers num="3.0.4" edition=":windows" />
        <vers num="3.0.4" edition=":mac" />
        <vers num="3.1" edition="" />
        <vers num="3.1" edition=":windows" />
        <vers num="3.1" edition=":mac" />
        <vers num="3.1.1" edition="" />
        <vers num="3.1.1" edition=":windows" />
        <vers num="3.1.1" edition=":mac" />
        <vers num="3.1.2" edition="" />
        <vers num="3.1.2" edition=":mac" />
        <vers num="3.1.2" edition=":windows" />
        <vers num="3.2" edition="-" />
        <vers num="3.2" edition="-:windows" />
        <vers num="3.2.1" edition="" />
        <vers num="3.2.1" edition=":mac" />
        <vers num="3.2.1" edition=":windows" />
        <vers num="3.2.2" edition="" />
        <vers num="3.2.2" edition=":windows" />
        <vers prev="1" num="3.2.3" edition="" />
        <vers prev="1" num="3.2.3" edition=":mac" />
        <vers prev="1" num="3.2.3" edition=":windows" />
        <vers prev="1" num="4.0_beta" edition="" />
        <vers prev="1" num="4.0_beta" edition=":mac" />
      </prod>
      <prod vendor="google" name="chrome">
        <vers num="1.0.154.53" />
      </prod>
      <prod vendor="apple" name="iphone_os">
        <vers num="1.0" />
        <vers num="1.0.0" edition="-" />
        <vers num="1.0.0" edition="-:iphone" />
        <vers num="1.0.1" edition="-" />
        <vers num="1.0.1" edition="-:iphone" />
        <vers num="1.0.2" edition="-" />
        <vers num="1.0.2" edition="-:iphone" />
        <vers num="1.1" />
        <vers num="1.1.0" edition="-" />
        <vers num="1.1.0" edition="-:ipodtouch" />
        <vers num="1.1.0" edition="-:iphone" />
        <vers num="1.1.1" edition="-" />
        <vers num="1.1.1" edition="-:ipodtouch" />
        <vers num="1.1.1" edition="-:iphone" />
        <vers num="1.1.2" edition="-" />
        <vers num="1.1.2" edition="-:ipodtouch" />
        <vers num="1.1.2" edition="-:iphone" />
        <vers num="1.1.3" edition="-" />
        <vers num="1.1.3" edition="-:iphone" />
        <vers num="1.1.3" edition="-:ipodtouch" />
        <vers num="1.1.4" edition="-" />
        <vers num="1.1.4" edition="-:ipodtouch" />
        <vers num="1.1.4" edition="-:iphone" />
        <vers num="1.1.5" edition="-" />
        <vers num="1.1.5" edition="-:iphone" />
        <vers num="1.1.5" edition="-:ipodtouch" />
        <vers num="2.0" />
        <vers num="2.0.0" edition="-" />
        <vers num="2.0.0" edition="-:iphone" />
        <vers num="2.0.0" edition="-:ipodtouch" />
        <vers num="2.0.1" edition="-" />
        <vers num="2.0.1" edition="-:ipodtouch" />
        <vers num="2.0.1" edition="-:iphone" />
        <vers num="2.0.2" edition="-" />
        <vers num="2.0.2" edition="-:iphone" />
        <vers num="2.0.2" edition="-:ipodtouch" />
        <vers num="2.1" edition="-" />
        <vers num="2.1" edition="-:ipodtouch" />
        <vers num="2.1" edition="-:iphone" />
        <vers num="2.2" edition="-" />
        <vers num="2.2" edition="-:iphone" />
        <vers num="2.2" edition="-:ipodtouch" />
        <vers num="2.2.1" edition="-" />
        <vers num="2.2.1" edition="-:iphone" />
        <vers num="2.2.1" edition="-:ipodtouch" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1691" published="2009-06-10" name="CVE-2009-1691" modified="2011-02-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in WebKit in Apple Safari before 4.0, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch 1.1 through 2.2.1 allows remote attackers to inject arbitrary web script or HTML via vectors related to insufficient access control for standard JavaScript prototypes in other domains.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2009/1522" source="VUPEN" patch="1" adv="1">ADV-2009-1522</ref>
      <ref url="http://www.securityfocus.com/bid/35260" source="BID" patch="1">35260</ref>
      <ref url="http://support.apple.com/kb/HT3613" source="CONFIRM" patch="1" adv="1">http://support.apple.com/kb/HT3613</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2009/jun/msg00002.html" source="APPLE" patch="1" adv="1">APPLE-SA-2009-06-08-1</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0212" source="VUPEN">ADV-2011-0212</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1621" source="VUPEN">ADV-2009-1621</ref>
      <ref url="http://www.securityfocus.com/bid/35330" source="BID">35330</ref>
      <ref url="http://support.apple.com/kb/HT3639" source="CONFIRM">http://support.apple.com/kb/HT3639</ref>
      <ref url="http://securitytracker.com/id?1022344" source="SECTRACK">1022344</ref>
      <ref url="http://secunia.com/advisories/43068" source="SECUNIA">43068</ref>
      <ref url="http://secunia.com/advisories/35379" source="SECUNIA" adv="1">35379</ref>
      <ref url="http://osvdb.org/54989" source="OSVDB">54989</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.html" source="SUSE">SUSE-SR:2011:002</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2009/Jun/msg00005.html" source="APPLE">APPLE-SA-2009-06-17-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="safari">
        <vers num="0.8" edition="-" />
        <vers num="0.8" edition="-:mac" />
        <vers num="0.9" edition="-" />
        <vers num="0.9" edition="-:mac" />
        <vers num="1.0" edition="-" />
        <vers num="1.0" edition="-:mac" />
        <vers num="1.0.3" edition="-" />
        <vers num="1.0.3" edition="-:mac" />
        <vers num="1.1" edition="-" />
        <vers num="1.1" edition="-:mac" />
        <vers num="1.2" edition="-" />
        <vers num="1.2" edition="-:mac" />
        <vers num="1.3" edition="-" />
        <vers num="1.3" edition="-:mac" />
        <vers num="1.3.1" edition="-" />
        <vers num="1.3.1" edition="-:mac" />
        <vers num="1.3.2" edition="-" />
        <vers num="1.3.2" edition="-:mac" />
        <vers num="2.0" edition="-" />
        <vers num="2.0" edition="-:mac" />
        <vers num="2.0.2" edition="-" />
        <vers num="2.0.2" edition="-:mac" />
        <vers num="2.0.4" edition="-" />
        <vers num="2.0.4" edition="-:mac" />
        <vers num="3.0" edition="-" />
        <vers num="3.0" edition="-:windows" />
        <vers num="3.0" edition="-:mac" />
        <vers num="3.0.1" edition="-" />
        <vers num="3.0.1" edition="-:windows" />
        <vers num="3.0.2" edition="-" />
        <vers num="3.0.2" edition="-:mac" />
        <vers num="3.0.2" edition="-:windows" />
        <vers num="3.0.3" edition="-" />
        <vers num="3.0.3" edition="-:windows" />
        <vers num="3.0.3" edition="-:mac" />
        <vers num="3.0.4" edition="-" />
        <vers num="3.0.4" edition="-:mac" />
        <vers num="3.0.4" edition="-:windows" />
        <vers num="3.1" edition="-" />
        <vers num="3.1" edition="-:mac" />
        <vers num="3.1" edition="-:windows" />
        <vers num="3.1.1" edition="-" />
        <vers num="3.1.1" edition="-:windows" />
        <vers num="3.1.1" edition="-:mac" />
        <vers num="3.1.2" edition="-" />
        <vers num="3.1.2" edition="-:mac" />
        <vers num="3.1.2" edition="-:windows" />
        <vers num="3.2" edition="-" />
        <vers num="3.2" edition="-:windows" />
        <vers num="3.2.1" edition="-" />
        <vers num="3.2.1" edition="-:mac" />
        <vers num="3.2.1" edition="-:windows" />
        <vers num="3.2.2" edition="-" />
        <vers num="3.2.2" edition="-:windows" />
        <vers prev="1" num="3.2.3" edition="-" />
        <vers prev="1" num="3.2.3" edition="-:windows" />
        <vers prev="1" num="3.2.3" edition="-:mac" />
        <vers prev="1" num="4.0_beta" edition="-" />
        <vers prev="1" num="4.0_beta" edition="-:mac" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1692" published="2009-06-19" name="CVE-2009-1692" modified="2011-09-14" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:C)" CVSS_score="7.1" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="8.6" CVSS_base_score="7.1">
    <desc>
      <descript source="cve">WebKit before r41741, as used in Apple iPhone OS 1.0 through 2.2.1, iPhone OS for iPod touch 1.1 through 2.2.1, Safari, and other software, allows remote attackers to cause a denial of service (memory consumption or device reset) via a web page containing an HTMLSelectElement object with a large length attribute, related to the length property of a Select object.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="https://bugs.webkit.org/show_bug.cgi?id=23319" source="MISC">https://bugs.webkit.org/show_bug.cgi?id=23319</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0212" source="VUPEN">ADV-2011-0212</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1621" source="VUPEN">ADV-2009-1621</ref>
      <ref url="http://www.securityfocus.com/bid/35446" source="BID">35446</ref>
      <ref url="http://www.securityfocus.com/bid/35414" source="BID">35414</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/505006/100/0/threaded" source="BUGTRAQ">20090716 Re[2]: [GSEC-TZO-44-2009] One bug to rule them all - Firefox, IE, Safari,Opera, Chrome,Seamonkey,iPhone,iPod,Wii,PS3....</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/504989/100/0/threaded" source="BUGTRAQ">20090715 Re: [GSEC-TZO-44-2009] One bug to rule them all - Firefox, IE, Safari,Opera, Chrome,Seamonkey,iPhone,iPod,Wii,PS3....</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/504988/100/0/threaded" source="BUGTRAQ">20090715 Re:[GSEC-TZO-44-2009] One bug to rule them all - Firefox, IE, Safari,Opera, Chrome,Seamonkey,iPhone,iPod,Wii,PS3....</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/504969/100/0/threaded" source="BUGTRAQ">20090715 [GSEC-TZO-44-2009] One bug to rule them all - Firefox, IE, Safari,Opera, Chrome,Seamonkey,iPhone,iPod,Wii,PS3....</ref>
      <ref url="http://www.milw0rm.com/exploits/9160" source="MILW0RM">9160</ref>
      <ref url="http://www.g-sec.lu/one-bug-to-rule-them-all.html" source="MISC">http://www.g-sec.lu/one-bug-to-rule-them-all.html</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1950" source="DEBIAN">DSA-1950</ref>
      <ref url="http://support.apple.com/kb/HT3639" source="CONFIRM" adv="1">http://support.apple.com/kb/HT3639</ref>
      <ref url="http://secunia.com/advisories/43068" source="SECUNIA">43068</ref>
      <ref url="http://secunia.com/advisories/37746" source="SECUNIA">37746</ref>
      <ref url="http://secunia.com/advisories/36977" source="SECUNIA">36977</ref>
      <ref url="http://osvdb.org/55242" source="OSVDB">55242</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.html" source="SUSE">SUSE-SR:2011:002</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2009/Jun/msg00005.html" source="APPLE" adv="1">APPLE-SA-2009-06-17-1</ref>
      <ref url="http://kb.palm.com/wps/portal/kb/na/pre/p100eww/sprint/solutions/article/50607_en.html#121" source="CONFIRM">http://kb.palm.com/wps/portal/kb/na/pre/p100eww/sprint/solutions/article/50607_en.html#121</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="iphone_os">
        <vers num="1.0.0" edition="-" />
        <vers num="1.0.0" edition="-:iphone" />
        <vers num="1.0.1" edition="-" />
        <vers num="1.0.1" edition="-:iphone" />
        <vers num="1.0.2" edition="-" />
        <vers num="1.0.2" edition="-:iphone" />
        <vers num="1.1.0" edition="-" />
        <vers num="1.1.0" edition="-:ipodtouch" />
        <vers num="1.1.0" edition="-:iphone" />
        <vers num="1.1.1" edition="-" />
        <vers num="1.1.1" edition="-:ipodtouch" />
        <vers num="1.1.1" edition="-:iphone" />
        <vers num="1.1.2" edition="-" />
        <vers num="1.1.2" edition="-:ipodtouch" />
        <vers num="1.1.2" edition="-:iphone" />
        <vers num="1.1.3" edition="-" />
        <vers num="1.1.3" edition="-:iphone" />
        <vers num="1.1.3" edition="-:ipodtouch" />
        <vers num="1.1.4" edition="-" />
        <vers num="1.1.4" edition="-:ipodtouch" />
        <vers num="1.1.4" edition="-:iphone" />
        <vers num="1.1.5" edition="-" />
        <vers num="1.1.5" edition="-:iphone" />
        <vers num="1.1.5" edition="-:ipodtouch" />
        <vers num="2.0.0" edition="-" />
        <vers num="2.0.0" edition="-:ipodtouch" />
        <vers num="2.0.0" edition="-:iphone" />
        <vers num="2.0.1" edition="-" />
        <vers num="2.0.1" edition="-:ipodtouch" />
        <vers num="2.0.1" edition="-:iphone" />
        <vers num="2.0.2" edition="-" />
        <vers num="2.0.2" edition="-:iphone" />
        <vers num="2.1" edition="-" />
        <vers num="2.1" edition="-:ipodtouch" />
        <vers num="2.1" edition="-:iphone" />
        <vers num="2.2" edition="-" />
        <vers num="2.2" edition="-:ipodtouch" />
        <vers num="2.2" edition="-:iphone" />
        <vers num="2.2.1" edition="-" />
        <vers num="2.2.1" edition="-:iphone" />
        <vers num="2.2.1" edition="-:ipodtouch" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1693" published="2009-06-10" name="CVE-2009-1693" modified="2011-02-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)" CVSS_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_base_score="5.8">
    <desc>
      <descript source="cve">WebKit in Apple Safari before 4.0, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch 1.1 through 2.2.1 allows remote attackers to read images from arbitrary web sites via a CANVAS element with an SVG image, related to a "cross-site image capture issue."</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2009/1522" source="VUPEN" patch="1" adv="1">ADV-2009-1522</ref>
      <ref url="http://www.securityfocus.com/bid/35260" source="BID" patch="1">35260</ref>
      <ref url="http://support.apple.com/kb/HT3613" source="CONFIRM" patch="1" adv="1">http://support.apple.com/kb/HT3613</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2009/jun/msg00002.html" source="APPLE" patch="1" adv="1">APPLE-SA-2009-06-08-1</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0212" source="VUPEN">ADV-2011-0212</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1621" source="VUPEN">ADV-2009-1621</ref>
      <ref url="http://www.securityfocus.com/bid/35331" source="BID">35331</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1950" source="DEBIAN">DSA-1950</ref>
      <ref url="http://support.apple.com/kb/HT3639" source="CONFIRM">http://support.apple.com/kb/HT3639</ref>
      <ref url="http://secunia.com/advisories/43068" source="SECUNIA">43068</ref>
      <ref url="http://secunia.com/advisories/37746" source="SECUNIA">37746</ref>
      <ref url="http://secunia.com/advisories/35379" source="SECUNIA" adv="1">35379</ref>
      <ref url="http://osvdb.org/55004" source="OSVDB">55004</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.html" source="SUSE">SUSE-SR:2011:002</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2009/Jun/msg00005.html" source="APPLE">APPLE-SA-2009-06-17-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="safari">
        <vers num="0.8" edition="-" />
        <vers num="0.8" edition="-:mac" />
        <vers num="0.9" edition="-" />
        <vers num="0.9" edition="-:mac" />
        <vers num="1.0" edition="-" />
        <vers num="1.0" edition="-:mac" />
        <vers num="1.0.3" edition="-" />
        <vers num="1.0.3" edition="-:mac" />
        <vers num="1.1" edition="-" />
        <vers num="1.1" edition="-:mac" />
        <vers num="1.2" edition="-" />
        <vers num="1.2" edition="-:mac" />
        <vers num="1.3" edition="-" />
        <vers num="1.3" edition="-:mac" />
        <vers num="1.3.1" edition="-" />
        <vers num="1.3.1" edition="-:mac" />
        <vers num="1.3.2" edition="-" />
        <vers num="1.3.2" edition="-:mac" />
        <vers num="2.0" edition="-" />
        <vers num="2.0" edition="-:mac" />
        <vers num="2.0.2" edition="-" />
        <vers num="2.0.2" edition="-:mac" />
        <vers num="2.0.4" edition="-" />
        <vers num="2.0.4" edition="-:mac" />
        <vers num="3.0" edition="-" />
        <vers num="3.0" edition="-:windows" />
        <vers num="3.0" edition="-:mac" />
        <vers num="3.0.1" edition="-" />
        <vers num="3.0.1" edition="-:windows" />
        <vers num="3.0.2" edition="-" />
        <vers num="3.0.2" edition="-:mac" />
        <vers num="3.0.2" edition="-:windows" />
        <vers num="3.0.3" edition="-" />
        <vers num="3.0.3" edition="-:windows" />
        <vers num="3.0.3" edition="-:mac" />
        <vers num="3.0.4" edition="-" />
        <vers num="3.0.4" edition="-:mac" />
        <vers num="3.0.4" edition="-:windows" />
        <vers num="3.1" edition="-" />
        <vers num="3.1" edition="-:mac" />
        <vers num="3.1" edition="-:windows" />
        <vers num="3.1.1" edition="-" />
        <vers num="3.1.1" edition="-:windows" />
        <vers num="3.1.1" edition="-:mac" />
        <vers num="3.1.2" edition="-" />
        <vers num="3.1.2" edition="-:mac" />
        <vers num="3.1.2" edition="-:windows" />
        <vers num="3.2" edition="-" />
        <vers num="3.2" edition="-:windows" />
        <vers num="3.2.1" edition="-" />
        <vers num="3.2.1" edition="-:mac" />
        <vers num="3.2.1" edition="-:windows" />
        <vers num="3.2.2" edition="-" />
        <vers num="3.2.2" edition="-:windows" />
        <vers prev="1" num="3.2.3" edition="-" />
        <vers prev="1" num="3.2.3" edition="-:windows" />
        <vers prev="1" num="3.2.3" edition="-:mac" />
        <vers prev="1" num="4.0_beta" edition="-" />
        <vers prev="1" num="4.0_beta" edition="-:mac" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1694" published="2009-06-10" name="CVE-2009-1694" modified="2011-02-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:N)" CVSS_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_base_score="5.8">
    <desc>
      <descript source="cve">WebKit in Apple Safari before 4.0, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch 1.1 through 2.2.1 does not properly handle redirects, which allows remote attackers to read images from arbitrary web sites via vectors involving a CANVAS element and redirection, related to a "cross-site image capture issue."</descript>
    </desc>
    <loss_types>
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2009/1522" source="VUPEN" patch="1" adv="1">ADV-2009-1522</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0212" source="VUPEN">ADV-2011-0212</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1621" source="VUPEN">ADV-2009-1621</ref>
      <ref url="http://www.securityfocus.com/bid/35322" source="BID">35322</ref>
      <ref url="http://www.securityfocus.com/bid/35260" source="BID">35260</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1950" source="DEBIAN">DSA-1950</ref>
      <ref url="http://support.apple.com/kb/HT3639" source="CONFIRM">http://support.apple.com/kb/HT3639</ref>
      <ref url="http://support.apple.com/kb/HT3613" source="CONFIRM" adv="1">http://support.apple.com/kb/HT3613</ref>
      <ref url="http://secunia.com/advisories/43068" source="SECUNIA">43068</ref>
      <ref url="http://secunia.com/advisories/37746" source="SECUNIA">37746</ref>
      <ref url="http://secunia.com/advisories/35379" source="SECUNIA" adv="1">35379</ref>
      <ref url="http://osvdb.org/55005" source="OSVDB">55005</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.html" source="SUSE">SUSE-SR:2011:002</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2009/Jun/msg00005.html" source="APPLE">APPLE-SA-2009-06-17-1</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2009/jun/msg00002.html" source="APPLE" adv="1">APPLE-SA-2009-06-08-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="safari">
        <vers num="0.8" edition="" />
        <vers num="0.8" edition=":mac" />
        <vers num="0.9" edition="" />
        <vers num="0.9" edition=":mac" />
        <vers num="1.0" edition="" />
        <vers num="1.0" edition=":mac" />
        <vers num="1.0.3" edition="" />
        <vers num="1.0.3" edition=":mac" />
        <vers num="1.1" edition="" />
        <vers num="1.1" edition=":mac" />
        <vers num="1.2" edition="" />
        <vers num="1.2" edition=":mac" />
        <vers num="1.3" edition="" />
        <vers num="1.3" edition=":mac" />
        <vers num="1.3.1" edition="" />
        <vers num="1.3.1" edition=":mac" />
        <vers num="1.3.2" edition="" />
        <vers num="1.3.2" edition=":mac" />
        <vers num="2.0" edition="" />
        <vers num="2.0" edition=":mac" />
        <vers num="2.0.2" edition="" />
        <vers num="2.0.2" edition=":mac" />
        <vers num="2.0.4" edition="" />
        <vers num="2.0.4" edition=":mac" />
        <vers num="3.0" edition="" />
        <vers num="3.0" edition=":windows" />
        <vers num="3.0" edition=":mac" />
        <vers num="3.0.1" edition="" />
        <vers num="3.0.1" edition=":windows" />
        <vers num="3.0.2" edition="" />
        <vers num="3.0.2" edition=":windows" />
        <vers num="3.0.2" edition="-" />
        <vers num="3.0.2" edition="-:mac" />
        <vers num="3.0.3" edition="" />
        <vers num="3.0.3" edition=":windows" />
        <vers num="3.0.3" edition=":mac" />
        <vers num="3.0.4" edition="" />
        <vers num="3.0.4" edition=":windows" />
        <vers num="3.0.4" edition=":mac" />
        <vers num="3.1" edition="" />
        <vers num="3.1" edition=":windows" />
        <vers num="3.1" edition=":mac" />
        <vers num="3.1.1" edition="" />
        <vers num="3.1.1" edition=":windows" />
        <vers num="3.1.1" edition=":mac" />
        <vers num="3.1.2" edition="" />
        <vers num="3.1.2" edition=":mac" />
        <vers num="3.1.2" edition=":windows" />
        <vers num="3.2" edition="-" />
        <vers num="3.2" edition="-:windows" />
        <vers num="3.2.1" edition="" />
        <vers num="3.2.1" edition=":mac" />
        <vers num="3.2.1" edition=":windows" />
        <vers num="3.2.2" edition="" />
        <vers num="3.2.2" edition=":windows" />
        <vers prev="1" num="3.2.3" edition="" />
        <vers prev="1" num="3.2.3" edition=":windows" />
        <vers prev="1" num="3.2.3" edition=":mac" />
        <vers prev="1" num="4.0_beta" edition="" />
        <vers prev="1" num="4.0_beta" edition=":mac" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1695" published="2009-06-10" name="CVE-2009-1695" modified="2011-02-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in WebKit in Apple Safari before 4.0, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch 1.1 through 2.2.1 allows remote attackers to inject arbitrary web script or HTML via vectors involving access to frame contents after completion of a page transition.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2009/1522" source="VUPEN" patch="1" adv="1">ADV-2009-1522</ref>
      <ref url="http://support.apple.com/kb/HT3613" source="CONFIRM" patch="1" adv="1">http://support.apple.com/kb/HT3613</ref>
      <ref url="http://securitytracker.com/id?1022344" source="SECTRACK" patch="1">1022344</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2009/jun/msg00002.html" source="APPLE" patch="1" adv="1">APPLE-SA-2009-06-08-1</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0212" source="VUPEN">ADV-2011-0212</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1621" source="VUPEN">ADV-2009-1621</ref>
      <ref url="http://www.securityfocus.com/bid/35328" source="BID">35328</ref>
      <ref url="http://www.securityfocus.com/bid/35260" source="BID">35260</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1950" source="DEBIAN">DSA-1950</ref>
      <ref url="http://support.apple.com/kb/HT3639" source="CONFIRM">http://support.apple.com/kb/HT3639</ref>
      <ref url="http://secunia.com/advisories/43068" source="SECUNIA">43068</ref>
      <ref url="http://secunia.com/advisories/37746" source="SECUNIA">37746</ref>
      <ref url="http://secunia.com/advisories/35379" source="SECUNIA" adv="1">35379</ref>
      <ref url="http://osvdb.org/54991" source="OSVDB">54991</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.html" source="SUSE">SUSE-SR:2011:002</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2009/Jun/msg00005.html" source="APPLE">APPLE-SA-2009-06-17-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="safari">
        <vers num="0.8" edition="" />
        <vers num="0.8" edition=":mac" />
        <vers num="0.9" edition="" />
        <vers num="0.9" edition=":mac" />
        <vers num="1.0" edition="" />
        <vers num="1.0" edition=":mac" />
        <vers num="1.0.3" edition="" />
        <vers num="1.0.3" edition=":mac" />
        <vers num="1.1" edition="" />
        <vers num="1.1" edition=":mac" />
        <vers num="1.2" edition="" />
        <vers num="1.2" edition=":mac" />
        <vers num="1.3" edition="" />
        <vers num="1.3" edition=":mac" />
        <vers num="1.3.1" edition="" />
        <vers num="1.3.1" edition=":mac" />
        <vers num="1.3.2" edition="" />
        <vers num="1.3.2" edition=":mac" />
        <vers num="2.0" edition="" />
        <vers num="2.0" edition=":mac" />
        <vers num="2.0.2" edition="" />
        <vers num="2.0.2" edition=":mac" />
        <vers num="2.0.4" edition="" />
        <vers num="2.0.4" edition=":mac" />
        <vers num="3.0" edition="" />
        <vers num="3.0" edition=":windows" />
        <vers num="3.0" edition=":mac" />
        <vers num="3.0.1" edition="" />
        <vers num="3.0.1" edition=":windows" />
        <vers num="3.0.2" edition="" />
        <vers num="3.0.2" edition=":windows" />
        <vers num="3.0.2" edition="-" />
        <vers num="3.0.2" edition="-:mac" />
        <vers num="3.0.3" edition="" />
        <vers num="3.0.3" edition=":windows" />
        <vers num="3.0.3" edition=":mac" />
        <vers num="3.0.4" edition="" />
        <vers num="3.0.4" edition=":windows" />
        <vers num="3.0.4" edition=":mac" />
        <vers num="3.1" edition="" />
        <vers num="3.1" edition=":windows" />
        <vers num="3.1" edition=":mac" />
        <vers num="3.1.1" edition="" />
        <vers num="3.1.1" edition=":windows" />
        <vers num="3.1.1" edition=":mac" />
        <vers num="3.1.2" edition="" />
        <vers num="3.1.2" edition=":mac" />
        <vers num="3.1.2" edition=":windows" />
        <vers num="3.2" edition="-" />
        <vers num="3.2" edition="-:windows" />
        <vers num="3.2.1" edition="" />
        <vers num="3.2.1" edition=":mac" />
        <vers num="3.2.1" edition=":windows" />
        <vers num="3.2.2" edition="" />
        <vers num="3.2.2" edition=":windows" />
        <vers prev="1" num="3.2.3" edition="" />
        <vers prev="1" num="3.2.3" edition=":windows" />
        <vers prev="1" num="3.2.3" edition=":mac" />
        <vers prev="1" num="4.0_beta" edition="" />
        <vers prev="1" num="4.0_beta" edition=":mac" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1696" published="2009-06-10" name="CVE-2009-1696" modified="2011-02-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">WebKit in Apple Safari before 4.0, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch 1.1 through 2.2.1 uses predictable random numbers in JavaScript applications, which makes it easier for remote web servers to track the behavior of a Safari user during a session.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2009/1522" source="VUPEN" patch="1" adv="1">ADV-2009-1522</ref>
      <ref url="http://support.apple.com/kb/HT3613" source="CONFIRM" patch="1" adv="1">http://support.apple.com/kb/HT3613</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2009/jun/msg00002.html" source="APPLE" patch="1" adv="1">APPLE-SA-2009-06-08-1</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0212" source="VUPEN">ADV-2011-0212</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1621" source="VUPEN">ADV-2009-1621</ref>
      <ref url="http://www.securityfocus.com/bid/35260" source="BID">35260</ref>
      <ref url="http://support.apple.com/kb/HT3639" source="CONFIRM">http://support.apple.com/kb/HT3639</ref>
      <ref url="http://secunia.com/advisories/43068" source="SECUNIA">43068</ref>
      <ref url="http://secunia.com/advisories/35379" source="SECUNIA" adv="1">35379</ref>
      <ref url="http://osvdb.org/55027" source="OSVDB">55027</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.html" source="SUSE">SUSE-SR:2011:002</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2009/Jun/msg00005.html" source="APPLE">APPLE-SA-2009-06-17-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="safari">
        <vers num="0.8" edition="" />
        <vers num="0.8" edition=":mac" />
        <vers num="0.9" edition="" />
        <vers num="0.9" edition=":mac" />
        <vers num="1.0" edition="" />
        <vers num="1.0" edition=":mac" />
        <vers num="1.0.3" edition="" />
        <vers num="1.0.3" edition=":mac" />
        <vers num="1.1" edition="" />
        <vers num="1.1" edition=":mac" />
        <vers num="1.2" edition="" />
        <vers num="1.2" edition=":mac" />
        <vers num="1.3" edition="" />
        <vers num="1.3" edition=":mac" />
        <vers num="1.3.1" edition="" />
        <vers num="1.3.1" edition=":mac" />
        <vers num="1.3.2" edition="" />
        <vers num="1.3.2" edition=":mac" />
        <vers num="2.0" edition="" />
        <vers num="2.0" edition=":mac" />
        <vers num="2.0.2" edition="" />
        <vers num="2.0.2" edition=":mac" />
        <vers num="2.0.4" edition="" />
        <vers num="2.0.4" edition=":mac" />
        <vers num="3.0" edition="" />
        <vers num="3.0" edition=":windows" />
        <vers num="3.0" edition=":mac" />
        <vers num="3.0.1" edition="" />
        <vers num="3.0.1" edition=":windows" />
        <vers num="3.0.2" edition="" />
        <vers num="3.0.2" edition=":windows" />
        <vers num="3.0.2" edition="-" />
        <vers num="3.0.2" edition="-:mac" />
        <vers num="3.0.3" edition="" />
        <vers num="3.0.3" edition=":windows" />
        <vers num="3.0.3" edition=":mac" />
        <vers num="3.0.4" edition="" />
        <vers num="3.0.4" edition=":windows" />
        <vers num="3.0.4" edition=":mac" />
        <vers num="3.1" edition="" />
        <vers num="3.1" edition=":windows" />
        <vers num="3.1" edition=":mac" />
        <vers num="3.1.1" edition="" />
        <vers num="3.1.1" edition=":windows" />
        <vers num="3.1.1" edition=":mac" />
        <vers num="3.1.2" edition="" />
        <vers num="3.1.2" edition=":mac" />
        <vers num="3.1.2" edition=":windows" />
        <vers num="3.2" edition="-" />
        <vers num="3.2" edition="-:windows" />
        <vers num="3.2.1" edition="" />
        <vers num="3.2.1" edition=":mac" />
        <vers num="3.2.1" edition=":windows" />
        <vers num="3.2.2" edition="" />
        <vers num="3.2.2" edition=":windows" />
        <vers prev="1" num="3.2.3" edition="" />
        <vers prev="1" num="3.2.3" edition=":windows" />
        <vers prev="1" num="3.2.3" edition=":mac" />
        <vers prev="1" num="4.0_beta" edition="" />
        <vers prev="1" num="4.0_beta" edition=":mac" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1697" published="2009-06-10" name="CVE-2009-1697" modified="2011-02-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">CRLF injection vulnerability in WebKit in Apple Safari before 4.0, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch 1.1 through 2.2.1 allows remote attackers to inject HTTP headers and bypass the Same Origin Policy via a crafted HTML document, related to cross-site scripting (XSS) attacks that depend on communication with arbitrary web sites on the same server through use of XMLHttpRequest without a Host header.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2009/1522" source="VUPEN" patch="1" adv="1">ADV-2009-1522</ref>
      <ref url="http://support.apple.com/kb/HT3613" source="CONFIRM" patch="1" adv="1">http://support.apple.com/kb/HT3613</ref>
      <ref url="http://securitytracker.com/id?1022344" source="SECTRACK" patch="1">1022344</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2009/jun/msg00002.html" source="APPLE" patch="1" adv="1">APPLE-SA-2009-06-08-1</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0212" source="VUPEN">ADV-2011-0212</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1621" source="VUPEN">ADV-2009-1621</ref>
      <ref url="http://www.securityfocus.com/bid/35260" source="BID">35260</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1950" source="DEBIAN">DSA-1950</ref>
      <ref url="http://support.apple.com/kb/HT3639" source="CONFIRM">http://support.apple.com/kb/HT3639</ref>
      <ref url="http://secunia.com/advisories/43068" source="SECUNIA">43068</ref>
      <ref url="http://secunia.com/advisories/37746" source="SECUNIA">37746</ref>
      <ref url="http://secunia.com/advisories/35379" source="SECUNIA" adv="1">35379</ref>
      <ref url="http://osvdb.org/54992" source="OSVDB">54992</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.html" source="SUSE">SUSE-SR:2011:002</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2009/Jun/msg00005.html" source="APPLE">APPLE-SA-2009-06-17-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="safari">
        <vers num="0.8" edition="" />
        <vers num="0.8" edition=":mac" />
        <vers num="0.9" edition="" />
        <vers num="0.9" edition=":mac" />
        <vers num="1.0" edition="" />
        <vers num="1.0" edition=":mac" />
        <vers num="1.0.3" edition="" />
        <vers num="1.0.3" edition=":mac" />
        <vers num="1.1" edition="" />
        <vers num="1.1" edition=":mac" />
        <vers num="1.2" edition="" />
        <vers num="1.2" edition=":mac" />
        <vers num="1.3" edition="" />
        <vers num="1.3" edition=":mac" />
        <vers num="1.3.1" edition="" />
        <vers num="1.3.1" edition=":mac" />
        <vers num="1.3.2" edition="" />
        <vers num="1.3.2" edition=":mac" />
        <vers num="2.0" edition="" />
        <vers num="2.0" edition=":mac" />
        <vers num="2.0.2" edition="" />
        <vers num="2.0.2" edition=":mac" />
        <vers num="2.0.4" edition="" />
        <vers num="2.0.4" edition=":mac" />
        <vers num="3.0" edition="" />
        <vers num="3.0" edition=":windows" />
        <vers num="3.0" edition=":mac" />
        <vers num="3.0.1" edition="" />
        <vers num="3.0.1" edition=":windows" />
        <vers num="3.0.2" edition="" />
        <vers num="3.0.2" edition=":windows" />
        <vers num="3.0.2" edition="-" />
        <vers num="3.0.2" edition="-:mac" />
        <vers num="3.0.3" edition="" />
        <vers num="3.0.3" edition=":windows" />
        <vers num="3.0.3" edition=":mac" />
        <vers num="3.0.4" edition="" />
        <vers num="3.0.4" edition=":windows" />
        <vers num="3.0.4" edition=":mac" />
        <vers num="3.1" edition="" />
        <vers num="3.1" edition=":windows" />
        <vers num="3.1" edition=":mac" />
        <vers num="3.1.1" edition="" />
        <vers num="3.1.1" edition=":windows" />
        <vers num="3.1.1" edition=":mac" />
        <vers num="3.1.2" edition="" />
        <vers num="3.1.2" edition=":mac" />
        <vers num="3.1.2" edition=":windows" />
        <vers num="3.2" edition="-" />
        <vers num="3.2" edition="-:windows" />
        <vers num="3.2.1" edition="" />
        <vers num="3.2.1" edition=":mac" />
        <vers num="3.2.1" edition=":windows" />
        <vers num="3.2.2" edition="" />
        <vers num="3.2.2" edition=":windows" />
        <vers prev="1" num="3.2.3" edition="" />
        <vers prev="1" num="3.2.3" edition=":windows" />
        <vers prev="1" num="3.2.3" edition=":mac" />
        <vers prev="1" num="4.0_beta" edition="" />
        <vers prev="1" num="4.0_beta" edition=":mac" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1698" published="2009-06-10" name="CVE-2009-1698" modified="2011-02-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">WebKit in Apple Safari before 4.0, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch 1.1 through 2.2.1 does not initialize a pointer during handling of a Cascading Style Sheets (CSS) attr function call with a large numerical argument, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted HTML document.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.zerodayinitiative.com/advisories/ZDI-09-032/" source="MISC" patch="1">http://www.zerodayinitiative.com/advisories/ZDI-09-032/</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1522" source="VUPEN" patch="1" adv="1">ADV-2009-1522</ref>
      <ref url="http://support.apple.com/kb/HT3613" source="CONFIRM" patch="1" adv="1">http://support.apple.com/kb/HT3613</ref>
      <ref url="http://securitytracker.com/id?1022345" source="SECTRACK" patch="1">1022345</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2009/jun/msg00002.html" source="APPLE" patch="1" adv="1">APPLE-SA-2009-06-08-1</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-July/msg01200.html" source="FEDORA">FEDORA-2009-8020</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-July/msg01199.html" source="FEDORA">FEDORA-2009-8046</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-July/msg01196.html" source="FEDORA">FEDORA-2009-8049</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-July/msg01177.html" source="FEDORA">FEDORA-2009-8039</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0212" source="VUPEN">ADV-2011-0212</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1621" source="VUPEN">ADV-2009-1621</ref>
      <ref url="http://www.ubuntu.com/usn/USN-857-1" source="UBUNTU">USN-857-1</ref>
      <ref url="http://www.ubuntu.com/usn/USN-836-1" source="UBUNTU">USN-836-1</ref>
      <ref url="http://www.ubuntu.com/usn/USN-822-1" source="UBUNTU">USN-822-1</ref>
      <ref url="http://www.securityfocus.com/bid/35318" source="BID">35318</ref>
      <ref url="http://www.securityfocus.com/bid/35260" source="BID">35260</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/504295/100/0/threaded" source="BUGTRAQ">20090614 [TZO-37-2009] Apple Safari &lt;v4 Remote code execution</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/504173/100/0/threaded" source="BUGTRAQ">20090608 ZDI-09-032: Apple WebKit attr() Invalid Attribute Memory Corruption Vulnerability</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-1128.html" source="REDHAT">RHSA-2009:1128</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:330" source="MANDRIVA">MDVSA-2009:330</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1950" source="DEBIAN">DSA-1950</ref>
      <ref url="http://support.apple.com/kb/HT3639" source="CONFIRM">http://support.apple.com/kb/HT3639</ref>
      <ref url="http://secunia.com/advisories/43068" source="SECUNIA">43068</ref>
      <ref url="http://secunia.com/advisories/37746" source="SECUNIA">37746</ref>
      <ref url="http://secunia.com/advisories/36790" source="SECUNIA">36790</ref>
      <ref url="http://secunia.com/advisories/36062" source="SECUNIA">36062</ref>
      <ref url="http://secunia.com/advisories/36057" source="SECUNIA">36057</ref>
      <ref url="http://secunia.com/advisories/35588" source="SECUNIA">35588</ref>
      <ref url="http://secunia.com/advisories/35379" source="SECUNIA" adv="1">35379</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9484" source="OVAL">oval:org.mitre.oval:def:9484</ref>
      <ref url="http://osvdb.org/55006" source="OSVDB">55006</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.html" source="SUSE">SUSE-SR:2011:002</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2009/Jun/msg00005.html" source="APPLE">APPLE-SA-2009-06-17-1</ref>
      <ref url="http://blog.zoller.lu/2009/05/advisory-apple-safari-remote-code.html" source="MISC">http://blog.zoller.lu/2009/05/advisory-apple-safari-remote-code.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="safari">
        <vers num="0.8" edition="" />
        <vers num="0.8" edition=":mac" />
        <vers num="0.9" edition="" />
        <vers num="0.9" edition=":mac" />
        <vers num="1.0" edition="" />
        <vers num="1.0" edition=":mac" />
        <vers num="1.0.3" edition="" />
        <vers num="1.0.3" edition=":mac" />
        <vers num="1.1" edition="" />
        <vers num="1.1" edition=":mac" />
        <vers num="1.2" edition="" />
        <vers num="1.2" edition=":mac" />
        <vers num="1.3" edition="" />
        <vers num="1.3" edition=":mac" />
        <vers num="1.3.1" edition="" />
        <vers num="1.3.1" edition=":mac" />
        <vers num="1.3.2" edition="" />
        <vers num="1.3.2" edition=":mac" />
        <vers num="2.0" edition="" />
        <vers num="2.0" edition=":mac" />
        <vers num="2.0.2" edition="" />
        <vers num="2.0.2" edition=":mac" />
        <vers num="2.0.4" edition="" />
        <vers num="2.0.4" edition=":mac" />
        <vers num="3.0" edition="" />
        <vers num="3.0" edition=":windows" />
        <vers num="3.0" edition=":mac" />
        <vers num="3.0.1" edition="" />
        <vers num="3.0.1" edition=":windows" />
        <vers num="3.0.2" edition="" />
        <vers num="3.0.2" edition=":windows" />
        <vers num="3.0.2" edition="-" />
        <vers num="3.0.2" edition="-:mac" />
        <vers num="3.0.3" edition="" />
        <vers num="3.0.3" edition=":windows" />
        <vers num="3.0.3" edition=":mac" />
        <vers num="3.0.4" edition="" />
        <vers num="3.0.4" edition=":windows" />
        <vers num="3.0.4" edition=":mac" />
        <vers num="3.1" edition="" />
        <vers num="3.1" edition=":windows" />
        <vers num="3.1" edition=":mac" />
        <vers num="3.1.1" edition="" />
        <vers num="3.1.1" edition=":windows" />
        <vers num="3.1.1" edition=":mac" />
        <vers num="3.1.2" edition="" />
        <vers num="3.1.2" edition=":mac" />
        <vers num="3.1.2" edition=":windows" />
        <vers num="3.2" edition="-" />
        <vers num="3.2" edition="-:windows" />
        <vers num="3.2.1" edition="" />
        <vers num="3.2.1" edition=":mac" />
        <vers num="3.2.1" edition=":windows" />
        <vers num="3.2.2" edition="" />
        <vers num="3.2.2" edition=":windows" />
        <vers prev="1" num="3.2.3" edition="" />
        <vers prev="1" num="3.2.3" edition=":windows" />
        <vers prev="1" num="3.2.3" edition=":mac" />
        <vers prev="1" num="4.0_beta" edition="" />
        <vers prev="1" num="4.0_beta" edition=":mac" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1699" published="2009-06-10" name="CVE-2009-1699" modified="2011-02-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:N/A:N)" CVSS_score="7.1" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="8.6" CVSS_base_score="7.1">
    <desc>
      <descript source="cve">The XSL stylesheet implementation in WebKit in Apple Safari before 4.0, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch 1.1 through 2.2.1 does not properly handle XML external entities, which allows remote attackers to read arbitrary files via a crafted DTD, as demonstrated by a file:///etc/passwd URL in an entity declaration, related to an "XXE attack."</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2009/1522" source="VUPEN" patch="1" adv="1">ADV-2009-1522</ref>
      <ref url="http://support.apple.com/kb/HT3613" source="CONFIRM" patch="1" adv="1">http://support.apple.com/kb/HT3613</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2009/jun/msg00002.html" source="APPLE" patch="1" adv="1">APPLE-SA-2009-06-08-1</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0212" source="VUPEN">ADV-2011-0212</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1621" source="VUPEN">ADV-2009-1621</ref>
      <ref url="http://www.ubuntu.com/usn/USN-857-1" source="UBUNTU">USN-857-1</ref>
      <ref url="http://www.securityfocus.com/bid/35321" source="BID">35321</ref>
      <ref url="http://www.securityfocus.com/bid/35260" source="BID">35260</ref>
      <ref url="http://www.milw0rm.com/exploits/8907" source="MILW0RM">8907</ref>
      <ref url="http://support.apple.com/kb/HT3639" source="CONFIRM">http://support.apple.com/kb/HT3639</ref>
      <ref url="http://secunia.com/advisories/43068" source="SECUNIA">43068</ref>
      <ref url="http://secunia.com/advisories/35379" source="SECUNIA" adv="1">35379</ref>
      <ref url="http://scarybeastsecurity.blogspot.com/2009/06/apples-safari-4-fixes-local-file-theft.html" source="MISC">http://scarybeastsecurity.blogspot.com/2009/06/apples-safari-4-fixes-local-file-theft.html</ref>
      <ref url="http://scary.beasts.org/security/CESA-2009-006.html" source="MISC">http://scary.beasts.org/security/CESA-2009-006.html</ref>
      <ref url="http://osvdb.org/54972" source="OSVDB">54972</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.html" source="SUSE">SUSE-SR:2011:002</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2009/Jun/msg00005.html" source="APPLE">APPLE-SA-2009-06-17-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="safari">
        <vers num="0.8" edition="" />
        <vers num="0.8" edition=":mac" />
        <vers num="0.9" edition="" />
        <vers num="0.9" edition=":mac" />
        <vers num="1.0" edition="" />
        <vers num="1.0" edition=":mac" />
        <vers num="1.0.3" edition="" />
        <vers num="1.0.3" edition=":mac" />
        <vers num="1.1" edition="" />
        <vers num="1.1" edition=":mac" />
        <vers num="1.2" edition="" />
        <vers num="1.2" edition=":mac" />
        <vers num="1.3" edition="" />
        <vers num="1.3" edition=":mac" />
        <vers num="1.3.1" edition="" />
        <vers num="1.3.1" edition=":mac" />
        <vers num="1.3.2" edition="" />
        <vers num="1.3.2" edition=":mac" />
        <vers num="2.0" edition="" />
        <vers num="2.0" edition=":mac" />
        <vers num="2.0.2" edition="" />
        <vers num="2.0.2" edition=":mac" />
        <vers num="2.0.4" edition="" />
        <vers num="2.0.4" edition=":mac" />
        <vers num="3.0" edition="" />
        <vers num="3.0" edition=":windows" />
        <vers num="3.0" edition=":mac" />
        <vers num="3.0.1" edition="" />
        <vers num="3.0.1" edition=":windows" />
        <vers num="3.0.2" edition="" />
        <vers num="3.0.2" edition=":windows" />
        <vers num="3.0.2" edition="-" />
        <vers num="3.0.2" edition="-:mac" />
        <vers num="3.0.3" edition="" />
        <vers num="3.0.3" edition=":windows" />
        <vers num="3.0.3" edition=":mac" />
        <vers num="3.0.4" edition="" />
        <vers num="3.0.4" edition=":windows" />
        <vers num="3.0.4" edition=":mac" />
        <vers num="3.1" edition="" />
        <vers num="3.1" edition=":windows" />
        <vers num="3.1" edition=":mac" />
        <vers num="3.1.1" edition="" />
        <vers num="3.1.1" edition=":windows" />
        <vers num="3.1.1" edition=":mac" />
        <vers num="3.1.2" edition="" />
        <vers num="3.1.2" edition=":mac" />
        <vers num="3.1.2" edition=":windows" />
        <vers num="3.2" edition="-" />
        <vers num="3.2" edition="-:windows" />
        <vers num="3.2.1" edition="" />
        <vers num="3.2.1" edition=":mac" />
        <vers num="3.2.1" edition=":windows" />
        <vers num="3.2.2" edition="" />
        <vers num="3.2.2" edition=":windows" />
        <vers prev="1" num="3.2.3" edition="" />
        <vers prev="1" num="3.2.3" edition=":windows" />
        <vers prev="1" num="3.2.3" edition=":mac" />
        <vers prev="1" num="4.0_beta" edition="" />
        <vers prev="1" num="4.0_beta" edition=":mac" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1700" published="2009-06-10" name="CVE-2009-1700" modified="2011-02-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">The XSLT implementation in WebKit in Apple Safari before 4.0, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch 1.1 through 2.2.1 does not properly handle redirects, which allows remote attackers to read XML content from arbitrary web pages via a crafted document.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2009/1522" source="VUPEN" patch="1" adv="1">ADV-2009-1522</ref>
      <ref url="http://support.apple.com/kb/HT3613" source="CONFIRM" patch="1" adv="1">http://support.apple.com/kb/HT3613</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2009/jun/msg00002.html" source="APPLE" patch="1" adv="1">APPLE-SA-2009-06-08-1</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0212" source="VUPEN">ADV-2011-0212</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1621" source="VUPEN">ADV-2009-1621</ref>
      <ref url="http://www.securityfocus.com/bid/35260" source="BID">35260</ref>
      <ref url="http://support.apple.com/kb/HT3639" source="CONFIRM">http://support.apple.com/kb/HT3639</ref>
      <ref url="http://secunia.com/advisories/43068" source="SECUNIA">43068</ref>
      <ref url="http://secunia.com/advisories/35379" source="SECUNIA" adv="1">35379</ref>
      <ref url="http://osvdb.org/54973" source="OSVDB">54973</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.html" source="SUSE">SUSE-SR:2011:002</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2009/Jun/msg00005.html" source="APPLE">APPLE-SA-2009-06-17-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="safari">
        <vers num="0.8" edition="" />
        <vers num="0.8" edition=":mac" />
        <vers num="0.9" edition="" />
        <vers num="0.9" edition=":mac" />
        <vers num="1.0" edition="" />
        <vers num="1.0" edition=":mac" />
        <vers num="1.0.3" edition="" />
        <vers num="1.0.3" edition=":mac" />
        <vers num="1.1" edition="" />
        <vers num="1.1" edition=":mac" />
        <vers num="1.2" edition="" />
        <vers num="1.2" edition=":mac" />
        <vers num="1.3" edition="" />
        <vers num="1.3" edition=":mac" />
        <vers num="1.3.1" edition="" />
        <vers num="1.3.1" edition=":mac" />
        <vers num="1.3.2" edition="" />
        <vers num="1.3.2" edition=":mac" />
        <vers num="2.0" edition="" />
        <vers num="2.0" edition=":mac" />
        <vers num="2.0.2" edition="" />
        <vers num="2.0.2" edition=":mac" />
        <vers num="2.0.4" edition="" />
        <vers num="2.0.4" edition=":mac" />
        <vers num="3.0" edition="" />
        <vers num="3.0" edition=":windows" />
        <vers num="3.0" edition=":mac" />
        <vers num="3.0.1" edition="" />
        <vers num="3.0.1" edition=":windows" />
        <vers num="3.0.2" edition="" />
        <vers num="3.0.2" edition=":windows" />
        <vers num="3.0.2" edition="-" />
        <vers num="3.0.2" edition="-:mac" />
        <vers num="3.0.3" edition="" />
        <vers num="3.0.3" edition=":windows" />
        <vers num="3.0.3" edition=":mac" />
        <vers num="3.0.4" edition="" />
        <vers num="3.0.4" edition=":windows" />
        <vers num="3.0.4" edition=":mac" />
        <vers num="3.1" edition="" />
        <vers num="3.1" edition=":windows" />
        <vers num="3.1" edition=":mac" />
        <vers num="3.1.1" edition="" />
        <vers num="3.1.1" edition=":windows" />
        <vers num="3.1.1" edition=":mac" />
        <vers num="3.1.2" edition="" />
        <vers num="3.1.2" edition=":mac" />
        <vers num="3.1.2" edition=":windows" />
        <vers num="3.2" edition="-" />
        <vers num="3.2" edition="-:windows" />
        <vers num="3.2.1" edition="" />
        <vers num="3.2.1" edition=":mac" />
        <vers num="3.2.1" edition=":windows" />
        <vers num="3.2.2" edition="" />
        <vers num="3.2.2" edition=":windows" />
        <vers prev="1" num="3.2.3" edition="" />
        <vers prev="1" num="3.2.3" edition=":windows" />
        <vers prev="1" num="3.2.3" edition=":mac" />
        <vers prev="1" num="4.0_beta" edition="" />
        <vers prev="1" num="4.0_beta" edition=":mac" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1701" published="2009-06-10" name="CVE-2009-1701" modified="2011-02-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Use-after-free vulnerability in the JavaScript DOM implementation in WebKit in Apple Safari before 4.0, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch 1.1 through 2.2.1 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) by destroying a document.body element that has an unspecified XML container with elements that support the dir attribute.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.zerodayinitiative.com/advisories/ZDI-09-033/" source="MISC" patch="1">http://www.zerodayinitiative.com/advisories/ZDI-09-033/</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1522" source="VUPEN" patch="1" adv="1">ADV-2009-1522</ref>
      <ref url="http://support.apple.com/kb/HT3613" source="CONFIRM" patch="1" adv="1">http://support.apple.com/kb/HT3613</ref>
      <ref url="http://securitytracker.com/id?1022345" source="SECTRACK" patch="1">1022345</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2009/jun/msg00002.html" source="APPLE" patch="1" adv="1">APPLE-SA-2009-06-08-1</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0212" source="VUPEN">ADV-2011-0212</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1621" source="VUPEN">ADV-2009-1621</ref>
      <ref url="http://www.securityfocus.com/bid/35325" source="BID">35325</ref>
      <ref url="http://www.securityfocus.com/bid/35260" source="BID">35260</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/504172/100/0/threaded" source="BUGTRAQ">20090608 ZDI-09-033: Apple WebKit dir Attribute Freeing Dangling Object Pointer Vulnerability</ref>
      <ref url="http://support.apple.com/kb/HT3639" source="CONFIRM">http://support.apple.com/kb/HT3639</ref>
      <ref url="http://secunia.com/advisories/43068" source="SECUNIA">43068</ref>
      <ref url="http://secunia.com/advisories/35379" source="SECUNIA" adv="1">35379</ref>
      <ref url="http://osvdb.org/55008" source="OSVDB">55008</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.html" source="SUSE">SUSE-SR:2011:002</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2009/Jun/msg00005.html" source="APPLE">APPLE-SA-2009-06-17-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="safari">
        <vers num="0.8" edition="" />
        <vers num="0.8" edition=":mac" />
        <vers num="0.9" edition="" />
        <vers num="0.9" edition=":mac" />
        <vers num="1.0" edition="" />
        <vers num="1.0" edition=":mac" />
        <vers num="1.0.3" edition="" />
        <vers num="1.0.3" edition=":mac" />
        <vers num="1.1" edition="" />
        <vers num="1.1" edition=":mac" />
        <vers num="1.2" edition="" />
        <vers num="1.2" edition=":mac" />
        <vers num="1.3" edition="" />
        <vers num="1.3" edition=":mac" />
        <vers num="1.3.1" edition="" />
        <vers num="1.3.1" edition=":mac" />
        <vers num="1.3.2" edition="" />
        <vers num="1.3.2" edition=":mac" />
        <vers num="2.0" edition="" />
        <vers num="2.0" edition=":mac" />
        <vers num="2.0.2" edition="" />
        <vers num="2.0.2" edition=":mac" />
        <vers num="2.0.4" edition="" />
        <vers num="2.0.4" edition=":mac" />
        <vers num="3.0" edition="" />
        <vers num="3.0" edition=":windows" />
        <vers num="3.0" edition=":mac" />
        <vers num="3.0.1" edition="" />
        <vers num="3.0.1" edition=":windows" />
        <vers num="3.0.2" edition="" />
        <vers num="3.0.2" edition=":windows" />
        <vers num="3.0.2" edition="-" />
        <vers num="3.0.2" edition="-:mac" />
        <vers num="3.0.3" edition="" />
        <vers num="3.0.3" edition=":windows" />
        <vers num="3.0.3" edition=":mac" />
        <vers num="3.0.4" edition="" />
        <vers num="3.0.4" edition=":windows" />
        <vers num="3.0.4" edition=":mac" />
        <vers num="3.1" edition="" />
        <vers num="3.1" edition=":windows" />
        <vers num="3.1" edition=":mac" />
        <vers num="3.1.1" edition="" />
        <vers num="3.1.1" edition=":windows" />
        <vers num="3.1.1" edition=":mac" />
        <vers num="3.1.2" edition="" />
        <vers num="3.1.2" edition=":mac" />
        <vers num="3.1.2" edition=":windows" />
        <vers num="3.2" edition="-" />
        <vers num="3.2" edition="-:windows" />
        <vers num="3.2.1" edition="" />
        <vers num="3.2.1" edition=":mac" />
        <vers num="3.2.1" edition=":windows" />
        <vers num="3.2.2" edition="" />
        <vers num="3.2.2" edition=":windows" />
        <vers prev="1" num="3.2.3" edition="" />
        <vers prev="1" num="3.2.3" edition=":windows" />
        <vers prev="1" num="3.2.3" edition=":mac" />
        <vers prev="1" num="4.0_beta" edition="" />
        <vers prev="1" num="4.0_beta" edition=":mac" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1702" published="2009-06-10" name="CVE-2009-1702" modified="2011-02-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in WebKit in Apple Safari before 4.0, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch 1.1 through 2.2.1 allows remote attackers to inject arbitrary web script or HTML via vectors related to improper handling of Location and History objects.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2009/1522" source="VUPEN" patch="1" adv="1">ADV-2009-1522</ref>
      <ref url="http://support.apple.com/kb/HT3613" source="CONFIRM" patch="1" adv="1">http://support.apple.com/kb/HT3613</ref>
      <ref url="http://securitytracker.com/id?1022344" source="SECTRACK" patch="1">1022344</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2009/jun/msg00002.html" source="APPLE" patch="1" adv="1">APPLE-SA-2009-06-08-1</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0212" source="VUPEN">ADV-2011-0212</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1621" source="VUPEN">ADV-2009-1621</ref>
      <ref url="http://www.securityfocus.com/bid/35327" source="BID">35327</ref>
      <ref url="http://www.securityfocus.com/bid/35260" source="BID">35260</ref>
      <ref url="http://support.apple.com/kb/HT3639" source="CONFIRM">http://support.apple.com/kb/HT3639</ref>
      <ref url="http://secunia.com/advisories/43068" source="SECUNIA">43068</ref>
      <ref url="http://secunia.com/advisories/35379" source="SECUNIA" adv="1">35379</ref>
      <ref url="http://osvdb.org/54993" source="OSVDB">54993</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.html" source="SUSE">SUSE-SR:2011:002</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2009/Jun/msg00005.html" source="APPLE">APPLE-SA-2009-06-17-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="safari">
        <vers num="0.8" edition="" />
        <vers num="0.8" edition=":mac" />
        <vers num="0.9" edition="" />
        <vers num="0.9" edition=":mac" />
        <vers num="1.0" edition="" />
        <vers num="1.0" edition=":mac" />
        <vers num="1.0.3" edition="" />
        <vers num="1.0.3" edition=":mac" />
        <vers num="1.1" edition="" />
        <vers num="1.1" edition=":mac" />
        <vers num="1.2" edition="" />
        <vers num="1.2" edition=":mac" />
        <vers num="1.3" edition="" />
        <vers num="1.3" edition=":mac" />
        <vers num="1.3.1" edition="" />
        <vers num="1.3.1" edition=":mac" />
        <vers num="1.3.2" edition="" />
        <vers num="1.3.2" edition=":mac" />
        <vers num="2.0" edition="" />
        <vers num="2.0" edition=":mac" />
        <vers num="2.0.2" edition="" />
        <vers num="2.0.2" edition=":mac" />
        <vers num="2.0.4" edition="" />
        <vers num="2.0.4" edition=":mac" />
        <vers num="3.0" edition="" />
        <vers num="3.0" edition=":windows" />
        <vers num="3.0" edition=":mac" />
        <vers num="3.0.1" edition="" />
        <vers num="3.0.1" edition=":windows" />
        <vers num="3.0.2" edition="" />
        <vers num="3.0.2" edition=":windows" />
        <vers num="3.0.2" edition="-" />
        <vers num="3.0.2" edition="-:mac" />
        <vers num="3.0.3" edition="" />
        <vers num="3.0.3" edition=":windows" />
        <vers num="3.0.3" edition=":mac" />
        <vers num="3.0.4" edition="" />
        <vers num="3.0.4" edition=":windows" />
        <vers num="3.0.4" edition=":mac" />
        <vers num="3.1" edition="" />
        <vers num="3.1" edition=":windows" />
        <vers num="3.1" edition=":mac" />
        <vers num="3.1.1" edition="" />
        <vers num="3.1.1" edition=":windows" />
        <vers num="3.1.1" edition=":mac" />
        <vers num="3.1.2" edition="" />
        <vers num="3.1.2" edition=":mac" />
        <vers num="3.1.2" edition=":windows" />
        <vers num="3.2" edition="-" />
        <vers num="3.2" edition="-:windows" />
        <vers num="3.2.1" edition="" />
        <vers num="3.2.1" edition=":mac" />
        <vers num="3.2.1" edition=":windows" />
        <vers num="3.2.2" edition="" />
        <vers num="3.2.2" edition=":windows" />
        <vers prev="1" num="3.2.3" edition="" />
        <vers prev="1" num="3.2.3" edition=":windows" />
        <vers prev="1" num="3.2.3" edition=":mac" />
        <vers prev="1" num="4.0_beta" edition="" />
        <vers prev="1" num="4.0_beta" edition=":mac" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1703" published="2009-06-10" name="CVE-2009-1703" modified="2011-02-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:N/A:N)" CVSS_score="7.1" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="8.6" CVSS_base_score="7.1">
    <desc>
      <descript source="cve">WebKit in Apple Safari before 4.0 does not prevent references to file: URLs within (1) audio and (2) video elements, which allows remote attackers to determine the existence of arbitrary files via a crafted HTML document.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2009/1522" source="VUPEN" patch="1" adv="1">ADV-2009-1522</ref>
      <ref url="http://support.apple.com/kb/HT3613" source="CONFIRM" patch="1" adv="1">http://support.apple.com/kb/HT3613</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2009/jun/msg00002.html" source="APPLE" patch="1" adv="1">APPLE-SA-2009-06-08-1</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0212" source="VUPEN">ADV-2011-0212</ref>
      <ref url="http://www.securityfocus.com/bid/35333" source="BID">35333</ref>
      <ref url="http://www.securityfocus.com/bid/35260" source="BID">35260</ref>
      <ref url="http://secunia.com/advisories/43068" source="SECUNIA">43068</ref>
      <ref url="http://secunia.com/advisories/35379" source="SECUNIA" adv="1">35379</ref>
      <ref url="http://osvdb.org/55009" source="OSVDB">55009</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.html" source="SUSE">SUSE-SR:2011:002</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="safari">
        <vers num="0.8" edition="" />
        <vers num="0.8" edition=":mac" />
        <vers num="0.9" edition="" />
        <vers num="0.9" edition=":mac" />
        <vers num="1.0" edition="" />
        <vers num="1.0" edition=":mac" />
        <vers num="1.0.3" edition="" />
        <vers num="1.0.3" edition=":mac" />
        <vers num="1.1" edition="" />
        <vers num="1.1" edition=":mac" />
        <vers num="1.2" edition="" />
        <vers num="1.2" edition=":mac" />
        <vers num="1.3" edition="" />
        <vers num="1.3" edition=":mac" />
        <vers num="1.3.1" edition="" />
        <vers num="1.3.1" edition=":mac" />
        <vers num="1.3.2" edition="" />
        <vers num="1.3.2" edition=":mac" />
        <vers num="2.0" edition="" />
        <vers num="2.0" edition=":mac" />
        <vers num="2.0.2" edition="" />
        <vers num="2.0.2" edition=":mac" />
        <vers num="2.0.4" edition="" />
        <vers num="2.0.4" edition=":mac" />
        <vers num="3.0" edition="" />
        <vers num="3.0" edition=":windows" />
        <vers num="3.0" edition=":mac" />
        <vers num="3.0.1" edition="" />
        <vers num="3.0.1" edition=":windows" />
        <vers num="3.0.2" edition="" />
        <vers num="3.0.2" edition=":windows" />
        <vers num="3.0.2" edition="-" />
        <vers num="3.0.2" edition="-:mac" />
        <vers num="3.0.3" edition="" />
        <vers num="3.0.3" edition=":windows" />
        <vers num="3.0.3" edition=":mac" />
        <vers num="3.0.4" edition="" />
        <vers num="3.0.4" edition=":windows" />
        <vers num="3.0.4" edition=":mac" />
        <vers num="3.1" edition="" />
        <vers num="3.1" edition=":windows" />
        <vers num="3.1" edition=":mac" />
        <vers num="3.1.1" edition="" />
        <vers num="3.1.1" edition=":windows" />
        <vers num="3.1.1" edition=":mac" />
        <vers num="3.1.2" edition="" />
        <vers num="3.1.2" edition=":mac" />
        <vers num="3.1.2" edition=":windows" />
        <vers num="3.2" edition="-" />
        <vers num="3.2" edition="-:windows" />
        <vers num="3.2.1" edition="" />
        <vers num="3.2.1" edition=":mac" />
        <vers num="3.2.1" edition=":windows" />
        <vers num="3.2.2" edition="" />
        <vers num="3.2.2" edition=":windows" />
        <vers prev="1" num="3.2.3" edition="" />
        <vers prev="1" num="3.2.3" edition=":windows" />
        <vers prev="1" num="3.2.3" edition=":mac" />
        <vers prev="1" num="4.0_beta" edition="" />
        <vers prev="1" num="4.0_beta" edition=":mac" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1704" published="2009-06-10" name="CVE-2009-1704" modified="2009-06-19" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">CFNetwork in Apple Safari before 4.0 misinterprets downloaded image files as local HTML documents in unspecified circumstances, which allows remote attackers to execute arbitrary JavaScript code by placing it in an image file.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2009/1522" source="VUPEN" patch="1" adv="1">ADV-2009-1522</ref>
      <ref url="http://support.apple.com/kb/HT3613" source="CONFIRM" patch="1" adv="1">http://support.apple.com/kb/HT3613</ref>
      <ref url="http://securitytracker.com/id?1022343" source="SECTRACK" patch="1">1022343</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2009/jun/msg00002.html" source="APPLE" patch="1" adv="1">APPLE-SA-2009-06-08-1</ref>
      <ref url="http://www.securityfocus.com/bid/35344" source="BID">35344</ref>
      <ref url="http://www.securityfocus.com/bid/35260" source="BID">35260</ref>
      <ref url="http://secunia.com/advisories/35379" source="SECUNIA" adv="1">35379</ref>
      <ref url="http://osvdb.org/55010" source="OSVDB">55010</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="safari">
        <vers num="0.8" edition="" />
        <vers num="0.8" edition=":mac" />
        <vers num="0.9" edition="" />
        <vers num="0.9" edition=":mac" />
        <vers num="1.0" edition="" />
        <vers num="1.0" edition=":mac" />
        <vers num="1.0.3" edition="" />
        <vers num="1.0.3" edition=":mac" />
        <vers num="1.1" edition="" />
        <vers num="1.1" edition=":mac" />
        <vers num="1.2" edition="" />
        <vers num="1.2" edition=":mac" />
        <vers num="1.3" edition="" />
        <vers num="1.3" edition=":mac" />
        <vers num="1.3.1" edition="" />
        <vers num="1.3.1" edition=":mac" />
        <vers num="1.3.2" edition="" />
        <vers num="1.3.2" edition=":mac" />
        <vers num="2.0" edition="" />
        <vers num="2.0" edition=":mac" />
        <vers num="2.0.2" edition="" />
        <vers num="2.0.2" edition=":mac" />
        <vers num="2.0.4" edition="" />
        <vers num="2.0.4" edition=":mac" />
        <vers num="3.0" edition="" />
        <vers num="3.0" edition=":windows" />
        <vers num="3.0" edition=":mac" />
        <vers num="3.0.1" edition="" />
        <vers num="3.0.1" edition=":windows" />
        <vers num="3.0.2" edition="" />
        <vers num="3.0.2" edition=":windows" />
        <vers num="3.0.2" edition="-" />
        <vers num="3.0.2" edition="-:mac" />
        <vers num="3.0.3" edition="" />
        <vers num="3.0.3" edition=":windows" />
        <vers num="3.0.3" edition=":mac" />
        <vers num="3.0.4" edition="" />
        <vers num="3.0.4" edition=":windows" />
        <vers num="3.0.4" edition=":mac" />
        <vers num="3.1" edition="" />
        <vers num="3.1" edition=":windows" />
        <vers num="3.1" edition=":mac" />
        <vers num="3.1.1" edition="" />
        <vers num="3.1.1" edition=":windows" />
        <vers num="3.1.1" edition=":mac" />
        <vers num="3.1.2" edition="" />
        <vers num="3.1.2" edition=":mac" />
        <vers num="3.1.2" edition=":windows" />
        <vers num="3.2" edition="-" />
        <vers num="3.2" edition="-:windows" />
        <vers num="3.2.1" edition="" />
        <vers num="3.2.1" edition=":mac" />
        <vers num="3.2.1" edition=":windows" />
        <vers num="3.2.2" edition="" />
        <vers num="3.2.2" edition=":windows" />
        <vers prev="1" num="3.2.3" edition="" />
        <vers prev="1" num="3.2.3" edition=":windows" />
        <vers prev="1" num="3.2.3" edition=":mac" />
        <vers prev="1" num="4.0_beta" edition="" />
        <vers prev="1" num="4.0_beta" edition=":mac" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1705" published="2009-06-10" name="CVE-2009-1705" modified="2009-06-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">CoreGraphics in Apple Safari before 4.0 on Windows does not properly use arithmetic during automatic hinting of TrueType fonts, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via crafted font data.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2009/1522" source="VUPEN" patch="1" adv="1">ADV-2009-1522</ref>
      <ref url="http://www.securityfocus.com/bid/35260" source="BID" patch="1">35260</ref>
      <ref url="http://support.apple.com/kb/HT3613" source="CONFIRM" patch="1" adv="1">http://support.apple.com/kb/HT3613</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2009/jun/msg00002.html" source="APPLE" patch="1" adv="1">APPLE-SA-2009-06-08-1</ref>
      <ref url="http://www.securityfocus.com/bid/35308" source="BID">35308</ref>
      <ref url="http://secunia.com/advisories/35379" source="SECUNIA" adv="1">35379</ref>
      <ref url="http://osvdb.org/54974" source="OSVDB">54974</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="safari">
        <vers num="3.0" edition="-" />
        <vers num="3.0" edition="-:windows" />
        <vers num="3.0.1" edition="-" />
        <vers num="3.0.1" edition="-:windows" />
        <vers num="3.0.2" edition="-" />
        <vers num="3.0.2" edition="-:windows" />
        <vers num="3.0.3" edition="-" />
        <vers num="3.0.3" edition="-:windows" />
        <vers num="3.0.4" edition="-" />
        <vers num="3.0.4" edition="-:windows" />
        <vers num="3.1" edition="-" />
        <vers num="3.1" edition="-:windows" />
        <vers num="3.1.1" edition="-" />
        <vers num="3.1.1" edition="-:windows" />
        <vers num="3.1.2" edition="-" />
        <vers num="3.1.2" edition="-:windows" />
        <vers num="3.2" edition="-" />
        <vers num="3.2" edition="-:windows" />
        <vers num="3.2.1" edition="-" />
        <vers num="3.2.1" edition="-:windows" />
        <vers num="3.2.2" edition="-" />
        <vers num="3.2.2" edition="-:windows" />
        <vers prev="1" num="3.2.3" edition="-" />
        <vers prev="1" num="3.2.3" edition="-:windows" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1706" published="2009-06-10" name="CVE-2009-1706" modified="2009-06-19" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The Private Browsing feature in Apple Safari before 4.0 on Windows does not remove cookies from the alternate cookie store in unspecified circumstances upon (1) disabling of the feature or (2) exit of the application, which makes it easier for remote web servers to track users via a cookie.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2009/1522" source="VUPEN" patch="1" adv="1">ADV-2009-1522</ref>
      <ref url="http://www.securityfocus.com/bid/35260" source="BID" patch="1">35260</ref>
      <ref url="http://support.apple.com/kb/HT3613" source="CONFIRM" patch="1" adv="1">http://support.apple.com/kb/HT3613</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2009/jun/msg00002.html" source="APPLE" patch="1" adv="1">APPLE-SA-2009-06-08-1</ref>
      <ref url="http://www.securityfocus.com/bid/35346" source="BID">35346</ref>
      <ref url="http://secunia.com/advisories/35379" source="SECUNIA" adv="1">35379</ref>
      <ref url="http://osvdb.org/54997" source="OSVDB">54997</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="safari">
        <vers num="3.0" edition="-" />
        <vers num="3.0" edition="-:windows" />
        <vers num="3.0.1" edition="-" />
        <vers num="3.0.1" edition="-:windows" />
        <vers num="3.0.2" edition="-" />
        <vers num="3.0.2" edition="-:windows" />
        <vers num="3.0.3" edition="-" />
        <vers num="3.0.3" edition="-:windows" />
        <vers num="3.0.4" edition="-" />
        <vers num="3.0.4" edition="-:windows" />
        <vers num="3.1" edition="-" />
        <vers num="3.1" edition="-:windows" />
        <vers num="3.1.1" edition="-" />
        <vers num="3.1.1" edition="-:windows" />
        <vers num="3.1.2" edition="-" />
        <vers num="3.1.2" edition="-:windows" />
        <vers num="3.2" edition="-" />
        <vers num="3.2" edition="-:windows" />
        <vers num="3.2.1" edition="-" />
        <vers num="3.2.1" edition="-:windows" />
        <vers num="3.2.2" edition="-" />
        <vers num="3.2.2" edition="-:windows" />
        <vers prev="1" num="3.2.3" edition="-" />
        <vers prev="1" num="3.2.3" edition="-:windows" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2009-1707" published="2009-06-10" name="CVE-2009-1707" modified="2010-12-10" CVSS_version="2.0" CVSS_vector="(AV:L/AC:H/Au:N/C:P/I:N/A:N)" CVSS_score="1.2" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="1.9" CVSS_base_score="1.2">
    <desc>
      <descript source="cve">Race condition in the Reset Safari implementation in Apple Safari before 4.0 on Windows might allow local users to read stored web-site passwords via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <local />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2009/1522" source="VUPEN" patch="1" adv="1">ADV-2009-1522</ref>
      <ref url="http://support.apple.com/kb/HT3613" source="CONFIRM" patch="1" adv="1">http://support.apple.com/kb/HT3613</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2009/jun/msg00002.html" source="APPLE" patch="1" adv="1">APPLE-SA-2009-06-08-1</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/3046" source="VUPEN">ADV-2010-3046</ref>
      <ref url="http://www.securityfocus.com/bid/35352" source="BID">35352</ref>
      <ref url="http://www.securityfocus.com/bid/35260" source="BID">35260</ref>
      <ref url="http://support.apple.com/kb/HT4456" source="CONFIRM">http://support.apple.com/kb/HT4456</ref>
      <ref url="http://secunia.com/advisories/42314" source="SECUNIA">42314</ref>
      <ref url="http://secunia.com/advisories/35379" source="SECUNIA" adv="1">35379</ref>
      <ref url="http://osvdb.org/55012" source="OSVDB">55012</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Nov/msg00003.html" source="APPLE">APPLE-SA-2010-11-22-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="safari">
        <vers num="3.0" edition="" />
        <vers num="3.0" edition=":windows" />
        <vers num="3.0.1" edition="" />
        <vers num="3.0.1" edition=":windows" />
        <vers num="3.0.2" edition="" />
        <vers num="3.0.2" edition=":windows" />
        <vers num="3.0.3" edition="" />
        <vers num="3.0.3" edition=":windows" />
        <vers num="3.0.4" edition="" />
        <vers num="3.0.4" edition=":windows" />
        <vers num="3.1" edition="" />
        <vers num="3.1" edition=":windows" />
        <vers num="3.1.1" edition="" />
        <vers num="3.1.1" edition=":windows" />
        <vers num="3.1.2" edition="" />
        <vers num="3.1.2" edition=":windows" />
        <vers num="3.2" edition="" />
        <vers num="3.2" edition=":windows" />
        <vers num="3.2.1" edition="" />
        <vers num="3.2.1" edition=":windows" />
        <vers num="3.2.2" edition="" />
        <vers num="3.2.2" edition=":windows" />
        <vers prev="1" num="3.2.3" edition="" />
        <vers prev="1" num="3.2.3" edition=":windows" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1708" published="2009-06-10" name="CVE-2009-1708" modified="2009-06-19" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Apple Safari before 4.0 does not prevent calls to the open-help-anchor URL handler by web sites, which allows remote attackers to open arbitrary local help files, and execute arbitrary code or obtain sensitive information, via a crafted call.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2009/1522" source="VUPEN" patch="1" adv="1">ADV-2009-1522</ref>
      <ref url="http://www.securityfocus.com/bid/35260" source="BID" patch="1">35260</ref>
      <ref url="http://support.apple.com/kb/HT3613" source="CONFIRM" patch="1" adv="1">http://support.apple.com/kb/HT3613</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2009/jun/msg00002.html" source="APPLE" patch="1" adv="1">APPLE-SA-2009-06-08-1</ref>
      <ref url="http://www.securityfocus.com/bid/35351" source="BID">35351</ref>
      <ref url="http://securitytracker.com/id?1022345" source="SECTRACK">1022345</ref>
      <ref url="http://secunia.com/advisories/35379" source="SECUNIA" adv="1">35379</ref>
      <ref url="http://osvdb.org/55011" source="OSVDB">55011</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="safari">
        <vers num="0.8" edition="-" />
        <vers num="0.8" edition="-:mac" />
        <vers num="0.9" edition="-" />
        <vers num="0.9" edition="-:mac" />
        <vers num="1.0" edition="-" />
        <vers num="1.0" edition="-:mac" />
        <vers num="1.0.3" edition="-" />
        <vers num="1.0.3" edition="-:mac" />
        <vers num="1.1" edition="-" />
        <vers num="1.1" edition="-:mac" />
        <vers num="1.2" edition="-" />
        <vers num="1.2" edition="-:mac" />
        <vers num="1.3" edition="-" />
        <vers num="1.3" edition="-:mac" />
        <vers num="1.3.1" edition="-" />
        <vers num="1.3.1" edition="-:mac" />
        <vers num="1.3.2" edition="-" />
        <vers num="1.3.2" edition="-:mac" />
        <vers num="2.0" edition="-" />
        <vers num="2.0" edition="-:mac" />
        <vers num="2.0.2" edition="-" />
        <vers num="2.0.2" edition="-:mac" />
        <vers num="2.0.4" edition="-" />
        <vers num="2.0.4" edition="-:mac" />
        <vers num="3.0" edition="-" />
        <vers num="3.0" edition="-:windows" />
        <vers num="3.0" edition="-:mac" />
        <vers num="3.0.1" edition="-" />
        <vers num="3.0.1" edition="-:windows" />
        <vers num="3.0.2" edition="-" />
        <vers num="3.0.2" edition="-:mac" />
        <vers num="3.0.2" edition="-:windows" />
        <vers num="3.0.3" edition="-" />
        <vers num="3.0.3" edition="-:windows" />
        <vers num="3.0.3" edition="-:mac" />
        <vers num="3.0.4" edition="-" />
        <vers num="3.0.4" edition="-:mac" />
        <vers num="3.0.4" edition="-:windows" />
        <vers num="3.1" edition="-" />
        <vers num="3.1" edition="-:mac" />
        <vers num="3.1" edition="-:windows" />
        <vers num="3.1.1" edition="-" />
        <vers num="3.1.1" edition="-:windows" />
        <vers num="3.1.1" edition="-:mac" />
        <vers num="3.1.2" edition="-" />
        <vers num="3.1.2" edition="-:mac" />
        <vers num="3.1.2" edition="-:windows" />
        <vers num="3.2" edition="-" />
        <vers num="3.2" edition="-:windows" />
        <vers num="3.2.1" edition="-" />
        <vers num="3.2.1" edition="-:mac" />
        <vers num="3.2.1" edition="-:windows" />
        <vers num="3.2.2" edition="-" />
        <vers num="3.2.2" edition="-:windows" />
        <vers prev="1" num="3.2.3" edition="-" />
        <vers prev="1" num="3.2.3" edition="-:windows" />
        <vers prev="1" num="3.2.3" edition="-:mac" />
        <vers prev="1" num="4.0_beta" edition="-" />
        <vers prev="1" num="4.0_beta" edition="-:mac" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1709" published="2009-06-10" name="CVE-2009-1709" modified="2011-02-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Use-after-free vulnerability in the garbage-collection implementation in WebCore in WebKit in Apple Safari before 4.0 allows remote attackers to execute arbitrary code or cause a denial of service (heap corruption and application crash) via an SVG animation element, related to SVG set objects, SVG marker elements, the targetElement attribute, and unspecified "caches."</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://support.apple.com/kb/HT3613" source="CONFIRM" patch="1" adv="1">http://support.apple.com/kb/HT3613</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2009/jun/msg00002.html" source="APPLE" patch="1" adv="1">APPLE-SA-2009-06-08-1</ref>
      <ref url="http://www.zerodayinitiative.com/advisories/ZDI-09-034/" source="MISC">http://www.zerodayinitiative.com/advisories/ZDI-09-034/</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0212" source="VUPEN">ADV-2011-0212</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1522" source="VUPEN" adv="1">ADV-2009-1522</ref>
      <ref url="http://www.ubuntulinux.org/support/documentation/usn/usn-823-1" source="UBUNTU">USN-823-1</ref>
      <ref url="http://www.securityfocus.com/bid/35334" source="BID">35334</ref>
      <ref url="http://www.securityfocus.com/bid/35260" source="BID">35260</ref>
      <ref url="http://www.redhat.com/support/errata/RHSA-2009-1130.html" source="REDHAT">RHSA-2009:1130</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2010:182" source="MANDRIVA">MDVSA-2010:182</ref>
      <ref url="http://securitytracker.com/id?1022345" source="SECTRACK">1022345</ref>
      <ref url="http://secunia.com/advisories/43068" source="SECUNIA">43068</ref>
      <ref url="http://secunia.com/advisories/36461" source="SECUNIA">36461</ref>
      <ref url="http://secunia.com/advisories/35576" source="SECUNIA">35576</ref>
      <ref url="http://secunia.com/advisories/35379" source="SECUNIA" adv="1">35379</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10162" source="OVAL">oval:org.mitre.oval:def:10162</ref>
      <ref url="http://osvdb.org/55013" source="OSVDB">55013</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.html" source="SUSE">SUSE-SR:2011:002</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="safari">
        <vers num="0.8" edition="-" />
        <vers num="0.8" edition="-:mac" />
        <vers num="0.9" edition="-" />
        <vers num="0.9" edition="-:mac" />
        <vers num="1.0" edition="-" />
        <vers num="1.0" edition="-:mac" />
        <vers num="1.0.3" edition="-" />
        <vers num="1.0.3" edition="-:mac" />
        <vers num="1.1" edition="-" />
        <vers num="1.1" edition="-:mac" />
        <vers num="1.2" edition="-" />
        <vers num="1.2" edition="-:mac" />
        <vers num="1.3" edition="-" />
        <vers num="1.3" edition="-:mac" />
        <vers num="1.3.1" edition="-" />
        <vers num="1.3.1" edition="-:mac" />
        <vers num="1.3.2" edition="-" />
        <vers num="1.3.2" edition="-:mac" />
        <vers num="2.0" edition="-" />
        <vers num="2.0" edition="-:mac" />
        <vers num="2.0.2" edition="-" />
        <vers num="2.0.2" edition="-:mac" />
        <vers num="2.0.4" edition="-" />
        <vers num="2.0.4" edition="-:mac" />
        <vers num="3.0" edition="-" />
        <vers num="3.0" edition="-:windows" />
        <vers num="3.0" edition="-:mac" />
        <vers num="3.0.1" edition="-" />
        <vers num="3.0.1" edition="-:windows" />
        <vers num="3.0.2" edition="-" />
        <vers num="3.0.2" edition="-:mac" />
        <vers num="3.0.2" edition="-:windows" />
        <vers num="3.0.3" edition="-" />
        <vers num="3.0.3" edition="-:windows" />
        <vers num="3.0.3" edition="-:mac" />
        <vers num="3.0.4" edition="-" />
        <vers num="3.0.4" edition="-:mac" />
        <vers num="3.0.4" edition="-:windows" />
        <vers num="3.1" edition="-" />
        <vers num="3.1" edition="-:mac" />
        <vers num="3.1" edition="-:windows" />
        <vers num="3.1.1" edition="-" />
        <vers num="3.1.1" edition="-:windows" />
        <vers num="3.1.1" edition="-:mac" />
        <vers num="3.1.2" edition="-" />
        <vers num="3.1.2" edition="-:mac" />
        <vers num="3.1.2" edition="-:windows" />
        <vers num="3.2" edition="-" />
        <vers num="3.2" edition="-:windows" />
        <vers num="3.2.1" edition="-" />
        <vers num="3.2.1" edition="-:mac" />
        <vers num="3.2.1" edition="-:windows" />
        <vers num="3.2.2" edition="-" />
        <vers num="3.2.2" edition="-:windows" />
        <vers prev="1" num="3.2.3" edition="-" />
        <vers prev="1" num="3.2.3" edition="-:windows" />
        <vers prev="1" num="3.2.3" edition="-:mac" />
        <vers prev="1" num="4.0_beta" edition="-" />
        <vers prev="1" num="4.0_beta" edition="-:mac" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2009-1710" published="2009-06-10" name="CVE-2009-1710" modified="2011-02-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:N/A:N)" CVSS_score="2.6" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="4.9" CVSS_base_score="2.6">
    <desc>
      <descript source="cve">WebKit in Apple Safari before 4.0 allows remote attackers to spoof the browser's display of (1) the host name, (2) security indicators, and unspecified other UI elements via a custom cursor in conjunction with a modified CSS3 hotspot property.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2009/1522" source="VUPEN" patch="1" adv="1">ADV-2009-1522</ref>
      <ref url="http://www.securityfocus.com/bid/35260" source="BID" patch="1">35260</ref>
      <ref url="http://support.apple.com/kb/HT3613" source="CONFIRM" patch="1" adv="1">http://support.apple.com/kb/HT3613</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2009/jun/msg00002.html" source="APPLE" patch="1" adv="1">APPLE-SA-2009-06-08-1</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/51263" source="XF">safari-uielements-spoofing(51263)</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0212" source="VUPEN">ADV-2011-0212</ref>
      <ref url="http://www.securityfocus.com/bid/35340" source="BID">35340</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1950" source="DEBIAN">DSA-1950</ref>
      <ref url="http://secunia.com/advisories/43068" source="SECUNIA">43068</ref>
      <ref url="http://secunia.com/advisories/37746" source="SECUNIA">37746</ref>
      <ref url="http://secunia.com/advisories/35379" source="SECUNIA" adv="1">35379</ref>
      <ref url="http://osvdb.org/55014" source="OSVDB">55014</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.html" source="SUSE">SUSE-SR:2011:002</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="safari">
        <vers num="0.8" edition="-" />
        <vers num="0.8" edition="-:mac" />
        <vers num="0.9" edition="-" />
        <vers num="0.9" edition="-:mac" />
        <vers num="1.0" edition="-" />
        <vers num="1.0" edition="-:mac" />
        <vers num="1.0.3" edition="-" />
        <vers num="1.0.3" edition="-:mac" />
        <vers num="1.1" edition="-" />
        <vers num="1.1" edition="-:mac" />
        <vers num="1.2" edition="-" />
        <vers num="1.2" edition="-:mac" />
        <vers num="1.3" edition="-" />
        <vers num="1.3" edition="-:mac" />
        <vers num="1.3.1" edition="-" />
        <vers num="1.3.1" edition="-:mac" />
        <vers num="1.3.2" edition="-" />
        <vers num="1.3.2" edition="-:mac" />
        <vers num="2.0" edition="-" />
        <vers num="2.0" edition="-:mac" />
        <vers num="2.0.2" edition="-" />
        <vers num="2.0.2" edition="-:mac" />
        <vers num="2.0.4" edition="-" />
        <vers num="2.0.4" edition="-:mac" />
        <vers num="3.0" edition="-" />
        <vers num="3.0" edition="-:windows" />
        <vers num="3.0" edition="-:mac" />
        <vers num="3.0.1" edition="-" />
        <vers num="3.0.1" edition="-:windows" />
        <vers num="3.0.2" edition="-" />
        <vers num="3.0.2" edition="-:mac" />
        <vers num="3.0.2" edition="-:windows" />
        <vers num="3.0.3" edition="-" />
        <vers num="3.0.3" edition="-:windows" />
        <vers num="3.0.3" edition="-:mac" />
        <vers num="3.0.4" edition="-" />
        <vers num="3.0.4" edition="-:mac" />
        <vers num="3.0.4" edition="-:windows" />
        <vers num="3.1" edition="-" />
        <vers num="3.1" edition="-:mac" />
        <vers num="3.1" edition="-:windows" />
        <vers num="3.1.1" edition="-" />
        <vers num="3.1.1" edition="-:windows" />
        <vers num="3.1.1" edition="-:mac" />
        <vers num="3.1.2" edition="-" />
        <vers num="3.1.2" edition="-:mac" />
        <vers num="3.1.2" edition="-:windows" />
        <vers num="3.2" edition="-" />
        <vers num="3.2" edition="-:windows" />
        <vers num="3.2.1" edition="-" />
        <vers num="3.2.1" edition="-:mac" />
        <vers num="3.2.1" edition="-:windows" />
        <vers num="3.2.2" edition="-" />
        <vers num="3.2.2" edition="-:windows" />
        <vers prev="1" num="3.2.3" edition="-" />
        <vers prev="1" num="3.2.3" edition="-:windows" />
        <vers prev="1" num="3.2.3" edition="-:mac" />
        <vers prev="1" num="4.0_beta" edition="-" />
        <vers prev="1" num="4.0_beta" edition="-:mac" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1711" published="2009-06-10" name="CVE-2009-1711" modified="2011-02-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">WebKit in Apple Safari before 4.0 does not properly initialize memory for Attr DOM objects, which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted HTML document.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2009/1522" source="VUPEN" patch="1" adv="1">ADV-2009-1522</ref>
      <ref url="http://www.securityfocus.com/bid/35260" source="BID" patch="1">35260</ref>
      <ref url="http://support.apple.com/kb/HT3613" source="CONFIRM" patch="1" adv="1">http://support.apple.com/kb/HT3613</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2009/jun/msg00002.html" source="APPLE" patch="1" adv="1">APPLE-SA-2009-06-08-1</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/51265" source="XF">safari-attrdom-code-execution(51265)</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0212" source="VUPEN">ADV-2011-0212</ref>
      <ref url="http://www.ubuntu.com/usn/USN-857-1" source="UBUNTU">USN-857-1</ref>
      <ref url="http://www.ubuntu.com/usn/USN-836-1" source="UBUNTU">USN-836-1</ref>
      <ref url="http://www.securityfocus.com/bid/35310" source="BID">35310</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1950" source="DEBIAN">DSA-1950</ref>
      <ref url="http://securitytracker.com/id?1022345" source="SECTRACK">1022345</ref>
      <ref url="http://secunia.com/advisories/43068" source="SECUNIA">43068</ref>
      <ref url="http://secunia.com/advisories/37746" source="SECUNIA">37746</ref>
      <ref url="http://secunia.com/advisories/36790" source="SECUNIA">36790</ref>
      <ref url="http://secunia.com/advisories/35379" source="SECUNIA" adv="1">35379</ref>
      <ref url="http://osvdb.org/55015" source="OSVDB">55015</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.html" source="SUSE">SUSE-SR:2011:002</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="safari">
        <vers num="0.8" edition="" />
        <vers num="0.8" edition=":mac" />
        <vers num="0.9" edition="" />
        <vers num="0.9" edition=":mac" />
        <vers num="1.0" edition="" />
        <vers num="1.0" edition=":mac" />
        <vers num="1.0.3" edition="" />
        <vers num="1.0.3" edition=":mac" />
        <vers num="1.1" edition="" />
        <vers num="1.1" edition=":mac" />
        <vers num="1.2" edition="" />
        <vers num="1.2" edition=":mac" />
        <vers num="1.3" edition="" />
        <vers num="1.3" edition=":mac" />
        <vers num="1.3.1" edition="" />
        <vers num="1.3.1" edition=":mac" />
        <vers num="1.3.2" edition="" />
        <vers num="1.3.2" edition=":mac" />
        <vers num="2.0" edition="" />
        <vers num="2.0" edition=":mac" />
        <vers num="2.0.2" edition="" />
        <vers num="2.0.2" edition=":mac" />
        <vers num="2.0.4" edition="" />
        <vers num="2.0.4" edition=":mac" />
        <vers num="3.0" edition="" />
        <vers num="3.0" edition=":windows" />
        <vers num="3.0" edition=":mac" />
        <vers num="3.0.1" edition="" />
        <vers num="3.0.1" edition=":windows" />
        <vers num="3.0.2" edition="" />
        <vers num="3.0.2" edition=":windows" />
        <vers num="3.0.2" edition="-" />
        <vers num="3.0.2" edition="-:mac" />
        <vers num="3.0.3" edition="" />
        <vers num="3.0.3" edition=":windows" />
        <vers num="3.0.3" edition=":mac" />
        <vers num="3.0.4" edition="" />
        <vers num="3.0.4" edition=":windows" />
        <vers num="3.0.4" edition=":mac" />
        <vers num="3.1" edition="" />
        <vers num="3.1" edition=":windows" />
        <vers num="3.1" edition=":mac" />
        <vers num="3.1.1" edition="" />
        <vers num="3.1.1" edition=":windows" />
        <vers num="3.1.1" edition=":mac" />
        <vers num="3.1.2" edition="" />
        <vers num="3.1.2" edition=":mac" />
        <vers num="3.1.2" edition=":windows" />
        <vers num="3.2" edition="" />
        <vers num="3.2" edition=":windows" />
        <vers num="3.2.1" edition="" />
        <vers num="3.2.1" edition=":mac" />
        <vers num="3.2.1" edition=":windows" />
        <vers num="3.2.2" edition="" />
        <vers num="3.2.2" edition=":windows" />
        <vers prev="1" num="3.2.3" edition="" />
        <vers prev="1" num="3.2.3" edition=":windows" />
        <vers prev="1" num="3.2.3" edition=":mac" />
        <vers prev="1" num="4.0_beta" edition="" />
        <vers prev="1" num="4.0_beta" edition=":mac" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1712" published="2009-06-10" name="CVE-2009-1712" modified="2011-02-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">WebKit in Apple Safari before 4.0 does not prevent remote loading of local Java applets, which allows remote attackers to execute arbitrary code, gain privileges, or obtain sensitive information via an APPLET or OBJECT element.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2009/1522" source="VUPEN" patch="1" adv="1">ADV-2009-1522</ref>
      <ref url="http://www.securityfocus.com/bid/35260" source="BID" patch="1">35260</ref>
      <ref url="http://support.apple.com/kb/HT3613" source="CONFIRM" patch="1" adv="1">http://support.apple.com/kb/HT3613</ref>
      <ref url="http://securitytracker.com/id?1022345" source="SECTRACK" patch="1">1022345</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2009/jun/msg00002.html" source="APPLE" patch="1" adv="1">APPLE-SA-2009-06-08-1</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/51266" source="XF">safari-applets-code-execution(51266)</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0212" source="VUPEN">ADV-2011-0212</ref>
      <ref url="http://www.ubuntu.com/usn/USN-857-1" source="UBUNTU">USN-857-1</ref>
      <ref url="http://www.ubuntu.com/usn/USN-836-1" source="UBUNTU">USN-836-1</ref>
      <ref url="http://www.securityfocus.com/bid/35350" source="BID">35350</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1950" source="DEBIAN">DSA-1950</ref>
      <ref url="http://secunia.com/advisories/43068" source="SECUNIA">43068</ref>
      <ref url="http://secunia.com/advisories/37746" source="SECUNIA">37746</ref>
      <ref url="http://secunia.com/advisories/36790" source="SECUNIA">36790</ref>
      <ref url="http://secunia.com/advisories/35379" source="SECUNIA" adv="1">35379</ref>
      <ref url="http://osvdb.org/55022" source="OSVDB">55022</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.html" source="SUSE">SUSE-SR:2011:002</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="safari">
        <vers num="0.8" edition="" />
        <vers num="0.8" edition=":mac" />
        <vers num="0.9" edition="" />
        <vers num="0.9" edition=":mac" />
        <vers num="1.0" edition="" />
        <vers num="1.0" edition=":mac" />
        <vers num="1.0.3" edition="" />
        <vers num="1.0.3" edition=":mac" />
        <vers num="1.1" edition="" />
        <vers num="1.1" edition=":mac" />
        <vers num="1.2" edition="" />
        <vers num="1.2" edition=":mac" />
        <vers num="1.3" edition="" />
        <vers num="1.3" edition=":mac" />
        <vers num="1.3.1" edition="" />
        <vers num="1.3.1" edition=":mac" />
        <vers num="1.3.2" edition="" />
        <vers num="1.3.2" edition=":mac" />
        <vers num="2.0" edition="" />
        <vers num="2.0" edition=":mac" />
        <vers num="2.0.2" edition="" />
        <vers num="2.0.2" edition=":mac" />
        <vers num="2.0.4" edition="" />
        <vers num="2.0.4" edition=":mac" />
        <vers num="3.0" edition="" />
        <vers num="3.0" edition=":windows" />
        <vers num="3.0" edition=":mac" />
        <vers num="3.0.1" edition="" />
        <vers num="3.0.1" edition=":windows" />
        <vers num="3.0.2" edition="" />
        <vers num="3.0.2" edition=":windows" />
        <vers num="3.0.2" edition="-" />
        <vers num="3.0.2" edition="-:mac" />
        <vers num="3.0.3" edition="" />
        <vers num="3.0.3" edition=":windows" />
        <vers num="3.0.3" edition=":mac" />
        <vers num="3.0.4" edition="" />
        <vers num="3.0.4" edition=":windows" />
        <vers num="3.0.4" edition=":mac" />
        <vers num="3.1" edition="" />
        <vers num="3.1" edition=":windows" />
        <vers num="3.1" edition=":mac" />
        <vers num="3.1.1" edition="" />
        <vers num="3.1.1" edition=":windows" />
        <vers num="3.1.1" edition=":mac" />
        <vers num="3.1.2" edition="" />
        <vers num="3.1.2" edition=":mac" />
        <vers num="3.1.2" edition=":windows" />
        <vers num="3.2" edition="-" />
        <vers num="3.2" edition="-:windows" />
        <vers num="3.2.1" edition="" />
        <vers num="3.2.1" edition=":mac" />
        <vers num="3.2.1" edition=":windows" />
        <vers num="3.2.2" edition="" />
        <vers num="3.2.2" edition=":windows" />
        <vers prev="1" num="3.2.3" edition="" />
        <vers prev="1" num="3.2.3" edition=":windows" />
        <vers prev="1" num="3.2.3" edition=":mac" />
        <vers prev="1" num="4.0_beta" edition="" />
        <vers prev="1" num="4.0_beta" edition=":mac" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1713" published="2009-06-10" name="CVE-2009-1713" modified="2011-02-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:N/A:N)" CVSS_score="7.1" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="8.6" CVSS_base_score="7.1">
    <desc>
      <descript source="cve">The XSLT functionality in WebKit in Apple Safari before 4.0 does not properly implement the document function, which allows remote attackers to read (1) arbitrary local files and (2) files from different security zones via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://support.apple.com/kb/HT3613" source="CONFIRM" patch="1" adv="1">http://support.apple.com/kb/HT3613</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2009/jun/msg00002.html" source="APPLE" patch="1" adv="1">APPLE-SA-2009-06-08-1</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/51267" source="XF">safari-document-information-disclosure(51267)</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0212" source="VUPEN">ADV-2011-0212</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1522" source="VUPEN" adv="1">ADV-2009-1522</ref>
      <ref url="http://www.ubuntu.com/usn/USN-857-1" source="UBUNTU">USN-857-1</ref>
      <ref url="http://www.securityfocus.com/bid/35260" source="BID">35260</ref>
      <ref url="http://secunia.com/advisories/43068" source="SECUNIA">43068</ref>
      <ref url="http://secunia.com/advisories/35379" source="SECUNIA" adv="1">35379</ref>
      <ref url="http://osvdb.org/54975" source="OSVDB">54975</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.html" source="SUSE">SUSE-SR:2011:002</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="safari">
        <vers num="0.8" edition="" />
        <vers num="0.8" edition=":mac" />
        <vers num="0.9" edition="" />
        <vers num="0.9" edition=":mac" />
        <vers num="1.0" edition="" />
        <vers num="1.0" edition=":mac" />
        <vers num="1.0.3" edition="" />
        <vers num="1.0.3" edition=":mac" />
        <vers num="1.1" edition="" />
        <vers num="1.1" edition=":mac" />
        <vers num="1.2" edition="" />
        <vers num="1.2" edition=":mac" />
        <vers num="1.3" edition="" />
        <vers num="1.3" edition=":mac" />
        <vers num="1.3.1" edition="" />
        <vers num="1.3.1" edition=":mac" />
        <vers num="1.3.2" edition="" />
        <vers num="1.3.2" edition=":mac" />
        <vers num="2.0" edition="" />
        <vers num="2.0" edition=":mac" />
        <vers num="2.0.2" edition="" />
        <vers num="2.0.2" edition=":mac" />
        <vers num="2.0.4" edition="" />
        <vers num="2.0.4" edition=":mac" />
        <vers num="3.0" edition="" />
        <vers num="3.0" edition=":windows" />
        <vers num="3.0" edition=":mac" />
        <vers num="3.0.1" edition="" />
        <vers num="3.0.1" edition=":windows" />
        <vers num="3.0.2" edition="" />
        <vers num="3.0.2" edition=":windows" />
        <vers num="3.0.2" edition="-" />
        <vers num="3.0.2" edition="-:mac" />
        <vers num="3.0.3" edition="" />
        <vers num="3.0.3" edition=":windows" />
        <vers num="3.0.3" edition=":mac" />
        <vers num="3.0.4" edition="" />
        <vers num="3.0.4" edition=":windows" />
        <vers num="3.0.4" edition=":mac" />
        <vers num="3.1" edition="" />
        <vers num="3.1" edition=":windows" />
        <vers num="3.1" edition=":mac" />
        <vers num="3.1.1" edition="" />
        <vers num="3.1.1" edition=":windows" />
        <vers num="3.1.1" edition=":mac" />
        <vers num="3.1.2" edition="" />
        <vers num="3.1.2" edition=":mac" />
        <vers num="3.1.2" edition=":windows" />
        <vers num="3.2" edition="-" />
        <vers num="3.2" edition="-:windows" />
        <vers num="3.2.1" edition="" />
        <vers num="3.2.1" edition=":mac" />
        <vers num="3.2.1" edition=":windows" />
        <vers num="3.2.2" edition="" />
        <vers num="3.2.2" edition=":windows" />
        <vers prev="1" num="3.2.3" edition="" />
        <vers prev="1" num="3.2.3" edition=":windows" />
        <vers prev="1" num="3.2.3" edition=":mac" />
        <vers prev="1" num="4.0_beta" edition="" />
        <vers prev="1" num="4.0_beta" edition=":mac" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1714" published="2009-06-10" name="CVE-2009-1714" modified="2011-02-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Web Inspector in WebKit in Apple Safari before 4.0 allows user-assisted remote attackers to inject arbitrary web script or HTML, and read local files, via vectors related to the improper escaping of HTML attributes.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2009/1522" source="VUPEN" patch="1" adv="1">ADV-2009-1522</ref>
      <ref url="http://www.securityfocus.com/bid/35260" source="BID" patch="1">35260</ref>
      <ref url="http://support.apple.com/kb/HT3613" source="CONFIRM" patch="1" adv="1">http://support.apple.com/kb/HT3613</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2009/jun/msg00002.html" source="APPLE" patch="1" adv="1">APPLE-SA-2009-06-08-1</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/51268" source="XF">safari-webinspector-xss(51268)</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0212" source="VUPEN">ADV-2011-0212</ref>
      <ref url="http://www.securityfocus.com/bid/35348" source="BID">35348</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1950" source="DEBIAN">DSA-1950</ref>
      <ref url="http://securitytracker.com/id?1022344" source="SECTRACK">1022344</ref>
      <ref url="http://secunia.com/advisories/43068" source="SECUNIA">43068</ref>
      <ref url="http://secunia.com/advisories/37746" source="SECUNIA">37746</ref>
      <ref url="http://secunia.com/advisories/35379" source="SECUNIA" adv="1">35379</ref>
      <ref url="http://osvdb.org/55023" source="OSVDB">55023</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.html" source="SUSE">SUSE-SR:2011:002</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="safari">
        <vers num="0.8" edition="-" />
        <vers num="0.8" edition="-:mac" />
        <vers num="0.9" edition="-" />
        <vers num="0.9" edition="-:mac" />
        <vers num="1.0" edition="-" />
        <vers num="1.0" edition="-:mac" />
        <vers num="1.0.3" edition="-" />
        <vers num="1.0.3" edition="-:mac" />
        <vers num="1.1" edition="-" />
        <vers num="1.1" edition="-:mac" />
        <vers num="1.2" edition="-" />
        <vers num="1.2" edition="-:mac" />
        <vers num="1.3" edition="-" />
        <vers num="1.3" edition="-:mac" />
        <vers num="1.3.1" edition="-" />
        <vers num="1.3.1" edition="-:mac" />
        <vers num="1.3.2" edition="-" />
        <vers num="1.3.2" edition="-:mac" />
        <vers num="2.0" edition="-" />
        <vers num="2.0" edition="-:mac" />
        <vers num="2.0.2" edition="-" />
        <vers num="2.0.2" edition="-:mac" />
        <vers num="2.0.4" edition="-" />
        <vers num="2.0.4" edition="-:mac" />
        <vers num="3.0" edition="-" />
        <vers num="3.0" edition="-:windows" />
        <vers num="3.0" edition="-:mac" />
        <vers num="3.0.1" edition="-" />
        <vers num="3.0.1" edition="-:windows" />
        <vers num="3.0.2" edition="-" />
        <vers num="3.0.2" edition="-:mac" />
        <vers num="3.0.2" edition="-:windows" />
        <vers num="3.0.3" edition="-" />
        <vers num="3.0.3" edition="-:windows" />
        <vers num="3.0.3" edition="-:mac" />
        <vers num="3.0.4" edition="-" />
        <vers num="3.0.4" edition="-:mac" />
        <vers num="3.0.4" edition="-:windows" />
        <vers num="3.1" edition="-" />
        <vers num="3.1" edition="-:mac" />
        <vers num="3.1" edition="-:windows" />
        <vers num="3.1.1" edition="-" />
        <vers num="3.1.1" edition="-:windows" />
        <vers num="3.1.1" edition="-:mac" />
        <vers num="3.1.2" edition="-" />
        <vers num="3.1.2" edition="-:mac" />
        <vers num="3.1.2" edition="-:windows" />
        <vers num="3.2" edition="-" />
        <vers num="3.2" edition="-:windows" />
        <vers num="3.2.1" edition="-" />
        <vers num="3.2.1" edition="-:mac" />
        <vers num="3.2.1" edition="-:windows" />
        <vers num="3.2.2" edition="-" />
        <vers num="3.2.2" edition="-:windows" />
        <vers prev="1" num="3.2.3" edition="-" />
        <vers prev="1" num="3.2.3" edition="-:windows" />
        <vers prev="1" num="3.2.3" edition="-:mac" />
        <vers prev="1" num="4.0_beta" edition="-" />
        <vers prev="1" num="4.0_beta" edition="-:mac" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1715" published="2009-06-10" name="CVE-2009-1715" modified="2011-02-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Web Inspector in WebKit in Apple Safari before 4.0 allows user-assisted remote attackers to inject arbitrary web script or HTML, and read local files, via vectors related to script execution with incorrect privileges.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2009/1522" source="VUPEN" patch="1" adv="1">ADV-2009-1522</ref>
      <ref url="http://support.apple.com/kb/HT3613" source="CONFIRM" patch="1" adv="1">http://support.apple.com/kb/HT3613</ref>
      <ref url="http://securitytracker.com/id?1022344" source="SECTRACK" patch="1">1022344</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2009/jun/msg00002.html" source="APPLE" patch="1" adv="1">APPLE-SA-2009-06-08-1</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0212" source="VUPEN">ADV-2011-0212</ref>
      <ref url="http://www.securityfocus.com/bid/35349" source="BID">35349</ref>
      <ref url="http://www.securityfocus.com/bid/35260" source="BID">35260</ref>
      <ref url="http://secunia.com/advisories/43068" source="SECUNIA">43068</ref>
      <ref url="http://secunia.com/advisories/35379" source="SECUNIA" adv="1">35379</ref>
      <ref url="http://osvdb.org/54996" source="OSVDB">54996</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.html" source="SUSE">SUSE-SR:2011:002</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="safari">
        <vers num="0.8" edition="" />
        <vers num="0.8" edition=":mac" />
        <vers num="0.9" edition="" />
        <vers num="0.9" edition=":mac" />
        <vers num="1.0" edition="" />
        <vers num="1.0" edition=":mac" />
        <vers num="1.0.3" edition="" />
        <vers num="1.0.3" edition=":mac" />
        <vers num="1.1" edition="" />
        <vers num="1.1" edition=":mac" />
        <vers num="1.2" edition="" />
        <vers num="1.2" edition=":mac" />
        <vers num="1.3" edition="" />
        <vers num="1.3" edition=":mac" />
        <vers num="1.3.1" edition="" />
        <vers num="1.3.1" edition=":mac" />
        <vers num="1.3.2" edition="" />
        <vers num="1.3.2" edition=":mac" />
        <vers num="2.0" edition="" />
        <vers num="2.0" edition=":mac" />
        <vers num="2.0.2" edition="" />
        <vers num="2.0.2" edition=":mac" />
        <vers num="2.0.4" edition="" />
        <vers num="2.0.4" edition=":mac" />
        <vers num="3.0" edition="" />
        <vers num="3.0" edition=":windows" />
        <vers num="3.0" edition=":mac" />
        <vers num="3.0.1" edition="" />
        <vers num="3.0.1" edition=":windows" />
        <vers num="3.0.2" edition="" />
        <vers num="3.0.2" edition=":windows" />
        <vers num="3.0.2" edition="-" />
        <vers num="3.0.2" edition="-:mac" />
        <vers num="3.0.3" edition="" />
        <vers num="3.0.3" edition=":windows" />
        <vers num="3.0.3" edition=":mac" />
        <vers num="3.0.4" edition="" />
        <vers num="3.0.4" edition=":windows" />
        <vers num="3.0.4" edition=":mac" />
        <vers num="3.1" edition="" />
        <vers num="3.1" edition=":windows" />
        <vers num="3.1" edition=":mac" />
        <vers num="3.1.1" edition="" />
        <vers num="3.1.1" edition=":windows" />
        <vers num="3.1.1" edition=":mac" />
        <vers num="3.1.2" edition="" />
        <vers num="3.1.2" edition=":mac" />
        <vers num="3.1.2" edition=":windows" />
        <vers num="3.2" edition="" />
        <vers num="3.2" edition=":windows" />
        <vers num="3.2.1" edition="" />
        <vers num="3.2.1" edition=":mac" />
        <vers num="3.2.1" edition=":windows" />
        <vers num="3.2.2" edition="" />
        <vers num="3.2.2" edition=":windows" />
        <vers prev="1" num="3.2.3" edition="" />
        <vers prev="1" num="3.2.3" edition=":windows" />
        <vers prev="1" num="3.2.3" edition=":mac" />
        <vers prev="1" num="4.0_beta" edition="" />
        <vers prev="1" num="4.0_beta" edition=":mac" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2009-1716" published="2009-06-10" name="CVE-2009-1716" modified="2009-06-19" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">CFNetwork in Apple Safari before 4.0 on Windows does not properly protect the temporary files created for downloads, which allows local users to obtain sensitive information by reading these files.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2009/1522" source="VUPEN" patch="1" adv="1">ADV-2009-1522</ref>
      <ref url="http://www.securityfocus.com/bid/35260" source="BID" patch="1">35260</ref>
      <ref url="http://support.apple.com/kb/HT3613" source="CONFIRM" patch="1" adv="1">http://support.apple.com/kb/HT3613</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2009/jun/msg00002.html" source="APPLE" patch="1" adv="1">APPLE-SA-2009-06-08-1</ref>
      <ref url="http://www.securityfocus.com/bid/35347" source="BID">35347</ref>
      <ref url="http://securitytracker.com/id?1022342" source="SECTRACK">1022342</ref>
      <ref url="http://secunia.com/advisories/35379" source="SECUNIA">35379</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="safari">
        <vers num="0.8" edition="-" />
        <vers num="0.8" edition="-:mac" />
        <vers num="0.9" edition="-" />
        <vers num="0.9" edition="-:mac" />
        <vers num="1.0" edition="-" />
        <vers num="1.0" edition="-:mac" />
        <vers num="1.0.3" edition="-" />
        <vers num="1.0.3" edition="-:mac" />
        <vers num="1.1" edition="-" />
        <vers num="1.1" edition="-:mac" />
        <vers num="1.2" edition="-" />
        <vers num="1.2" edition="-:mac" />
        <vers num="1.3" edition="-" />
        <vers num="1.3" edition="-:mac" />
        <vers num="1.3.1" edition="-" />
        <vers num="1.3.1" edition="-:mac" />
        <vers num="1.3.2" edition="-" />
        <vers num="1.3.2" edition="-:mac" />
        <vers num="2.0" edition="-" />
        <vers num="2.0" edition="-:mac" />
        <vers num="2.0.2" edition="-" />
        <vers num="2.0.2" edition="-:mac" />
        <vers num="2.0.4" edition="-" />
        <vers num="2.0.4" edition="-:mac" />
        <vers num="3.0" edition="-" />
        <vers num="3.0" edition="-:windows" />
        <vers num="3.0" edition="-:mac" />
        <vers num="3.0.1" edition="-" />
        <vers num="3.0.1" edition="-:windows" />
        <vers num="3.0.2" edition="-" />
        <vers num="3.0.2" edition="-:mac" />
        <vers num="3.0.2" edition="-:windows" />
        <vers num="3.0.3" edition="-" />
        <vers num="3.0.3" edition="-:windows" />
        <vers num="3.0.3" edition="-:mac" />
        <vers num="3.0.4" edition="-" />
        <vers num="3.0.4" edition="-:mac" />
        <vers num="3.0.4" edition="-:windows" />
        <vers num="3.1" edition="-" />
        <vers num="3.1" edition="-:mac" />
        <vers num="3.1" edition="-:windows" />
        <vers num="3.1.1" edition="-" />
        <vers num="3.1.1" edition="-:windows" />
        <vers num="3.1.1" edition="-:mac" />
        <vers num="3.1.2" edition="-" />
        <vers num="3.1.2" edition="-:mac" />
        <vers num="3.1.2" edition="-:windows" />
        <vers num="3.2" edition="-" />
        <vers num="3.2" edition="-:windows" />
        <vers num="3.2.1" edition="-" />
        <vers num="3.2.1" edition="-:mac" />
        <vers num="3.2.1" edition="-:windows" />
        <vers num="3.2.2" edition="-" />
        <vers num="3.2.2" edition="-:windows" />
        <vers prev="1" num="3.2.3" edition="-" />
        <vers prev="1" num="3.2.3" edition="-:windows" />
        <vers prev="1" num="3.2.3" edition="-:mac" />
        <vers prev="1" num="4.0_beta" edition="-" />
        <vers prev="1" num="4.0_beta" edition="-:mac" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1717" published="2009-06-05" name="CVE-2009-1717" modified="2009-06-29" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Integer overflow in Terminal in Apple Mac OS X 10.5 before 10.5.7 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted size value in a CSI[4 xterm resize escape sequence that triggers a heap-based buffer overflow.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot user="1" />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/35182" source="BID" patch="1">35182</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/504031/100/0/threaded" source="BUGTRAQ" patch="1">20090602 TPTI-09-04: Apple Terminal xterm Resize Escape Sequence Memory Corruption Vulnerability</ref>
      <ref url="http://support.apple.com/kb/HT3549" source="CONFIRM" patch="1" adv="1">http://support.apple.com/kb/HT3549</ref>
      <ref url="http://securitytracker.com/id?1022322" source="SECTRACK" patch="1">1022322</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/50982" source="XF">macos-terminal-bo(50982)</ref>
      <ref url="http://dvlabs.tippingpoint.com/advisory/TPTI-09-04" source="MISC">http://dvlabs.tippingpoint.com/advisory/TPTI-09-04</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.5" />
        <vers num="10.5.0" />
        <vers num="10.5.1" />
        <vers num="10.5.2" />
        <vers num="10.5.3" />
        <vers num="10.5.4" />
        <vers num="10.5.5" />
        <vers num="10.5.6" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.5" />
        <vers num="10.5.0" />
        <vers num="10.5.1" />
        <vers num="10.5.2" />
        <vers num="10.5.3" />
        <vers num="10.5.4" />
        <vers num="10.5.5" />
        <vers num="10.5.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1718" published="2009-06-10" name="CVE-2009-1718" modified="2011-02-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:N/A:N)" CVSS_score="7.1" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="8.6" CVSS_base_score="7.1">
    <desc>
      <descript source="cve">WebKit in Apple Safari before 4.0 allows user-assisted remote attackers to obtain sensitive information via vectors involving drag events and the dragging of content over a crafted web page.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2009/1522" source="VUPEN" patch="1" adv="1">ADV-2009-1522</ref>
      <ref url="http://www.securityfocus.com/bid/35260" source="BID" patch="1">35260</ref>
      <ref url="http://support.apple.com/kb/HT3613" source="CONFIRM" patch="1" adv="1">http://support.apple.com/kb/HT3613</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2009/jun/msg00002.html" source="APPLE" patch="1" adv="1">APPLE-SA-2009-06-08-1</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0212" source="VUPEN">ADV-2011-0212</ref>
      <ref url="http://secunia.com/advisories/43068" source="SECUNIA">43068</ref>
      <ref url="http://secunia.com/advisories/35379" source="SECUNIA" adv="1">35379</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.html" source="SUSE">SUSE-SR:2011:002</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="safari">
        <vers num="0.8" edition="" />
        <vers num="0.8" edition=":mac" />
        <vers num="0.9" edition="" />
        <vers num="0.9" edition=":mac" />
        <vers num="1.0" edition="" />
        <vers num="1.0" edition=":mac" />
        <vers num="1.0.3" edition="" />
        <vers num="1.0.3" edition=":mac" />
        <vers num="1.1" edition="" />
        <vers num="1.1" edition=":mac" />
        <vers num="1.2" edition="" />
        <vers num="1.2" edition=":mac" />
        <vers num="1.3" edition="" />
        <vers num="1.3" edition=":mac" />
        <vers num="1.3.1" edition="" />
        <vers num="1.3.1" edition=":mac" />
        <vers num="1.3.2" edition="" />
        <vers num="1.3.2" edition=":mac" />
        <vers num="2.0" edition="" />
        <vers num="2.0" edition=":mac" />
        <vers num="2.0.2" edition="" />
        <vers num="2.0.2" edition=":mac" />
        <vers num="2.0.4" edition="" />
        <vers num="2.0.4" edition=":mac" />
        <vers num="3.0" edition="" />
        <vers num="3.0" edition=":windows" />
        <vers num="3.0" edition=":mac" />
        <vers num="3.0.1" edition="" />
        <vers num="3.0.1" edition=":windows" />
        <vers num="3.0.2" edition="" />
        <vers num="3.0.2" edition=":windows" />
        <vers num="3.0.2" edition="-" />
        <vers num="3.0.2" edition="-:mac" />
        <vers num="3.0.3" edition="" />
        <vers num="3.0.3" edition=":windows" />
        <vers num="3.0.3" edition=":mac" />
        <vers num="3.0.4" edition="" />
        <vers num="3.0.4" edition=":windows" />
        <vers num="3.0.4" edition=":mac" />
        <vers num="3.1" edition="" />
        <vers num="3.1" edition=":windows" />
        <vers num="3.1" edition=":mac" />
        <vers num="3.1.1" edition="" />
        <vers num="3.1.1" edition=":windows" />
        <vers num="3.1.1" edition=":mac" />
        <vers num="3.1.2" edition="" />
        <vers num="3.1.2" edition=":mac" />
        <vers num="3.1.2" edition=":windows" />
        <vers num="3.2" edition="-" />
        <vers num="3.2" edition="-:windows" />
        <vers num="3.2.1" edition="" />
        <vers num="3.2.1" edition=":mac" />
        <vers num="3.2.1" edition=":windows" />
        <vers num="3.2.2" edition="" />
        <vers num="3.2.2" edition=":windows" />
        <vers prev="1" num="3.2.3" edition="" />
        <vers prev="1" num="3.2.3" edition=":windows" />
        <vers prev="1" num="3.2.3" edition=":mac" />
        <vers prev="1" num="4.0_beta" edition="" />
        <vers prev="1" num="4.0_beta" edition=":mac" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1719" published="2009-06-16" name="CVE-2009-1719" modified="2009-06-23" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The Aqua Look and Feel for Java implementation in Java 1.5 on Mac OS X 10.5 allows remote attackers to execute arbitrary code via a call to the undocumented apple.laf.CColourUIResource constructor with a crafted value in the first argument, which is dereferenced as a pointer.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/35401" source="BID" patch="1">35401</ref>
      <ref url="http://www.securityfocus.com/bid/35381" source="BID" patch="1">35381</ref>
      <ref url="http://support.apple.com/kb/HT3632" source="CONFIRM" patch="1" adv="1">http://support.apple.com/kb/HT3632</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2009/Jun/msg00003.html" source="APPLE" patch="1" adv="1">APPLE-SA-2009-06-15-1</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/51185" source="XF">hotspot-ccolouruiresource-code-execution(51185)</ref>
      <ref url="http://www.zerodayinitiative.com/advisories/ZDI-09-043" source="MISC">http://www.zerodayinitiative.com/advisories/ZDI-09-043</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/504364/100/0/threaded" source="BUGTRAQ">20090616 ZDI-09-043: Apple Java CColorUIResource Pointer Derference Code Execution Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="jre">
        <vers num="1.5.0" edition="update1" />
        <vers num="1.5.0" edition="update10" />
        <vers num="1.5.0" edition="update11" />
        <vers num="1.5.0" edition="update12" />
        <vers num="1.5.0" edition="update13" />
        <vers num="1.5.0" edition="update14" />
        <vers num="1.5.0" edition="update15" />
        <vers num="1.5.0" edition="update16" />
        <vers num="1.5.0" edition="update17" />
        <vers num="1.5.0" edition="update2" />
        <vers num="1.5.0" edition="update3" />
        <vers num="1.5.0" edition="update4" />
        <vers num="1.5.0" edition="update5" />
        <vers num="1.5.0" edition="update6" />
        <vers num="1.5.0" edition="update7" />
        <vers num="1.5.0" edition="update8" />
        <vers num="1.5.0" edition="update9" />
        <vers num="1.5.0_11-b03" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1720" published="2009-07-31" name="CVE-2009-1720" modified="2009-08-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple integer overflows in OpenEXR 1.2.2 and 1.6.1 allow context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via unspecified vectors that trigger heap-based buffer overflows, related to (1) the Imf::PreviewImage::PreviewImage function and (2) compressor constructors.  NOTE: some of these details are obtained from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-218A.html" source="CERT">TA09-218A</ref>
      <ref url="http://www.securityfocus.com/bid/35838" source="BID" patch="1">35838</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1842" source="DEBIAN" patch="1">DSA-1842</ref>
      <ref url="http://security.debian.org/pool/updates/main/o/openexr/openexr_1.6.1-3+lenny3.diff.gz" source="CONFIRM" patch="1">http://security.debian.org/pool/updates/main/o/openexr/openexr_1.6.1-3+lenny3.diff.gz</ref>
      <ref url="http://security.debian.org/pool/updates/main/o/openexr/openexr_1.2.2-4.3+etch2.diff.gz" source="CONFIRM" patch="1">http://security.debian.org/pool/updates/main/o/openexr/openexr_1.2.2-4.3+etch2.diff.gz</ref>
      <ref url="http://release.debian.org/proposed-updates/stable_diffs/openexr_1.6.1-3%2Blenny3.debdiff" source="CONFIRM" patch="1">http://release.debian.org/proposed-updates/stable_diffs/openexr_1.6.1-3%2Blenny3.debdiff</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-July/msg01290.html" source="FEDORA">FEDORA-2009-8136</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-July/msg01286.html" source="FEDORA">FEDORA-2009-8132</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/2172" source="VUPEN">ADV-2009-2172</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/2035" source="VUPEN" adv="1">ADV-2009-2035</ref>
      <ref url="http://www.securitytracker.com/id?1022674" source="SECTRACK">1022674</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:191" source="MANDRIVA">MDVSA-2009:191</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:190" source="MANDRIVA">MDVSA-2009:190</ref>
      <ref url="http://support.apple.com/kb/HT3757" source="CONFIRM">http://support.apple.com/kb/HT3757</ref>
      <ref url="http://secunia.com/advisories/36123" source="SECUNIA">36123</ref>
      <ref url="http://secunia.com/advisories/36096" source="SECUNIA">36096</ref>
      <ref url="http://secunia.com/advisories/36032" source="SECUNIA" adv="1">36032</ref>
      <ref url="http://secunia.com/advisories/36030" source="SECUNIA" adv="1">36030</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2009/Aug/msg00001.html" source="APPLE">APPLE-SA-2009-08-05-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="openexr" name="openexr">
        <vers num="1.2.2" />
        <vers num="1.6.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1721" published="2009-07-31" name="CVE-2009-1721" modified="2009-08-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">The decompression implementation in the Imf::hufUncompress function in OpenEXR 1.2.2 and 1.6.1 allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via vectors that trigger a free of an uninitialized pointer.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-218A.html" source="CERT">TA09-218A</ref>
      <ref url="http://www.securityfocus.com/bid/35838" source="BID" patch="1">35838</ref>
      <ref url="http://security.debian.org/pool/updates/main/o/openexr/openexr_1.6.1-3+lenny3.diff.gz" source="CONFIRM" patch="1">http://security.debian.org/pool/updates/main/o/openexr/openexr_1.6.1-3+lenny3.diff.gz</ref>
      <ref url="http://security.debian.org/pool/updates/main/o/openexr/openexr_1.2.2-4.3+etch2.diff.gz" source="CONFIRM" patch="1">http://security.debian.org/pool/updates/main/o/openexr/openexr_1.2.2-4.3+etch2.diff.gz</ref>
      <ref url="http://release.debian.org/proposed-updates/stable_diffs/openexr_1.6.1-3%2Blenny3.debdiff" source="CONFIRM" patch="1">http://release.debian.org/proposed-updates/stable_diffs/openexr_1.6.1-3%2Blenny3.debdiff</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-July/msg01290.html" source="FEDORA">FEDORA-2009-8136</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-July/msg01286.html" source="FEDORA">FEDORA-2009-8132</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/2172" source="VUPEN">ADV-2009-2172</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/2035" source="VUPEN" adv="1">ADV-2009-2035</ref>
      <ref url="http://www.securitytracker.com/id?1022674" source="SECTRACK">1022674</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:191" source="MANDRIVA">MDVSA-2009:191</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:190" source="MANDRIVA">MDVSA-2009:190</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1842" source="DEBIAN">DSA-1842</ref>
      <ref url="http://support.apple.com/kb/HT3757" source="CONFIRM">http://support.apple.com/kb/HT3757</ref>
      <ref url="http://secunia.com/advisories/36123" source="SECUNIA">36123</ref>
      <ref url="http://secunia.com/advisories/36096" source="SECUNIA">36096</ref>
      <ref url="http://secunia.com/advisories/36032" source="SECUNIA" adv="1">36032</ref>
      <ref url="http://secunia.com/advisories/36030" source="SECUNIA" adv="1">36030</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2009/Aug/msg00001.html" source="APPLE">APPLE-SA-2009-08-05-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="openexr" name="openexr">
        <vers num="1.2.2" />
        <vers num="1.6.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1722" published="2009-07-31" name="CVE-2009-1722" modified="2009-08-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Heap-based buffer overflow in the compression implementation in OpenEXR 1.2.2 allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-218A.html" source="CERT">TA09-218A</ref>
      <ref url="http://www.securityfocus.com/bid/35838" source="BID" patch="1">35838</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1842" source="DEBIAN" patch="1">DSA-1842</ref>
      <ref url="http://security.debian.org/pool/updates/main/o/openexr/openexr_1.2.2-4.3+etch2.diff.gz" source="CONFIRM" patch="1">http://security.debian.org/pool/updates/main/o/openexr/openexr_1.2.2-4.3+etch2.diff.gz</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/2172" source="VUPEN">ADV-2009-2172</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/2035" source="VUPEN" adv="1">ADV-2009-2035</ref>
      <ref url="http://www.securitytracker.com/id?1022674" source="SECTRACK">1022674</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:191" source="MANDRIVA">MDVSA-2009:191</ref>
      <ref url="http://support.apple.com/kb/HT3757" source="CONFIRM">http://support.apple.com/kb/HT3757</ref>
      <ref url="http://secunia.com/advisories/36096" source="SECUNIA">36096</ref>
      <ref url="http://secunia.com/advisories/36032" source="SECUNIA" adv="1">36032</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2009/Aug/msg00001.html" source="APPLE">APPLE-SA-2009-08-05-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="openexr" name="openexr">
        <vers num="1.2.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1723" published="2009-08-06" name="CVE-2009-1723" modified="2010-06-24" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">CFNetwork in Apple Mac OS X 10.5 before 10.5.8 places an incorrect URL in a certificate warning in certain 302 redirection scenarios, which makes it easier for remote attackers to trick a user into visiting an arbitrary https web site by leveraging an open redirect vulnerability, a different issue than CVE-2009-2062.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-218A.html" source="CERT">TA09-218A</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/2172" source="VUPEN" patch="1" adv="1">ADV-2009-2172</ref>
      <ref url="http://www.securityfocus.com/bid/35954" source="BID" patch="1">35954</ref>
      <ref url="http://support.apple.com/kb/HT3757" source="CONFIRM" patch="1" adv="1">http://support.apple.com/kb/HT3757</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2009/Aug/msg00001.html" source="APPLE" patch="1" adv="1">APPLE-SA-2009-08-05-1</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/52418" source="XF">macosx-cfnetwork-weak-security(52418)</ref>
      <ref url="http://support.apple.com/kb/HT4225" source="CONFIRM">http://support.apple.com/kb/HT4225</ref>
      <ref url="http://secunia.com/advisories/36096" source="SECUNIA" adv="1">36096</ref>
      <ref url="http://osvdb.org/56846" source="OSVDB">56846</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010/Jun/msg00003.html" source="APPLE">APPLE-SA-2010-06-21-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.5.6" />
      </prod>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.5" />
        <vers num="10.5.0" />
        <vers num="10.5.1" />
        <vers num="10.5.2" edition="2008-002" />
        <vers num="10.5.3" />
        <vers num="10.5.4" />
        <vers num="10.5.5" />
        <vers num="10.5.6" />
        <vers num="10.5.7" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.5" />
        <vers num="10.5.0" />
        <vers num="10.5.1" />
        <vers num="10.5.2" />
        <vers num="10.5.3" />
        <vers num="10.5.4" />
        <vers num="10.5.5" />
        <vers num="10.5.6" />
        <vers num="10.5.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1724" published="2009-07-09" name="CVE-2009-1724" modified="2011-02-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in WebKit in Apple Safari before 4.0.2, as used on iPhone OS before 3.1, iPhone OS before 3.1.1 for iPod touch, and other platforms, allows remote attackers to inject arbitrary web script or HTML via vectors related to parent and top objects.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://support.apple.com/kb/HT3666" source="CONFIRM" patch="1" adv="1">http://support.apple.com/kb/HT3666</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2009/Jul/msg00000.html" source="APPLE" patch="1" adv="1">APPLE-SA-2009-07-08-1</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0212" source="VUPEN">ADV-2011-0212</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1827" source="VUPEN">ADV-2009-1827</ref>
      <ref url="http://www.securitytracker.com/id?1022525" source="SECTRACK">1022525</ref>
      <ref url="http://www.securityfocus.com/bid/35441" source="BID">35441</ref>
      <ref url="http://support.apple.com/kb/HT3860" source="CONFIRM">http://support.apple.com/kb/HT3860</ref>
      <ref url="http://secunia.com/advisories/43068" source="SECUNIA">43068</ref>
      <ref url="http://secunia.com/advisories/36677" source="SECUNIA">36677</ref>
      <ref url="http://secunia.com/advisories/35758" source="SECUNIA">35758</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6208" source="OVAL">oval:org.mitre.oval:def:6208</ref>
      <ref url="http://osvdb.org/55738" source="OSVDB">55738</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.html" source="SUSE">SUSE-SR:2011:002</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2009/Sep/msg00001.html" source="APPLE">APPLE-SA-2009-09-09-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="safari">
        <vers num="" edition=":windows" />
        <vers num="0.8" edition="" />
        <vers num="0.8" edition=":mac" />
        <vers num="0.8" edition="-" />
        <vers num="0.8" edition="-:mac" />
        <vers num="0.9" edition="" />
        <vers num="0.9" edition=":mac" />
        <vers num="0.9" edition="-" />
        <vers num="0.9" edition="-:mac" />
        <vers num="1.0" edition="" />
        <vers num="1.0" edition=":mac" />
        <vers num="1.0" edition="-" />
        <vers num="1.0" edition="-:mac" />
        <vers num="1.0" edition="beta" />
        <vers num="1.0" edition="beta2" />
        <vers num="1.0.0" />
        <vers num="1.0.0b1" />
        <vers num="1.0.0b2" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" edition="" />
        <vers num="1.0.3" edition=":mac" />
        <vers num="1.0.3" edition="-" />
        <vers num="1.0.3" edition="-:mac" />
        <vers num="1.0.3" edition="85.8" />
        <vers num="1.0.3" edition="85.8.1" />
        <vers num="1.0b1" edition="-" />
        <vers num="1.0b1" edition="-:mac" />
        <vers num="1.1" edition="" />
        <vers num="1.1" edition=":mac" />
        <vers num="1.1" edition="-" />
        <vers num="1.1" edition="-:mac" />
        <vers num="1.1.0" />
        <vers num="1.1.1" />
        <vers num="1.2" edition="" />
        <vers num="1.2" edition=":mac" />
        <vers num="1.2" edition="-" />
        <vers num="1.2" edition="-:mac" />
        <vers num="1.2.0" />
        <vers num="1.2.1" />
        <vers num="1.2.2" />
        <vers num="1.2.3" />
        <vers num="1.2.4" />
        <vers num="1.2.5" />
        <vers num="1.3" edition="" />
        <vers num="1.3" edition=":mac" />
        <vers num="1.3" edition="-" />
        <vers num="1.3" edition="-:mac" />
        <vers num="1.3.0" />
        <vers num="1.3.1" edition="" />
        <vers num="1.3.1" edition=":mac" />
        <vers num="1.3.1" edition="-" />
        <vers num="1.3.1" edition="-:mac" />
        <vers num="1.3.2" edition="" />
        <vers num="1.3.2" edition=":mac" />
        <vers num="1.3.2" edition="-" />
        <vers num="1.3.2" edition="-:mac" />
        <vers num="1.3.2" edition="312.5" />
        <vers num="1.3.2" edition="312.6" />
        <vers num="2" />
        <vers num="2.0" edition="" />
        <vers num="2.0" edition=":mac" />
        <vers num="2.0" edition="-" />
        <vers num="2.0" edition="-:mac" />
        <vers num="2.0.0" />
        <vers num="2.0.1" />
        <vers num="2.0.2" edition="" />
        <vers num="2.0.2" edition=":mac" />
        <vers num="2.0.2" edition="-" />
        <vers num="2.0.2" edition="-:mac" />
        <vers num="2.0.3" edition="417.8" />
        <vers num="2.0.3" edition="417.9" />
        <vers num="2.0.3" edition="417.9.2" />
        <vers num="2.0.3" edition="417.9.3" />
        <vers num="2.0.3_417.9.3" edition="" />
        <vers num="2.0.3_417.9.3" edition=":mac_os_x_10.4.6" />
        <vers num="2.0.4" edition="" />
        <vers num="2.0.4" edition=":mac" />
        <vers num="2.0.4" edition="-" />
        <vers num="2.0.4" edition="-:mac" />
        <vers num="2.0.4_419.3" />
        <vers num="2.0_pre" />
        <vers num="3.0" edition="" />
        <vers num="3.0" edition=":mac" />
        <vers num="3.0" edition=":windows" />
        <vers num="3.0" edition="-" />
        <vers num="3.0" edition="-:windows" />
        <vers num="3.0" edition="-:mac" />
        <vers num="3.0..3" edition="-" />
        <vers num="3.0..3" edition="-:windows" />
        <vers num="3.0.0" edition="-" />
        <vers num="3.0.0" edition="-:mac" />
        <vers num="3.0.0b" edition="-" />
        <vers num="3.0.0b" edition="-:windows" />
        <vers num="3.0.1" edition="" />
        <vers num="3.0.1" edition=":windows" />
        <vers num="3.0.1" edition="-" />
        <vers num="3.0.1" edition="-:mac" />
        <vers num="3.0.1" edition="-:windows" />
        <vers num="3.0.1" edition="beta" />
        <vers num="3.0.1_beta" edition="-" />
        <vers num="3.0.1_beta" edition="-:windows" />
        <vers num="3.0.1b" edition="-" />
        <vers num="3.0.1b" edition="-:windows" />
        <vers num="3.0.2" edition="" />
        <vers num="3.0.2" edition=":windows" />
        <vers num="3.0.2" edition="-" />
        <vers num="3.0.2" edition="-:mac" />
        <vers num="3.0.2" edition="-:windows" />
        <vers num="3.0.2b" edition="-" />
        <vers num="3.0.2b" edition="-:windows" />
        <vers num="3.0.3" edition="" />
        <vers num="3.0.3" edition=":mac" />
        <vers num="3.0.3" edition=":windows" />
        <vers num="3.0.3" edition="-" />
        <vers num="3.0.3" edition="-:windows" />
        <vers num="3.0.3" edition="-:mac" />
        <vers num="3.0.3" edition="522.15.5" />
        <vers num="3.0.3b" edition="-" />
        <vers num="3.0.3b" edition="-:windows" />
        <vers num="3.0.4" edition="" />
        <vers num="3.0.4" edition=":windows" />
        <vers num="3.0.4" edition=":mac" />
        <vers num="3.0.4" edition="-" />
        <vers num="3.0.4" edition="-:mac" />
        <vers num="3.0.4" edition="-:windows" />
        <vers num="3.0.4_beta" edition="" />
        <vers num="3.0.4_beta" edition=":windows" />
        <vers num="3.0.4_beta" edition="-" />
        <vers num="3.0.4_beta" edition="-:windows" />
        <vers num="3.0.4b" edition="-" />
        <vers num="3.0.4b" edition="-:windows" />
        <vers num="3.1" edition="" />
        <vers num="3.1" edition=":mac" />
        <vers num="3.1" edition=":windows" />
        <vers num="3.1" edition="-" />
        <vers num="3.1" edition="-:windows" />
        <vers num="3.1" edition="-:mac" />
        <vers num="3.1.0" edition="-" />
        <vers num="3.1.0" edition="-:mac" />
        <vers num="3.1.0b" edition="-" />
        <vers num="3.1.0b" edition="-:windows" />
        <vers num="3.1.1" edition="" />
        <vers num="3.1.1" edition=":windows" />
        <vers num="3.1.1" edition=":mac" />
        <vers num="3.1.1" edition="-" />
        <vers num="3.1.1" edition="-:windows" />
        <vers num="3.1.1" edition="-:mac" />
        <vers num="3.1.1b" edition="-" />
        <vers num="3.1.1b" edition="-:windows" />
        <vers num="3.1.2" edition="" />
        <vers num="3.1.2" edition=":mac" />
        <vers num="3.1.2" edition=":windows" />
        <vers num="3.1.2" edition="-" />
        <vers num="3.1.2" edition="-:mac" />
        <vers num="3.1.2" edition="-:windows" />
        <vers num="3.1.2b" edition="-" />
        <vers num="3.1.2b" edition="-:windows" />
        <vers num="3.2" edition="" />
        <vers num="3.2" edition=":windows" />
        <vers num="3.2" edition="-" />
        <vers num="3.2" edition="-:mac" />
        <vers num="3.2" edition="-:windows" />
        <vers num="3.2.0" />
        <vers num="3.2.0b" edition="-" />
        <vers num="3.2.0b" edition="-:windows" />
        <vers num="3.2.1" edition="" />
        <vers num="3.2.1" edition=":windows" />
        <vers num="3.2.1" edition=":mac" />
        <vers num="3.2.1" edition="-" />
        <vers num="3.2.1" edition="-:mac" />
        <vers num="3.2.1" edition="-:windows" />
        <vers num="3.2.1b" edition="-" />
        <vers num="3.2.1b" edition="-:windows" />
        <vers num="3.2.2" edition="" />
        <vers num="3.2.2" edition=":windows" />
        <vers num="3.2.2" edition="-" />
        <vers num="3.2.2" edition="-:windows" />
        <vers num="3.2.2b" edition="-" />
        <vers num="3.2.2b" edition="-:windows" />
        <vers num="3.2.3" edition="" />
        <vers num="3.2.3" edition=":mac" />
        <vers num="3.2.3" edition=":windows" />
        <vers num="3.2.3" edition="-" />
        <vers num="3.2.3" edition="-:windows" />
        <vers num="3.2.3" edition="-:mac" />
        <vers num="4.0" edition="beta" />
        <vers num="4.0.0b" />
        <vers prev="1" num="4.0.1" edition="-" />
        <vers prev="1" num="4.0.1" edition="-:windows" />
        <vers prev="1" num="4.0.1" edition="-:mac" />
        <vers num="4.0_beta" edition="" />
        <vers num="4.0_beta" edition=":mac" />
        <vers num="4.0_beta" edition="-" />
        <vers num="4.0_beta" edition="-:mac" />
        <vers num="4.0_beta" edition="528.16" />
        <vers num="beta2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1725" published="2009-07-09" name="CVE-2009-1725" modified="2011-02-17" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">WebKit in Apple Safari before 4.0.2, as used on iPhone OS before 3.1, iPhone OS before 3.1.1 for iPod touch, and other platforms; KHTML in kdelibs in KDE; QtWebKit (aka Qt toolkit); and possibly other products do not properly handle numeric character references, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted HTML document.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/35607" source="BID" patch="1">35607</ref>
      <ref url="http://support.apple.com/kb/HT3666" source="CONFIRM" patch="1" adv="1">http://support.apple.com/kb/HT3666</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2009/Jul/msg00000.html" source="APPLE" patch="1" adv="1">APPLE-SA-2009-07-08-1</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-July/msg01200.html" source="FEDORA">FEDORA-2009-8020</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-July/msg01199.html" source="FEDORA">FEDORA-2009-8046</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-July/msg01196.html" source="FEDORA">FEDORA-2009-8049</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-July/msg01177.html" source="FEDORA">FEDORA-2009-8039</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-August/msg00933.html" source="FEDORA">FEDORA-2009-8802</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-August/msg00931.html" source="FEDORA">FEDORA-2009-8800</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=513813" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=513813</ref>
      <ref url="http://www.vupen.com/english/advisories/2011/0212" source="VUPEN">ADV-2011-0212</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1827" source="VUPEN">ADV-2009-1827</ref>
      <ref url="http://www.ubuntu.com/usn/USN-857-1" source="UBUNTU">USN-857-1</ref>
      <ref url="http://www.ubuntu.com/usn/USN-836-1" source="UBUNTU">USN-836-1</ref>
      <ref url="http://www.securitytracker.com/id?1022526" source="SECTRACK">1022526</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:330" source="MANDRIVA">MDVSA-2009:330</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1950" source="DEBIAN">DSA-1950</ref>
      <ref url="http://websvn.kde.org/?view=rev&amp;revision=1002164" source="CONFIRM">http://websvn.kde.org/?view=rev&amp;revision=1002164</ref>
      <ref url="http://websvn.kde.org/?view=rev&amp;revision=1002163" source="CONFIRM">http://websvn.kde.org/?view=rev&amp;revision=1002163</ref>
      <ref url="http://websvn.kde.org/?view=rev&amp;revision=1002162" source="CONFIRM">http://websvn.kde.org/?view=rev&amp;revision=1002162</ref>
      <ref url="http://support.apple.com/kb/HT3860" source="CONFIRM">http://support.apple.com/kb/HT3860</ref>
      <ref url="http://secunia.com/advisories/43068" source="SECUNIA">43068</ref>
      <ref url="http://secunia.com/advisories/37746" source="SECUNIA">37746</ref>
      <ref url="http://secunia.com/advisories/36790" source="SECUNIA">36790</ref>
      <ref url="http://secunia.com/advisories/36677" source="SECUNIA">36677</ref>
      <ref url="http://secunia.com/advisories/36347" source="SECUNIA">36347</ref>
      <ref url="http://secunia.com/advisories/36062" source="SECUNIA">36062</ref>
      <ref url="http://secunia.com/advisories/36057" source="SECUNIA">36057</ref>
      <ref url="http://secunia.com/advisories/35758" source="SECUNIA">35758</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5777" source="OVAL">oval:org.mitre.oval:def:5777</ref>
      <ref url="http://osvdb.org/55739" source="OSVDB">55739</ref>
      <ref url="http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.html" source="SUSE">SUSE-SR:2011:002</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2009/Sep/msg00001.html" source="APPLE">APPLE-SA-2009-09-09-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="safari">
        <vers num="" edition=":windows" />
        <vers num="0.8" edition="" />
        <vers num="0.8" edition=":mac" />
        <vers num="0.8" edition="-" />
        <vers num="0.8" edition="-:mac" />
        <vers num="0.9" edition="" />
        <vers num="0.9" edition=":mac" />
        <vers num="0.9" edition="-" />
        <vers num="0.9" edition="-:mac" />
        <vers num="1.0" edition="" />
        <vers num="1.0" edition=":mac" />
        <vers num="1.0" edition="-" />
        <vers num="1.0" edition="-:mac" />
        <vers num="1.0" edition="beta" />
        <vers num="1.0" edition="beta2" />
        <vers num="1.0.0" />
        <vers num="1.0.0b1" />
        <vers num="1.0.0b2" />
        <vers num="1.0.1" />
        <vers num="1.0.2" />
        <vers num="1.0.3" edition="" />
        <vers num="1.0.3" edition=":mac" />
        <vers num="1.0.3" edition="-" />
        <vers num="1.0.3" edition="-:mac" />
        <vers num="1.0.3" edition="85.8" />
        <vers num="1.0.3" edition="85.8.1" />
        <vers num="1.0b1" edition="-" />
        <vers num="1.0b1" edition="-:mac" />
        <vers num="1.1" edition="" />
        <vers num="1.1" edition=":mac" />
        <vers num="1.1" edition="-" />
        <vers num="1.1" edition="-:mac" />
        <vers num="1.1.0" />
        <vers num="1.1.1" />
        <vers num="1.2" edition="" />
        <vers num="1.2" edition=":mac" />
        <vers num="1.2" edition="-" />
        <vers num="1.2" edition="-:mac" />
        <vers num="1.2.0" />
        <vers num="1.2.1" />
        <vers num="1.2.2" />
        <vers num="1.2.3" />
        <vers num="1.2.4" />
        <vers num="1.2.5" />
        <vers num="1.3" edition="" />
        <vers num="1.3" edition=":mac" />
        <vers num="1.3" edition="-" />
        <vers num="1.3" edition="-:mac" />
        <vers num="1.3.0" />
        <vers num="1.3.1" edition="" />
        <vers num="1.3.1" edition=":mac" />
        <vers num="1.3.1" edition="-" />
        <vers num="1.3.1" edition="-:mac" />
        <vers num="1.3.2" edition="" />
        <vers num="1.3.2" edition=":mac" />
        <vers num="1.3.2" edition="-" />
        <vers num="1.3.2" edition="-:mac" />
        <vers num="1.3.2" edition="312.5" />
        <vers num="1.3.2" edition="312.6" />
        <vers num="2" />
        <vers num="2.0" edition="" />
        <vers num="2.0" edition=":mac" />
        <vers num="2.0" edition="-" />
        <vers num="2.0" edition="-:mac" />
        <vers num="2.0.0" />
        <vers num="2.0.1" />
        <vers num="2.0.2" edition="" />
        <vers num="2.0.2" edition=":mac" />
        <vers num="2.0.2" edition="-" />
        <vers num="2.0.2" edition="-:mac" />
        <vers num="2.0.3" edition="417.8" />
        <vers num="2.0.3" edition="417.9" />
        <vers num="2.0.3" edition="417.9.2" />
        <vers num="2.0.3" edition="417.9.3" />
        <vers num="2.0.3_417.9.3" edition="" />
        <vers num="2.0.3_417.9.3" edition=":mac_os_x_10.4.6" />
        <vers num="2.0.4" edition="" />
        <vers num="2.0.4" edition=":mac" />
        <vers num="2.0.4" edition="-" />
        <vers num="2.0.4" edition="-:mac" />
        <vers num="2.0.4_419.3" />
        <vers num="2.0_pre" />
        <vers num="3.0" edition="" />
        <vers num="3.0" edition=":mac" />
        <vers num="3.0" edition=":windows" />
        <vers num="3.0" edition="-" />
        <vers num="3.0" edition="-:windows" />
        <vers num="3.0" edition="-:mac" />
        <vers num="3.0..3" edition="-" />
        <vers num="3.0..3" edition="-:windows" />
        <vers num="3.0.0" edition="-" />
        <vers num="3.0.0" edition="-:mac" />
        <vers num="3.0.0b" edition="-" />
        <vers num="3.0.0b" edition="-:windows" />
        <vers num="3.0.1" edition="" />
        <vers num="3.0.1" edition=":windows" />
        <vers num="3.0.1" edition="-" />
        <vers num="3.0.1" edition="-:mac" />
        <vers num="3.0.1" edition="-:windows" />
        <vers num="3.0.1" edition="beta" />
        <vers num="3.0.1_beta" edition="-" />
        <vers num="3.0.1_beta" edition="-:windows" />
        <vers num="3.0.1b" edition="-" />
        <vers num="3.0.1b" edition="-:windows" />
        <vers num="3.0.2" edition="" />
        <vers num="3.0.2" edition=":windows" />
        <vers num="3.0.2" edition="-" />
        <vers num="3.0.2" edition="-:mac" />
        <vers num="3.0.2" edition="-:windows" />
        <vers num="3.0.2b" edition="-" />
        <vers num="3.0.2b" edition="-:windows" />
        <vers num="3.0.3" edition="" />
        <vers num="3.0.3" edition=":mac" />
        <vers num="3.0.3" edition=":windows" />
        <vers num="3.0.3" edition="-" />
        <vers num="3.0.3" edition="-:windows" />
        <vers num="3.0.3" edition="-:mac" />
        <vers num="3.0.3" edition="522.15.5" />
        <vers num="3.0.3b" edition="-" />
        <vers num="3.0.3b" edition="-:windows" />
        <vers num="3.0.4" edition="" />
        <vers num="3.0.4" edition=":windows" />
        <vers num="3.0.4" edition=":mac" />
        <vers num="3.0.4" edition="-" />
        <vers num="3.0.4" edition="-:mac" />
        <vers num="3.0.4" edition="-:windows" />
        <vers num="3.0.4_beta" edition="" />
        <vers num="3.0.4_beta" edition=":windows" />
        <vers num="3.0.4_beta" edition="-" />
        <vers num="3.0.4_beta" edition="-:windows" />
        <vers num="3.0.4b" edition="-" />
        <vers num="3.0.4b" edition="-:windows" />
        <vers num="3.1" edition="" />
        <vers num="3.1" edition=":mac" />
        <vers num="3.1" edition=":windows" />
        <vers num="3.1" edition="-" />
        <vers num="3.1" edition="-:windows" />
        <vers num="3.1" edition="-:mac" />
        <vers num="3.1.0" edition="-" />
        <vers num="3.1.0" edition="-:mac" />
        <vers num="3.1.0b" edition="-" />
        <vers num="3.1.0b" edition="-:windows" />
        <vers num="3.1.1" edition="" />
        <vers num="3.1.1" edition=":windows" />
        <vers num="3.1.1" edition=":mac" />
        <vers num="3.1.1" edition="-" />
        <vers num="3.1.1" edition="-:windows" />
        <vers num="3.1.1" edition="-:mac" />
        <vers num="3.1.1b" edition="-" />
        <vers num="3.1.1b" edition="-:windows" />
        <vers num="3.1.2" edition="" />
        <vers num="3.1.2" edition=":mac" />
        <vers num="3.1.2" edition=":windows" />
        <vers num="3.1.2" edition="-" />
        <vers num="3.1.2" edition="-:mac" />
        <vers num="3.1.2" edition="-:windows" />
        <vers num="3.1.2b" edition="-" />
        <vers num="3.1.2b" edition="-:windows" />
        <vers num="3.2" edition="" />
        <vers num="3.2" edition=":windows" />
        <vers num="3.2" edition="-" />
        <vers num="3.2" edition="-:mac" />
        <vers num="3.2" edition="-:windows" />
        <vers num="3.2.0" />
        <vers num="3.2.0b" edition="-" />
        <vers num="3.2.0b" edition="-:windows" />
        <vers num="3.2.1" edition="" />
        <vers num="3.2.1" edition=":windows" />
        <vers num="3.2.1" edition=":mac" />
        <vers num="3.2.1" edition="-" />
        <vers num="3.2.1" edition="-:mac" />
        <vers num="3.2.1" edition="-:windows" />
        <vers num="3.2.1b" edition="-" />
        <vers num="3.2.1b" edition="-:windows" />
        <vers num="3.2.2" edition="" />
        <vers num="3.2.2" edition=":windows" />
        <vers num="3.2.2" edition="-" />
        <vers num="3.2.2" edition="-:windows" />
        <vers num="3.2.2b" edition="-" />
        <vers num="3.2.2b" edition="-:windows" />
        <vers num="3.2.3" edition="" />
        <vers num="3.2.3" edition=":mac" />
        <vers num="3.2.3" edition=":windows" />
        <vers num="3.2.3" edition="-" />
        <vers num="3.2.3" edition="-:windows" />
        <vers num="3.2.3" edition="-:mac" />
        <vers num="4.0" edition="beta" />
        <vers num="4.0.0b" />
        <vers prev="1" num="4.0.1" edition="-" />
        <vers prev="1" num="4.0.1" edition="-:windows" />
        <vers prev="1" num="4.0.1" edition="-:mac" />
        <vers num="4.0_beta" edition="" />
        <vers num="4.0_beta" edition=":mac" />
        <vers num="4.0_beta" edition="-" />
        <vers num="4.0_beta" edition="-:mac" />
        <vers num="4.0_beta" edition="528.16" />
        <vers num="beta2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1726" published="2009-08-06" name="CVE-2009-1726" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Heap-based buffer overflow in ColorSync in Apple Mac OS X 10.4.11 and 10.5 before 10.5.8 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted image containing an embedded ColorSync profile.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-218A.html" source="CERT">TA09-218A</ref>
      <ref url="http://www.securityfocus.com/bid/35954" source="BID" patch="1">35954</ref>
      <ref url="http://support.apple.com/kb/HT3757" source="CONFIRM" patch="1" adv="1">http://support.apple.com/kb/HT3757</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2009/Aug/msg00001.html" source="APPLE" patch="1" adv="1">APPLE-SA-2009-08-05-1</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/59162" source="XF">safari-colorsync-profile-bo(59162)</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/52419" source="XF">macosx-colorsync-profile-bo(52419)</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1512" source="VUPEN">ADV-2010-1512</ref>
      <ref url="http://www.vupen.com/english/advisories/2010/1373" source="VUPEN">ADV-2010-1373</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/2172" source="VUPEN" adv="1">ADV-2009-2172</ref>
      <ref url="http://www.securitytracker.com/id?1022674" source="SECTRACK">1022674</ref>
      <ref url="http://support.apple.com/kb/HT4220" source="CONFIRM">http://support.apple.com/kb/HT4220</ref>
      <ref url="http://support.apple.com/kb/HT4196" source="CONFIRM">http://support.apple.com/kb/HT4196</ref>
      <ref url="http://secunia.com/advisories/40196" source="SECUNIA">40196</ref>
      <ref url="http://secunia.com/advisories/40105" source="SECUNIA">40105</ref>
      <ref url="http://secunia.com/advisories/36096" source="SECUNIA" adv="1">36096</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7499" source="OVAL">oval:org.mitre.oval:def:7499</ref>
      <ref url="http://osvdb.org/56845" source="OSVDB">56845</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010/Jun/msg00000.html" source="APPLE">APPLE-SA-2010-06-07-1</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2010//Jun/msg00002.html" source="APPLE">APPLE-SA-2010-06-16-1</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.5.6" />
      </prod>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.4.11" />
        <vers num="10.5" />
        <vers num="10.5.0" />
        <vers num="10.5.1" />
        <vers num="10.5.2" edition="2008-002" />
        <vers num="10.5.3" />
        <vers num="10.5.4" />
        <vers num="10.5.5" />
        <vers num="10.5.6" />
        <vers num="10.5.7" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.4.11" />
        <vers num="10.5" />
        <vers num="10.5.0" />
        <vers num="10.5.1" />
        <vers num="10.5.2" />
        <vers num="10.5.3" />
        <vers num="10.5.4" />
        <vers num="10.5.5" />
        <vers num="10.5.6" />
        <vers num="10.5.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1727" published="2009-08-06" name="CVE-2009-1727" modified="2009-08-19" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Incomplete blacklist vulnerability in CoreTypes in Apple Mac OS X 10.5 before 10.5.8 makes it easier for user-assisted remote attackers to execute arbitrary JavaScript via a web page that offers a download with a Content-Type value that is not on the list of possibly unsafe content types for Safari.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-218A.html" source="CERT">TA09-218A</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/2172" source="VUPEN" patch="1" adv="1">ADV-2009-2172</ref>
      <ref url="http://www.securityfocus.com/bid/35954" source="BID" patch="1">35954</ref>
      <ref url="http://support.apple.com/kb/HT3757" source="CONFIRM" patch="1" adv="1">http://support.apple.com/kb/HT3757</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2009/Aug/msg00001.html" source="APPLE" patch="1" adv="1">APPLE-SA-2009-08-05-1</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/52420" source="XF">macosx-coretype-code-execution(52420)</ref>
      <ref url="http://secunia.com/advisories/36096" source="SECUNIA" adv="1">36096</ref>
      <ref url="http://osvdb.org/56844" source="OSVDB">56844</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.5.6" />
      </prod>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.5" />
        <vers num="10.5.0" />
        <vers num="10.5.1" />
        <vers num="10.5.2" />
        <vers num="10.5.3" />
        <vers num="10.5.4" />
        <vers num="10.5.5" />
        <vers num="10.5.6" />
        <vers num="10.5.7" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.5" />
        <vers num="10.5.0" />
        <vers num="10.5.1" />
        <vers num="10.5.2" />
        <vers num="10.5.3" />
        <vers num="10.5.4" />
        <vers num="10.5.5" />
        <vers num="10.5.6" />
        <vers num="10.5.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1728" published="2009-08-06" name="CVE-2009-1728" modified="2009-08-19" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Stack-based buffer overflow in Image RAW in Apple Mac OS X 10.5 before 10.5.8, and 10.4 before Digital Camera RAW Compatibility Update 2.6, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted Canon RAW image.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.us-cert.gov/cas/techalerts/TA09-218A.html" source="CERT">TA09-218A</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/2172" source="VUPEN" patch="1" adv="1">ADV-2009-2172</ref>
      <ref url="http://www.securityfocus.com/bid/35954" source="BID" patch="1">35954</ref>
      <ref url="http://support.apple.com/kb/HT3757" source="CONFIRM" patch="1" adv="1">http://support.apple.com/kb/HT3757</ref>
      <ref url="http://lists.apple.com/archives/security-announce/2009/Aug/msg00001.html" source="APPLE" patch="1" adv="1">APPLE-SA-2009-08-05-1</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/52423" source="XF">macosx-imageraw-bo(52423)</ref>
      <ref url="http://www.securitytracker.com/id?1022674" source="SECTRACK">1022674</ref>
      <ref url="http://secunia.com/advisories/36096" source="SECUNIA" adv="1">36096</ref>
      <ref url="http://osvdb.org/56843" source="OSVDB">56843</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.5.6" />
      </prod>
      <prod vendor="apple" name="mac_os_x">
        <vers num="10.4" edition="digital_camera_raw_compatibility_update_2.1" />
        <vers num="10.4" edition="digital_camera_raw_compatibility_update_2.2" />
        <vers num="10.4" edition="digital_camera_raw_compatibility_update_2.3" />
        <vers num="10.4" edition="digital_camera_raw_compatibility_update_2.4" />
        <vers num="10.4" edition="digital_camera_raw_compatibility_update_2.5" />
        <vers num="10.4.0" />
        <vers num="10.4.1" />
        <vers num="10.4.10" />
        <vers num="10.4.11" />
        <vers num="10.4.2" />
        <vers num="10.4.3" />
        <vers num="10.4.4" />
        <vers num="10.4.5" />
        <vers num="10.4.6" />
        <vers num="10.4.7" />
        <vers num="10.4.8" />
        <vers num="10.5" />
        <vers num="10.5.0" />
        <vers num="10.5.1" />
        <vers num="10.5.2" />
        <vers num="10.5.3" />
        <vers num="10.5.4" />
        <vers num="10.5.5" />
        <vers num="10.5.6" />
        <vers num="10.5.7" />
      </prod>
      <prod vendor="apple" name="mac_os_x_server">
        <vers num="10.4" edition="digital_camera_raw_compatibility_update_2.1" />
        <vers num="10.4" edition="digital_camera_raw_compatibility_update_2.2" />
        <vers num="10.4" edition="digital_camera_raw_compatibility_update_2.3" />
        <vers num="10.4" edition="digital_camera_raw_compatibility_update_2.4" />
        <vers num="10.4" edition="digital_camera_raw_compatibility_update_2.5" />
        <vers num="10.4.0" />
        <vers num="10.4.1" />
        <vers num="10.4.10" />
        <vers num="10.4.11" />
        <vers num="10.4.2" />
        <vers num="10.4.3" />
        <vers num="10.4.4" />
        <vers num="10.4.5" />
        <vers num="10.4.6" />
        <vers num="10.4.7" />
        <vers num="10.4.8" />
        <vers num="10.4.9" />
        <vers num="10.5" />
        <vers num="10.5.0" />
        <vers num="10.5.1" />
        <vers num="10.5.2" />
        <vers num="10.5.3" />
        <vers num="10.5.4" />
        <vers num="10.5.5" />
        <vers num="10.5.6" />
        <vers num="10.5.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1729" published="2009-05-21" name="CVE-2009-1729" modified="2009-06-09" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Sun Java System Communications Express 6 2005Q4 (aka 6.2) and 6.3 allow remote attackers to inject arbitrary web script or HTML via (1) the abperson_displayName parameter to uwc/abs/search.xml in the Add Contact implementation in the Personal Address Book component or (2) the temporaryCalendars parameter to uwc/base/UWCMain.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/34155" source="BID" patch="1">34155</ref>
      <ref url="http://www.securityfocus.com/bid/34154" source="BID" patch="1">34154</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/503675/100/0/threaded" source="BUGTRAQ" patch="1" adv="1">20090520 CORE-2009-0109 - Multiple XSS in Sun Communications Express</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-258068-1" source="SUNALERT" patch="1" adv="1">258068</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-21-122793-26-1" source="CONFIRM" patch="1" adv="1">http://sunsolve.sun.com/search/document.do?assetkey=1-21-122793-26-1</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/50658" source="XF">communications-express-search-xss(50658)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1389" source="VUPEN">ADV-2009-1389</ref>
      <ref url="http://www.coresecurity.com/content/sun-communications-express" source="MISC">http://www.coresecurity.com/content/sun-communications-express</ref>
      <ref url="http://securitytracker.com/alerts/2009/May/1022266.html" source="SECTRACK">1022266</ref>
      <ref url="http://secunia.com/advisories/32474" source="SECUNIA">32474</ref>
      <ref url="http://seclists.org/fulldisclosure/2009/May/0177.html" source="FULLDISC">20090520 CORE-2009-0109 - Multiple XSS in Sun Communications Express</ref>
      <ref url="http://osvdb.org/54610" source="OSVDB">54610</ref>
      <ref url="http://osvdb.org/54609" source="OSVDB">54609</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="java_system_communications_express">
        <vers num="6.2" edition="" />
        <vers num="6.2" edition=":x86" />
        <vers num="6.2" edition=":linux" />
        <vers num="6.2" edition=":sparc" />
        <vers num="6.3" edition="" />
        <vers num="6.3" edition=":x86" />
        <vers num="6.3" edition=":linux" />
        <vers num="6.3" edition=":sparc" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1730" published="2009-05-20" name="CVE-2009-1730" modified="2009-05-20" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Multiple directory traversal vulnerabilities in NetMechanica NetDecision TFTP Server 4.2 allow remote attackers to read or modify arbitrary files via directory traversal sequences in the (1) GET or (2) PUT command.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/50574" source="XF">netdecision-tftp-dir-traversal(50574)</ref>
      <ref url="http://www.securityfocus.com/bid/35002" source="BID">35002</ref>
      <ref url="http://www.princeofnigeria.org/blogs/index.php/2009/05/17/netdecision-tftp-server-4-2-tftp-directo?blog=1" source="MISC">http://www.princeofnigeria.org/blogs/index.php/2009/05/17/netdecision-tftp-server-4-2-tftp-directo?blog=1</ref>
      <ref url="http://secunia.com/advisories/35131" source="SECUNIA" adv="1">35131</ref>
    </refs>
    <vuln_soft>
      <prod vendor="netmechanica" name="netdecision_tftp_server">
        <vers num="4.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1731" published="2009-05-20" name="CVE-2009-1731" modified="2009-05-20" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in panel/index.php in MLFFAT 2.1 allows remote attackers to execute arbitrary SQL commands via a base64-encoded supervisor cookie.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/50526" source="XF">mlffat-index-sql-injection(50526)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1308" source="VUPEN" adv="1">ADV-2009-1308</ref>
      <ref url="http://www.securityfocus.com/bid/34982" source="BID">34982</ref>
      <ref url="http://www.sebug.net/exploit/11292/" source="MISC">http://www.sebug.net/exploit/11292/</ref>
      <ref url="http://securityreason.com/exploitalert/6198" source="MISC">http://securityreason.com/exploitalert/6198</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mlffat" name="mlffat">
        <vers num="2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1732" published="2009-05-20" name="CVE-2009-1732" modified="2009-07-10" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in admin/usermanager in IPplan 4.91a allows remote attackers to inject arbitrary web script or HTML via the grp parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/35037" source="BID">35037</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1827" source="DEBIAN">DSA-1827</ref>
      <ref url="http://secunia.com/advisories/35714" source="SECUNIA">35714</ref>
      <ref url="http://secunia.com/advisories/34985" source="SECUNIA" adv="1">34985</ref>
      <ref url="http://osvdb.org/54600" source="OSVDB">54600</ref>
      <ref url="http://holisticinfosec.org/content/view/113/45/" source="MISC">http://holisticinfosec.org/content/view/113/45/</ref>
    </refs>
    <vuln_soft>
      <prod vendor="richard_ellerbrock" name="ipplan">
        <vers num="4.91a" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1733" published="2009-05-20" name="CVE-2009-1733" modified="2009-06-09" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site request forgery (CSRF) vulnerability in IPplan 4.91a allows remote attackers to hijack the authentication of administrators for requests that (1) change the password, (2) add users, or (3) delete users via unknown vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/50632" source="XF">ipplan-unspecified-csrf(50632)</ref>
      <ref url="http://secunia.com/advisories/34985" source="SECUNIA" adv="1">34985</ref>
      <ref url="http://osvdb.org/54601" source="OSVDB">54601</ref>
      <ref url="http://holisticinfosec.org/content/view/113/45/" source="MISC">http://holisticinfosec.org/content/view/113/45/</ref>
    </refs>
    <vuln_soft>
      <prod vendor="richard_ellerbrock" name="ipplan">
        <vers num="4.91a" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1734" published="2009-05-20" name="CVE-2009-1734" modified="2009-06-09" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in listing_video.php in VidSharePro allows remote attackers to execute arbitrary SQL commands via the catid parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/35033" source="BID">35033</ref>
      <ref url="http://www.milw0rm.com/exploits/8737" source="MILW0RM">8737</ref>
      <ref url="http://secunia.com/advisories/35149" source="SECUNIA" adv="1">35149</ref>
      <ref url="http://osvdb.org/54598" source="OSVDB">54598</ref>
    </refs>
    <vuln_soft>
      <prod vendor="omnisoftsol" name="vidsharepro">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1735" published="2009-05-20" name="CVE-2009-1735" modified="2009-06-09" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in search.php in VidSharePro allows remote attackers to inject arbitrary web script or HTML via the searchtxt parameter.  NOTE: some of these details are obtained from third party information.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/50635" source="XF">vidshare-listingvideo-sql-injection(50635)</ref>
      <ref url="http://www.securityfocus.com/bid/35033" source="BID">35033</ref>
      <ref url="http://www.milw0rm.com/exploits/8737" source="MILW0RM">8737</ref>
      <ref url="http://secunia.com/advisories/35149" source="SECUNIA" adv="1">35149</ref>
      <ref url="http://osvdb.org/54599" source="OSVDB">54599</ref>
    </refs>
    <vuln_soft>
      <prod vendor="omnisoftsol" name="vidsharepro">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1736" published="2009-05-20" name="CVE-2009-1736" modified="2009-05-20" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in the GridSupport (GS) Ticket System (com_gsticketsystem) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter in a viewCategory action to index.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/50624" source="XF">gsticketsystem-index-sql-injection(50624)</ref>
      <ref url="http://www.securityfocus.com/bid/35025" source="BID">35025</ref>
      <ref url="http://www.milw0rm.com/exploits/8731" source="MILW0RM">8731</ref>
    </refs>
    <vuln_soft>
      <prod vendor="joomla" name="com_gsticketsystem">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1737" published="2009-05-20" name="CVE-2009-1737" modified="2009-05-20" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:N/A:N)" CVSS_score="7.8" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="10.0" CVSS_base_score="7.8">
    <desc>
      <descript source="cve">Directory traversal vulnerability in bom.php in MyPic 2.1 allows remote attackers to list files in arbitrary directories via a .. (dot dot) in the dir parameter.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/50621" source="XF">mypic-dir-directory-traversal(50621)</ref>
      <ref url="http://www.securityfocus.com/bid/35030" source="BID">35030</ref>
      <ref url="http://www.osvdb.org/54565" source="OSVDB">54565</ref>
      <ref url="http://secunia.com/advisories/35092" source="SECUNIA" adv="1">35092</ref>
      <ref url="http://hi.baidu.com/hirfire/blog/item/c3c0f6dda3ca47d18d10291a.html" source="MISC">http://hi.baidu.com/hirfire/blog/item/c3c0f6dda3ca47d18d10291a.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="diqiye" name="mypic">
        <vers num="2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2009-1738" published="2009-05-20" name="CVE-2009-1738" modified="2009-07-13" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:S/C:N/I:P/A:N)" CVSS_score="3.5" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="6.8" CVSS_base_score="3.5">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Feed Block 6.x-1.x before 6.x-1.1, a module for Drupal, allows remote authenticated users with administrator feed permissions to inject arbitrary web script or HTML via unspecified vectors in "aggregator items."</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://drupal.org/node/461706" source="CONFIRM" patch="1" adv="1">http://drupal.org/node/461706</ref>
      <ref url="http://drupal.org/node/453098" source="CONFIRM" patch="1">http://drupal.org/node/453098</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/50521" source="XF">feedblock-unspecified-xss(50521)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1319" source="VUPEN" adv="1">ADV-2009-1319</ref>
      <ref url="http://www.securityfocus.com/bid/34953" source="BID">34953</ref>
      <ref url="http://www.osvdb.org/54429" source="OSVDB">54429</ref>
      <ref url="http://secunia.com/advisories/35044" source="SECUNIA" adv="1">35044</ref>
    </refs>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1739" published="2009-05-20" name="CVE-2009-1739" modified="2009-06-09" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">PAD Site Scripts 3.6 allows remote attackers to bypass authentication and gain privileges as other users, including administrative privileges, by setting the authuser cookie parameter to a valid username.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/50622" source="XF">padsite-cookie-security-bypass(50622)</ref>
      <ref url="http://www.securityfocus.com/bid/35027" source="BID">35027</ref>
      <ref url="http://www.milw0rm.com/exploits/8735" source="MILW0RM">8735</ref>
      <ref url="http://secunia.com/advisories/35155" source="SECUNIA" adv="1">35155</ref>
      <ref url="http://osvdb.org/54593" source="OSVDB">54593</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpeasycode" name="pad_site_scripts">
        <vers num="3.6" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1740" published="2009-05-20" name="CVE-2009-1740" modified="2009-05-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Multiple heap-based buffer overflows in the D-Link MPEG4 Viewer ActiveX Control (csviewer.ocx) 2.11.918.2006 allow remote attackers to execute arbitrary code via a long argument to the (1) SetFilePath and (2) SetClientCookie methods.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/50556" source="XF">mpeg4viewer-csviewer-bo(50556)</ref>
      <ref url="http://www.securityfocus.com/bid/34990" source="BID">34990</ref>
      <ref url="http://secunia.com/advisories/35066" source="SECUNIA" adv="1">35066</ref>
      <ref url="http://osvdb.org/54458" source="OSVDB">54458</ref>
    </refs>
    <vuln_soft>
      <prod vendor="dlink" name="mpeg4_viewer_activex_control">
        <vers num="2.11.918.2006" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1741" published="2009-05-20" name="CVE-2009-1741" modified="2009-06-09" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in login.php in DM FileManager 3.9.2, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) Username and (2) Password fields.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/35035" source="BID">35035</ref>
      <ref url="http://www.milw0rm.com/exploits/8741" source="MILW0RM">8741</ref>
      <ref url="http://secunia.com/advisories/35167" source="SECUNIA" adv="1">35167</ref>
      <ref url="http://osvdb.org/54597" source="OSVDB">54597</ref>
    </refs>
    <vuln_soft>
      <prod vendor="dutchmonkey" name="dm_filemanager">
        <vers num="3.9.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1742" published="2009-05-20" name="CVE-2009-1742" modified="2009-05-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">code.php in PC4Arb Pc4 Uploader 9.0 and earlier makes it easier for remote attackers to conduct SQL injection attacks via crafted keyword sequences that are removed from a filter in the id parameter in a banner action, as demonstrated via the "UNIunionON" string, which is collapsed into "UNION" by the filter_sql function.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/50586" source="XF">pc4uploader-code-sql-injection(50586)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1364" source="VUPEN" adv="1">ADV-2009-1364</ref>
      <ref url="http://www.securityfocus.com/bid/35004" source="BID">35004</ref>
      <ref url="http://www.milw0rm.com/exploits/8709" source="MILW0RM">8709</ref>
      <ref url="http://secunia.com/advisories/35122" source="SECUNIA" adv="1">35122</ref>
      <ref url="http://osvdb.org/54572" source="OSVDB">54572</ref>
    </refs>
    <vuln_soft>
      <prod vendor="pc4arb" name="pc4_uploader">
        <vers prev="1" num="9.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1743" published="2009-05-20" name="CVE-2009-1743" modified="2009-07-01" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Directory traversal vulnerability in InstallHFZ.exe 6.5.201.0 in Pinnacle Hollywood Effects 6, a module in Pinnacle Systems Pinnacle Studio 12, allows remote attackers to create and overwrite arbitrary files via a filename containing a ..\ (dot dot backslash) sequence in a Hollywood FX Compressed Archive (.hfz) file.  NOTE: this can be leveraged for code execution by decompressing a file to a Startup folder.  NOTE: some of these details are obtained from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/50510" source="XF">pinnaclestudio-hfz-directory-traversal(50510)</ref>
      <ref url="http://www.securityfocus.com/bid/34936" source="BID">34936</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/503476/100/0/threaded" source="BUGTRAQ">20090513 Pinnacle Studio 12 "Hollywood FX Compressed Archive" (.hfz) directory traversal vulnerability poc</ref>
      <ref url="http://www.milw0rm.com/exploits/8670" source="MILW0RM">8670</ref>
      <ref url="http://secunia.com/advisories/35078" source="SECUNIA" adv="1">35078</ref>
      <ref url="http://retrogod.altervista.org/9sg_pinnacle_studio_12_hfz.htm" source="MISC">http://retrogod.altervista.org/9sg_pinnacle_studio_12_hfz.htm</ref>
      <ref url="http://osvdb.org/54430" source="OSVDB">54430</ref>
    </refs>
    <vuln_soft>
      <prod vendor="pinnaclesys" name="pinnacle_studio">
        <vers num="12" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1744" published="2009-05-20" name="CVE-2009-1744" modified="2009-06-09" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">InstallHFZ.exe 6.5.201.0 in Pinnacle Hollywood Effects 6, a module in Pinnacle Systems Pinnacle Studio 12, allows remote attackers to cause a denial of service (application crash) via a crafted Hollywood FX Compressed Archive (.hfz) file.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/50856" source="XF">pinnaclestudio-hfz-dos(50856)</ref>
      <ref url="http://www.securityfocus.com/bid/35137" source="BID">35137</ref>
      <ref url="http://www.milw0rm.com/exploits/8670" source="MILW0RM">8670</ref>
    </refs>
    <vuln_soft>
      <prod vendor="pinnaclesys" name="pinnacle_studio">
        <vers num="12" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1745" published="2009-05-21" name="CVE-2009-1745" modified="2009-06-09" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Armorlogic Profense Web Application Firewall before 2.2.22, and 2.4.x before 2.4.4, has a default root password hash, and permits password-based root logins over SSH, which makes it easier for remote attackers to obtain access.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/50852" source="XF">profense-default-password(50852)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/503649/100/0/threaded" source="BUGTRAQ">20090520 Armorlogic Profense Web Application Firewall 2.4 multiple vulnerabilities.</ref>
    </refs>
    <vuln_soft>
      <prod vendor="armorlogic" name="profense_web_application_firewall">
        <vers prev="1" num="2.2.21" />
        <vers num="2.4" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1746" published="2009-05-21" name="CVE-2009-1746" modified="2009-06-09" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in berita.php in Dian Gemilang DGNews 3.0 Beta allows remote attackers to execute arbitrary SQL commands via the id parameter in a detail action.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/35016" source="BID">35016</ref>
      <ref url="http://www.milw0rm.com/exploits/8727" source="MILW0RM">8727</ref>
      <ref url="http://osvdb.org/54658" source="OSVDB">54658</ref>
    </refs>
    <vuln_soft>
      <prod vendor="diangemilang" name="dgnews">
        <vers num="3.0_beta" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1747" published="2009-05-22" name="CVE-2009-1747" modified="2009-05-22" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in index.php in 26th Avenue bSpeak 1.10 allows remote attackers to execute arbitrary SQL commands via the forumid parameter in a post action.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/35049" source="BID">35049</ref>
      <ref url="http://www.milw0rm.com/exploits/8751" source="MILW0RM">8751</ref>
      <ref url="http://secunia.com/advisories/35139" source="SECUNIA" adv="1">35139</ref>
    </refs>
    <vuln_soft>
      <prod vendor="26thavenue" name="bspeak">
        <vers num="1.10" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1748" published="2009-05-22" name="CVE-2009-1748" modified="2009-06-09" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple directory traversal vulnerabilities in index.php in Catviz 0.4.0 Beta 1 allow remote attackers to read arbitrary files via a .. (dot dot) in the (1) webpages_form or (2) userman_form parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/35042" source="BID">35042</ref>
      <ref url="http://www.milw0rm.com/exploits/8745" source="MILW0RM">8745</ref>
      <ref url="http://osvdb.org/54657" source="OSVDB">54657</ref>
    </refs>
    <vuln_soft>
      <prod vendor="joost_horward" name="catviz">
        <vers num="0.4.0" edition="beta_1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1749" published="2009-05-22" name="CVE-2009-1749" modified="2009-06-09" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in index.php in Catviz 0.4.0 beta 1 allow remote attackers to inject arbitrary web script or HTML via the (1) userman_form and (2) webpages_form parameters.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/35042" source="BID">35042</ref>
      <ref url="http://www.milw0rm.com/exploits/8745" source="MILW0RM">8745</ref>
      <ref url="http://osvdb.org/54656" source="OSVDB">54656</ref>
    </refs>
    <vuln_soft>
      <prod vendor="joost_horward" name="catviz">
        <vers num="0.4.0" edition="beta_1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1750" published="2009-05-22" name="CVE-2009-1750" modified="2009-06-09" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:S/C:P/I:P/A:P)" CVSS_score="6.0" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="6.8" CVSS_base_score="6.0">
    <desc>
      <descript source="cve">Unrestricted file upload vulnerability in VidSharePro allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, then accessing it via unspecified vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/50625" source="XF">vidshare-unspecified-file-upload(50625)</ref>
      <ref url="http://www.securityfocus.com/bid/35024" source="BID">35024</ref>
      <ref url="http://www.milw0rm.com/exploits/8730" source="MILW0RM">8730</ref>
      <ref url="http://osvdb.org/54611" source="OSVDB">54611</ref>
    </refs>
    <vuln_soft>
      <prod vendor="omnisoftsol" name="vidsharepro">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1751" published="2009-05-22" name="CVE-2009-1751" modified="2009-06-09" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in list_list.php in Realty Webware Technologies Web-Base 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/50646" source="XF">realtywebbase-listlist-sql-injection(50646)</ref>
      <ref url="http://www.securityfocus.com/bid/35043" source="BID">35043</ref>
      <ref url="http://www.milw0rm.com/exploits/8748" source="MILW0RM">8748</ref>
      <ref url="http://osvdb.org/54655" source="OSVDB">54655</ref>
    </refs>
    <vuln_soft>
      <prod vendor="realtywebware" name="realty_web-base">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1752" published="2009-05-22" name="CVE-2009-1752" modified="2009-05-22" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">exJune Office Message System 1 does not properly restrict access to (1) configure.asp and (2) addmessage2.asp, which allows remote attackers to gain privileges a direct request.  NOTE: some of these details are obtained from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/50647" source="XF">oms-configure-addmessage2-security-bypass(50647)</ref>
      <ref url="http://www.milw0rm.com/exploits/8744" source="MILW0RM">8744</ref>
      <ref url="http://secunia.com/advisories/35172" source="SECUNIA" adv="1">35172</ref>
    </refs>
    <vuln_soft>
      <prod vendor="exjune" name="office_message_system">
        <vers num="1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2009-1753" published="2009-05-22" name="CVE-2009-1753" modified="2009-06-23" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:N/I:P/A:P)" CVSS_score="3.3" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="3.4" CVSS_base_score="3.3">
    <desc>
      <descript source="cve">Coccinelle 0.1.7 allows local users to overwrite arbitrary files via a symlink attack on an unspecified "result file."</descript>
    </desc>
    <loss_types>
      <avail />
      <int />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://packages.debian.org/changelogs/pool/main/c/coccinelle/coccinelle_0.1.7.deb-3/changelog" source="CONFIRM" patch="1">http://packages.debian.org/changelogs/pool/main/c/coccinelle/coccinelle_0.1.7.deb-3/changelog</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-June/msg00731.html" source="FEDORA">FEDORA-2009-5368</ref>
      <ref url="http://www.securityfocus.com/bid/34848" source="BID">34848</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2009/05/06/2" source="MLIST">[oss-security] 20090506 CVE id request: coccinelle</ref>
      <ref url="http://secunia.com/advisories/35459" source="SECUNIA">35459</ref>
      <ref url="http://secunia.com/advisories/35012" source="SECUNIA" adv="1">35012</ref>
    </refs>
    <vuln_soft>
      <prod vendor="emn" name="coccinelle">
        <vers num="0.1.7" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1754" published="2009-05-26" name="CVE-2009-1754" modified="2009-06-18" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">The PackageManagerService class in services/java/com/android/server/PackageManagerService.java in Android 1.5 through 1.5 CRB42 does not properly check developer certificates during processing of sharedUserId requests at an application's installation time, which allows remote user-assisted attackers to access application data by creating a package that specifies a shared user ID with an arbitrary application.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.ocert.org/advisories/ocert-2009-006.html" source="MISC" patch="1">http://www.ocert.org/advisories/ocert-2009-006.html</ref>
      <ref url="http://android.git.kernel.org/?p=platform/frameworks/base.git;a=commit;h=5d6d773fab559fdc12e553d60d789f3991ac552c" source="CONFIRM" patch="1" adv="1">http://android.git.kernel.org/?p=platform/frameworks/base.git;a=commit;h=5d6d773fab559fdc12e553d60d789f3991ac552c</ref>
      <ref url="http://www.securityfocus.com/bid/35090" source="BID">35090</ref>
      <ref url="http://www.securityfocus.com/archive/1/503770" source="BUGTRAQ">20090522 [oCERT-2009-006] Android improper package verification when using shared uids</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2009/05/22/14" source="MLIST">[oss-security] 20090522 [oCERT-2009-006] Android improper package verification when using shared uids</ref>
    </refs>
    <vuln_soft>
      <prod vendor="android" name="android">
        <vers num="1.5" />
        <vers num="1.5_crb42" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1755" published="2009-05-22" name="CVE-2009-1755" modified="2009-05-29" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Off-by-one error in the packet_read_query_section function in packet.c in nsd 3.2.1, and process_query_section in query.c in nsd 2.3.7, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unspecified vectors that trigger a buffer overflow.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.nlnetlabs.nl/publications/NSD_vulnerability_announcement.html" source="CONFIRM" patch="1" adv="1">http://www.nlnetlabs.nl/publications/NSD_vulnerability_announcement.html</ref>
      <ref url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=529420" source="CONFIRM" patch="1">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=529420</ref>
      <ref url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=529418" source="CONFIRM" patch="1">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=529418</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2009/05/19/1" source="MLIST">[oss-security] 20090519 CVE id request: nsd</ref>
    </refs>
    <vuln_soft>
      <prod vendor="nlnetlabs" name="nsd">
        <vers num="2.0.0" />
        <vers num="2.0.1" />
        <vers num="2.0.2" />
        <vers num="2.1.0" />
        <vers num="2.1.1" />
        <vers num="2.1.2" />
        <vers num="2.1.3" />
        <vers num="2.1.4" />
        <vers num="2.1.5" />
        <vers num="2.3.7" />
        <vers num="3.2.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Low" seq="2009-1756" published="2009-05-22" name="CVE-2009-1756" modified="2010-06-13" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="2.1" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="3.9" CVSS_base_score="2.1">
    <desc>
      <descript source="cve">SLiM Simple Login Manager 1.3.0 places the X authority magic cookie (mcookie) on the command line when invoking xauth from (1) app.cpp and (2) switchuser.cpp, which allows local users to access the X session by listing the process and its arguments.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2010-January/msg00009.html" source="FEDORA">FEDORA-2009-13552</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2010-January/msg00000.html" source="FEDORA">FEDORA-2009-13551</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/50611" source="XF">slim-xauthority-info-disclosure(50611)</ref>
      <ref url="http://www.securityfocus.com/bid/35015" source="BID">35015</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2009/05/18/2" source="MLIST">[oss-security] 20090518 CVE id request: slim</ref>
      <ref url="http://secunia.com/advisories/38070" source="SECUNIA" adv="1">38070</ref>
      <ref url="http://secunia.com/advisories/35132" source="SECUNIA" adv="1">35132</ref>
      <ref url="http://osvdb.org/54583" source="OSVDB">54583</ref>
      <ref url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=529306" source="CONFIRM">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=529306</ref>
    </refs>
    <vuln_soft>
      <prod vendor="simone_rota" name="slim_simple_login_manager">
        <vers num="1.3.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1757" published="2009-05-22" name="CVE-2009-1757" modified="2009-05-22" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Cross-site request forgery (CSRF) vulnerability in Transmission 1.5 before 1.53 and 1.6 before 1.61 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.transmissionbt.com/index.php" source="CONFIRM" patch="1" adv="1">http://www.transmissionbt.com/index.php</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2009/05/21/1" source="MLIST" patch="1">[oss-security] 20090521 CVE request: transmission &lt;1.61 CSRF</ref>
    </refs>
    <vuln_soft>
      <prod vendor="transmissionbt" name="transmission">
        <vers num="1.50" />
        <vers num="1.51" />
        <vers num="1.52" />
        <vers num="1.60" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1758" published="2009-05-22" name="CVE-2009-1758" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The hypervisor_callback function in Xen, possibly before 3.4.0, as applied to the Linux kernel 2.6.30-rc4, 2.6.18, and probably other versions allows guest user applications to cause a denial of service (kernel oops) of the guest OS by triggering a segmentation fault in "certain address ranges."</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/34957" source="BID">34957</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2009/05/14/2" source="MLIST">[oss-security] 20090514 CVE Request: XEN local denial of service</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1809" source="DEBIAN">DSA-1809</ref>
      <ref url="http://secunia.com/advisories/35298" source="SECUNIA">35298</ref>
      <ref url="http://secunia.com/advisories/35093" source="SECUNIA">35093</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10313" source="OVAL">oval:org.mitre.oval:def:10313</ref>
      <ref url="http://lists.xensource.com/archives/html/xen-devel/2009-05/msg00561.html" source="MLIST">[Xen-devel] 20090513 [PATCH] linux/i386: hypervisor_callback adjustments</ref>
    </refs>
    <vuln_soft>
      <prod vendor="xen" name="xen">
        <vers num="2.0" />
        <vers num="3.0.2" />
        <vers num="3.0.3" />
        <vers num="3.0.4" />
        <vers num="3.1.2" />
        <vers num="3.1.3" />
        <vers num="3.1.4" />
        <vers num="3.2" />
        <vers num="3.2.0" />
        <vers num="3.2.1" />
        <vers num="3.2.2" />
        <vers num="3.2.3" />
        <vers num="3.3.0" />
        <vers prev="1" num="3.3.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1759" published="2009-05-22" name="CVE-2009-1759" modified="2009-09-02" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Stack-based buffer overflow in the btFiles::BuildFromMI function (trunk/btfiles.cpp) in Enhanced CTorrent (aka dTorrent) 3.3.2 and probably earlier, and CTorrent 1.3.4, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a Torrent file containing a long path.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/34584" source="BID" patch="1">34584</ref>
      <ref url="http://www.openwall.com/lists/oss-security/2009/05/20/3" source="MLIST" patch="1">[oss-security] 20090520 CVE request: ctorrent</ref>
      <ref url="http://dtorrent.svn.sourceforge.net/viewvc/dtorrent/dtorrent/trunk/btfiles.cpp?r1=296&amp;r2=301&amp;view=patch" source="CONFIRM" patch="1">http://dtorrent.svn.sourceforge.net/viewvc/dtorrent/dtorrent/trunk/btfiles.cpp?r1=296&amp;r2=301&amp;view=patch</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-August/msg01102.html" source="FEDORA">FEDORA-2009-8969</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-August/msg01010.html" source="FEDORA">FEDORA-2009-8897</ref>
      <ref url="https://bugzilla.redhat.com/show_bug.cgi?id=501813" source="CONFIRM">https://bugzilla.redhat.com/show_bug.cgi?id=501813</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/49959" source="XF">ctorrent-btfiles-bo(49959)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1092" source="VUPEN" adv="1">ADV-2009-1092</ref>
      <ref url="http://www.milw0rm.com/exploits/8470" source="MILW0RM">8470</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1817" source="DEBIAN">DSA-1817</ref>
      <ref url="http://sourceforge.net/tracker/?func=detail&amp;aid=2782875&amp;group_id=202532&amp;atid=981959" source="CONFIRM">http://sourceforge.net/tracker/?func=detail&amp;aid=2782875&amp;group_id=202532&amp;atid=981959</ref>
      <ref url="http://secunia.com/advisories/36471" source="SECUNIA">36471</ref>
      <ref url="http://secunia.com/advisories/35499" source="SECUNIA">35499</ref>
      <ref url="http://secunia.com/advisories/34752" source="SECUNIA" adv="1">34752</ref>
    </refs>
    <vuln_soft>
      <prod vendor="rahul" name="ctorrent">
        <vers num="1.3.4" />
      </prod>
      <prod vendor="rahul" name="dtorrent">
        <vers num="3.2.0" />
        <vers num="3.3.0" />
        <vers num="3.3.1" />
        <vers num="3.3.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1760" published="2009-06-11" name="CVE-2009-1760" modified="2009-07-01" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:P)" CVSS_score="5.8" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="8.6" CVSS_base_score="5.8">
    <desc>
      <descript source="cve">Directory traversal vulnerability in src/torrent_info.cpp in Rasterbar libtorrent before 0.14.4, as used in firetorrent, qBittorrent, deluge Torrent, and other applications, allows remote attackers to create or overwrite arbitrary files via a .. (dot dot) and partial relative pathname in a Multiple File Mode list element in a .torrent file.</descript>
    </desc>
    <loss_types>
      <avail />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/51008" source="XF" patch="1">libtorrent-path-element-dir-traversal(51008)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1534" source="VUPEN" patch="1" adv="1">ADV-2009-1534</ref>
      <ref url="http://www.securityfocus.com/bid/35262" source="BID" patch="1">35262</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/504151/100/0/threaded" source="BUGTRAQ" patch="1">20090608 Rasterbar libtorrent arbitrary file overwrite vulnerability</ref>
      <ref url="http://sourceforge.net/project/shownotes.php?group_id=79942&amp;release_id=686456" source="CONFIRM" patch="1">http://sourceforge.net/project/shownotes.php?group_id=79942&amp;release_id=686456</ref>
      <ref url="http://census-labs.com/news/2009/06/08/libtorrent-rasterbar/" source="MISC" patch="1">http://census-labs.com/news/2009/06/08/libtorrent-rasterbar/</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:139" source="MANDRIVA">MDVSA-2009:139</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1815" source="DEBIAN">DSA-1815</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200907-14.xml" source="GENTOO">GLSA-200907-14</ref>
      <ref url="http://secunia.com/advisories/35848" source="SECUNIA">35848</ref>
      <ref url="http://secunia.com/advisories/35277" source="SECUNIA" adv="1">35277</ref>
    </refs>
    <vuln_soft>
      <prod vendor="rasterbar_software" name="libtorrent">
        <vers num="0" />
        <vers num="0.12" />
        <vers num="0.12.1" />
        <vers prev="1" num="0.14.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1761" published="2009-06-16" name="CVE-2009-1761" modified="2009-06-23" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The message engine in CA ARCserve Backup r12.0 and r12.0 SP1 for Windows allows remote attackers to cause a denial of service (crash) via (1) an invalid 0x13 message, which is not properly handled in the ASCORE module, or (2) a 0x3B message with invalid stub data that triggers an RPC marshalling error.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://support.ca.com/irj/portal/anonymous/phpsupcontent?contentID=209502" source="CONFIRM" patch="1" adv="1">http://support.ca.com/irj/portal/anonymous/phpsupcontent?contentID=209502</ref>
      <ref url="http://community.ca.com/blogs/casecurityresponseblog/archive/2009/06/15/ca20090615-01-ca-arcserve-backup-message-engine-denial-of-service-vulnerabilities.aspx" source="CONFIRM" patch="1">http://community.ca.com/blogs/casecurityresponseblog/archive/2009/06/15/ca20090615-01-ca-arcserve-backup-message-engine-denial-of-service-vulnerabilities.aspx</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/51169" source="XF">ca-arcserve-ascore-dos(51169)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1608" source="VUPEN">ADV-2009-1608</ref>
      <ref url="http://www.securitytracker.com/id?1022405" source="SECTRACK">1022405</ref>
      <ref url="http://www.securityfocus.com/bid/35396" source="BID">35396</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/504349/100/0/threaded" source="BUGTRAQ">20090616 CA20090615-01: CA ARCserve Backup Message Engine Denial of Service Vulnerabilities (Updated)</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/504348/100/0/threaded" source="BUGTRAQ">20090616 CA20090615-01: CA ARCserve Backup Message Engine Denial of Service Vulnerabilities</ref>
      <ref url="http://www.ivizsecurity.com/security-advisory-iviz-sr-09004.html" source="MISC">http://www.ivizsecurity.com/security-advisory-iviz-sr-09004.html</ref>
      <ref url="http://www.ivizsecurity.com/security-advisory-iviz-sr-09003.html" source="MISC">http://www.ivizsecurity.com/security-advisory-iviz-sr-09003.html</ref>
      <ref url="http://secunia.com/advisories/35473" source="SECUNIA" adv="1">35473</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ca" name="arcserve_backup">
        <vers num="r12.0" edition="" />
        <vers num="r12.0" edition=":windows" />
        <vers num="r12.0" edition="sp1" />
        <vers num="r12.0" edition="sp1:windows" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1762" published="2009-05-22" name="CVE-2009-1762" modified="2009-05-28" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in the WebAccess login page (aka gw/webacc) in Novell GroupWise 7.x before 7.03 HP2 allow remote attackers to inject arbitrary web script or HTML via the (1) GWAP.version or (2) User.Theme (aka User.Theme.index) parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.novell.com/support/search.do?cmd=displayKC&amp;externalId=7003271" source="CONFIRM" patch="1" adv="1">http://www.novell.com/support/search.do?cmd=displayKC&amp;externalId=7003271</ref>
      <ref url="https://bugzilla.novell.com/show_bug.cgi?id=484942" source="MISC">https://bugzilla.novell.com/show_bug.cgi?id=484942</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1393" source="VUPEN">ADV-2009-1393</ref>
      <ref url="http://www.securityfocus.com/bid/35061" source="BID">35061</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/503700/100/0/threaded" source="BUGTRAQ">20090521 Novell GroupWise Web Access Multiple XSS</ref>
      <ref url="http://securitytracker.com/id?1022267" source="SECTRACK">1022267</ref>
      <ref url="http://secunia.com/advisories/35177" source="SECUNIA">35177</ref>
      <ref url="http://packetstorm.linuxsecurity.com/0905-exploits/groupwise-xss.txt" source="MISC">http://packetstorm.linuxsecurity.com/0905-exploits/groupwise-xss.txt</ref>
    </refs>
    <vuln_soft>
      <prod vendor="novell" name="groupwise">
        <vers num="7.0" edition="sp1" />
        <vers num="7.0" edition="sp2" />
        <vers num="7.0" edition="sp3" />
        <vers num="7.0.0" edition="sp1" />
        <vers num="7.0.0" edition="sp2" />
        <vers num="7.0.2" />
        <vers num="7.0.3" />
        <vers num="7.01" />
        <vers num="7.02x" />
        <vers num="7.03" edition="hp1a" />
        <vers num="7.03" edition="hp2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1763" published="2009-05-22" name="CVE-2009-1763" modified="2009-06-09" CVSS_version="2.0" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="7.2" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.9" CVSS_base_score="7.2">
    <desc>
      <descript source="cve">Unspecified vulnerability in the Solaris Secure Digital slot driver (aka sdhost) in Sun OpenSolaris snv_105 through snv_108 on the x86 platform allows local users to gain privileges or cause a denial of service (filesystem or memory corruption) via unknown vectors.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/50687" source="XF">solaris-slotdriver-code-execution(50687)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1410" source="VUPEN">ADV-2009-1410</ref>
      <ref url="http://www.securitytracker.com/id?1022271" source="SECTRACK">1022271</ref>
      <ref url="http://www.securityfocus.com/bid/35069" source="BID">35069</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-259408-1" source="SUNALERT" adv="1">259408</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="opensolaris">
        <vers num="snv_105" edition="" />
        <vers num="snv_105" edition=":x86" />
        <vers num="snv_106" edition="" />
        <vers num="snv_106" edition=":x86" />
        <vers num="snv_107" edition="" />
        <vers num="snv_107" edition=":x86" />
        <vers num="snv_108" edition="" />
        <vers num="snv_108" edition=":x86" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1764" published="2009-05-22" name="CVE-2009-1764" modified="2009-07-01" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">SQL injection vulnerability in inc/ajax.asp in MaxCMS 2.0 allows remote attackers to execute arbitrary SQL commands via the id parameter in a digg action.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/50553" source="XF">maxcms-ajax-sql-injection(50553)</ref>
      <ref url="http://www.securityfocus.com/bid/34981" source="BID">34981</ref>
      <ref url="http://www.milw0rm.com/exploits/8726" source="MILW0RM">8726</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bokecc" name="maxcms">
        <vers num="2.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1765" published="2009-05-22" name="CVE-2009-1765" modified="2009-05-24" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple directory traversal vulnerabilities in pluck 4.6.2, when register_globals is enabled, allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the langpref parameter to (1) data/modules/contactform/module_info.php, (2) data/modules/blog/module_info.php, and (3) data/modules/albums/module_info.php, different vectors than CVE-2008-3194.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/35007" source="BID">35007</ref>
      <ref url="http://www.milw0rm.com/exploits/8715" source="MILW0RM">8715</ref>
      <ref url="http://secunia.com/advisories/35145" source="SECUNIA" adv="1">35145</ref>
    </refs>
    <vuln_soft>
      <prod vendor="pluck-cms" name="pluck">
        <vers num="4.6.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1766" published="2009-05-22" name="CVE-2009-1766" modified="2009-06-09" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:P)" CVSS_score="6.4" CVSS_impact_subscore="4.9" CVSS_exploit_subscore="10.0" CVSS_base_score="6.4">
    <desc>
      <descript source="cve">SQL injection vulnerability in index.php in LightOpenCMS 0.1 allows remote attackers to execute arbitrary SQL commands via the id parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/504101/100/0/threaded" source="BUGTRAQ">20090604 SQL INJECTION VULNERABILITY--LightOpen CMS Devel 0.1--></ref>
      <ref url="http://www.milw0rm.com/exploits/8724" source="MILW0RM">8724</ref>
    </refs>
    <vuln_soft>
      <prod vendor="teozkr" name="lightopencms">
        <vers num="0.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1767" published="2009-05-22" name="CVE-2009-1767" modified="2009-05-24" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">admin/edituser.php in 2daybiz Template Monster Clone does not require administrative authentication, which allows remote attackers to modify arbitrary accounts via the (1) loginname, (2) password, (3) email, (4) firstname, or (5) lastname parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/50561" source="XF">tmc-edituser-security-bypass(50561)</ref>
      <ref url="http://www.securityfocus.com/bid/34977" source="BID">34977</ref>
      <ref url="http://www.milw0rm.com/exploits/8691" source="MILW0RM">8691</ref>
      <ref url="http://secunia.com/advisories/35090" source="SECUNIA" adv="1">35090</ref>
    </refs>
    <vuln_soft>
      <prod vendor="2daybiz" name="template_monster_clone">
        <vers num="-" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1768" published="2009-05-22" name="CVE-2009-1768" modified="2009-07-01" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">Directory traversal vulnerability in download.php in Rama Zaiten CMS 0.9.8 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/50572" source="XF">ramacms-download-file-include(50572)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1343" source="VUPEN" adv="1">ADV-2009-1343</ref>
      <ref url="http://www.securityfocus.com/bid/34995" source="BID">34995</ref>
      <ref url="http://www.milw0rm.com/exploits/8700" source="MILW0RM">8700</ref>
      <ref url="http://secunia.com/advisories/35116" source="SECUNIA" adv="1">35116</ref>
      <ref url="http://osvdb.org/54546" source="OSVDB">54546</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ramazeiten" name="ramazaitencms0.9.7.5">
        <vers num="" />
      </prod>
      <prod vendor="ramazeiten" name="ramazaitencms0.9.7.6">
        <vers num="" />
      </prod>
      <prod vendor="ramazeiten" name="ramazaitencms0.9.7.8">
        <vers num="" />
      </prod>
      <prod vendor="ramazeiten" name="ramazaitencms0.9.8">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1769" published="2009-05-22" name="CVE-2009-1769" modified="2009-09-09" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">The web interface in Open Computer and Software Inventory Next Generation (OCS Inventory NG) 1.01 generates different error messages depending on whether a username is valid, which allows remote attackers to enumerate valid usernames.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.ocsinventory-ng.org/index.php?mact=News,cntnt01,detail,0&amp;cntnt01articleid=133&amp;cntnt01returnid=69" source="MISC" patch="1">http://www.ocsinventory-ng.org/index.php?mact=News,cntnt01,detail,0&amp;cntnt01articleid=133&amp;cntnt01returnid=69</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-June/msg00063.html" source="FEDORA">FEDORA-2009-5773</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-June/msg00057.html" source="FEDORA">FEDORA-2009-5769</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-June/msg00050.html" source="FEDORA">FEDORA-2009-5764</ref>
      <ref url="http://www.securityfocus.com/bid/35023" source="BID">35023</ref>
      <ref url="http://secunia.com/advisories/35313" source="SECUNIA" adv="1">35313</ref>
      <ref url="http://secunia.com/advisories/35157" source="SECUNIA" adv="1">35157</ref>
      <ref url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=529344" source="CONFIRM">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=529344</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ocsinventory-ng" name="ocs_inventory_ng">
        <vers num="1.01" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1770" published="2009-05-22" name="CVE-2009-1770" modified="2009-06-09" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Directory traversal vulnerability in includes/database/examples/addressbook.php in Flyspeck CMS 6.8 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the lang parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2009/1367" source="VUPEN">ADV-2009-1367</ref>
      <ref url="http://www.securityfocus.com/bid/35011" source="BID">35011</ref>
      <ref url="http://www.milw0rm.com/exploits/8714" source="MILW0RM">8714</ref>
    </refs>
    <vuln_soft>
      <prod vendor="flyspeck" name="flyspeck_cms">
        <vers num="6.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1771" published="2009-05-22" name="CVE-2009-1771" modified="2009-06-09" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">index.php in Flyspeck CMS 6.8 does not require administrative authentication for the updateExistingContent action, which allows remote attackers to create or modify admin accounts via the (1) users[fullname], (2) users[email], (3) users[role_id], (4) users[username], and (5) users[password] parameters.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2009/1367" source="VUPEN">ADV-2009-1367</ref>
      <ref url="http://www.securityfocus.com/bid/35011" source="BID">35011</ref>
      <ref url="http://www.milw0rm.com/exploits/8714" source="MILW0RM">8714</ref>
    </refs>
    <vuln_soft>
      <prod vendor="flyspeck" name="flyspeck_cms">
        <vers num="6.8" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1772" published="2009-05-22" name="CVE-2009-1772" modified="2009-05-24" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in activeCollab 2.1 Corporate allows remote attackers to inject arbitrary web script or HTML via the re_route parameter to the login script.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/35022" source="BID">35022</ref>
      <ref url="http://secunia.com/advisories/35079" source="SECUNIA" adv="1">35079</ref>
      <ref url="http://pridels-team.blogspot.com/2009/05/activecollab-xss-and-full-path.html" source="MISC">http://pridels-team.blogspot.com/2009/05/activecollab-xss-and-full-path.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="activecollab" name="activecollab">
        <vers num="2.1" edition="-" />
        <vers num="2.1" edition="-:corp" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1773" published="2009-05-22" name="CVE-2009-1773" modified="2009-05-24" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">activeCollab 2.1 Corporate allows remote attackers to obtain sensitive information via an invalid re_route parameter to the login script, which reveals the installation path in an error message.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/35022" source="BID">35022</ref>
      <ref url="http://secunia.com/advisories/35079" source="SECUNIA" adv="1">35079</ref>
      <ref url="http://pridels-team.blogspot.com/2009/05/activecollab-xss-and-full-path.html" source="MISC">http://pridels-team.blogspot.com/2009/05/activecollab-xss-and-full-path.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="activecollab" name="activecollab">
        <vers num="2.1" edition="-" />
        <vers num="2.1" edition="-:corp" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1774" published="2009-05-22" name="CVE-2009-1774" modified="2009-06-30" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Directory traversal vulnerability in plugins/ddb/foot.php in Strawberry 1.1.1 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the file parameter to example/index.php.  NOTE: this was originally reported as an issue affecting the do parameter, but traversal with that parameter might depend on a modified example/index.php.  NOTE: some of these details are obtained from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/50562" source="XF" adv="1">strawberry-index-file-include(50562)</ref>
      <ref url="http://www.securityfocus.com/bid/34971" source="BID">34971</ref>
      <ref url="http://www.milw0rm.com/exploits/8681" source="MILW0RM">8681</ref>
      <ref url="http://secunia.com/advisories/28330" source="SECUNIA" adv="1">28330</ref>
    </refs>
    <vuln_soft>
      <prod vendor="strawberry" name="strawberry">
        <vers num="1.1.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1775" published="2009-05-22" name="CVE-2009-1775" modified="2009-06-30" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in Ulteo Open Virtual Desktop 1.0 allow remote attackers to inject arbitrary web script or HTML via the id parameter to (1) admin/applications.php, (2) admin/appsgroup.php, (3) admin/users.php, (4) admin/usersgroup.php, and (5) admin/tasks.php; (6) show parameter to admin/logs.php; and (7) mode parameter to admin/configuration-partial.php.  NOTE: some of these details are obtained from third party information.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.ulteo.com/home/en/ovdi/openvirtualdesktop/downloadnow?autolang=en" source="CONFIRM" adv="1">http://www.ulteo.com/home/en/ovdi/openvirtualdesktop/downloadnow?autolang=en</ref>
      <ref url="http://www.securityfocus.com/bid/34927" source="BID">34927</ref>
      <ref url="http://www.insight-tech.org/index.php?p=Ulteo-Open-Virtual-Desktop-v1-0-multiple-XSS" source="MISC">http://www.insight-tech.org/index.php?p=Ulteo-Open-Virtual-Desktop-v1-0-multiple-XSS</ref>
      <ref url="http://secunia.com/advisories/34923" source="SECUNIA" adv="1">34923</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ulteo" name="open_virtual_desktop">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1776" published="2009-05-22" name="CVE-2009-1776" modified="2009-06-04" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in FormMail.pl in Matt Wright FormMail 1.92, and possibly earlier, allow remote attackers to inject arbitrary web script or HTML via javascript: URIs in the (1) request and (2) return_link_url parameters.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.ush.it/team/ush/hack-formmail_192/adv.txt" source="MISC">http://www.ush.it/team/ush/hack-formmail_192/adv.txt</ref>
      <ref url="http://www.securityfocus.com/bid/34929" source="BID">34929</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/503446/100/0/threaded" source="BUGTRAQ">20090512 FormMail 1.92 Multiple Vulnerabilities</ref>
      <ref url="http://secunia.com/advisories/35068" source="SECUNIA" adv="1">35068</ref>
    </refs>
    <vuln_soft>
      <prod vendor="matt_wright" name="formmail">
        <vers prev="1" num="1.92" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1777" published="2009-05-22" name="CVE-2009-1777" modified="2009-06-04" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">CRLF injection vulnerability in FormMail.pl in Matt Wright FormMail 1.92, and possibly earlier, allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the redirect parameter.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.ush.it/team/ush/hack-formmail_192/adv.txt" source="MISC">http://www.ush.it/team/ush/hack-formmail_192/adv.txt</ref>
      <ref url="http://www.securityfocus.com/bid/34929" source="BID">34929</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/503446/100/0/threaded" source="BUGTRAQ">20090512 FormMail 1.92 Multiple Vulnerabilities</ref>
      <ref url="http://secunia.com/advisories/35068" source="SECUNIA" adv="1">35068</ref>
    </refs>
    <vuln_soft>
      <prod vendor="matt_wright" name="formmail">
        <vers num="1.92" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1778" published="2009-05-22" name="CVE-2009-1778" modified="2009-05-27" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">SQL injection vulnerability in the new user registration feature in BigACE CMS 2.5, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the username parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.bigace.de/Security-Fix-for-2.5.html" source="CONFIRM" patch="1" adv="1">http://www.bigace.de/Security-Fix-for-2.5.html</ref>
      <ref url="http://www.bigace.de/BIGACE-2.6.html" source="CONFIRM" patch="1" adv="1">http://www.bigace.de/BIGACE-2.6.html</ref>
      <ref url="http://www.securityfocus.com/bid/34920" source="BID">34920</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/503448/100/0/threaded" source="BUGTRAQ">20090512 User options changer (SQLi) EXPLOIT --Bigace CMS -stable release- 2.5--></ref>
      <ref url="http://www.milw0rm.com/exploits/8664" source="MILW0RM">8664</ref>
      <ref url="http://secunia.com/advisories/35063" source="SECUNIA" adv="1">35063</ref>
    </refs>
    <vuln_soft>
      <prod vendor="bigace" name="bigace_cms">
        <vers num="2.5" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1779" published="2009-05-22" name="CVE-2009-1779" modified="2009-05-24" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">PHP remote file inclusion vulnerability in admin.php in Frax.dk Php Recommend 1.3 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the form_include_template parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2009/1287" source="VUPEN" adv="1">ADV-2009-1287</ref>
      <ref url="http://www.securityfocus.com/bid/34909" source="BID">34909</ref>
      <ref url="http://www.milw0rm.com/exploits/8658" source="MILW0RM">8658</ref>
    </refs>
    <vuln_soft>
      <prod vendor="roboform" name="frax.dk_php_recommend">
        <vers prev="1" num="1.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1780" published="2009-05-22" name="CVE-2009-1780" modified="2009-05-27" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">admin.php in Frax.dk Php Recommend 1.3 and earlier does not require authentication when the user password is changed, which allows remote attackers to gain administrative privileges via modified form_admin_user and form_admin_pass parameters.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2009/1287" source="VUPEN" adv="1">ADV-2009-1287</ref>
      <ref url="http://www.securityfocus.com/bid/34909" source="BID">34909</ref>
      <ref url="http://www.milw0rm.com/exploits/8658" source="MILW0RM">8658</ref>
    </refs>
    <vuln_soft>
      <prod vendor="roboform" name="frax.dk_php_recommend">
        <vers prev="1" num="1.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1781" published="2009-05-22" name="CVE-2009-1781" modified="2009-05-27" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Static code injection vulnerability in admin.php in Frax.dk Php Recommend 1.3 and earlier allows remote attackers to inject arbitrary PHP code into phpre_config.php via the form_aula parameter.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2009/1287" source="VUPEN" adv="1">ADV-2009-1287</ref>
      <ref url="http://www.securityfocus.com/bid/34909" source="BID">34909</ref>
      <ref url="http://www.milw0rm.com/exploits/8658" source="MILW0RM">8658</ref>
    </refs>
    <vuln_soft>
      <prod vendor="roboform" name="frax.dk_php_recommend">
        <vers prev="1" num="1.3" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1782" published="2009-05-22" name="CVE-2009-1782" modified="2009-05-27" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple F-Secure anti-virus products, including Anti-Virus for Microsoft Exchange 7.10 and earlier; Internet Gatekeeper for Windows 6.61 and earlier, Windows 6.61 and earlier, and Linux 2.16 and earlier; Internet Security 2009 and earlier, Anti-Virus 2009 and earlier, Client Security 8.0 and earlier, and others; allow remote attackers to bypass malware detection via a crafted (1) ZIP and (2) RAR archive.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.f-secure.com/en_EMEA/support/security-advisory/fsc-2009-1.html" source="CONFIRM" patch="1" adv="1">http://www.f-secure.com/en_EMEA/support/security-advisory/fsc-2009-1.html</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/50346" source="XF">fsecure-rar-zip-security-bypass(50346)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1262" source="VUPEN" adv="1">ADV-2009-1262</ref>
      <ref url="http://www.securitytracker.com/id?1022172" source="SECTRACK">1022172</ref>
      <ref url="http://www.securitytracker.com/id?1022171" source="SECTRACK">1022171</ref>
      <ref url="http://www.securitytracker.com/id?1022170" source="SECTRACK">1022170</ref>
      <ref url="http://www.securityfocus.com/bid/34849" source="BID">34849</ref>
      <ref url="http://secunia.com/advisories/35008" source="SECUNIA" adv="1">35008</ref>
    </refs>
    <vuln_soft>
      <prod vendor="f-secure" name="anti-virus">
        <vers prev="1" num="2009" />
        <vers prev="1" num="4.65" edition="-" />
        <vers prev="1" num="4.65" edition="-:linux_servers" />
        <vers prev="1" num="5.54" edition="-" />
        <vers prev="1" num="5.54" edition="-:linux_server_security" />
        <vers prev="1" num="5.54" edition="-:inux_client_security" />
        <vers prev="1" num="5.61" edition="-" />
        <vers prev="1" num="5.61" edition="-:mime_sweeper" />
        <vers prev="1" num="6.62" edition="-" />
        <vers prev="1" num="6.62" edition="-:microsoft_exchange" />
        <vers prev="1" num="7.0" edition="-" />
        <vers prev="1" num="7.0" edition="-:microsoft_exchange" />
        <vers prev="1" num="7.00" edition="-" />
        <vers prev="1" num="7.00" edition="-:citrix_servers" />
        <vers prev="1" num="7.10" edition="-" />
        <vers prev="1" num="7.10" edition="-:microsoft_exchange" />
        <vers prev="1" num="8.0" edition="-" />
        <vers prev="1" num="8.0" edition="-:workstations" />
        <vers prev="1" num="8.00" edition="-" />
        <vers prev="1" num="8.00" edition="-:windows_server" />
      </prod>
      <prod vendor="f-secure" name="client_security">
        <vers prev="1" num="8.0" />
      </prod>
      <prod vendor="f-secure" name="home_server_security">
        <vers prev="1" num="2009" />
      </prod>
      <prod vendor="f-secure" name="internet_gatekeeper">
        <vers prev="1" num="2.16" edition="-" />
        <vers prev="1" num="2.16" edition="-:linux" />
        <vers prev="1" num="3.01" edition="-" />
        <vers prev="1" num="3.01" edition="-:linux_japanese" />
        <vers prev="1" num="6.61" edition="-" />
        <vers prev="1" num="6.61" edition="-:windows" />
      </prod>
      <prod vendor="f-secure" name="internet_security">
        <vers prev="1" num="2009" />
      </prod>
      <prod vendor="f-secure" name="linux_security">
        <vers prev="1" num="7.01" />
        <vers prev="1" num="7.02" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1783" published="2009-05-22" name="CVE-2009-1783" modified="2009-05-29" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">Multiple FRISK Software F-Prot anti-virus products, including Antivirus for Exchange, Linux on IBM zSeries, Linux x86 File Servers, Linux x86 Mail Servers, Linux x86 Workstations, Solaris Mail Servers, Antivirus for Windows, and others, allow remote attackers to bypass malware detection via a crafted CAB archive.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/50427" source="XF">fprot-cab-security-bypass(50427)</ref>
      <ref url="http://www.securityfocus.com/bid/34896" source="BID">34896</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/503393/100/0/threaded" source="BUGTRAQ">20090509 [TZO-21-2009] Fprot CAB bypass / evasion</ref>
      <ref url="http://blog.zoller.lu/2009/04/advisory-f-prot-frisk-cab-bypass.html" source="MISC">http://blog.zoller.lu/2009/04/advisory-f-prot-frisk-cab-bypass.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="f-prot" name="f-prot_antivirus">
        <vers num="" edition="exchange" />
        <vers num="" edition="linux_on_ibm_zseries" />
        <vers num="" edition="linux_x86_file_servers" />
        <vers num="" edition="linux_x86_mail_servers" />
        <vers num="" edition="linux_x86_workstations" />
        <vers num="" edition="solaris_mail_servers" />
        <vers num="" edition="windows" />
        <vers num="" edition="windows_mail_servers" />
      </prod>
      <prod vendor="f-prot" name="f-prot_aves">
        <vers num="" />
      </prod>
      <prod vendor="f-prot" name="f-prot_milter">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1784" published="2009-05-22" name="CVE-2009-1784" modified="2009-05-29" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_score="10.0" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="10.0" CVSS_base_score="10.0">
    <desc>
      <descript source="cve">The AVG parsing engine 8.5 323, as used in multiple AVG anti-virus products including Anti-Virus Network Edition, Internet Security Netzwerk Edition, Server Edition für Linux/FreeBSD, Anti-Virus SBS Edition, and others allows remote attackers to bypass malware detection via a crafted (1) RAR and (2) ZIP archive.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/50426" source="XF">avg-zip-security-bypass(50426)</ref>
      <ref url="http://www.securityfocus.com/bid/34895" source="BID">34895</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/503392/100/0/threaded" source="BUGTRAQ">20090509 [TZO-20-2009] AVG ZIP evasion / bypass</ref>
      <ref url="http://blog.zoller.lu/2009/04/avg-zip-evasion-bypass.html" source="MISC">http://blog.zoller.lu/2009/04/avg-zip-evasion-bypass.html</ref>
    </refs>
    <vuln_soft>
      <prod vendor="avg" name="avg_anti-virus">
        <vers num="6.0.710" />
        <vers num="7.0" />
        <vers num="7.0.251" />
        <vers num="7.0.323" />
        <vers num="7.1.308" />
        <vers num="7.1.407" />
        <vers num="7.5.448" />
        <vers num="7.5.476" />
        <vers num="7.5.51" />
        <vers num="8.0" />
        <vers prev="1" num="8.0.156" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1785" published="2009-05-22" name="CVE-2009-1785" modified="2009-05-24" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Ulteo Open Virtual Desktop 1.0 allows remote attackers to inject arbitrary web script or HTML via the error parameter to header.php.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.ulteo.com/home/en/ovdi/openvirtualdesktop/downloadnow?autolang=en" source="MISC">http://www.ulteo.com/home/en/ovdi/openvirtualdesktop/downloadnow?autolang=en</ref>
      <ref url="http://secunia.com/advisories/34923" source="SECUNIA" adv="1">34923</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ulteo" name="open_virtual_desktop">
        <vers num="1.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1786" published="2009-05-26" name="CVE-2009-1786" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:L/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="6.9" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="3.4" CVSS_base_score="6.9">
    <desc>
      <descript source="cve">The malloc subsystem in libc in IBM AIX 5.3 and 6.1 allows local users to create or overwrite arbitrary files via a symlink attack on the log file associated with the MALLOCDEBUG environment variable.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot admin="1" />
    </loss_types>
    <range>
      <local />
    </range>
    <refs>
      <ref url="http://securitytracker.com/id?1022261" source="SECTRACK" patch="1">1022261</ref>
      <ref url="http://aix.software.ibm.com/aix/efixes/security/libc_advisory.asc" source="CONFIRM" patch="1" adv="1">http://aix.software.ibm.com/aix/efixes/security/libc_advisory.asc</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/50636" source="XF">aix-mallocdebug-privilege-escalation(50636)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1380" source="VUPEN" adv="1">ADV-2009-1380</ref>
      <ref url="http://www.securityfocus.com/bid/35034" source="BID">35034</ref>
      <ref url="http://www.osvdb.org/54617" source="OSVDB">54617</ref>
      <ref url="http://www.milw0rm.com/exploits/9306" source="MILW0RM">9306</ref>
      <ref url="http://www.ibm.com/support/docview.wss?uid=isg1IZ50517" source="AIXAPAR">IZ50517</ref>
      <ref url="http://www.ibm.com/support/docview.wss?uid=isg1IZ50500" source="AIXAPAR">IZ50500</ref>
      <ref url="http://www.ibm.com/support/docview.wss?uid=isg1IZ50447" source="AIXAPAR">IZ50447</ref>
      <ref url="http://www.ibm.com/support/docview.wss?uid=isg1IZ50445" source="AIXAPAR">IZ50445</ref>
      <ref url="http://www.ibm.com/support/docview.wss?uid=isg1IZ50139" source="AIXAPAR">IZ50139</ref>
      <ref url="http://www.ibm.com/support/docview.wss?uid=isg1IZ50129" source="AIXAPAR">IZ50129</ref>
      <ref url="http://www.ibm.com/support/docview.wss?uid=isg1IZ50121" source="AIXAPAR">IZ50121</ref>
      <ref url="http://secunia.com/advisories/35146" source="SECUNIA" adv="1">35146</ref>
      <ref url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6276" source="OVAL">oval:org.mitre.oval:def:6276</ref>
      <ref url="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=802" source="IDEFENSE">20090520 IBM AIX libc MALLOCDEBUG File Overwrite Vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="ibm" name="aix">
        <vers num="5.3" />
        <vers num="6.1" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1787" published="2009-05-26" name="CVE-2009-1787" modified="2009-06-09" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in PHP Dir Submit (aka WebsiteSubmitter and Submitter Script) allow remote attackers to bypass authentication and gain administrative access via the (1) username and (2) password parameters.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2009/1365" source="VUPEN">ADV-2009-1365</ref>
      <ref url="http://www.securityfocus.com/bid/35003" source="BID">35003</ref>
      <ref url="http://www.milw0rm.com/exploits/8710" source="MILW0RM">8710</ref>
      <ref url="http://secunia.com/advisories/35125" source="SECUNIA">35125</ref>
    </refs>
    <vuln_soft>
      <prod vendor="phpdirsubmit" name="php_dir_submit">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1788" published="2009-05-26" name="CVE-2009-1788" modified="2009-06-23" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Heap-based buffer overflow in voc_read_header in libsndfile 1.0.15 through 1.0.19, as used in Winamp 5.552 and possibly other media programs, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a VOC file with an invalid header value.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/50541" source="XF" patch="1">libsndfile-aiff-voc-bo(50541)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1348" source="VUPEN" patch="1" adv="1">ADV-2009-1348</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1324" source="VUPEN" patch="1" adv="1">ADV-2009-1324</ref>
      <ref url="http://www.securityfocus.com/bid/34978" source="BID" patch="1">34978</ref>
      <ref url="http://www.mega-nerd.com/libsndfile/" source="CONFIRM" patch="1">http://www.mega-nerd.com/libsndfile/</ref>
      <ref url="http://www.mega-nerd.com/erikd/Blog/CodeHacking/libsndfile/" source="CONFIRM" patch="1" adv="1">http://www.mega-nerd.com/erikd/Blog/CodeHacking/libsndfile/</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/50827" source="XF">libsndfile-voc-bo(50827)</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:132" source="MANDRIVA">MDVSA-2009:132</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1814" source="DEBIAN">DSA-1814</ref>
      <ref url="http://trapkit.de/advisories/TKADV2009-006.txt" source="MISC">http://trapkit.de/advisories/TKADV2009-006.txt</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200905-09.xml" source="GENTOO">GLSA-200905-09</ref>
      <ref url="http://secunia.com/advisories/35443" source="SECUNIA">35443</ref>
      <ref url="http://secunia.com/advisories/35247" source="SECUNIA">35247</ref>
      <ref url="http://secunia.com/advisories/35126" source="SECUNIA">35126</ref>
      <ref url="http://secunia.com/advisories/35076" source="SECUNIA" adv="1">35076</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mega-nerd" name="libsndfile">
        <vers num="1.0.15" />
        <vers num="1.0.16" />
        <vers num="1.0.17" />
        <vers num="1.0.18" />
        <vers num="1.0.19" />
      </prod>
      <prod vendor="nullsoft" name="winamp">
        <vers num="5.5" />
        <vers num="5.51" />
        <vers num="5.52" />
        <vers num="5.54" />
        <vers num="5.541" />
        <vers num="5.55" />
        <vers num="5.552" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1789" published="2009-05-26" name="CVE-2009-1789" modified="2009-07-10" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:P)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">mod/server.mod/servmsg.c in Eggheads Eggdrop and Windrop 1.6.19 and earlier allows remote attackers to cause a denial of service (crash) via a crafted PRIVMSG that causes an empty string to trigger a negative string length copy.  NOTE: this issue exists because of an incorrect fix for CVE-2007-2807.</descript>
    </desc>
    <loss_types>
      <avail />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.vupen.com/english/advisories/2009/1340" source="VUPEN" patch="1" adv="1">ADV-2009-1340</ref>
      <ref url="http://cvs.eggheads.org/viewvc/viewvc.cgi/eggdrop1.6/doc/Changes1.6?revision=1.20&amp;view=markup" source="CONFIRM" patch="1" adv="1">http://cvs.eggheads.org/viewvc/viewvc.cgi/eggdrop1.6/doc/Changes1.6?revision=1.20&amp;view=markup</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-May/msg01337.html" source="FEDORA">FEDORA-2009-5572</ref>
      <ref url="https://www.redhat.com/archives/fedora-package-announce/2009-May/msg01333.html" source="FEDORA">FEDORA-2009-5568</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/50547" source="XF">eggdrop-servmsg-dos(50547)</ref>
      <ref url="http://www.securityfocus.com/bid/34985" source="BID">34985</ref>
      <ref url="http://www.securityfocus.com/archive/1/503574" source="BUGTRAQ">20090515 eggdrop/windrop remote crash vulnerability</ref>
      <ref url="http://www.milw0rm.com/exploits/8695" source="MILW0RM">8695</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:126" source="MANDRIVA">MDVSA-2009:126</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1826" source="DEBIAN">DSA-1826</ref>
      <ref url="http://secunia.com/advisories/35690" source="SECUNIA">35690</ref>
      <ref url="http://secunia.com/advisories/35158" source="SECUNIA">35158</ref>
      <ref url="http://secunia.com/advisories/35104" source="SECUNIA" adv="1">35104</ref>
      <ref url="http://osvdb.org/54460" source="OSVDB">54460</ref>
      <ref url="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=528778" source="CONFIRM">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=528778</ref>
      <ref url="http://archives.neohapsis.com/archives/fulldisclosure/2009-05/0129.html" source="FULLDISC">20090514 eggdrop/windrop remote crash vulnerability</ref>
    </refs>
    <vuln_soft>
      <prod vendor="eggheads" name="eggdrop">
        <vers num="1.6.0" />
        <vers num="1.6.1" />
        <vers num="1.6.10" />
        <vers num="1.6.11" />
        <vers num="1.6.12" />
        <vers num="1.6.13" />
        <vers num="1.6.14" />
        <vers num="1.6.15" />
        <vers num="1.6.16" />
        <vers num="1.6.17" />
        <vers num="1.6.18" edition="rc1" />
        <vers num="1.6.2" />
        <vers num="1.6.3" />
        <vers num="1.6.4" />
        <vers num="1.6.5" />
        <vers num="1.6.6" />
        <vers num="1.6.7" />
        <vers num="1.6.8" />
        <vers num="1.6.9" />
      </prod>
      <prod vendor="eggheads" name="eggdrop_irc_bot">
        <vers prev="1" num="1.6.19" />
      </prod>
      <prod vendor="philip_moore" name="windrop">
        <vers num="1.4.4" edition="" />
        <vers num="1.4.4" edition=":final" />
        <vers num="1.4.6" />
        <vers num="1.5.4" edition="" />
        <vers num="1.5.4" edition=":final" />
        <vers num="1.5.4" edition="rc1" />
        <vers num="1.5.4" edition="rc2" />
        <vers num="1.5.4a" />
        <vers num="1.6.0" edition="" />
        <vers num="1.6.0" edition=":final" />
        <vers num="1.6.0" edition="rc1" />
        <vers num="1.6.0" edition="rc1-rel2" />
        <vers num="1.6.1" />
        <vers num="1.6.10" />
        <vers num="1.6.12" />
        <vers num="1.6.13" />
        <vers num="1.6.15" />
        <vers num="1.6.16" />
        <vers num="1.6.17" />
        <vers num="1.6.18" />
        <vers prev="1" num="1.6.19" />
        <vers num="1.6.19+ctcpfix" />
        <vers num="1.6.2+bindsfix" />
        <vers num="1.6.3" />
        <vers num="1.6.4" edition="sr1" />
        <vers num="1.6.6" />
        <vers num="1.6.7" />
        <vers num="1.6.8" />
        <vers num="1.6.9" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1790" published="2009-05-26" name="CVE-2009-1790" modified="2009-05-27" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in CGI RESCUE Trees before 2.11 allows remote attackers to inject arbitrary web script or HTML via unspecified parameters.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/34999" source="BID" patch="1">34999</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/50579" source="XF">rescuetrees-unspecified-xss(50579)</ref>
      <ref url="http://www.rescue.ne.jp/whatsnew/blog.cgi/permalink/20090512155247" source="CONFIRM" adv="1">http://www.rescue.ne.jp/whatsnew/blog.cgi/permalink/20090512155247</ref>
      <ref url="http://secunia.com/advisories/35123" source="SECUNIA" adv="1">35123</ref>
      <ref url="http://osvdb.org/54545" source="OSVDB">54545</ref>
      <ref url="http://jvndb.jvn.jp/en/contents/2009/JVNDB-2009-000028.html" source="JVNDB">JVNDB-2009-000028</ref>
      <ref url="http://jvn.jp/en/jp/JVN28521500/index.html" source="JVN">JVN#28521500</ref>
    </refs>
    <vuln_soft>
      <prod vendor="cgi_rescue" name="rescue">
        <vers prev="1" num="cgi_rescue_trees" edition="2.10" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1791" published="2009-05-26" name="CVE-2009-1791" modified="2009-06-23" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">Heap-based buffer overflow in aiff_read_header in libsndfile 1.0.15 through 1.0.19, as used in Winamp 5.552 and possibly other media programs, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via an AIFF file with an invalid header value.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/50541" source="XF" patch="1">libsndfile-aiff-voc-bo(50541)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1324" source="VUPEN" patch="1" adv="1">ADV-2009-1324</ref>
      <ref url="http://www.securityfocus.com/bid/34978" source="BID" patch="1">34978</ref>
      <ref url="http://www.mega-nerd.com/libsndfile/" source="CONFIRM" patch="1" adv="1">http://www.mega-nerd.com/libsndfile/</ref>
      <ref url="http://www.mega-nerd.com/erikd/Blog/CodeHacking/libsndfile/" source="CONFIRM" patch="1" adv="1">http://www.mega-nerd.com/erikd/Blog/CodeHacking/libsndfile/</ref>
      <ref url="http://www.mandriva.com/security/advisories?name=MDVSA-2009:132" source="MANDRIVA">MDVSA-2009:132</ref>
      <ref url="http://www.debian.org/security/2009/dsa-1814" source="DEBIAN">DSA-1814</ref>
      <ref url="http://security.gentoo.org/glsa/glsa-200905-09.xml" source="GENTOO">GLSA-200905-09</ref>
      <ref url="http://secunia.com/advisories/35443" source="SECUNIA">35443</ref>
      <ref url="http://secunia.com/advisories/35247" source="SECUNIA">35247</ref>
      <ref url="http://secunia.com/advisories/35076" source="SECUNIA" adv="1">35076</ref>
    </refs>
    <vuln_soft>
      <prod vendor="mega-nerd" name="libsndfile">
        <vers num="1.0.15" />
        <vers num="1.0.16" />
        <vers num="1.0.17" />
        <vers num="1.0.18" />
        <vers num="1.0.19" />
      </prod>
      <prod vendor="nullsoft" name="winamp">
        <vers num="5.5" />
        <vers num="5.51" />
        <vers num="5.52" />
        <vers num="5.54" />
        <vers num="5.541" />
        <vers num="5.55" />
        <vers num="5.552" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1792" published="2009-05-29" name="CVE-2009-1792" modified="2009-06-10" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_score="9.3" CVSS_impact_subscore="10.0" CVSS_exploit_subscore="8.6" CVSS_base_score="9.3">
    <desc>
      <descript source="cve">The system.openURL function in StoneTrip Ston3D StandalonePlayer (aka S3DPlayer StandAlone) 1.6.2.4 and 1.7.0.1 and WebPlayer (aka S3DPlayer Web) 1.6.0.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the first argument (the sURL argument).</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/35105" source="BID">35105</ref>
      <ref url="http://www.securityfocus.com/archive/1/archive/1/503887/100/0/threaded" source="BUGTRAQ">20090528 CORE-2009-0401 - StoneTrip S3DPlayers remote command injection</ref>
      <ref url="http://www.coresecurity.com/content/StoneTrip-S3DPlayers" source="MISC">http://www.coresecurity.com/content/StoneTrip-S3DPlayers</ref>
      <ref url="http://secunia.com/advisories/35256" source="SECUNIA">35256</ref>
    </refs>
    <vuln_soft>
      <prod vendor="stonetrip" name="s3dplayer_standalone">
        <vers num="1.6.2.4" />
        <vers num="1.7.0.1" />
      </prod>
      <prod vendor="stonetrip" name="s3dplayer_web">
        <vers num="1.6.0.0" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1796" published="2009-05-26" name="CVE-2009-1796" modified="2009-06-04" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Cross-site scripting (XSS) vulnerability in Sun Java System Portal Server 6.3.1, 7.1, and 7.2 allows remote attackers to inject arbitrary web script or HTML via vectors related to an error page.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/35082" source="BID" patch="1">35082</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-66-256588-1" source="SUNALERT" patch="1" adv="1">256588</ref>
      <ref url="http://sunsolve.sun.com/search/document.do?assetkey=1-21-118950-38-1" source="CONFIRM" patch="1" adv="1">http://sunsolve.sun.com/search/document.do?assetkey=1-21-118950-38-1</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/50704" source="XF">javasystem-portalserver-xss(50704)</ref>
      <ref url="http://www.vupen.com/english/advisories/2009/1411" source="VUPEN">ADV-2009-1411</ref>
      <ref url="http://www.securitytracker.com/id?1022273" source="SECTRACK">1022273</ref>
      <ref url="http://secunia.com/advisories/35221" source="SECUNIA">35221</ref>
      <ref url="http://osvdb.org/54705" source="OSVDB">54705</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sun" name="java_system_portal_server">
        <vers num="6.3.1" edition="" />
        <vers num="6.3.1" edition=":x86" />
        <vers num="6.3.1" edition=":linux" />
        <vers num="6.3.1" edition=":sparc" />
        <vers num="7.1" edition="" />
        <vers num="7.1" edition=":sparc" />
        <vers num="7.1" edition=":x86" />
        <vers num="7.1" edition=":linux" />
        <vers num="7.2" edition="" />
        <vers num="7.2" edition=":x86" />
        <vers num="7.2" edition=":sparc" />
        <vers num="7.2" edition=":linux" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1797" published="2009-12-28" name="CVE-2009-1797" modified="2010-06-29" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple cross-site request forgery (CSRF) vulnerabilities on the Network Management Card (NMC) on American Power Conversion (APC) Switched Rack PDU (aka Rack Mount Power Distribution) devices and other devices allow remote attackers to hijack the authentication of (1) administrator or (2) device users for requests that create new administrative users or have unspecified other impact.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/166739" source="CERT-VN">VU#166739</ref>
      <ref url="http://secunia.com/advisories/37744" source="SECUNIA" adv="1">37744</ref>
      <ref url="http://nam-en.apc.com/cgi-bin/nam_en.cfg/php/enduser/std_adp.php?p_faqid=10887" source="CONFIRM" adv="1">http://nam-en.apc.com/cgi-bin/nam_en.cfg/php/enduser/std_adp.php?p_faqid=10887</ref>
      <ref url="http://holisticinfosec.org/content/view/111/45/" source="MISC">http://holisticinfosec.org/content/view/111/45/</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apc" name="network_management_card">
        <vers num="" />
      </prod>
      <prod vendor="apc" name="switched_rack_pdu">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1798" published="2009-12-28" name="CVE-2009-1798" modified="2010-06-29" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities on the Network Management Card (NMC) on American Power Conversion (APC) Switched Rack PDU (aka Rack Mount Power Distribution) devices and other devices allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.  NOTE: the login_username vector for Forms/login1 is already covered by CVE-2009-4406.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.kb.cert.org/vuls/id/166739" source="CERT-VN">VU#166739</ref>
      <ref url="http://secunia.com/advisories/37744" source="SECUNIA" adv="1">37744</ref>
      <ref url="http://nam-en.apc.com/cgi-bin/nam_en.cfg/php/enduser/std_adp.php?p_faqid=10887" source="CONFIRM" adv="1">http://nam-en.apc.com/cgi-bin/nam_en.cfg/php/enduser/std_adp.php?p_faqid=10887</ref>
      <ref url="http://holisticinfosec.org/content/view/111/45/" source="MISC">http://holisticinfosec.org/content/view/111/45/</ref>
    </refs>
    <vuln_soft>
      <prod vendor="apc" name="network_management_card">
        <vers num="" />
      </prod>
      <prod vendor="apc" name="switched_rack_pdu">
        <vers num="" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1799" published="2009-05-28" name="CVE-2009-1799" modified="2009-05-28" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in the getGalleryImage function in st_admin/gallery_output.php in ST-Gallery 0.1 alpha, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) gallery_category or (2) gallery_show parameter to example.php.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/50378" source="XF">stgallery-example-sql-injection(50378)</ref>
      <ref url="http://www.securityfocus.com/bid/34875" source="BID">34875</ref>
      <ref url="http://www.milw0rm.com/exploits/8636" source="MILW0RM">8636</ref>
      <ref url="http://marc.info/?l=bugtraq&amp;m=124171333011782&amp;w=2" source="BUGTRAQ">20090507 SQL INJECTION VULNERABILITIES--ST-Gallery version 0.1 alpha</ref>
    </refs>
    <vuln_soft>
      <prod vendor="sebastian-thiele" name="st-gallery">
        <vers num="0.1_alpha" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1800" published="2009-05-28" name="CVE-2009-1800" modified="2009-05-28" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Stack-based buffer overflow in the Chinagames CGAgent ActiveX control 1.x in CGAgent.dll, as distributed in Chinagames iGame 2009, allows remote attackers to execute arbitrary code via a long argument to the CreateChinagames method, as exploited in the wild in April and May 2009.  NOTE: some of these details are obtained from third party information.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
      <sec_prot other="1" />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/34871" source="BID">34871</ref>
      <ref url="http://www.cisrt.org/enblog/read.php?245" source="MISC">http://www.cisrt.org/enblog/read.php?245</ref>
      <ref url="http://secunia.com/advisories/35005" source="SECUNIA" adv="1">35005</ref>
      <ref url="http://hi.baidu.com/wi4r/blog/item/8b1c06fb2e3de8819f514671.html" source="MISC">http://hi.baidu.com/wi4r/blog/item/8b1c06fb2e3de8819f514671.html</ref>
      <ref url="http://downloads.securityfocus.com/vulnerabilities/exploits/34871.html" source="MISC">http://downloads.securityfocus.com/vulnerabilities/exploits/34871.html</ref>
      <ref url="http://bbs.pediy.com/showthread.php?t=87615" source="MISC">http://bbs.pediy.com/showthread.php?t=87615</ref>
    </refs>
    <vuln_soft>
      <prod vendor="chinagames" name="igame">
        <vers num="2009" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1801" published="2009-05-28" name="CVE-2009-1801" modified="2009-05-28" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_score="4.3" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="8.6" CVSS_base_score="4.3">
    <desc>
      <descript source="cve">Multiple cross-site scripting (XSS) vulnerabilities in FreePBX 2.5.1, and other 2.4.x, 2.5.x, and pre-release 2.6.x versions, allow remote attackers to inject arbitrary web script or HTML via the (1) display parameter to reports.php, the (2) order and (3) extdisplay parameters to config.php, and the (4) sort parameter to recordings/index.php. NOTE: some of these details are obtained from third party information.</descript>
    </desc>
    <loss_types>
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/34857" source="BID" patch="1">34857</ref>
      <ref url="http://xforce.iss.net/xforce/xfdb/50361" source="XF">freepbx-reports-xss(50361)</ref>
      <ref url="http://secunia.com/advisories/34772" source="SECUNIA" adv="1">34772</ref>
      <ref url="http://osvdb.org/54261" source="OSVDB">54261</ref>
      <ref url="http://osvdb.org/54260" source="OSVDB">54260</ref>
      <ref url="http://osvdb.org/54259" source="OSVDB">54259</ref>
      <ref url="http://freepbx.org/trac/ticket/3660" source="CONFIRM">http://freepbx.org/trac/ticket/3660</ref>
    </refs>
    <vuln_soft>
      <prod vendor="freepbx" name="freepbx">
        <vers num="2.4" />
        <vers num="2.4.0" />
        <vers num="2.4.0_beta1" />
        <vers num="2.4.0_beta2" />
        <vers num="2.4.1" />
        <vers num="2.5.0" />
        <vers num="2.5.0_beta1" />
        <vers num="2.5.0rc2" />
        <vers num="2.5.0rc3" />
        <vers num="2.5.1" />
        <vers num="2.5.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1802" published="2009-05-28" name="CVE-2009-1802" modified="2009-05-28" CVSS_version="2.0" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_score="6.8" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="8.6" CVSS_base_score="6.8">
    <desc>
      <descript source="cve">Multiple cross-site request forgery (CSRF) vulnerabilities in FreePBX 2.5.1, and other 2.4.x, 2.5.x, and pre-release 2.6.x versions, allow remote attackers to hijack the authentication of admins for requests that create a new admin account or have unspecified other impact.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
      <user_init />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/34857" source="BID" patch="1">34857</ref>
      <ref url="http://secunia.com/advisories/34772" source="SECUNIA" adv="1">34772</ref>
      <ref url="http://osvdb.org/54262" source="OSVDB">54262</ref>
      <ref url="http://freepbx.org/trac/ticket/3660" source="CONFIRM">http://freepbx.org/trac/ticket/3660</ref>
    </refs>
    <vuln_soft>
      <prod vendor="freepbx" name="freepbx">
        <vers num="2.4" />
        <vers num="2.4.0" />
        <vers num="2.4.0_beta1" />
        <vers num="2.4.0_beta2" />
        <vers num="2.4.1" />
        <vers num="2.5" />
        <vers num="2.5.0" />
        <vers num="2.5.0_beta1" />
        <vers num="2.5.0rc2" />
        <vers num="2.5.0rc3" />
        <vers num="2.5.1" />
        <vers num="2.5.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1803" published="2009-05-28" name="CVE-2009-1803" modified="2009-05-29" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_score="5.0" CVSS_impact_subscore="2.9" CVSS_exploit_subscore="10.0" CVSS_base_score="5.0">
    <desc>
      <descript source="cve">FreePBX 2.5.1, and other 2.4.x, 2.5.x, and pre-release 2.6.x versions, generates different error messages for a failed login attempt depending on whether the user account exists, which allows remote attackers to enumerate valid usernames.</descript>
    </desc>
    <loss_types>
      <conf />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://www.securityfocus.com/bid/34857" source="BID" patch="1">34857</ref>
      <ref url="http://www.osvdb.org/54263" source="OSVDB">54263</ref>
      <ref url="http://secunia.com/advisories/34772" source="SECUNIA" adv="1">34772</ref>
      <ref url="http://freepbx.org/trac/ticket/3660" source="CONFIRM">http://freepbx.org/trac/ticket/3660</ref>
    </refs>
    <vuln_soft>
      <prod vendor="freepbx" name="freepbx">
        <vers num="2.4" />
        <vers num="2.4.0" />
        <vers num="2.4.0_beta1" />
        <vers num="2.4.0_beta2" />
        <vers num="2.4.1" />
        <vers num="2.5" />
        <vers num="2.5.0" />
        <vers num="2.5.0_beta1" />
        <vers num="2.5.0rc2" />
        <vers num="2.5.0rc3" />
        <vers num="2.5.1" />
        <vers num="2.5.2" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="High" seq="2009-1804" published="2009-05-28" name="CVE-2009-1804" modified="2009-06-01" CVSS_version="2.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_score="7.5" CVSS_impact_subscore="6.4" CVSS_exploit_subscore="10.0" CVSS_base_score="7.5">
    <desc>
      <descript source="cve">Multiple SQL injection vulnerabilities in admin/index.php in VideoScript.us YouTube Video Script allow remote attackers to execute arbitrary SQL commands via the (1) username and (2) password parameters.</descript>
    </desc>
    <loss_types>
      <avail />
      <conf />
      <int />
    </loss_types>
    <range>
      <network />
    </range>
    <refs>
      <ref url="http://xforce.iss.net/xforce/xfdb/50373" source="XF">videoscript-index-sql-injection(50373)</ref>
      <ref url="http://www.securityfocus.com/bid/34868" source="BID">34868</ref>
      <ref url="http://www.milw0rm.com/exploits/8635" source="MILW0RM">8635</ref>
    </refs>
    <vuln_soft>
      <prod vendor="videoscript" name="youtube_video_script">
        <vers num="-" />
      </prod>
    </vuln_soft>
  </entry>
  <entry type="CVE" severity="Medium" seq="2009-1805" published="2009-06-01" name="CVE-2009-1805" modified="2010-08-21" CVSS_version="2.0" CVSS_vector="(AV:L/AC:H/Au:N/C:N/I:N/A:C)" CVSS_score="4.0" CVSS_impact_subscore="6.9" CVSS_exploit_subscore="1.9" CVSS_base_score="4.0">
    <desc>
      <descript source="cve">Unspecified vulnerability in the VMware Descheduled Time Accounting driver in VMware Workstation 6.5.1
